Risk assessment method and system based on network security situation awareness

By using a network security situational awareness-based approach to capture the characteristic attributes of network security incidents, delineate risk areas, and construct a propagation weight map, the problem of inaccurate risk assessment in existing technologies is solved. This enables precise location and dynamic response to network security incidents, improves the comprehensiveness of risk assessment and the pertinence of response, and reduces the losses caused by risk spread.

CN120880757APending Publication Date: 2025-10-31HEBEI XIUAN NETWORK TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511147203.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-15
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

Existing network security monitoring platforms suffer from problems in risk assessment, such as inaccurate definition of the scope of impact of network security incidents, insufficient identification of risk propagation paths, and untimely and untargeted response to protective measures, leading to the spread of risks and the expansion of losses.

Method used

By using a network security situation awareness-based approach, threat detection mechanisms are used to capture the characteristic attributes of network security incidents, divide core risk areas, edge risk areas, and security buffer zones, construct a risk propagation weight graph, apply the maximum flow algorithm to determine key propagation paths, and trigger risk mitigation operations based on response priorities.

Benefits of technology

It enables precise location and dynamic response to the impact of cybersecurity incidents, improves the comprehensiveness of risk assessment and the pertinence of response, and reduces losses caused by the spread of risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880757A_ABST
    Figure CN120880757A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security protection, and discloses a risk assessment method and system based on network security situation awareness. The method comprises the following steps: firstly, capturing feature attributes of a target network security event through a preset threat detection mechanism, and extracting network resource entities influenced by the feature attributes in a monitoring period; on the basis of the threat level label, dividing the related security area into a core risk area, an edge risk area and a security buffer area, and identifying a potential risk propagation area to form a risk assessment object set; calculating risk propagation intensity values of adjacent regions, and constructing a risk propagation weight map by taking the regions as vertexes and the intensity values as edge weights; then determining a key propagation path from the core risk area to other areas by applying a maximum flow algorithm, and deducing a response priority sequence of each area; and finally, triggering the risk relief operation of the corresponding region according to the sequence, and executing network security protection. The method can comprehensively and accurately evaluate the network risk, and improves the protection effectiveness.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security protection technology, specifically to a risk assessment method and system based on network security situation awareness. Background Technology

[0002] With the rapid development of information technology, the network environment is becoming increasingly complex, and various cybersecurity incidents are occurring frequently, posing severe challenges to the information systems of enterprises, institutions, and even nations. Currently, while network security monitoring platforms can continuously collect network operation status data, they still have significant shortcomings in risk assessment.

[0003] Traditional risk assessment methods often focus on analyzing single security incidents or isolated network resources, lacking a dynamic definition of the scope of impact of cybersecurity incidents. For example, when a cyberattack occurs, existing methods struggle to accurately delineate the affected security areas, distinguish between core risk areas, peripheral risk areas, and security buffer zones, and find it even more difficult to identify potential risk propagation areas. This significantly reduces the comprehensiveness and accuracy of risk assessments.

[0004] Traditional methods for analyzing risk propagation paths fail to effectively utilize the interrelationships between different areas of a network, making it difficult to construct a scientific risk propagation model. Because they cannot accurately calculate the intensity of risk propagation between different areas, they cannot identify critical propagation paths, and consequently, cannot rationally prioritize responses to each area. This often leads to untimely responses and inadequately targeted protective measures when facing complex cybersecurity incidents, resulting in risk contagion and greater losses.

[0005] Existing risk mitigation mechanisms are rather rigid, typically following fixed procedures or preset rules, and lack the ability to dynamically adjust based on real-time risk assessment results. This makes it difficult for protective measures to adapt in a timely manner to the constantly changing cybersecurity landscape, hindering the effective containment of risk spread. Summary of the Invention

[0006] The purpose of this invention is to provide a risk assessment method and system based on network security situation awareness to solve the problems mentioned in the background art.

[0007] To achieve the above objectives, the present invention provides a risk assessment method based on network security situation awareness, the method comprising:

[0008] The system captures the characteristic attributes of target network security events through a preset threat detection mechanism, and extracts the network resource entities affected by the target network security events during the monitoring period based on the characteristic attributes.

[0009] Based on the threat level label of the target network security event, the security area covered by the network resource entity is divided into core risk area, edge risk area and security buffer zone, and potential risk propagation area is identified in the security area not covered by the network resource entity. The core risk area, edge risk area, security buffer zone and potential risk propagation area together constitute a risk assessment object set.

[0010] Calculate the risk propagation intensity value between any two adjacent regions in the risk assessment object set, and construct a risk propagation weight graph of the risk assessment object set using the regions in the risk assessment object set as vertices and the risk propagation intensity value as the edge weight value connecting the vertices.

[0011] The maximum flow algorithm is applied to analyze the risk propagation weight graph to determine the critical propagation path from the core risk area to other areas, and the response priority order of each area is derived based on the critical propagation path.

[0012] Based on the response priority order, risk mitigation operations corresponding to each region in the risk assessment object set are triggered sequentially to perform network security protection.

[0013] Preferably, extracting the network resource entities affected by the target network security event during the monitoring period based on the characteristic attributes includes:

[0014] The historical security log database is used to statistically analyze the network resource entities affected by the target network security incident within a specified time range;

[0015] Based on the exposure index of each network resource entity in a security incident, the statistically obtained network resource entities are classified and processed to form one or more risk entity sets.

[0016] Match the set of target risk entities in the set of risk entities that matches the current threat level label of the target network security event, and take the scope covered by the set of target risk entities as the network resource entities affected by the target network security event during the monitoring period.

[0017] Preferably, the statistically obtained network resource entities are classified according to the exposure level index of each network resource entity in a security incident, including:

[0018] Obtain the predefined core asset protection zones in the network security monitoring platform;

[0019] For any network resource entity obtained from the statistics, analyze the core asset protection interval category to which the exposure index of the network resource entity belongs, and assign the network resource entity to the risk entity set corresponding to the identified core asset protection interval category.

[0020] Preferably, based on the threat level label of the target network security event, dividing the security area covered by the network resource entity into core risk areas and edge risk areas includes:

[0021] Identify the primary and secondary affected areas indicated by the threat level label of the target network security incident;

[0022] The first range of activity for locating the primary affected part within the security area covered by the network resource entity, and the second range of activity for locating the secondary affected part within the security area covered by the network resource entity;

[0023] The first activity range is marked as a core risk area within the security area covered by the network security monitoring platform, and the second activity range is marked as a peripheral risk area within the security area covered by the network security monitoring platform.

[0024] Preferably, identifying potential risk propagation areas in security areas not covered by the network resource entities includes:

[0025] Set a main propagation coefficient for the core risk area covered by the network resource entity, and set an auxiliary propagation coefficient for the edge risk area covered by the network resource entity;

[0026] For security areas not covered by the network resource entities, if they are adjacent to the core risk areas, the security areas with the number of main propagation coefficients are selected as potential risk propagation areas; if they are adjacent to the edge risk areas, the security areas with the number of auxiliary propagation coefficients are selected as potential risk propagation areas.

[0027] Preferably, calculating the risk propagation intensity value between any two adjacent areas in the risk assessment object set includes:

[0028] For adjacent first and second regions in the risk assessment object set, the respective region types of the first and second regions are identified, and the region type includes one of core risk region, edge risk region, safety buffer zone and potential risk propagation region;

[0029] Based on the identified region type, the initial risk propagation parameters for the first region are derived, and the subsequent risk propagation parameters for the second region are derived.

[0030] The deviation between the initial risk propagation parameter and the subsequent risk propagation parameter is measured, and the risk propagation intensity value between the first region and the second region is calculated based on the deviation value.

[0031] Preferably, calculating the risk propagation intensity value between the first region and the second region based on the deviation value includes:

[0032] Identify the risk propagation parameters for each region in the set of risk assessment objects, and calculate the median of the distribution of the identified risk propagation parameters;

[0033] Multiple deviation value ranges are defined based on the median of the distribution, and the target deviation value range in which the measured deviation value between the initial risk propagation parameter and the subsequent risk propagation parameter is located is determined.

[0034] The preset intensity value corresponding to the target deviation value range is determined as the risk transmission intensity value between the first region and the second region.

[0035] Preferably, triggering risk mitigation operations corresponding to each region in the risk assessment object set sequentially according to the response priority order includes:

[0036] The operation parameters of each response node in the response priority order are identified, and a parameter sequence is generated based on the identified operation parameters, wherein the order of each parameter in the parameter sequence is consistent with the response priority order;

[0037] The parameter sequence is input into a pre-trained behavior decision model to output protection strategy instructions for each response node.

[0038] The system executes corresponding risk mitigation operations according to the output protection policy instructions in order to perform network security protection.

[0039] Preferably, the present invention further includes a risk assessment system based on network security situation awareness, used to implement the risk assessment method based on network security situation awareness as described above. The system is applied in a network security monitoring platform, which is configured to continuously collect network operation status data. The system includes:

[0040] The event capture unit is used to capture the characteristic attributes of the target network security event through a preset threat detection mechanism, and extract the network resource entities affected by the target network security event within the monitoring period based on the characteristic attributes.

[0041] The region segmentation unit is used to divide the security area covered by the network resource entity into core risk areas, edge risk areas, and security buffer zones based on the threat level label of the target network security event, and to identify potential risk propagation areas in the security areas not covered by the network resource entity. The core risk areas, edge risk areas, security buffer zones, and potential risk propagation areas together constitute a risk assessment object set.

[0042] The weighted graph construction unit is used to calculate the risk propagation intensity value between any two adjacent regions in the risk assessment object set, and construct the risk propagation weighted graph of the risk assessment object set by using the regions in the risk assessment object set as vertices and the risk propagation intensity value as the edge weight value connecting the vertices.

[0043] The sequential derivation unit is used to apply the maximum flow algorithm to analyze the risk propagation weight graph to determine the critical propagation path from the core risk area to other areas, and to derive the response priority order of each area based on the critical propagation path.

[0044] The protection execution unit is used to sequentially trigger the risk mitigation operations corresponding to each area in the risk assessment object set according to the response priority order, so as to perform network security protection.

[0045] Preferably, the protection execution unit is specifically used to: identify the operation parameters of each response node in the response priority order, and generate a parameter sequence based on the identified operation parameters, wherein the order of each parameter in the parameter sequence is consistent with the response priority order; input the parameter sequence into a pre-trained behavior decision model to output protection strategy instructions for each response node through the behavior decision model; and execute corresponding risk mitigation operations according to the output protection strategy instructions to perform network security protection.

[0046] Compared with the prior art, the beneficial effects of the present invention are:

[0047] By capturing the characteristic attributes of target cybersecurity events through a pre-defined threat detection mechanism and extracting the affected network resource entities accordingly, the scope of the security event's impact is accurately located. This approach overcomes the limitations of traditional methods that analyze single events or isolated resources, enabling a holistic understanding of the network resources involved in the event and laying a solid foundation for subsequent risk area delineation.

[0048] Based on the threat level labels of target cybersecurity incidents, the security areas covered by network resource entities are divided into core risk areas, peripheral risk areas, and security buffer zones. Potential risk propagation areas are also identified, forming a set of risk assessment objects. This classification method makes the risk assessment objects more specific and comprehensive, including not only affected areas but also potential areas that may be affected by risk propagation. This allows for a more comprehensive understanding of the cybersecurity situation and avoids risk omissions caused by the incomplete assessment scope of traditional methods.

[0049] This method calculates the risk propagation intensity between any two adjacent areas in the risk assessment object set, constructs a risk propagation weight graph, and applies the maximum flow algorithm to analyze and determine the critical propagation path from the core risk area to other areas, thereby deriving the response priority order for each area. This process fully utilizes the interrelationships between areas in the network, and through scientific algorithmic analysis, it can accurately identify the critical path of risk propagation, making the determination of response priorities more reasonable. Compared to traditional methods, this approach avoids the blindness of response ordering, allowing protective forces to be prioritized for key areas, thus improving the targeting and effectiveness of risk response.

[0050] By triggering risk mitigation operations in each region sequentially according to response priority, the execution of risk protection measures becomes more orderly and efficient. This dynamic, priority-based triggering mechanism can adjust protection strategies in a timely manner based on real-time risk assessment results, adapt to changes in the cybersecurity landscape, effectively curb the spread of risks, and reduce losses caused by risk proliferation. Attached Figure Description

[0051] Figure 1 This is a schematic diagram illustrating the working principle of a risk assessment method based on network security situation awareness as described in this invention.

[0052] Figure 2 A flowchart for extracting network resource entities;

[0053] Figure 3 A flowchart for dividing the safety zone;

[0054] Figure 4 A flowchart for calculating the risk transmission intensity value;

[0055] Figure 5 This is a flowchart for calculating the intensity value based on the deviation value. Detailed Implementation

[0056] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0057] Please see Figure 1 This invention provides a risk assessment method based on network security situation awareness, the method comprising:

[0058] The network security monitoring platform is configured to continuously collect network operation status data. This method captures the characteristic attributes of target network security events through a pre-set threat detection mechanism, and extracts the network resource entities affected by the target network security events within the monitoring period based on these characteristics. Based on the threat level labels of the target network security events, the security areas covered by network resource entities are divided into core risk areas, edge risk areas, and security buffer zones. Potential risk propagation areas are identified in the security areas not covered by network resource entities; these areas collectively form a risk assessment object set. The risk propagation intensity value between any two adjacent areas in the risk assessment object set is calculated. Using the areas as vertices and the risk propagation intensity value as the edge weight connecting the vertices, a risk propagation weight graph is constructed. The maximum flow algorithm is applied to analyze the risk propagation weight graph to determine the critical propagation path from the core risk area to other areas, and the response priority order of each area is derived based on the critical propagation path. Risk mitigation operations corresponding to each area in the risk assessment object set are triggered sequentially according to the response priority order to perform network security protection.

[0059] Example 1: See Figure 2 This involves the extraction and classification of network resource entities affected by cybersecurity incidents. This process relies on network operational status data continuously collected by a cybersecurity monitoring platform, and uses systematic analysis methods to accurately define the scope of impact of target security incidents.

[0060] The historical security log database serves as the foundational data source, recording complete information on various security events within the network system. The database employs a distributed architecture, comprising three main tables: an event log table, a resource entity table, and a relationship table. The event log table stores basic information such as the event's occurrence time, type, and severity; the resource entity table records the attributes and status of entities such as network devices, servers, and terminals; and the relationship table maintains the mapping between events and affected entities. The database utilizes a combination of time partitioning and hash indexes to optimize query performance, supporting the rapid retrieval of all network resource entities related to a specific security event within a specified time frame.

[0061] When statistically analyzing the network resource entities affected by target cybersecurity incidents, the system first generates query conditions based on event characteristic attributes. These attributes include identifying information such as event fingerprints, attack signatures, and abnormal behavior patterns. The query engine parses these attributes, converts them into corresponding database query statements, and filters historical event records with the same or similar characteristics from the event log table. The time range parameter is dynamically adjusted according to the event type; a longer monitoring period is set for persistent attacks, while a shorter time window is used for transient attacks.

[0062] After obtaining relevant historical event records, the system searches for the corresponding network resource entities through a relational table. The exposure level index for each entity is calculated through multi-dimensional analysis. Exposure frequency reflects the number of times the entity appears in historical events, obtained by statistically analyzing the frequency of the entity ID in the relational table. Affected duration is calculated based on the timestamp information in the event record table, determining the total duration the entity is in an abnormal state. The degree of impact is comprehensively assessed based on the event severity and the difficulty of entity recovery; the system pre-sets impact coefficient matrices for different event types. These three dimensions of data are normalized and then weighted to generate the final exposure level index value.

[0063] The classification of network resource entities employs a hierarchical strategy. The system presets three exposure level thresholds: high, medium, and low. The calculated exposure index is compared with these thresholds to determine the risk level of each entity. High-exposure entities typically include core business servers, critical database nodes, and other infrastructure; medium-exposure entities include application servers, network boundary devices, and other important components; low-exposure entities mainly involve ordinary office terminals and non-critical network equipment. During the classification process, the system dynamically adjusts the threshold range to adapt to the characteristics of different network environments, avoiding overly concentrated or dispersed classification results.

[0064] The matching process for the target risk entity set considers the correspondence between event threat level and entity exposure level. The system maintains a threat-exposure mapping table, defining the handling strategies for entities at different exposure levels under different threat levels. For high-risk events, the focus is on entities with high and medium exposure levels; for medium-risk events, high-exposure level entities are mainly handled; and for low-risk events, only high-exposure level entities are monitored. The matching algorithm traverses the classified risk entity set and filters out the target set that meets the conditions based on the threat level label of the current event. The matching results undergo topological relationship verification to ensure that the selected entities logically constitute a complete affected scope.

[0065] The coverage area of ​​network resource entities is determined using a network topology-based diffusion algorithm. The system loads the latest network topology map and expands outward along connections, starting from members of the target risk entity set. During the expansion, factors such as device type, communication protocol, and data flow are considered to calculate the association strength of each adjacent node. Diffusion stops when the association strength falls below a set threshold, and the resulting connected subgraph represents the range of network resource entities affected by the target network security event during the monitoring period. The system records the diffusion path and decision-making basis, providing a traceability basis for subsequent analysis.

[0066] The definition of core asset protection zones adopts a hierarchical model. Network resources are assessed according to three dimensions: business importance, data sensitivity, and system dependency, with each dimension divided into five levels. The assessment results are mapped to the division of core asset zones, important asset zones, and ordinary asset zones using a three-dimensional coordinate system. The core asset zone contains entities that are assessed at the highest level in all dimensions, the important asset zone requires at least two dimensions to reach a high level, and the rest are classified as ordinary asset zones. The zone boundaries can be dynamically adjusted according to actual operational needs, and the system provides visualization tools to assist administrators in defining the zones.

[0067] The association between asset protection zones and risk entity sets is achieved through an automated rules engine. The system has built-in standard association rules, such as classifying entities in the core asset zone into the high-exposure set by default. It also supports the addition of custom rules, allowing administrators to create exception rules based on specific security needs. The rules engine uses the Rete algorithm for efficient pattern matching, automatically triggering a reclassification process when the attributes or status of network resource entities change. The classification results are updated in real-time to the security monitoring view, helping operations personnel quickly grasp the current risk distribution.

[0068] The system interface provides multi-dimensional data display capabilities. The network topology view intuitively presents the distribution of affected entities, supporting various filtering methods such as by region and by type. The timeline view displays the evolution of the event's impact, helping to analyze attack paths and spread trends. The statistics panel summarizes various key indicators, such as the number of highly exposed entities and the percentage of core assets affected. All views support drill-down operations, allowing for quick location of specific device details and event logs. These visualization tools greatly enhance the ability of operations and maintenance personnel to understand and manage complex security situations.

[0069] An exception handling mechanism ensures the reliability of the implementation process. When data inconsistency or logical conflict is detected, the system automatically pauses the current operation and issues an alarm. Common problem types include entity state anomalies, broken topological relationships, and exceeding metric calculation limits. Administrators can view detailed error information through diagnostic tools and resume process execution manually or by adjusting parameters. Rollback points are provided for critical operation steps to ensure recovery to a stable state in the event of a serious error. This defensive design significantly improves the system's robustness and availability.

[0070] Example 2: See Figure 3 The process of delineating and marking the affected areas of cybersecurity incidents involves classifying and managing the security areas covered by network resource entities in a refined manner based on the threat level labels of the target cybersecurity incidents.

[0071] Threat level label parsing is the first step in the implementation process. The network security monitoring platform generates threat level labels based on factors such as attack characteristics, scope of impact, and duration of the event. These labels are stored in a structured data format and include key fields such as event type, severity, and affected locations. The system uses a parsing engine to extract information on the primary and secondary affected locations from the labels. The primary affected location typically points to the direct target of the attack, such as the compromised server or infected terminal device; the secondary affected location includes peripheral system components that have data interactions or dependencies with the primary target.

[0072] The security area analysis of network resource entity coverage employs topology association technology. The system loads a topology diagram of the current network environment, where nodes represent network devices, edges represent connections, and each node's attribute information is labeled, such as device type, IP address, and affiliated business system. When locating the first active range of the main affected area in the topology diagram, the system first identifies network nodes directly related to the target event and then analyzes their communication paths along the data flow direction. For server nodes, the focus is on examining their provided service ports and connected clients; for network devices, the abnormal traffic characteristics they forward are analyzed. The boundary determination of the first active range is based on traffic mutation detection; when the traffic characteristics on a certain path return to normal distribution, it is considered the boundary of the affected range.

[0073] The identification of the secondary impact area's scope of activity employs dependency analysis. The system maintains a business system dependency graph, recording the call relationships and data flows between components. Once the primary impact area is determined, the system searches the dependency graph for all other nodes directly dependent on that component, forming a preliminary secondary impact area. Further analysis of these nodes' status indicators, such as response latency and error rate, filters out nodes exhibiting abnormal characteristics for inclusion in the secondary impact area. For database systems, the connection pool status and query response time are checked; for application services, their API call success rate is monitored. This verification mechanism based on actual operational status avoids over-expanding the impact area.

[0074] The process of dividing and marking security zones adopts a hierarchical strategy. The marking of core risk areas is based on the geographical and logical distribution characteristics of the first activity area. At the physical level, the system highlights specific information such as the location of affected data centers and rack numbers in the geographic information view; at the logical level, core risk nodes are marked with specific icons on the network topology map, and a list of affected VLANs is automatically generated. Edge risk areas are marked with a different visual style, appearing semi-transparently overlaid on the periphery of the core area on the monitoring interface, while also indicating the direction of risk propagation with arrows. Security buffer zones serve as a reference benchmark, maintaining the standard network topology display style, but with added boundary lines.

[0075] The storage of region marking information employs a multi-version management mechanism. Each region division result generated during security incident handling is saved as an independent version, containing metadata such as timestamp, operator, and division criteria. The version management system supports rapid backtracking of historical division records, facilitating comparative analysis of the evolution patterns of similar events. Marking data is synchronized in real-time to various analysis modules via a distributed cache, ensuring consistent region definitions across monitoring views, risk assessments, and protection strategies. For large-scale network environments, the system uses an incremental update algorithm to optimize the propagation efficiency of marking information, synchronizing only the changed region data.

[0076] The analysis of the affected area's activity range also considers the time dimension. The system incorporates a time decay model to weight historical activity records. Recent anomalous activities have a higher weight in range determination, while the impact of earlier records gradually weakens. This time-series analysis method effectively identifies the attacker's lateral movement path, distinguishing between the currently active impact range and historically mitigated impact areas. Time-dimensional data is visualized in the form of heatmaps, helping operations and maintenance personnel intuitively understand the temporal characteristics of attack activities.

[0077] The status monitoring of network resource entities employs a multi-metric fusion strategy. In addition to traditional basic monitoring items such as CPU and memory, the system also collects security-related specialized metrics, such as the number of abnormal login attempts and sensitive file access records. These metrics are calculated in real time through a stream processing engine. When multiple metrics for a node simultaneously show anomalies, the system increases the priority of that node in the impact scope analysis. Metric weights are dynamically adjusted based on node type; for example, for database nodes, data access patterns have a higher weight than resource utilization; for application servers, service response quality metrics are given more attention.

[0078] The verification of the regional classification results employs a cross-validation mechanism. The system compares the automatically analyzed impact range with the following data sources: alarm distribution from intrusion detection systems, reports from endpoint protection software, and detection results from network traffic analysis devices. When significant differences are found, a manual review process is triggered, where security analysts examine the basis for the automatic classification and make a final decision. The comparative data used in the verification process is fed back into the machine learning model to continuously optimize the accuracy of the automatic classification. For critical business systems, the system establishes stricter verification rules, such as requiring corroboration from at least two independent data sources to confirm that a region is included in the impact range.

[0079] The implementation process is deeply integrated with the Network Configuration Management Database (CMDB). The system regularly synchronizes the latest asset information from the CMDB, including management attributes such as the business unit to which the device belongs, the responsible person, and the maintenance window. This information is used to optimize the area division strategy; for example, for devices under maintenance, the anomaly detection threshold is appropriately relaxed, while for devices in critical business units, stricter standards are applied. Change records in the CMDB also serve as an important reference. When a recent configuration change is detected affecting a specific area, the system will prompt a check to see if there are any security issues caused by configuration errors.

[0080] The application of zone labeling information is integrated throughout the entire security incident handling lifecycle. During the incident analysis phase, labeled zones are prioritized for inspection, and the system automatically collects logs and traffic data from these zones for in-depth analysis. In the impact assessment phase, the degree of business impact is calculated based on the labeled zones. During the response and handling phase, protective resources are preferentially deployed to labeled zones. In the recovery and verification phase, the recovery status of labeled zones is closely monitored. The entire process forms a closed loop, with data generated at each stage updating the zone labeling information, enabling dynamic adjustments.

[0081] The visualization layer provides regional analysis tools from multiple perspectives. The geographic distribution view shows the physical distribution of affected areas; the logical topology view highlights the risk propagation path; and the business architecture view presents affected service components from the application system perspective. All views support interactive exploration, allowing users to click on areas to view detailed information, including a list of associated security events, current status indicators, and existing protective measures. The cross-analysis function between views allows operations personnel to cross-verify the rationality of the impact scope determination from different dimensions.

[0082] An anomaly handling mechanism ensures the reliability of the implementation process. When a significant change in network topology or abnormal missing monitoring data is detected, the system automatically pauses the automatic process segmentation and switches to a conservative manual confirmation mode. For ambiguous boundary situations, such as a node maintaining connections to both core and edge areas simultaneously, the system will temporarily classify it as pending confirmation, awaiting further evidence or manual decision-making. All abnormal events and operations during the processing are recorded in the audit log, supporting post-event traceability, analysis, and improvement.

[0083] Example 3: See Figure 4The process of identifying and calculating the intensity of cybersecurity risk propagation areas involves establishing a quantitative risk assessment model to systematically analyze potential risk propagation paths. The main propagation coefficient for core risk areas considers three dimensions: event type, network topology, and asset value. The event type dimension categorizes security events into network layer attacks, system layer intrusions, and application layer vulnerability exploits, each corresponding to a different base propagation coefficient value. The network topology dimension analyzes the centrality of the core area within the network structure, using an improved betweenness centrality algorithm to calculate the hub status of nodes in the network path. The asset value dimension scores resource entities based on their business criticality and data sensitivity. The evaluation results from these three dimensions are weighted and fused to generate the final main propagation coefficient value.

[0084] α = w t ·T+w n ·N+w a ·A

[0085] Where α represents the main propagation coefficient, T is the event type coefficient, N is the network topology coefficient, A is the asset value coefficient, and w t w n w a These represent the weighting factors for each dimension. The weighting factors are dynamically adjusted based on the organization's security strategy; for example, the financial industry may focus more on asset value, while internet companies may pay more attention to network topology characteristics. The master propagation coefficient is limited to a range of 1.0 to 5.0, and normalization is used to ensure comparability across different network environments.

[0086] The auxiliary propagation coefficient for edge risk areas is calculated using a derivation method from the main propagation coefficient. The system first analyzes the connection strength between the edge and core areas, which is determined by the historical average traffic, protocol type, and security level matching degree. For edge areas with high-strength connections, the auxiliary propagation coefficient is set to 60%-80% of α; for medium-strength connections, it is set to 40%-60%; and for weak connections, it is set to 20%-40%. This tiered setting reflects the probability differences in risk propagation while avoiding excessive dispersion of coefficient values. The dynamic adjustment mechanism of the auxiliary propagation coefficient continuously monitors abnormal indicators in the edge areas, automatically increasing the coefficient value of the corresponding area when intensified abnormal activity is detected.

[0087] The identification of potential risk propagation areas employs a graph-theoretic breadth-first search algorithm. Starting from the core risk area, the system determines the search depth based on the main propagation coefficient, expanding by one hop distance in the corresponding network topology at each layer. During the search, the cumulative path risk value is calculated in real-time; the search stops when the cumulative value exceeds a threshold. For searches originating from edge risk areas, the algorithm uses similar logic but with auxiliary propagation coefficients as constraints. Deduplication of search results merges overlapping areas from different starting points, resulting in a final set of potential risk propagation areas containing all potentially affected network nodes.

[0088] The risk propagation intensity calculation for adjacent areas employs a multi-dimensional feature matching method. Regional type features encode core risk areas, peripheral risk areas, safety buffer zones, and potential risk propagation areas as four-dimensional vectors. The derivation of initial risk propagation parameters considers three factors: the frequency of historical events in the region, current threat indicators, and the completeness of protective measures, mapping them to a standardized parameter space through linear transformation. Subsequent risk propagation parameters are then supplemented with attenuation factors for path hop count and intermediate node types, forming a recursive calculation model. The deviation value is calculated using an improved cosine similarity algorithm, considering both absolute differences in parameters and the consistency of their changing trends.

[0089] The risk propagation intensity value interval division adopts an adaptive threshold technique. The system periodically collects historical propagation parameter samples and constructs a parameter distribution model using the kernel density estimation method. The median of the distribution is calculated using an anti-interference algorithm to eliminate the influence of extreme values ​​on the statistical results. The deviation value interval range is dynamically adjusted according to the quartiles of the parameter distribution to ensure that each interval contains a reasonable proportion of sample data. The interval boundary setting takes into account network security policy requirements, and a more stringent interval division standard is adopted for high-risk environments. The matching process of the target deviation value interval adopts a binary search algorithm to optimize the computational efficiency in large-scale network environments.

[0090] The implementation process is deeply integrated with network access control policies. When a high-risk propagation path is identified, the system automatically generates temporary access control lists (ACLs) to restrict unnecessary communication between risky and insecure areas. ACL rules are granular down to the protocol and port level to avoid excessive blocking that could impact normal business operations. Policy deployment adopts a gradual approach, first observing the effects in monitoring mode before formal implementation. Access control logs are fed back to the risk propagation model in real time to verify the effectiveness of protective measures and adjust parameters promptly.

[0091] The extended temporal dimension of risk propagation analysis supports multi-temporal modeling. The system maintains a time-varying graph model of risk propagation, recording changes in propagation intensity across different time segments. Time-series analysis algorithms identify temporal patterns in propagation, such as increased lateral movement risk during specific periods. The predictive model combines historical time-series data with the current state to generate short-term risk propagation trend predictions. A time-sliding window mechanism ensures that the analysis model always uses the latest data while retaining necessary historical reference information.

[0092] Anomaly propagation path detection employs deviation analysis technology. The system establishes a baseline model of normal propagation patterns, triggering special review when the observed propagation path deviates significantly from the baseline characteristics. The deviation calculation considers the comprehensive differences of multiple feature vectors, including path length, node type sequence, and intensity change curve. The review results of anomaly paths are used to discover new attack methods or unexpected system vulnerabilities, continuously enriching the risk propagation knowledge base.

[0093] Example 4: See Figure 5 The process involves the interval processing and standardized assessment of cybersecurity risk propagation intensity values. This process establishes a structured deviation value analysis framework to achieve a quantitative comparison of risk propagation intensity across different network regions. In a case where a financial enterprise's network suffered a ransomware attack, the system detected abnormal encryption behavior on the core transaction database server and immediately initiated a risk assessment process. The cybersecurity monitoring platform collected propagation parameter data from the affected areas, including indicators such as network traffic anomaly degree, security alarm density, and device vulnerability scores, forming the following basic dataset:

[0094] Table 1: Sampling data table of risk transmission parameters.

[0095]

[0096] The system first cleans and standardizes the collected propagation parameters. In the financial case, the raw data includes monitoring indicators from over 300 network devices. The data cleaning process eliminates outlier sampling points caused by network latency and corrects distorted values ​​caused by sensor malfunctions. Standardization converts the indicator values ​​of each dimension to a uniform dimension of 0-100, eliminating unit differences between different monitoring indicators. The processed data is then stored in a distributed analysis cluster for subsequent calculations.

[0097] The median was calculated using a robust statistical method. For the 85 affected regions in the aforementioned financial case, the system excluded the highest and lowest 10% extreme values ​​before calculating the 50th percentile of the remaining data. This method effectively suppressed the interference of a few outlier regions on the overall statistical results. During the calculation process, the system monitored the skewness and kurtosis characteristics of the data distribution in real time. When the distribution shape significantly deviated from the normality assumption, it automatically switched to a more suitable nonparametric estimation algorithm. The median calculation result was used as a benchmark value for subsequent interval division.

[0098] The deviation range is set with consideration for network security level protection requirements. In the financial industry case, the system divides the parameter distribution into three ranges: the low deviation range covers parameter values ​​below 35% of the median, corresponding to the standard monitoring level; the medium deviation range includes parameter values ​​between 35% and 80% of the median, triggering enhanced monitoring measures; and the high deviation range includes parameter values ​​exceeding 80% of the median, requiring immediate action. The range boundary values ​​are dynamically adjusted according to network size; large networks use a more granular five-level division, while small networks use a simplified three-level division. The preset intensity value corresponding to each range has been calibrated by industry experts, forming a standardized risk rating system.

[0099] The matching process for the target deviation range employs an efficient search algorithm. When analyzing the propagation relationship between the transaction database (R-101) and the backup server (R-205) in a financial case, the system calculates the absolute deviation of their propagation parameters to be 23.3. Based on the current median of 62.5, this deviation accounts for 37.3% of the median, falling within the preset medium deviation range. The matching result triggers the system to generate a medium-risk propagation path alert, prompting the security team to pay attention to the potential threat spread in this direction. The matching algorithm has an optimized caching mechanism for large-scale networks, directly returning cached results for repeatedly calculated region pairs.

[0100] The application of risk propagation strength values ​​is reflected in multiple security control stages. In the financial case, the system marks the propagation strength from the transaction database to the core switch as high-level, automatically triggering traffic mirroring and deep packet inspection along that path. Medium-level strength marking is applied to the connection between the database and the application server, enabling protocol compliance checks. Low-level marking only involves routine monitoring and logging. The dynamic update mechanism of the strength values ​​reassesses every 5 minutes, reflecting changes in network status in real time.

[0101] The visual interface intuitively displays the intensity analysis results. On the large screen of the security operations and maintenance center of a financial enterprise, the connecting lines in the network topology diagram are displayed with different colors and thicknesses according to the propagation intensity values: thick red lines represent high-intensity propagation paths, medium yellow lines correspond to medium intensity, and thin green lines represent low intensity. Hovering the mouse over the line displays detailed parameter information, including the deviation value calculation process and the basis for interval matching. The view supports filtering by intensity threshold, helping operations and maintenance personnel quickly locate critical risk paths.

[0102] The continuous optimization of the strength assessment model relies on a feedback mechanism. After the financial case is resolved, the system collects comparative data between the actual attack paths and the predicted results. Analysis shows that the predictive model underestimates the propagation strength between database clusters, and the parameter weights for this type of device are subsequently adjusted. After the optimized model is validated in the test environment, it is gradually pushed to the production system through a canary release approach. The version control system records detailed descriptions of each model change and supports reverting to historical versions when necessary.

[0103] Regional differences provide in-depth insights. Analysis of financial cases revealed that transaction databases and clearing systems, both located in core risk areas, exhibited different propagation characteristics. Databases primarily displayed high-intensity peer-to-peer propagation, while clearing systems exhibited moderate-intensity broadcast propagation. This difference prompted security teams to design differentiated protection strategies for different types of critical systems, enhancing the effectiveness of defensive measures.

[0104] The assessment results generate reports that meet compliance requirements. Upon completion of financial case handling, the system automatically generates risk assessment reports conforming to industry regulatory formats, detailing the basis for determining the intensity of transmission in each region. Data visualization in the reports uses standard charts approved by regulatory agencies, facilitating external review. Report version management ensures the traceability of each submission, supporting rapid response to regulatory inquiries.

[0105] Example 5: The dynamic generation process of prioritizing network security risk responses and generating protection strategies. This process transforms risk assessment results into actionable security measures through an intelligent decision-making mechanism. At the operational level, the system first parses the response priority data structure, which is organized using a tree-like hierarchical model. The root node represents the highest priority core risk area, and branch nodes sequentially arrange peripheral risk areas and potential risk propagation areas. Each response node contains complete contextual information, including metadata such as area identifier, risk level, list of affected assets, and prerequisite dependencies. The topological relationships between nodes accurately reflect the critical paths derived from the risk propagation weight graph, ensuring that the response order conforms to the actual threat diffusion patterns.

[0106] The extraction of operational parameters employs multi-source data fusion technology. For each response node, the system retrieves basic device information from the configuration management database, imports the latest detection results from the vulnerability scanning system, and collects recent communication pattern characteristics from the traffic analysis platform. This raw data is normalized to generate a standardized set of operational parameters. The parameter set uses a hierarchical storage structure: the basic layer contains static attributes such as device model and IP address; the dynamic layer records real-time status such as current CPU load and memory usage; and the security layer summarizes risk indicators such as existing vulnerabilities and abnormal sessions. The parameter extraction module has a built-in data quality check mechanism that automatically identifies and repairs missing fields or abnormal values, ensuring the reliability of subsequent decision-making.

[0107] The parameter sequence is constructed following a strict order of response priority. The system arranges the operation parameters of each response node in descending order of priority, forming a linear execution sequence. Logical checkpoints are inserted between adjacent nodes in the sequence to verify whether the effects of the preceding operations have achieved the expected results. The sequence encoding uses a lightweight binary format, balancing transmission efficiency and parsing performance. In large network environments, the system supports dividing the complete sequence into multiple subsequences for parallel processing, ensuring the atomicity and consistency of operations through a distributed transaction mechanism. The sequence version control function records the history of each modification, supporting rapid rollback to any stable version.

[0108] The behavioral decision-making model employs a hybrid intelligent approach in its architecture. The core of the model comprises two main components: a rule-based inference engine and a deep learning network. The rule-based inference engine loads a pre-defined security policy library from the organization, which is categorized and stored according to multiple dimensions such as network region, asset type, and threat level. The deep learning network is trained based on historical handling cases and is capable of recognizing complex environmental feature patterns. The outputs of the two components are fused through a weighted voting mechanism to generate the final protection policy instruction. A feature selection mechanism is specifically designed in the model input layer to automatically filter parameters irrelevant to the current risk scenario, improving decision-making efficiency. The model update mechanism supports online learning, using the results of each manual adjustment as new samples for training.

[0109] The generation process of protection policy instructions emphasizes executability and accuracy. The system output instructions include complete elements such as specific operation commands, target devices, execution parameters, and expected effects. For network isolation operations, the instructions explicitly specify the source IP, destination port, and protocol type to be blocked; for patch upgrade operations, accurate patch numbers and installation sequences are provided. The instruction format is compatible with the control interfaces of mainstream security devices, including firewalls, intrusion prevention systems, and endpoint protection platforms. After key instructions are generated, their execution effects are automatically simulated to check for business interruption risks or policy conflicts, triggering a manual review process if necessary.

[0110] Risk mitigation operations employ a tiered authorization mechanism. High-priority core area operations are executed automatically and immediately by the system; medium-priority operations require online confirmation from the security supervisor before execution; and low-priority operations are scheduled and processed periodically in a planned task queue. The execution engine monitors the completion status of each operation in real time, automatically attempting backup solutions or escalating the process for failed operations. Operation logs record detailed information such as execution time, operators, and scope of impact, seamlessly integrating with network change management processes. Resource contention during execution is resolved using a distributed lock mechanism to ensure the orderly execution of concurrent operations.

[0111] The effectiveness of operations is verified through a multi-dimensional evaluation system. After each protective measure is implemented, the system continuously monitors changes in indicators such as traffic patterns, system logs, and security alerts in the target area. The effectiveness evaluation algorithm compares the differences in key indicators before and after implementation to calculate the degree of risk mitigation. For operations that do not meet expectations, the system automatically analyzes the reasons and generates corrective suggestions, such as adjusting the granularity of firewall rules or increasing the frequency of vulnerability detection. Verification data is fed back to the behavioral decision model, forming a closed-loop optimization mechanism. Operations that fail to achieve ideal results over a long period are marked for review, and their necessity is reassessed by the security team.

[0112] The anomaly handling process emphasizes rapid recovery capabilities. When a protective operation is detected as causing an anomaly in the business system, the system immediately initiates a rollback procedure to undo the most recent operational changes. The rollback process follows the reverse order of dependencies to ensure the consistency of system state recovery. For complex fault scenarios, the system provides diagnostic tools to quickly locate the root cause of the problem, such as a policy conflict analyzer or a network path tracer. All anomalies are handled according to their severity; critical business interruptions trigger emergency response plans, while non-critical issues are incorporated into the regular fault handling process.

[0113] The knowledge management function accumulates experience in handling situations, forming organizational memory. The system structurally stores data such as the sequence of operational parameters, decision-making logic, and actual effects of each risk response process, establishing a searchable case library. Case retrieval supports multi-dimensional conditional queries, helping security personnel quickly find historical handling solutions for similar scenarios. Knowledge base maintenance includes regular deduplication, case classification, and validity labeling to ensure the quality and usability of stored information. Advanced analysis functions can identify common patterns among different cases, assisting in the discovery of potential systemic risks.

[0114] System performance optimizations are specifically designed for large-scale network environments. The acquisition of response node operation parameters employs an incremental update strategy, synchronizing only changed data items. The reasoning process of the behavioral decision model supports distributed computing, splitting large parameter sequences into multiple segments for parallel processing. The generation of protection policy instructions utilizes a caching mechanism, directly returning verified solutions for recurring or similar risk patterns.

[0115] The security audit function meets compliance requirements. The system fully records the entire data chain from priority parsing to the execution of protective operations, including personnel confirmation records at key decision points. Audit logs are stored using tamper-proof technology and support digital signature verification. Regularly generated compliance reports automatically check whether various operations comply with industry regulatory requirements, such as payment system isolation standards in the financial industry or access control specifications for medical data.

[0116] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0117] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A risk assessment method based on network security situation awareness, characterized in that, The method is applied in a network security monitoring platform, which is configured to continuously collect network operation status data. The method includes: The system captures the characteristic attributes of target network security events through a preset threat detection mechanism, and extracts the network resource entities affected by the target network security events during the monitoring period based on the characteristic attributes. Based on the threat level label of the target network security event, the security area covered by the network resource entity is divided into core risk area, edge risk area and security buffer zone, and potential risk propagation area is identified in the security area not covered by the network resource entity. The core risk area, edge risk area, security buffer zone and potential risk propagation area together constitute a risk assessment object set. Calculate the risk propagation intensity value between any two adjacent regions in the risk assessment object set, and construct a risk propagation weight graph of the risk assessment object set using the regions in the risk assessment object set as vertices and the risk propagation intensity value as the edge weight value connecting the vertices. The maximum flow algorithm is applied to analyze the risk propagation weight graph to determine the critical propagation path from the core risk area to other areas, and the response priority order of each area is derived based on the critical propagation path. Based on the response priority order, risk mitigation operations corresponding to each region in the risk assessment object set are triggered sequentially to perform network security protection.

2. The risk assessment method based on network security situation awareness according to claim 1, characterized in that, Based on the aforementioned characteristic attributes, the network resource entities affected by the target network security event during the monitoring period include: The historical security log database is used to statistically analyze the network resource entities affected by the target network security incident within a specified time range; Based on the exposure index of each network resource entity in a security incident, the statistically obtained network resource entities are classified and processed to form one or more risk entity sets. Match the set of target risk entities in the set of risk entities that matches the current threat level label of the target network security event, and take the scope covered by the set of target risk entities as the network resource entities affected by the target network security event during the monitoring period.

3. The risk assessment method based on network security situation awareness according to claim 2, characterized in that, Based on the exposure level indicators of each network resource entity in security incidents, the statistically obtained network resource entities are classified and processed as follows: Obtain the predefined core asset protection zones in the network security monitoring platform; For any network resource entity obtained from the statistics, analyze the core asset protection interval category to which the exposure index of the network resource entity belongs, and assign the network resource entity to the risk entity set corresponding to the identified core asset protection interval category.

4. The risk assessment method based on network security situation awareness according to claim 1, characterized in that, Based on the threat level label of the target network security event, the security area covered by the network resource entity is divided into core risk areas and edge risk areas, including: Identify the primary and secondary affected areas indicated by the threat level label of the target cybersecurity incident; The first range of activity for locating the primary affected part within the security area covered by the network resource entity, and the second range of activity for locating the secondary affected part within the security area covered by the network resource entity; The first activity range is marked as a core risk area within the security area covered by the network security monitoring platform, and the second activity range is marked as a peripheral risk area within the security area covered by the network security monitoring platform.

5. The risk assessment method based on network security situation awareness according to claim 1, characterized in that, Identifying potential risk propagation areas in security areas not covered by the network resource entities includes: Set a main propagation coefficient for the core risk area covered by the network resource entity, and set an auxiliary propagation coefficient for the edge risk area covered by the network resource entity; For security areas not covered by the network resource entities, if they are adjacent to the core risk areas, the security areas with the number of main propagation coefficients are selected as potential risk propagation areas; if they are adjacent to the edge risk areas, the security areas with the number of auxiliary propagation coefficients are selected as potential risk propagation areas.

6. The risk assessment method based on network security situation awareness according to claim 1, characterized in that, Calculating the risk propagation intensity value between any two adjacent areas in the risk assessment object set includes: For adjacent first and second regions in the risk assessment object set, the respective region types of the first and second regions are identified, and the region type includes one of core risk region, edge risk region, safety buffer zone and potential risk propagation region; Based on the identified region type, the initial risk propagation parameters for the first region are derived, and the subsequent risk propagation parameters for the second region are derived. The deviation between the initial risk propagation parameter and the subsequent risk propagation parameter is measured, and the risk propagation intensity value between the first region and the second region is calculated based on the deviation value.

7. The risk assessment method based on network security situation awareness according to claim 6, characterized in that, Calculating the risk transmission intensity value between the first region and the second region based on the deviation value includes: Identify the risk propagation parameters for each region in the set of risk assessment objects, and calculate the median of the distribution of the identified risk propagation parameters; Multiple deviation value ranges are defined based on the median of the distribution, and the target deviation value range in which the measured deviation value between the initial risk propagation parameter and the subsequent risk propagation parameter is located is determined. The preset intensity value corresponding to the target deviation value range is determined as the risk transmission intensity value between the first region and the second region.

8. The risk assessment method based on network security situation awareness according to claim 1, characterized in that, The risk mitigation operations corresponding to each region in the risk assessment object set are triggered sequentially according to the response priority order, including: The operation parameters of each response node in the response priority order are identified, and a parameter sequence is generated based on the identified operation parameters, wherein the order of each parameter in the parameter sequence is consistent with the response priority order; The parameter sequence is input into a pre-trained behavior decision model to output protection strategy instructions for each response node. The system executes corresponding risk mitigation operations according to the output protection policy instructions in order to perform network security protection.

9. A risk assessment system based on network security situation awareness, used to implement the risk assessment method based on network security situation awareness as described in any one of claims 1-8, characterized in that, The system is used in a network security monitoring platform, which is configured to continuously collect network operation status data. The system includes: The event capture unit is used to capture the characteristic attributes of the target network security event through a preset threat detection mechanism, and extract the network resource entities affected by the target network security event within the monitoring period based on the characteristic attributes. The region segmentation unit is used to divide the security area covered by the network resource entity into core risk areas, edge risk areas, and security buffer zones based on the threat level label of the target network security event, and to identify potential risk propagation areas in the security areas not covered by the network resource entity. The core risk areas, edge risk areas, security buffer zones, and potential risk propagation areas together constitute a risk assessment object set. The weighted graph construction unit is used to calculate the risk propagation intensity value between any two adjacent regions in the risk assessment object set, and construct the risk propagation weighted graph of the risk assessment object set by using the regions in the risk assessment object set as vertices and the risk propagation intensity value as the edge weight value connecting the vertices. The sequential derivation unit is used to apply the maximum flow algorithm to analyze the risk propagation weight graph to determine the critical propagation path from the core risk area to other areas, and to derive the response priority order of each area based on the critical propagation path. The protection execution unit is used to sequentially trigger the risk mitigation operations corresponding to each area in the risk assessment object set according to the response priority order, so as to perform network security protection.

10. The system according to claim 9, characterized in that, The protection execution unit is specifically used to: identify the operation parameters of each response node in the response priority order, and generate a parameter sequence based on the identified operation parameters, wherein the order of each parameter in the parameter sequence is consistent with the response priority order; input the parameter sequence into a pre-trained behavior decision model to output protection strategy instructions for each response node through the behavior decision model; and execute the corresponding risk mitigation operations according to the output protection strategy instructions to perform network security protection.