Threat perception method and device of information system based on human body internal perception mechanism, electronic equipment and storage medium

By introducing micro-sensing probes and central control units into information systems, internal threats can be monitored and identified, solving the problem of existing technologies being unable to identify unknown vulnerability attacks. This enables rapid response and self-protection, improving the security and stability of the system.

CN120850280APending Publication Date: 2025-10-28ZHENGZHOU UNIV +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510932755.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-07
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

Existing security defense systems rely heavily on external interface defenses and cannot effectively identify attacks caused by unknown vulnerabilities. This results in information systems requiring lengthy recovery processes after being attacked, causing serious losses.

Method used

This paper proposes an information system threat perception method based on the internal perception mechanism of the human body. It uses micro-sensing probes to monitor the micro-sensing characteristics and target operations of the information system, and uses the micro-sensing center to perform anomaly detection and threat classification, thereby realizing internal perception of potential attack patterns and threat sources.

Benefits of technology

It enhances the information system's ability to perceive unknown threats, enables rapid response and self-protection, reduces losses caused by attacks, and improves the system's security and stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120850280A_ABST
    Figure CN120850280A_ABST
Patent Text Reader

Abstract

The invention discloses a threat perception method and device of an information system based on a human body internal perception mechanism, electronic equipment and a storage medium. The method comprises the steps that under the condition that an information system is started, n micro-sensing features and target operation in a micro-sensing feature library are monitored through a micro-sensing probe, a monitoring result is obtained, a micro-sensing center is arranged in the information system, and the micro-sensing center at least comprises the micro-sensing feature library, the target operation and the target operation, the target operation is an unauthorized operation oriented to the micro-sensing center; when the monitoring result indicates that no abnormal micro-sensing feature exists in the information system and the target operation is not monitored, determining that the information system is in a safe state; and under the condition that the monitoring result indicates that the abnormal micro-sensing feature exists in the information system and / or the target operation is monitored, sensing a threat category existing in the information system and a system state of the information system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cybersecurity technology, and more specifically, to a threat perception method, device, electronic device, and storage medium for an information system based on human internal perception mechanisms. Background Technology

[0002] Existing security defense systems primarily aim to detect and defend against attacks, relying on external interface-based defenses such as firewalls, antivirus software, and intrusion detection systems to achieve precise protection by identifying threat characteristics. This "shell-like" security defense system heavily depends on prior knowledge of attack behaviors and mechanisms obtained from external sources as the basis for effective defense. Once an information system is successfully attacked by an attacker using an unknown vulnerability, the "shell-like" security defense system becomes powerless. The information system can only resume its interrupted tasks after undergoing a lengthy process involving downtime recovery, cleanup, vulnerability patching, and backdoor blocking. In the current context of vigorously developing the digital economy and placing great emphasis on data security, the losses caused by the above situation are extremely serious, potentially causing significant financial and reputational damage to enterprises and even countries.

[0003] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention

[0004] This application provides a threat perception method, device, electronic device, and storage medium for information systems based on human internal perception mechanisms, in order to at least solve the technical problem in related technologies of lacking effective perception of potential attack patterns and threat sources of information systems.

[0005] According to one aspect of the embodiments of this application, a threat perception method for an information system based on the human body's internal sensing mechanism is provided, comprising: when the information system is started, monitoring n micro-sensing features and target operations in a micro-sensing feature library using a micro-sensing probe to obtain monitoring results, wherein the information system is equipped with a micro-sensing center, the micro-sensing center including at least: the micro-sensing feature library, the target operation being an unauthorized operation directed to the micro-sensing center, and n being a positive integer; when the monitoring results indicate that there are no abnormal micro-sensing features in the information system and no target operation is detected, determining that the information system is in a secure state; when the monitoring results indicate that the abnormal micro-sensing features exist in the information system and / or the target operation is detected, perceiving the threat category present in the information system and the system state of the information system.

[0006] Optionally, the micro-sensing center includes: a set of threat behaviors A = {a1, a2, ..., a...} m}, where ai (1≤i≤m) represents the category of the i-th threatening behavior, where m and i are positive integers; the micro-sensing feature library F = {f1,f2,...,f...} n}, wherein the micro-sensing feature is used to indicate the operating parameter information of the information system, f i (1≤i≤n) represents the i-th micro-sensing feature; the standard value set S = {s1, s2, ..., s} corresponding to the micro-sensing feature library is denoted as {s1, s2, ..., s}. n}, where s i (1≤i≤n) represents the i-th micro-sensing feature f i The corresponding standard values; the set of limit values ​​L = {l1, l2, ..., l} corresponding to the micro-sensing feature library. n}, where l i (1≤i≤n) represents the i-th micro-sensing feature f i The corresponding limit value; the set of micro-sensory features G = {g1, g2, ..., g m}, where g i (1≤i≤m) represents the i-th threatening action a. i Associated micro-sensory feature combinations,

[0007] Optionally, monitoring multiple micro-sensing features and target operations in the micro-sensing feature library using a micro-sensing probe to obtain monitoring results includes: using the micro-sensing probe to perform feature recognition on the operating parameter information of the information system based on the n micro-sensing features to obtain the operating parameter features corresponding to the operating parameter information; and verifying the operating parameter features according to the standard value set to determine whether the operating parameter features are abnormal micro-sensing features, thereby obtaining a first monitoring result, wherein the feature value of the abnormal micro-sensing feature is greater than the standard value corresponding to the operating parameter feature, and the monitoring result includes the first monitoring result.

[0008] Optionally, when the monitoring results indicate the presence of the abnormal micro-sensing feature in the information system and / or the detection of the target operation, the system senses the threat category and system state of the information system, including: matching the abnormal micro-sensing feature with the micro-sensing feature set to determine whether the abnormal micro-sensing feature matches a target threat behavior; and verifying the abnormal micro-sensing feature with the limit value set to determine whether there are any micro-sensing features that do not exceed the corresponding limit value; if no target threat behavior is matched, or if the target threat behavior is matched and there are micro-sensing features that do not exceed the corresponding limit value, the information system is determined to be in a state of alert; if the target threat behavior is matched and multiple micro-sensing features in the abnormal micro-sensing feature set exceed the corresponding limit value, the information system is determined to be in a state of danger.

[0009] Optionally, after sensing the threat categories and system status of the information system, the method further includes: when it is determined that the information system is in the alert state, monitoring the target task currently in execution in the information system; when the target task is detected to be completed, instructing the defense system to perform system repair on the information system; when it is determined that the information system is in the dangerous state, instructing the defense system to terminate the target task and take the first defense measure corresponding to the target threat behavior.

[0010] Optionally, monitoring multiple micro-sensing features and target operations in the micro-sensing feature library using a micro-sensing probe to obtain monitoring results includes: monitoring the target operation using the micro-sensing probe to obtain a second monitoring result, wherein the target operation is directed to at least one of the following: the micro-sensing feature library, the threat behavior set, the micro-sensing feature group, and the target operation is categorized as at least one of the following: addition, deletion, modification, and the monitoring result includes the second monitoring result.

[0011] Optionally, after sensing the threat categories and system status of the information system, the method further includes: determining that the information system is in a dangerous state when the second monitoring result indicates that the target operation has been detected; instructing the defense system to terminate the target task in the execution state in the information system and execute the second defense measure corresponding to the target operation.

[0012] According to another aspect of the embodiments of this application, a threat perception device for an information system based on the human body's internal perception mechanism is also provided, comprising: a monitoring module, configured to monitor n micro-perception features and target operations in a micro-perception feature library through a micro-perception probe when the information system is started, and obtain monitoring results, wherein the information system is provided with a micro-perception center, the micro-perception center including at least: the micro-perception feature library, the target operation being an unauthorized operation directed towards the micro-perception center, and n being a positive integer; a determination module, configured to determine that the information system is in a secure state when the monitoring results indicate that there are no abnormal micro-perception features in the information system and the target operation is not detected; and a perception module, configured to perceive the threat category and system state of the information system when the monitoring results indicate that the abnormal micro-perception features exist in the information system and / or the target operation is detected.

[0013] According to another aspect of the embodiments of this application, an electronic device is also provided, including: a memory and a processor, the processor being configured to run a program stored in the memory, wherein the program executes a threat perception method of an information system based on human internal perception mechanisms during runtime.

[0014] According to another aspect of the embodiments of this application, a non-volatile storage medium is also provided, the non-volatile storage medium including a stored computer program, wherein the device where the non-volatile storage medium is located executes a threat perception method of an information system based on human body perception mechanisms by running the computer program.

[0015] According to another aspect of the embodiments of this application, a computer program product is also provided, including a computer program that, when executed by a processor, implements the steps in any of the above method embodiments.

[0016] In this embodiment, drawing on the mechanism of the human nervous system in monitoring and maintaining stability by perceiving internal environmental information, a threat perception method for information systems based on the human body's internal perception mechanism is proposed. After the information system is started, a micro-perception probe monitors n micro-perception features and target operations in a micro-perception feature library to obtain monitoring results. The information system has a micro-perception center containing the micro-perception feature library, and the target operation is an unauthorized operation directed towards the micro-perception center, where m is a positive integer. If the monitoring result indicates that there are no abnormal micro-perception features in the information system and the target operation is not detected, the information system is determined to be in a secure state. If the detection result indicates that there are abnormal micro-perception features in the information system and / or the target operation is detected, the threat category and system state of the information system are perceived. This approach, using the overall idea of ​​abstracting low-level features to map high-level behaviors, aims to solve the complex and diverse threat perception needs of information systems with low usage costs, ultimately achieving effective perception of threat behaviors from within the information system. This solves the problem in related technologies of lacking effective perception of potential attack patterns and threat sources in information systems. Attached Figure Description

[0017] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0018] Figure 1 This is a hardware structure block diagram of a computer terminal (or electronic device) for implementing a threat perception method for an information system based on human internal perception mechanisms, according to an embodiment of this application.

[0019] Figure 2 This is a schematic diagram of a threat perception method for an information system based on the human body's internal perception mechanism, according to an embodiment of this application.

[0020] Figure 3 This is a flowchart illustrating an endogenous micro-sensing method for an information system based on the human body's internal sensing mechanism, according to an embodiment of this application.

[0021] Figure 4 This is a schematic diagram of a system architecture for a micro-sensing center and a micro-sensing probe according to an embodiment of this application;

[0022] Figure 5 This is a schematic diagram of the sensing process of a micro-sensing method provided according to an embodiment of this application;

[0023] Figure 6This is a line graph showing the number of times CreateFile is called per second by a single process, as monitored by a micro-sensing probe during T1 to T12, according to an embodiment of this application.

[0024] Figure 7 This is a line graph showing the number of times a single process calls WriteFile per second, as monitored by a micro-sensing probe during T1 to T12, according to an embodiment of this application.

[0025] Figure 8 This is a line graph showing the number of times QueryDirectory has been called by a single process detected by a micro-sensing probe during T1 to T12, according to an embodiment of this application.

[0026] Figure 9 This is a line graph showing the number of new SYN_RECEIVED connections per second monitored by a micro-sensing probe during T1 to T12, according to an embodiment of this application.

[0027] Figure 10 This is a line graph showing the total number of TCP and TCP-based data packets sent per second as monitored by a micro-sensing probe during T1 to T12, according to an embodiment of this application.

[0028] Figure 11 This is a line graph showing the bandwidth received per second monitored by a micro-sensing probe during T1 to T12, according to an embodiment of this application.

[0029] Figure 12 This is a line graph of CPU utilization monitored by a micro-sensing probe in T1 to T12 according to an embodiment of this application;

[0030] Figure 13 This is a line graph of memory usage monitored by a micro-sensing probe during T1 to T12, provided according to an embodiment of this application.

[0031] Figure 14 This is a line graph showing the number of overwritten files in the first 10 files written by a single process, as monitored by a micro-sensing probe during T1 to T12, according to an embodiment of this application.

[0032] Figure 15 This is a schematic diagram of the structure of a threat sensing device for an information system based on the human body's internal sensing mechanism, according to an embodiment of this application. Detailed Implementation

[0033] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0034] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0035] According to an embodiment of this application, a method embodiment for adjusting dependencies is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0036] The methods and embodiments provided in this application can be executed on mobile terminals, computer terminals, or similar computing devices. Figure 1 A hardware block diagram of a computer terminal (or electronic device) for implementing a threat perception method in an information system based on human internal perception mechanisms is shown. Figure 1 As shown, the computer terminal 10 (or electronic device 10) may include one or more processors 102 (shown as 102a, 102b, ..., 102n in the figure) 102 (processor 102 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 1The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 10 may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.

[0037] It should be noted that the aforementioned one or more processors 102 and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be wholly or partially embodied in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be wholly or partially integrated into any other element within the computer terminal 10 (or electronic device). As involved in the embodiments of this application, the data processing circuits function as processor control.

[0038] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the threat perception method of the information system based on the human body's internal perception mechanism in this embodiment of the application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby realizing the aforementioned threat perception method of the information system based on the human body's internal perception mechanism. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0039] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0040] The display may be, for example, a touchscreen liquid crystal display (LCD) that allows the user to interact with the user interface of the computer terminal 10 (or electronic device).

[0041] In recent years, a series of policy documents targeting cybersecurity and resilience have been released internationally, promoting in-depth development of information system security research and practice. In 2023, the United States released a new National Cybersecurity Strategy, which prioritized cyber resilience as a core component, aiming to ensure that critical technologies and information systems can recover rapidly in the face of cyberattacks. The strategy introduced the concepts of "design security" and "default security," emphasizing the embedding of security measures into the fundamental parts of architecture and design, thereby shifting cybersecurity responsibility from the application service level to the manufacturing level. Furthermore, the European Union's Digital Operations Resilience Act (DORA) of 2022 requires financial institutions to enhance the security of their digital infrastructure, establish emergency recovery capabilities, and strengthen cooperation with third-party service providers to enhance the digital operational resilience of the financial industry. Further, the EU's Cyber ​​Resilience Act, formally introduced in 2024, explicitly requires the embedding of robust cyber resilience measures in the design, development, and lifecycle management of digital products and services to ensure their continued stable operation in the face of cyberattacks. From these international trends, it is clear that the research focus of information system protection is gradually shifting from traditional "shell-like" defense systems to intrinsically resilient defense systems.

[0042] The four core objectives of network resilience are perception, recovery, adaptation, and continuity, with perception being the foundation. All defensive measures and response strategies against network threats must be built upon accurate threat perception. Only by promptly identifying potential attack patterns and threat sources can a basis be provided for subsequent protective measures. Whether adjusting firewall policies, updating intrusion detection rules, or implementing response measures such as traffic restrictions, all depend on effective threat perception.

[0043] Detecting security threats from within an information system offers significant advantages. By collecting and analyzing system-level information, resource consumption, and process behavior—lower-level characteristics—from within the information system, subtle changes caused by threats can be effectively detected. Furthermore, internal threat detection boasts a faster response time, providing rapid and precise support for the defense, recovery, and adaptation of the information system, greatly enhancing the overall security and reliability of the security defense system.

[0044] Therefore, in order to realize an endogenous defense system with strong defensive capabilities, it is essential to design a threat perception method based on the internal structure of the information system.

[0045] This application provides a threat perception method for information systems based on human internal perception mechanisms. Figure 2This is a schematic diagram of a threat perception method for an information system based on the human body's internal perception mechanism, according to an embodiment of this application. Figure 2 As shown, the method includes the following steps:

[0046] Step S202: When the information system is started, the micro-sensing probe monitors n micro-sensing features and target operations in the micro-sensing feature library to obtain monitoring results. The information system is equipped with a micro-sensing center, which includes at least the micro-sensing feature library and the target operation is an unauthorized operation directed to the micro-sensing center. n is a positive integer.

[0047] It should be noted that micro-sensing probes correspond to the interreceptors distributed throughout the human body's sensory system, and are used to monitor the micro-sensing characteristics within the entire information system. Micro-sensing characteristics refer to the underlying features such as system-level information and outputs generated during system operation, resource consumption indicators, and parameters generated during processes that serve to prove their correctness.

[0048] Optionally, the micro-sensing center includes: a set of threat behaviors A = {a1, a2, ..., a...} m}, where a i (1≤i≤m) represents the category of the i-th threatening behavior, where m and i are positive integers; the micro-sensing feature library F = {f1,f2,...,f...} n}, wherein the micro-sensing feature is used to indicate the operating parameter information of the information system, f i (1≤i≤n) represents the i-th micro-sensing feature; the standard value set S = {s1, s2, ..., s} corresponding to the micro-sensing feature library is denoted as {s1, s2, ..., s}. n}, where s i (1≤i≤n) represents the i-th micro-sensing feature f i The corresponding standard values; the set of limit values ​​L = {l1, l2, ..., l} corresponding to the micro-sensing feature library. n}, where l i (1≤i≤n) represents the i-th micro-sensing feature f i The corresponding limit value; the set of micro-sensory features G = {g1, g2, ... g} m}, where g i (1≤i≤m) represents the i-th threatening action a. i Associated micro-sensory feature combinations,

[0049] The micro-sensing center stores a micro-sensing feature library, a set of threat behaviors, and a set of micro-sensing feature groups used to map each threat behavior. The micro-sensing feature library contains the set of micro-sensing features, as well as the set of standard values ​​and limit values ​​corresponding to each micro-sensing feature. The micro-sensing center corresponds to the central nervous system in the human body's sensory system, used to integrate and analyze the micro-sensing features monitored by micro-sensing probes to determine whether a security threat exists in the information system and to provide basic support for subsequent defense and response.

[0050] Specifically, this can be represented by a 6-tuple M(A,F,S,L,G,C):

[0051] A: The set of threat behaviors stored in the micro-sensing center, in the form A = {a1, a2, ..., a...} m}. Where, a i (1≤i≤m) represents the category of the i-th threat behavior, such as malware infection, DDoS attack, internal data breach, etc. m represents the total number of threat behavior categories stored in the micro-sensing center. This set is predefined and populated by system designers according to the different types of attacks that information systems may suffer, to ensure that the micro-sensing center can cover the main threat scenarios faced by information systems.

[0052] f: Micro-sensory features refer to the underlying features such as system-level information and output generated during system operation, system resource consumption indicators, and parameters generated during the process that have the function of proving their own correctness.

[0053] F: The set of all micro-sensing features stored in the micro-sensing feature library, in the form F = {f1, f2, ..., f...} n}. Where n represents the total number of categories of micro-sensing features stored in the micro-sensing feature library, f i (1≤i≤n) represents the i-th micro-sensing feature stored in the micro-sensing feature library. These micro-sensing features cover key aspects of system operation, such as hardware operating status, disk I / O activity, API call frequency, resource consumption level, network connectivity, and traffic metrics.

[0054] S: The set of standard values ​​for each micro-sensing feature stored in the micro-sensing feature library, in the form S = {s1, s2, ..., s...} n}. Among them, s i (1≤i≤n) represents the i-th micro-sensing feature f i The corresponding standard values. The set of standard values ​​contains the baseline values ​​that each micro-sensing feature should maintain under normal operating conditions. These standard values ​​reflect the operating parameters of the information system in a healthy state and help the micro-sensing center identify abnormal behavior.

[0055] L: The set of limit values ​​for each micro-sensing feature stored in the micro-sensing feature library, in the form L={l1,l2,...,l n}. Among them, l i (1≤i≤n) represents the i-th micro-sensing feature f i The corresponding limit values. The set of limit values ​​defines the critical values ​​of the system's operating parameters. These limit values ​​are used to determine under what circumstances the system's operating characteristics are considered to have exceeded the normal range, reaching an emergency state requiring immediate response.

[0056] G: The set of micro-sensory feature groups stored in the micro-sensory center for mapping various threat behaviors, in the form of G = {g1, g2, ... g}. m}. Among them, g i (1≤i≤m) represents the i-th threatening behavior a i The associated micro-sensory feature combinations are in the following form: Where k represents the i-th threatening behavior a i The total number of micro-sensory features in the associated micro-sensory feature combination. ij (1≤j≤k) represents the i-th threatening action a i The j-th micro-sensory feature in the associated micro-sensory feature combination. ij ∈g i Satisfy f ij =f p (1≤p≤n), f p ∈F. These feature combinations are associated with elements in the threat behavior set A through a mapping mechanism, enabling the micro-sensing center to quickly identify specific threat types based on the detected feature sets.

[0057] For example, ransomware may be associated with frequent file creation (f1), file writing (f2), directory queries (f3), and file overwriting (f9), so its corresponding characteristic set could be defined as g1 = {f1, f2, f3, f9}. A SYN Flood attack, on the other hand, may involve a large number of new TCP connections (f4), high bandwidth reception (f6), and CPU load (f7), so its characteristic set could be defined as g2 = {f4, f6, f7}.

[0058] C: The micro-sensing center stores a set of threat behaviors (A), a set of micro-sensing features (F), a set of standard values ​​for each micro-sensing feature (S), a set of limit values ​​for each micro-sensing feature (L), and a set of micro-sensing feature groups used to map each threat behavior (G). Its function is to integrate and analyze abnormal micro-sensing features detected by the micro-sensing probes based on the stored information, thereby achieving threat perception in the information system. Micro-sensing probes are also deployed within the micro-sensing center.

[0059] The micro-sensing center C is the brain of the entire endogenous micro-sensing method. It stores the threat behavior set A, the micro-sensing feature set F, the standard value set S, the limit value set L, and the micro-sensing feature group set G. The main responsibility of the micro-sensing center is to quickly analyze the data received from the micro-sensing probes, determine the current state of the system (safe, alert, or dangerous), and issue instructions to the defense system based on the system state, selecting appropriate defense strategies. Through its internal algorithms and logic, the micro-sensing center can effectively analyze the information transmitted by the micro-sensing probes, identify whether the micro-sensing features are abnormal, and whether such abnormalities map to specific threat behaviors, thereby achieving accurate perception and timely response to threats to the information system.

[0060] The micro-sensing center not only processes data from probes within the information system but also continuously monitors its own status to ensure it is protected from unauthorized operations. This step further enhances the security and reliability of the entire system, ensuring that the micro-sensing center can maintain its functionality even in extreme situations, providing accurate threat perception information to the defense system.

[0061] Through the above design, the intrinsic micro-sensing method for information systems based on the internal sensing mechanisms of the human body can achieve comprehensive protection of information systems. It can not only monitor and identify common external threats, but also capture covert attacks that are difficult to detect using traditional protection methods through the micro-sensing characteristics within the system. This provides strong support for building an intrinsically resilient network defense system. This method not only improves the ability of information systems to counter threats, but also promotes the transformation of defense systems from passive response to proactive sensing and prevention, representing a significant advancement in information security technology.

[0062] Optionally, monitoring multiple micro-sensing features and target operations in the micro-sensing feature library using a micro-sensing probe to obtain monitoring results includes: using the micro-sensing probe to identify the operating parameter information of the information system based on the n micro-sensing features to obtain the operating parameter features corresponding to the operating parameter information; and verifying the operating parameter features according to the standard value set to determine whether the operating parameter features are abnormal micro-sensing features, thereby obtaining a first monitoring result, wherein the feature value of the abnormal micro-sensing feature is greater than the standard value corresponding to the operating parameter feature, and the monitoring result includes the first monitoring result.

[0063] First, the micro-sensing probe focuses on n micro-sensing features in the micro-sensing feature library. These features cover the operational parameters of the information system, including but not limited to CPU utilization, memory usage, disk I / O activity, network traffic, and system call frequency. The micro-sensing probe continuously tracks and records the real-time dynamics of these parameters through deep integration within the information system. During monitoring, the micro-sensing probe can identify and extract operational parameter features directly related to the information system's operating status. For example, if the monitored object is a running application, the micro-sensing probe might record information such as the application's CPU usage, peak memory usage, and file access request frequency—all manifestations of operational parameter features.

[0064] The micro-sensing probe extracts operational parameter features and compares them in real time with corresponding standard values ​​stored in the standard value set S. The standard value set S stores the expected value of each micro-sensing feature under normal operating conditions, which is equivalent to the baseline parameters of a healthy human body.

[0065] By comparison, if the value of an operational parameter feature is greater than the corresponding standard value, then that feature is identified as an abnormal micro-sensing feature. A preset threshold is a pre-defined safety boundary used to determine whether the deviation of the feature value is sufficient to constitute a warning signal. Once an abnormal micro-sensing feature is identified, the micro-sensing probe incorporates it into the first monitoring result, which is an immediate assessment of the current operational status of the information system.

[0066] The initial monitoring results not only identify whether the current operating parameters are abnormal, but also indirectly reflect potential threats or malfunctions in the information system. For example, an abnormally high CPU utilization may mean that the system is under a DDoS attack, or that malware is performing high-load operations internally.

[0067] The initial monitoring results detected by the micro-sensing probes are then transmitted to the micro-sensing center, which performs further analysis and judgment based on these results. The micro-sensing center not only possesses information on the micro-sensing feature library, standard value set, limit value set, and micro-sensing feature group set associated with threat behaviors, but also has the ability to analyze and integrate this information in order to identify specific threat behavior categories.

[0068] Based on the first monitoring result received, the micro-sensing center performs pattern matching on abnormal micro-sensing features in conjunction with the micro-sensing feature set G to identify whether there are feature combinations corresponding to specific threat behaviors. If such combinations exist, and the feature values ​​within all combinations exceed the threshold values ​​in the limit value set L, the micro-sensing center will determine that the information system is in a dangerous state and immediately initiate corresponding defense strategies, such as isolating the affected system and executing backup and recovery procedures.

[0069] If no abnormal micro-sensing features are detected, or only a few features deviate slightly from standard values, the information system will be considered to be in a safe or alert state. In this case, the micro-sensing center will instruct the defense system to remain vigilant, but will still allow the information system to operate normally while continuously collecting data for subsequent analysis.

[0070] Through the above process, the micro-sensing probes and the micro-sensing center work together to form a closed-loop system of continuous monitoring, real-time analysis, and immediate response. This effectively improves the security and stability of information systems, laying a solid foundation for building an endogenous defense architecture with network resilience. This method not only addresses known threats but also possesses a certain degree of generalization capability, capable of identifying and responding to unforeseen attack patterns, demonstrating the powerful potential of endogenous defense mechanisms.

[0071] Optionally, monitoring multiple micro-sensing features and target operations in the micro-sensing feature library using a micro-sensing probe to obtain monitoring results includes: monitoring the target operation using the micro-sensing probe to obtain a second monitoring result, wherein the target operation is directed to at least one of the following: the micro-sensing feature library, the threat behavior set, the micro-sensing feature group, and the target operation is categorized as at least one of the following: addition, deletion, modification, and the monitoring result includes the second monitoring result.

[0072] The objects monitored by the micro-sensing probe include not only the routine operating parameters of the information system, but also operations that directly affect the internal information database of the micro-sensing center, including any changes to the micro-sensing feature database, threat behavior sets, and micro-sensing feature groups. These operations may include adding (adding new micro-sensing features, threat behaviors, or feature groups), deleting (removing existing entries), and modifying (changing stored information, such as standard values ​​or limit values).

[0073] When the micro-sensing probe detects any of the aforementioned operations targeting the internal information database of the micro-sensing center, it immediately records and analyzes these operations to determine whether they constitute a threat or interference to the system. For example, if an unauthorized user attempts to modify the standard values ​​of micro-sensing characteristics in an attempt to deceive the micro-sensing center's threat detection capabilities, this will be considered an anomaly in the second monitoring result.

[0074] The second monitoring result is the direct feedback from the micro-sensing probe to changes in the internal environment of the micro-sensing center. If unauthorized operations are detected, regardless of whether these operations directly affect the system's operating parameters, they will be considered potential threats because they may disrupt the system's self-defense mechanisms or introduce new risk points. For example, modifying the classification in the threat behavior set may affect the system's accuracy in identifying specific threats, thereby allowing the real threats to remain hidden.

[0075] Similar to the first monitoring result, the second monitoring result will also be transmitted to the micro-sensing center in real time. The micro-sensing center will determine whether the information system has been subjected to internal interference or attack based on the received results. Such interference or attack may be directly aimed at the micro-sensing center itself, attempting to weaken its functions or mislead its decision-making.

[0076] Once the micro-sensing center confirms unauthorized operations, regardless of whether these operations are related to the detection of abnormal micro-sensing features, it will immediately determine that the information system is in a dangerous state. At this time, the micro-sensing center will respond quickly, instructing the defense system to take emergency measures, such as locking relevant permissions, rolling back erroneous modifications, or completely isolating the micro-sensing center, until the threat is completely eliminated, in order to prevent the micro-sensing center from being used or destroyed by attackers.

[0077] This embodiment highlights the self-protective characteristics of the micro-sensing method. By placing micro-sensing probes within the micro-sensing hub, it ensures that its information database cannot be easily tampered with or interfered with. In this way, even when the information system suffers complex internal and external threats, the micro-sensing hub can maintain its integrity and accurately perform its core tasks—real-time threat detection, accurate system status assessment, and guiding the defense system to respond appropriately. This self-protective mechanism greatly enhances the robustness and reliability of the micro-sensing method in practical applications, making it an indispensable part of building a network-resilient intrinsic defense architecture.

[0078] In summary, by monitoring target operations, this embodiment not only enhances the information system's ability to perceive and respond to internal threats, but also further improves the flexibility and adaptability of the micro-perception method, enabling it to continue to play a role in the ever-changing network environment and safeguard the secure and stable operation of the information system.

[0079] Step S204: If the monitoring results indicate that there are no abnormal micro-sensing features in the information system and no target operation is detected, the information system is determined to be in a safe state.

[0080] Step S206: If the monitoring results indicate the presence of the abnormal micro-sensing features in the information system and / or the target operation is detected, the threat category and system status of the information system are perceived.

[0081] Optionally, when the monitoring results indicate the presence of the abnormal micro-sensing feature in the information system and / or the detection of the target operation, the system senses the threat category and system state of the information system, including: matching the abnormal micro-sensing feature with the micro-sensing feature set to determine whether the abnormal micro-sensing feature matches a target threat behavior; and verifying the abnormal micro-sensing feature with the limit value set to determine whether there are any micro-sensing features that do not exceed the corresponding limit value; if no target threat behavior is matched, or if the target threat behavior is matched and there are micro-sensing features that do not exceed the corresponding limit value, the information system is determined to be in a state of alert; if the target threat behavior is matched and multiple micro-sensing features in the abnormal micro-sensing feature set exceed the corresponding limit value, the information system is determined to be in a state of danger.

[0082] First, among the operational parameters detected by the micro-sensing probe, if a certain feature value exceeds its corresponding standard value, it is defined as an abnormal micro-sensing feature. This means that some aspect of the system's operation has deviated from the normal operating range, which may be caused by improper internal operation, resource abuse, or external attack.

[0083] Next, the micro-sensing center compares the detected abnormal micro-sensing features with the set G of micro-sensing feature groups to look for target threatening behaviors that match these abnormal features. This process is similar to symptom comparison in medical diagnosis, where observed abnormalities are matched with known disease patterns to determine specific health problems.

[0084] If no matching combination is found, it indicates that the current anomalous characteristics may not yet constitute a complete pattern of known threat behavior, but are still worthy of attention, and the system may be in a potentially unstable state.

[0085] If a matching combination is found, but the values ​​of some abnormal micro-sensing features within that combination have not yet reached the threshold in the limit set L, this also indicates that the system may have some kind of threat, but it has not yet reached the point where defensive measures should be triggered immediately. At this time, the system enters an alert state, requiring continuous monitoring and preparation to take action when necessary.

[0086] Alert Status: When monitoring results fail to fully match any target threat behavior, or although they match but some characteristics do not exceed the limit values, the micro-sensing center determines that the information system is in an alert status. In the alert status, although potential threats exist, the system's operation is still within a controllable range. The micro-sensing center will notify the defense system to prioritize the normal execution of the current task, while simultaneously strengthening monitoring. Further checks and repairs will be conducted after the current task is completed.

[0087] Dangerous State: If an abnormal micro-sensing feature perfectly matches a specific threat behavior, and the values ​​of all included micro-sensing features exceed the thresholds in the limit set, the micro-sensing center will immediately determine that the information system is in a dangerous state. In this situation, the system faces a serious threat and may have already suffered substantial damage or is about to suffer a significant risk. The micro-sensing center will instruct the defense system to take immediate action, such as terminating current tasks, isolating the affected area, or initiating emergency recovery procedures, to prevent further spread of the threat and reduce potential losses.

[0088] The micro-sensing center can flexibly adjust its defense strategy based on the combination of abnormal micro-sensing features and the determination of the system state. In an alert state, the defense system may tend to adopt more lenient measures to balance the needs of security and business continuity. However, in a dangerous state, the defense strategy will shift to more stringent and aggressive measures, sparing no expense to ensure the security and stability of the system.

[0089] In this way, the intrinsic micro-sensing method for information systems, based on the internal sensing mechanisms of the human body, enables refined management and response to threats to information systems. This not only improves defense efficiency but also reduces false alarms and unnecessary system outages, providing solid theoretical and technical support for building a resilient intrinsic defense architecture. In practical applications, this method can significantly enhance the adaptability of information systems to complex and ever-changing network environments and their ability to resist unknown threats, ensuring the long-term stability and secure operation of information systems.

[0090] Optionally, after sensing the threat categories and system status of the information system, the method further includes: when it is determined that the information system is in the alert state, monitoring the target task currently in execution in the information system; when the target task is detected to be completed, instructing the defense system to perform system repair on the information system; when it is determined that the information system is in the dangerous state, instructing the defense system to terminate the target task and take the first defense measure corresponding to the target threat behavior.

[0091] When an information system is in a state of alert, the monitoring center focuses on the target tasks currently being executed within the system. After determining that the information system is in a state of alert, the micro-sensing center will prioritize monitoring these tasks to ensure they are not affected or have their system status deteriorated by potential threats.

[0092] System repair upon task completion: In alert mode, the information system prioritizes ensuring the successful completion of ongoing tasks. Once the completion of an important task is detected, the micro-sensing center immediately instructs the defense system to perform comprehensive repair measures. These measures may include scanning the system to find and eliminate potential malware, updating system configurations to patch security vulnerabilities, cleaning up abnormal processes, or restarting relevant services, thereby eliminating potential threats and restoring the system to a secure state without affecting business continuity.

[0093] When an information system is in a dangerous state, all current tasks should be immediately terminated. A dangerous state indicates that the information system is facing a serious threat, and the micro-sensing center will take decisive action, instructing the defense system to stop all currently executing non-critical tasks. This step aims to prevent the threat from spreading further and reduce potential damage.

[0094] First-line defense: Based on the previously determined threat category, the micro-sensing center will issue instructions to the defense system to implement the first-line defense measures corresponding to that threat. These measures may include, but are not limited to, disconnecting suspicious network connections, isolating infected system components, activating advanced firewall rules, and initiating emergency backup and recovery processes to quickly contain the threat and protect the core functions and data security of the information system.

[0095] Through the above embodiments, we can see that the endogenous micro-sensing method for information systems based on the human body's internal sensing mechanism can not only perceive the security status of the system in real time, but also flexibly adjust defense strategies according to different states. This mechanism is similar to the human body automatically regulating its physiological functions to cope with disease attacks. It can quickly respond to and adapt to various security threats while ensuring the basic functions of the system, thereby providing information systems with multi-layered and intelligent security protection capabilities.

[0096] When an information system is in a state of alert, the micro-sensing center focuses on monitoring and remediation, reflecting the system's cautious approach and preventative measures in the face of uncertain threats. Conversely, in a dangerous situation, the system immediately takes aggressive defensive measures, including task termination and emergency response, to prevent the threat from spreading and mitigate damage. This ability to intelligently switch defense strategies based on threat level significantly enhances the network resilience and adaptability of information systems, making it a crucial component of modern network security defense systems.

[0097] The intrinsic micro-sensing method for information systems, based on the human body's internal sensing mechanisms, provides comprehensive and sophisticated security assurance for information systems through its unique state perception and response mechanisms. It can detect potential threats at an early stage and adopt different response strategies according to the severity of the threat, protecting both business continuity and stability while effectively resisting various security threats, demonstrating its powerful potential and application value in building network resilience.

[0098] Optionally, after sensing the threat categories and system status of the information system, the method further includes: determining that the information system is in a dangerous state when the second monitoring result indicates that the target operation has been detected; instructing the defense system to terminate the target task in the execution state in the information system and execute the second defense measure corresponding to the target operation.

[0099] When the micro-sensing probe detects any unauthorized operation against the micro-sensing feature library, threat behavior set, or micro-sensing feature group set, such as illegal addition, deletion, or modification, this will be considered a serious anomaly in the secondary monitoring results.

[0100] In this scenario, regardless of whether the current operating parameters are abnormal or not, and regardless of whether they map to specific threat behaviors, the micro-sensing center will immediately determine that the information system is in a dangerous state. This is because tampering with the micro-sensing center's internal database could be an indication that an attacker is attempting to interfere with or mislead the micro-sensing center, thereby weakening the system's defense capabilities.

[0101] Once a dangerous situation is identified, the micro-sensing center immediately instructs the defense system to terminate all ongoing tasks within the information system. This is to prevent any potential threats from further impacting the system or causing data loss, while also preventing attackers from potentially using these tasks to continue their destructive activities.

[0102] Unlike the first defense measure, which addresses abnormal operating parameters, the second defense measure is specifically designed to prevent unauthorized operations. These measures may include, but are not limited to, immediately blocking access to the micro-sensing center, initiating emergency logging to trace the source of the operation, executing system recovery procedures to restore the tampered database, and strengthening the auditing and control of external access to prevent similar incidents from recurring.

[0103] This embodiment highlights another important characteristic of the micro-sensing method—its emphasis on its own security. By monitoring the status of the micro-sensing center in real time and ensuring the integrity and reliability of its information database, it can effectively prevent insider threats and advanced persistent threats (APTs), which are often difficult to detect through conventional operational parameter monitoring. The unauthorized operation monitoring mechanism enhances the defense-in-depth capability of the entire defense system, enabling timely action to prevent the situation from escalating even if attackers attempt to evade monitoring by altering system configurations.

[0104] The following example illustrates the process of the threat perception method described above:

[0105] 1. Micro-sensing probe monitoring: The micro-sensing probe continuously monitors the operating parameters of the information system and simultaneously monitors various operations targeting the micro-sensing center.

[0106] 2. Abnormal Feature Identification: After identifying abnormal micro-sensory features, the feature set is matched to determine whether there are known threatening behaviors.

[0107] 3. Operation behavior monitoring: If an unauthorized target operation is detected, the system will be immediately determined to be in a dangerous state, regardless of whether the current operating parameters are abnormal.

[0108] 4. System Status Determination and Response: Based on the monitoring results, the micro-sensing center quickly determines the system status (safe, alert, or dangerous) and issues corresponding instructions according to the status.

[0109] 5. Execution of defensive measures: When the system is in a state of alert or danger, the defense system, according to the instructions of the micro-sensing center, either monitors normal operation tasks or immediately terminates the tasks in progress, and at the same time takes targeted defense and recovery measures to ensure the security and stability of the information system.

[0110] In summary, this embodiment further improves the intrinsic defense mechanism of information systems. Through monitoring and response, it ensures that the defense system can comprehensively cover all possible risk points from external threats to internal security vulnerabilities, enabling information systems to demonstrate stronger resilience and autonomous defense capabilities when facing complex and ever-changing security challenges.

[0111] By drawing upon the mechanism of the human nervous system in monitoring and maintaining stability through the perception of internal environmental information, a threat perception method for information systems based on the human body's internal perception mechanism is proposed. After the information system is started, micro-perception probes monitor n micro-perception features and target operations in the micro-perception feature library to obtain monitoring results. The information system has a micro-perception center containing the micro-perception feature library, and the target operation is an unauthorized operation directed at the micro-perception center, where n is a positive integer. If the monitoring result indicates that there are no abnormal micro-perception features in the information system and the target operation is not detected, the information system is determined to be in a safe state. If the detection result indicates that there are abnormal micro-perception features in the information system and / or the target operation is detected, the threat category and system state of the information system are perceived. This approach, using the overall idea of ​​abstracting low-level features to map high-level behaviors, aims to solve the complex and diverse threat perception needs of information systems with low usage costs, ultimately achieving effective perception of threat behaviors from within the information system. This solves the problem in related technologies of lacking effective perception of potential attack patterns and threat sources in information systems.

[0112] Optionally, the threat perception method for information systems based on the human body's internal perception mechanism described above will be explained below with reference to a specific embodiment.

[0113] In this application embodiment, an endogenous micro-sensing method for information systems based on the human body's internal sensing mechanism is proposed. The following is combined with... Figure 3 The process steps of this method are described below. Specifically, the method includes the following steps:

[0114] Step A: Establish a micro-sensing center and deploy micro-sensing probes during the information system manufacturing process. The micro-sensing center includes a micro-sensing feature library, a set of threat behaviors, and a set of micro-sensing feature groups.

[0115] In this embodiment, taking a computer system as an example, threat perception is performed on the information system to be perceived. Specifically, a virtual machine system is built, which has all the functions of a real computer system. During the construction of the virtual machine system, a micro-perception hub is constructed, which includes a micro-perception feature library, a set of threat behaviors, and a set of micro-perception feature groups used to map each threat behavior, as shown in Tables 1 and 2, respectively. At the same time, relevant tools are used as micro-perception probes to monitor in real time each micro-perception feature in the micro-perception feature library and the micro-perception feature library, threat behavior set, and micro-perception feature group set used to map each threat behavior stored in the micro-perception hub.

[0116] Table 1 Micro-sensing feature library

[0117]

[0118]

[0119] Table 2. Threat behaviors stored in the microsensing center and the microsensing feature groups used to map them.

[0120]

[0121] To facilitate the presentation of the charts, the micro-sensing features involved in each micro-sensing feature group in Table 2 have been numbered. Specifically, the number of times a single process calls CreateFile per second is labeled F1; the number of times a single process calls WriteFile per second is labeled F2; the number of times a single process has called QueryDirectory is labeled F3; the number of new SYN_RECEIVED connections per second is labeled F4; the total number of TCP and TCP-based data packets sent per second is labeled F5; the bandwidth received per second is labeled F6; CPU utilization is labeled F7; memory utilization is labeled F8; and the number of files overwritten in the first 10 files written by a single process is labeled F9.

[0122] It should be noted that the aforementioned micro-sensing method requires the establishment of a micro-sensing center and the deployment of micro-sensing probes during the manufacturing process of the information system. Its specific architecture is as follows: Figure 4 As shown.

[0123] Step B: After the information system is started, the micro-sensing probe monitors all micro-sensing features in the micro-sensing feature library and operations oriented towards the micro-sensing center.

[0124] After starting the target virtual machine system with the micro-perception mechanism of this invention, attacks were launched on the virtual machine system using three ransomware behavior simulators (labeled T1, T2, and T3, respectively), two SYN Flood attack simulators (labeled T4 and T5, respectively), and three self-propagating worm behavior simulators (labeled T6, T7, and T8, respectively). In addition, four benign programs with similar behavior to the three types of attack examples—AxCrypt (labeled T9), Dropbox (labeled T10), Nmap (labeled T11), and Adobe Premiere Pro (labeled T12)—were used as references and run on the target virtual machine system.

[0125] During the above experiment, micro-sensing probes were used to monitor in real time all micro-sensing features contained in the micro-sensing feature library and operations oriented towards the micro-sensing center.

[0126] Step C: Based on the monitoring results of the micro-sensing probes, the micro-sensing center senses the type of threat and the system status in the information system, and instructs the defense system to take corresponding defense strategies according to the status of the information system, so as to ensure the continuity and stability of the information system tasks within an acceptable range.

[0127] The micro-sensing probe transmits its monitoring results on micro-sensing features and related operations to the micro-sensing center in real time. The micro-sensing center then integrates and analyzes these monitoring results to determine whether the information system is currently under threat. The sensing process of the micro-sensing method is as follows: Figure 5 As shown, it includes the following steps:

[0128] Step 1: Start the information system;

[0129] Step 2: Activate the micro-sensing probe to monitor the information system;

[0130] Step 3: Determine whether abnormal micro-sensing features are detected. If yes, proceed to step 4; otherwise, continue with step 2.

[0131] Step 4: Confirm whether there are combinations of detected abnormal micro-sensing features that can be mapped to specific threat behaviors. If yes, proceed to step 5; otherwise, proceed to step 6.

[0132] Step 5: The micro-sensing center outputs the categories of perceived threatening behaviors;

[0133] Step 6: The micro-sensing center determines that the information system is in an alert state;

[0134] Step 7: Determine whether all micro-sensory features in the mapping combination have reached their corresponding limit values. If yes, proceed to step 8; otherwise, proceed to step 6.

[0135] Step 8: The micro-sensing center determines that the information system is in a dangerous state;

[0136] While executing step 3, the system also executes step 9, which includes: determining whether the micro-sensing center has detected unauthorized behavior; if so, executing step 8; otherwise, continuing to execute step 2.

[0137] The monitoring results of the micro-sensing probes from T1 to T12 are shown in Table 3 and Figures 6 to 14 As shown.

[0138] Table 3 Monitoring results of the microsensing probe

[0139]

[0140] The abnormal micro-sensing feature groups detected by the micro-sensing probes in T1, T2, and T3 included F1, F2, F3, and F9. The combination of these four micro-sensing features maps to ransomware and all exceed their respective limits. Therefore, during T1, T2, and T3, the micro-sensing center determined that the target virtual machine system was threatened by ransomware and was in a dangerous state, requiring immediate termination of ongoing system tasks and the implementation of emergency measures.

[0141] The abnormal micro-sensing feature groups detected by the micro-sensing probes in T4 and T5 included F4, F6, and F7. The combination of these three micro-sensing features maps to a SYN Flood attack. Therefore, during T4 and T5, the micro-sensing center determined that the target virtual machine system was threatened by a SYN Flood attack. However, in T4, F4, F6, and F7 all exceeded their respective limit values. Therefore, during T4, the micro-sensing center determined that the target virtual machine system was in a dangerous state, requiring immediate termination of ongoing tasks and emergency measures. In T5, F4, F6, and F7 only exceeded their respective standard values ​​but not their limit values. Therefore, during T5, the micro-sensing center determined that the host was in a state of alert and could wait for the current system tasks to complete before repairs could be performed.

[0142] The abnormal micro-sensing feature groups detected by the micro-sensing probes in T6, T7, and T8 included F1, F5, F7, and F8. The combination of these four micro-sensing features maps to a self-propagating worm. Therefore, during T6, T7, and T8, the micro-sensing center determined that the target virtual machine system was threatened by a self-propagating worm. However, in T6 and T7, F1, F5, F7, and F8 all exceeded their respective limits. Therefore, during T6 and T7, the micro-sensing center determined that the target virtual machine system was in a dangerous state, requiring immediate termination of ongoing tasks and emergency measures. In T8, F1, F5, F7, and F8 only exceeded their respective standard values ​​but not their limits. Therefore, during T8, the micro-sensing center determined that the host was in a state of alert and could wait for the current system task to complete before repairs could be performed.

[0143] Step D: If the micro-sensing probe does not detect any abnormal micro-sensing features or unauthorized operations targeting the micro-sensing center, then proceed to step B.

[0144] Table 3 and Figures 4 to 12 As shown, during T9 to T12, the micro-sensing probes did not detect any micro-sensing features in the target virtual machine system exceeding their corresponding standard values. Therefore, during T9 to T12, the micro-sensing center determined that the target virtual machine system was not under any threat and was in a safe state. In this safe state, the micro-sensing center will maintain routine monitoring of the micro-sensing probes in the target virtual machine system.

[0145] Thus, this embodiment has successfully achieved accurate threat perception of three types of attack instances, while no misjudgments occurred for four normally functioning benign programs.

[0146] In summary, the endogenous micro-sensing method for information systems based on the human body's internal perception mechanism proposed in this embodiment has high perception performance, can effectively perceive multiple threats, and has a strong ability to distinguish benign programs, demonstrating good stability and practicality. It can help build the threat perception front end of the defense system and provide basic theoretical support for realizing an endogenous defense architecture with network resilience.

[0147] According to an embodiment of this application, an embodiment of a threat perception device for an information system based on human internal perception mechanisms is also provided. Figure 15 This is a schematic diagram of the structure of a threat detection device for an information system based on the human body's internal perception mechanism, according to an embodiment of this application. Figure 15 As shown, the device includes:

[0148] The monitoring module 152 is used to monitor n micro-sensing features and target operations in the micro-sensing feature library through a micro-sensing probe when the information system is started, and to obtain monitoring results. The information system is equipped with a micro-sensing center, which includes at least the micro-sensing feature library, and the target operation is an unauthorized operation directed to the micro-sensing center, where n is a positive integer.

[0149] The determination module 154 is used to determine that the information system is in a safe state when the monitoring result indicates that there are no abnormal micro-sensing features in the information system and no target operation is detected.

[0150] The perception module 156 is used to perceive the threat category and system status of the information system when the monitoring result indicates that the abnormal micro-sensing feature exists in the information system and / or the target operation is detected.

[0151] It should be noted that the modules in the threat perception device of the information system based on the human body's internal perception mechanism can be program modules (e.g., a set of program instructions to implement a certain function) or hardware modules. For the latter, they can be in the following forms, but are not limited to these: each of the above modules is in the form of a processor, or the functions of each of the above modules are implemented by a processor.

[0152] It should be noted that the threat perception device of the information system based on the human body's internal perception mechanism provided in this embodiment can be used to perform... Figure 2The threat perception method of the information system based on the human body's internal perception mechanism shown above also applies to the embodiments of this application, and will not be repeated here.

[0153] This application embodiment also provides a non-volatile storage medium, which includes a stored computer program. The device containing the non-volatile storage medium executes the following threat perception method for an information system based on human internal perception mechanisms by running the computer program: When the information system is started, a micro-perception probe monitors n micro-perception features and target operations in a micro-perception feature library to obtain monitoring results. The information system is equipped with a micro-perception center, which includes at least the micro-perception feature library, and the target operation is an unauthorized operation directed to the micro-perception center, where n is a positive integer. If the monitoring results indicate that there are no abnormal micro-perception features in the information system and no target operation is detected, the information system is determined to be in a secure state. If the monitoring results indicate that the abnormal micro-perception features exist in the information system and / or the target operation is detected, the threat category and system state of the information system are perceived.

[0154] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0155] Embodiments of this application also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in any of the above method embodiments.

[0156] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0157] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.

[0158] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0159] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0160] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.

[0161] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. A threat perception method for an information system based on human internal perception mechanisms, characterized in that, include: When the information system is started, the micro-sensing probe monitors n micro-sensing features and target operations in the micro-sensing feature library to obtain monitoring results. The information system is equipped with a micro-sensing center, which includes at least the micro-sensing feature library and the target operation is an unauthorized operation directed to the micro-sensing center, where n is a positive integer. If the monitoring results indicate that there are no abnormal micro-sensing features in the information system and no target operation is detected, the information system is determined to be in a safe state. When the monitoring results indicate the presence of the abnormal micro-sensing features in the information system, and / or the target operation is detected, the threat category and system status of the information system are perceived.

2. The threat perception method for an information system based on the human body's internal perception mechanism according to claim 1, characterized in that, The micro-sensing center includes: The set of threatening behaviors A = {a1, a2, ..., a...} m }, where a i (1≤i≤m) represents the category of the i-th threatening behavior. m and i are positive integers; The micro-sensing feature library F = {f1, f2, ..., f n }, wherein the micro-sensing feature is used to indicate the operating parameter information of the information system, f i (1≤i≤n) represents the i-th micro-sensing feature; The standard value set S = {s1, s2, ..., s} corresponding to the micro-sensing feature library is S = {s1, s2, ..., s}. n }, where s i (1≤i≤n) represents the i-th micro-sensing feature f i The corresponding standard value; The limit value set L = {l1, l2, ..., l} corresponding to the micro-sensing feature library is L = {l1, l2, ..., l}. n }, where l i (1≤i≤n) represents the i-th micro-sensing feature f i The corresponding limit value; The set of micro-sensory features G = {g1, g2, ..., g m }, where g i (1≤i≤m) represents the i-th threatening action a. i Associated micro-sensory feature combinations, g i ={f i1 ,f i2 ,...,f ik }, 3. The threat perception method for an information system based on the human body's internal sensory mechanism according to claim 2, characterized in that, Multiple micro-sensing features and target operations in the micro-sensing feature library are monitored using micro-sensing probes, and the monitoring results are obtained, including: Using the micro-sensing probe, the operating parameter information of the information system is identified based on the n micro-sensing features to obtain the operating parameter features corresponding to the operating parameter information; The operating parameter features are examined according to the set of standard values ​​to determine whether the operating parameter features are abnormal micro-sensing features, and a first monitoring result is obtained. The feature value of the abnormal micro-sensing feature is greater than the standard value corresponding to the operating parameter feature. The monitoring result includes the first monitoring result.

4. The threat perception method for an information system based on the human body's internal perception mechanism according to claim 3, characterized in that, When the monitoring results indicate the presence of the abnormal micro-sensing features in the information system, and / or the target operation is detected, the system senses the threat category and system status of the information system, including: The abnormal micro-sensing features are matched in the micro-sensing feature set to determine whether the abnormal micro-sensing features match the target threat behavior, and the abnormal micro-sensing features are verified according to the limit value set to determine whether there are any micro-sensing features in the abnormal micro-sensing features that do not exceed the corresponding limit value. If no target threat behavior is matched, or if the target threat behavior is matched and there are micro-sensory features among the abnormal micro-sensory features that do not exceed the corresponding limit value, the information system is determined to be in a state of alert. If the target threat behavior is matched and multiple micro-sensory features in the abnormal micro-sensory features exceed the corresponding limit values, the information system is determined to be in a dangerous state.

5. The threat perception method for an information system based on the human body's internal perception mechanism according to claim 4, characterized in that, After sensing the threat categories present in the information system and the system status of the information system, the method further includes: If the information system is determined to be in the alert state, the target task currently being executed in the information system is monitored. If the target task is found to be completed, the defense system is instructed to repair the information system. If the information system is determined to be in the dangerous state, the defense system is instructed to terminate the target mission and take the first defensive measure corresponding to the target threat behavior.

6. The threat perception method for an information system based on the human body's internal perception mechanism according to claim 2, characterized in that, Multiple micro-sensing features and target operations in the micro-sensing feature library are monitored using micro-sensing probes, and the monitoring results are obtained, including: The target operation is monitored by the micro-sensing probe to obtain a second monitoring result, wherein the target operation is directed to at least one of the following: the micro-sensing feature library, the threat behavior set, the micro-sensing feature group, and the target operation is categorized as at least one of the following: addition, deletion, modification, and the monitoring result includes the second monitoring result.

7. The threat perception method for an information system based on the human body's internal perception mechanism according to claim 6, characterized in that, After sensing the threat categories present in the information system and the system status of the information system, the method further includes: If the second monitoring result indicates that the target operation has been detected, the information system is determined to be in a dangerous state; The system is instructed to terminate the target task in the information system that is currently in execution, and to execute the second defense measure corresponding to the target operation.

8. A threat detection device for an information system based on human internal perception mechanisms, characterized in that, include: The monitoring module is used to monitor n micro-sensing features and target operations in the micro-sensing feature library through micro-sensing probes when the information system is started, and to obtain monitoring results. The information system is equipped with a micro-sensing center, which includes at least the micro-sensing feature library, and the target operation is an unauthorized operation directed to the micro-sensing center, where n is a positive integer. The determination module is used to determine that the information system is in a safe state when the monitoring results indicate that there are no abnormal micro-sensing features in the information system and no target operation is detected. The perception module is used to perceive the threat category and system status of the information system when the monitoring results indicate that the abnormal micro-sensing features exist in the information system and / or the target operation is detected.

9. An electronic device, characterized in that, include: A memory and a processor, the processor being configured to run a program stored in the memory, wherein the program, when running, executes the threat perception method of an information system based on human internal perception mechanisms as described in any one of claims 1 to 7.

10. A non-volatile storage medium, characterized in that, The non-volatile storage medium includes a stored computer program, wherein the device containing the non-volatile storage medium executes the threat perception method of the information system based on the human body's internal perception mechanism according to any one of claims 1 to 7 by running the computer program.