Threat detection response agent security protection method and system based on terminal deployment
By deploying a threat detection and response agent on the endpoint, and combining a rule base and a lightweight AI model for threat detection and tiered response, the problem of slow response and low intelligence in existing endpoint security protection systems is solved, achieving flexible and accurate endpoint protection and model self-adaptation.
Patent Information
- Application Number
- CN202511384981.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-26
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2045-09-26
AI Technical Summary
Existing endpoint security protection systems are weak in responding to advanced persistent threats, fileless attacks, and lateral movement attacks. They rely on manual intervention, lack judgment capabilities, are not flexible in their response actions, consume a lot of endpoint performance, and are difficult to adapt to low- to medium-configuration environments.
Design a threat detection and response agent based on terminal deployment, which monitors terminal behavior data in real time, combines a preset rule base and a lightweight AI model to perform threat detection, provides tiered responses, and transmits the data back to the cloud platform via encrypted communication for iterative optimization of the model and rule base.
It achieves lightweight, intelligent, and interconnected endpoint threat detection, with real-time detection, tiered response, policy linkage, and model self-adaptation capabilities. It improves the accuracy and coverage of threat identification, adapts to various endpoint environments, and supports tiered response based on threat level and unified cloud management of policies/models.
Smart Images

Figure CN120880798A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, specifically to a security protection method and system for a threat detection and response intelligent agent based on terminal deployment. Background Technology
[0002] As endpoints become a key point of attack for attackers, traditional security protection methods such as virus scanning and static rule matching are proving inadequate in dealing with advanced persistent threats (APTs), fileless attacks, and lateral movement attacks. At the same time, threat detection and response systems usually rely on the analysis results of backend operation platforms, resulting in extended response times, poor linkage capabilities, and an inability to achieve rapid closed-loop response at endpoints.
[0003] Although some terminal security protection systems exist, their response capabilities are weak, they rely on manual intervention, lack judgment capabilities, their response actions are not flexible enough, they consume a lot of terminal performance, and they are difficult to adapt to low- and medium-configuration environments. Summary of the Invention
[0004] The purpose of this invention is to solve the above problems by designing a security protection method and system for threat detection and response intelligent agents based on terminal deployment.
[0005] The first aspect of this invention provides a security protection method for a threat detection and response intelligent agent based on terminal deployment, the method comprising the following steps:
[0006] The threat detection and response agent deployed on the endpoint monitors the endpoint's behavioral data, including processes, network, and files, in real time.
[0007] The system quickly screens behavioral data based on a pre-defined rule base and uses a lightweight AI model to detect threats in dynamic behaviors.
[0008] The system assesses the risk level of detected threats and executes tiered response actions based on the assessment results. Low-risk threats are logged or prompted, medium-risk threats are given pop-up warnings and user confirmation is required, and high-risk threats are automatically blocked, terminated, or isolated from the network.
[0009] After completing a threat detection and response operation, the threat detection and response agent, through an encrypted communication channel, transmits the response results and user selection behavior back to the cloud security operations platform in real time.
[0010] Based on user feedback and aggregated data, the lightweight AI model and rule base are iteratively optimized.
[0011] Optionally, in a first implementation of the first aspect of the present invention, the step of rapidly screening behavioral data based on a preset rule base includes:
[0012] Feature fields are extracted from process, network, and file behavior data obtained from real-time terminal monitoring. These feature fields include process path, IP and port of network connection, and path and type of file operation.
[0013] The scattered feature fields are integrated into a structured data sequence in chronological order, and a preset rule base is invoked, which includes the names of malicious processes known to threaten, hash values of suspicious files, and ranges of abnormal network ports.
[0014] The structured data sequence is matched against each rule in the rule base. If data that matches the rule is found, it is marked as a suspected threat, and the matching rule number and related behavioral details are recorded.
[0015] Optionally, in a second implementation of the first aspect of the present invention, the step of calling a lightweight AI model to perform threat detection on dynamic behavior includes:
[0016] For behavioral data that was not marked as a suspected threat after being screened by the rule base, dynamic features were extracted. These dynamic features included the changing trends of process resource usage, the fluctuation patterns of network communication traffic, the frequency of file operations, and their correlations.
[0017] Dynamic features are converted into feature vectors that the model can recognize and input into a lightweight AI model. The degree of deviation is calculated by comparing the current feature vector with the baseline of normal behavior patterns. The lightweight AI model includes a One-Class SVM model and a lightweight graph model.
[0018] When the deviation exceeds a preset threshold, the current dynamic behavior is determined to be abnormal, marked as a potential threat, and the abnormality confidence level is output.
[0019] The system combines suspected threats identified through rapid screening using a rule-based database with potential threats identified through detection by a lightweight AI model, forming a preliminary threat detection result set.
[0020] Optionally, in a third implementation of the first aspect of the present invention, the step of assessing the risk level of the detected threat and executing a graded response action based on the assessment result includes:
[0021] From the detected threat-related behavior data, risk features are extracted for assessment, including process behavior features, network features, file features, and CPU usage features.
[0022] Each extracted risk feature dimension is assigned a corresponding weight, and the risk level is evaluated through a risk scoring function to obtain a comprehensive risk score.
[0023] Based on the preset range of the comprehensive risk score, the threat is divided into three risk levels: low, medium, and high. The corresponding response action is triggered according to the risk level.
[0024] Optionally, in a fourth implementation of the first aspect of the present invention, the risk scoring function is:
[0025]
[0026] in: The overall risk score of the i-th terminal or agent; the higher the value, the greater the potential threat. The raw monitoring data of the i-th terminal includes CPU behavior, file activity, network communication, process behavior, etc. These represent risk functions based on CPU usage patterns, such as sudden increases in CPU utilization or continuous abnormal fluctuations.
[0027] Optionally, in a fifth implementation of the first aspect of the present invention, the threat detection and response agent via the encrypted communication channel, after completing a threat detection and response operation, transmits the response result and user selection behavior back to the cloud security operation platform in real time, including:
[0028] After completing threat detection and response operations, the threat detection and response agent automatically collects the operation data, which includes the threat detection results, the response actions performed, the execution status of the response actions, and the user's selection behavior during the response process.
[0029] The agent sends an encrypted channel establishment request to the cloud security operations platform. The request includes the terminal identifier, agent version information, and encryption method negotiation parameters.
[0030] After receiving the request, the cloud platform returns confirmation information for the establishment of the encrypted channel and the session key. The intelligent agent uses the encryption mechanism in the HTTPS protocol to encrypt the prepared response results and user selection behavior data.
[0031] The intelligent agent sends the encrypted data to the cloud security operation platform in a preset transmission format through the established encrypted channel.
[0032] Optionally, in the sixth implementation of the first aspect of the present invention, the iterative optimization of the lightweight AI model and rule base based on user feedback and aggregated data includes:
[0033] The cloud-based security operations platform receives response results and user selection behavior data from threat detection and response agents on each terminal through an encrypted channel. It categorizes these data according to data type, marking feedback data involving false alarms and false negatives as model optimization data, and marking newly emerging threat feature data as key data for supplementing the rule base.
[0034] The labeled data is combined with the existing threat sample set to form a model training dataset. By adjusting the model parameters, the threshold for judging abnormal behavior and the feature weights are optimized to obtain a lightweight AI model and an optimized rule base after iterative training.
[0035] A second aspect of the present invention provides a threat detection and response intelligent agent security protection system based on terminal deployment, the system comprising:
[0036] The real-time monitoring module is used by the threat detection and response agent deployed on the terminal to monitor the terminal's behavioral data, including processes, network, and files.
[0037] The threat detection module is used to quickly screen behavioral data based on a preset rule base and call a lightweight AI model to detect threats in dynamic behaviors.
[0038] The response decision module is used to assess the risk level of detected threats and execute graded response actions based on the assessment results. For low-risk threats, log recording or prompting is performed; for medium-risk threats, pop-up warnings are executed and user confirmation is awaited; and for high-risk threats, blocking, process termination, or network isolation is automatically performed.
[0039] The communication interface module is used to transmit the response results and user selection behavior back to the cloud security operations platform in real time after the threat detection and response agent completes a threat detection and response operation through an encrypted communication channel.
[0040] The iterative optimization module is used to iteratively optimize the lightweight AI model and rule base based on user feedback and aggregated data.
[0041] A third aspect of the present invention provides a terminal-based threat detection and response agent security protection device, the terminal-based threat detection and response agent security protection device including a memory and at least one processor, the memory storing instructions; the at least one processor calling the instructions in the memory to cause the terminal-based threat detection and response agent security protection device to perform the various steps of the terminal-based threat detection and response agent security protection method as described in any of the preceding claims.
[0042] A fourth aspect of the present invention provides a computer-readable storage medium storing instructions that, when executed by a processor, implement the steps of the terminal-based threat detection and response agent security protection method as described in any of the preceding claims.
[0043] In the technical solution provided by this invention, a threat detection and response intelligent agent deployed on the terminal monitors the terminal's behavioral data, including processes, networks, and files, in real time; it quickly screens the behavioral data based on a preset rule base and calls a lightweight AI model to detect threats in dynamic behaviors; it assesses the risk level of detected threats and executes graded response actions based on the assessment results; after completing a threat detection and response operation, the threat detection and response intelligent agent transmits the response results and user-selected behaviors back to the cloud security operation platform in real time through an encrypted communication channel; based on user feedback and aggregated data, iteratively optimizes the lightweight AI model and rule base; this invention aims to solve... To address the shortcomings of existing endpoint security protection systems, such as slow response, low intelligence, and lack of closed-loop control capabilities, this paper provides a lightweight, intelligent, and interconnected endpoint threat detection and response agent. It features real-time detection, tiered response, policy linkage, and model self-adaptation capabilities. Through a hybrid detection mechanism combining rules and models, it improves the accuracy and coverage of threat identification. Supporting tiered response based on threat level enhances the flexibility and accuracy of endpoint protection. Linked with an operations platform, it enables unified cloud management and push of policies / models, offering controllability and scalability, adaptability to various endpoint environments, and continuous model optimization through user feedback mechanisms, demonstrating self-learning capabilities. Attached Figure Description
[0044] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention.
[0045] Figure 1 A flowchart of a terminal-based threat detection and response agent security protection method provided in an embodiment of the present invention;
[0046] Figure 2 This is a schematic diagram of the structure of a threat detection and response intelligent agent security protection system based on terminal deployment provided in an embodiment of the present invention;
[0047] Figure 3 This is a schematic diagram of the structure of a terminal-based threat detection and response intelligent agent security protection device provided in an embodiment of the present invention. Detailed Implementation
[0048] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” or “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, apparatus, product, or device that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.
[0049] For ease of understanding, the specific process of the embodiments of the present invention is described below. Please refer to [link / reference]. Figure 1 The flowchart of the threat detection and response agent security protection method based on terminal deployment provided in this embodiment of the invention includes the following steps:
[0050] Step 101: The threat detection and response agent deployed on the terminal monitors the terminal's behavioral data, including processes, network, and files, in real time.
[0051] In this embodiment, the Threat Detection and Response Agent (DRAgent) deployed on the terminal runs as a service process within the terminal's operating system. Upon startup, it immediately loads basic monitoring configurations and performs real-time and comprehensive monitoring of the terminal's process, network, and file behavior data. Specifically, for process behavior, it continuously tracks process start and termination times, process IDs, parent process relationships, module loading status, and changes in CPU and memory resource usage. For network behavior, it records the source IP address, destination IP address, communication port, protocol type used, number of bytes transmitted, frequency of data transmission, and connection establishment and disconnection times. For file behavior, it monitors file creation, deletion, modification, and movement operations, recording file paths, operation times, file hash values, permission changes, and whether access to sensitive system directories such as the system registry and user privacy folders was conducted. All monitored behavior data is stored in real-time in a local cache in timestamp order, forming a continuous and complete terminal behavior log.
[0052] Step 102: Quickly screen behavioral data based on a preset rule base, and call a lightweight AI model to perform threat detection on dynamic behaviors;
[0053] In this embodiment, feature fields are extracted from process, network, and file behavior data obtained from real-time monitoring of the terminal. These feature fields include process paths, network connection IPs and ports, and file operation paths and types. The scattered feature fields are integrated into a structured data sequence in chronological order. A preset rule base is then invoked, which includes the names of known malicious processes, hash values of suspicious files, and abnormal network port ranges. The structured data sequence is matched against each rule in the rule base. If data that matches a rule is found, it is marked as a suspected threat, and the matched rule number and related behavior details are recorded.
[0054] In this embodiment, dynamic features are extracted from behavioral data that has not been marked as suspected threats after being screened by the rule base. These dynamic features include trends in process resource usage, fluctuations in network communication traffic, and the frequency and relationships of file operations. The dynamic features are converted into feature vectors that can be recognized by the model and input into a lightweight AI model. The deviation is calculated by comparing the current feature vector with the baseline of normal behavior patterns. The lightweight AI model includes a One-Class SVM model and a lightweight graph model. When the deviation exceeds a preset threshold, the current dynamic behavior is determined to be abnormal, marked as a potential threat, and an anomaly confidence level is output. The suspected threats marked by the rule base and the potential threats marked by the lightweight AI model are summarized to form a preliminary threat detection result set.
[0055] Step 103: Assess the risk level of the detected threats and execute tiered response actions based on the assessment results;
[0056] In this embodiment, low-risk threats perform log recording or prompting operations, medium-risk threats perform pop-up warnings and wait for user confirmation, and high-risk threats automatically perform blocking, process termination, or network isolation operations.
[0057] In this embodiment, the system systematically sorts out and extracts key features that can be used for risk assessment from the detected threat-related behavioral data. Process behavior features include whether the process is an unknown program, whether there is process injection or code obfuscation, and whether child processes are frequently created. Network features include whether the connected IP address is in the known malicious IP list, whether communication uses non-standard ports, whether data transmission is encrypted and has no obvious business association, and whether there are abnormal connection frequencies or traffic fluctuations. File features involve whether sensitive system directories such as the operating system kernel file directory and user permission configuration file directory are accessed or modified, whether a large number of files are encrypted or deleted, and whether the file hash value matches the malicious sample library. CPU usage features include whether there is a sudden increase in CPU utilization without business triggers, whether it is in a continuous high-load state and cannot be alleviated by normal operations. These features together constitute the basic dimensions of risk assessment, ensuring comprehensive coverage of the terminal behavior level that threats may involve.
[0058] Based on the degree of influence of each risk feature dimension on the severity of the threat, corresponding weights are assigned to each dimension. For example, process behavior features involving process injection, network features connecting to known malicious IPs, and file features encrypting sensitive files have a greater impact on the threat level and are assigned higher weights; while features such as only slight CPU fluctuations have a smaller impact and are assigned lower weights. Subsequently, the features of each dimension are quantitatively calculated through a risk scoring function: first, the specific performance of each feature is converted into a corresponding score; if it matches the malicious feature, a high score is assigned, and if there is no abnormality, a low score is assigned. Then, each feature score is multiplied by its corresponding weight. Finally, all the product results are summed to obtain the comprehensive risk score of the threat, thereby quantitatively reflecting the overall severity of the threat.
[0059] The system presets three risk score ranges, corresponding to low, medium, and high risk levels, respectively. When the overall risk score is below the first threshold, it is judged as a low-risk threat. The system automatically performs log recording operations, recording in detail the time of the threat occurrence, the processes / files / network information involved, and the risk level, and generates a simple prompt in the terminal notification bar. When the score is between the two thresholds, it is judged as a medium-risk threat, and a pop-up warning is immediately triggered, displaying threat details, risk level, and suggested handling methods. After the user views the information, they can choose "Allow," "Block," or "Further Analysis," and the corresponding operation will be executed according to the user's instructions. When the score is above the second threshold, it is judged as a high-risk threat. Without user intervention, the emergency response mechanism is directly activated, performing operations such as forcibly terminating the process, cutting off abnormal network connections, and isolating the at-risk files to a dedicated secure area to quickly curb the spread of the threat.
[0060] In this embodiment, the risk scoring function is:
[0061]
[0062] in: The overall risk score of the i-th terminal or agent; the higher the value, the greater the potential threat. The raw monitoring data of the i-th terminal includes CPU behavior, file activity, network communication, process behavior, etc. These represent risk functions based on CPU usage patterns, such as sudden increases in CPU utilization or continuous abnormal fluctuations.
[0063] Step 104: After completing a threat detection and response operation, the threat detection and response agent transmits the response results and user selection behavior back to the cloud security operations platform in real time through the encrypted communication channel.
[0064] In this embodiment, after completing the threat detection and response operations, the threat detection and response agent automatically collects the operation data, which includes the threat detection results, the executed response actions, the execution status of the response actions, and the user's selection behavior during the response process. The agent sends an encrypted channel establishment request to the cloud security operations platform, which includes the terminal identifier, agent version information, and encryption method negotiation parameters. After receiving the request, the cloud platform returns confirmation information for the encrypted channel establishment and a session key. The agent uses the encryption mechanism in the HTTPS protocol to encrypt the prepared response results and user selection behavior data. The agent sends the encrypted data to the cloud security operations platform through the established encrypted channel in a preset transmission format.
[0065] Step 105: Based on user feedback and aggregated data, iteratively optimize the lightweight AI model and rule base.
[0066] In this embodiment, the cloud security operation platform receives response results and user selection behavior data from threat detection response agents of each terminal through an encrypted channel. The response results include successful interception, process termination, and false alarm confirmation, while the user selection behavior includes allowing access and adding to the whitelist. The platform classifies the data according to the data type, marking feedback data involving false alarms and missed alarms as key data for model optimization, and marking newly emerging threat feature data as key data for supplementing the rule base.
[0067] The received feedback data and summary data are cleaned to remove duplicate, invalid, and incorrectly formatted data. For example, duplicate false alarm records reported by the same terminal are deleted. At the same time, the valid data is standardized to unify the data format and description method. For example, the different descriptions of process injection behavior of different terminals are unified into standard terms to ensure that the data can be effectively identified and used by subsequent processing steps.
[0068] Data is labeled based on user-selected behaviors. For example, detection results marked as false alarms by users are labeled with false alarm tags and the corresponding behavioral characteristics are recorded; processes or files selected to be allowed by users are labeled with trust tags and related attributes. These tags will serve as important references for model training and rule base optimization, clarifying the actual threat status corresponding to the data.
[0069] The platform calls the model training module to combine the labeled feedback data with the existing threat sample set and security event labels to form a model training dataset. Using an incremental learning approach, the new dataset is input into a lightweight AI model such as One-ClassSVM or a lightweight graph model. By adjusting the model parameters, the model's judgment threshold and feature weights for abnormal behavior are optimized, enabling the model to identify previously false or missed behavior patterns and improve the model's detection accuracy.
[0070] The analysis summarizes new threat features not covered by the existing rule base. Combining these features with an expert knowledge base, the analysis transforms them into specific rule entries. For example, newly discovered malicious file hash values and abnormal network connection patterns are added to the rule base. At the same time, the analysis checks the existing rules, deletes outdated or redundant rules, and adjusts the matching thresholds of the rules to ensure that the rule base can accurately identify newly emerging threats.
[0071] The lightweight AI model and optimized rule base, after iterative training, are validated in a test environment. Historical threat data and newly collected typical data are input to check the detection accuracy of the model and the matching effect of the rule base. The validated model version and rule base update are selected, and the parts with obvious defects found during the validation process are removed to ensure the reliability of the optimized model and rule base.
[0072] The platform dynamically distributes the verified, optimized, lightweight AI model and rule base to the threat detection and response agents on each terminal via an encrypted channel. After receiving the model and rule base, the agent replaces the original model and rule base, loads and takes effect locally, and completes the deployment of this iteration optimization, enabling the terminal to apply the updated model and rules for threat detection and response.
[0073] In this embodiment, bidirectional encrypted communication with the operation platform is supported via encrypted channels such as HTTPS and MQTT. The transmitted content includes terminal detection logs, policy synchronization, model update instructions, and user feedback data, ensuring integrity and confidentiality during transmission. Users can input query requests in natural language on the terminal side, such as "What attacks have occurred recently?" or "How many isolation operations were performed in a week?". The agent's built-in semantic recognition module can understand the user's input intent and extract keywords, identifying key elements such as query target, time range, and content type. The agent packages the structured query intent into an API request, which is then transmitted to the operation platform. The platform interface retrieves multiple data sources, including the security log database, threat intelligence database, and alarm record database, to complete the query summary analysis. The results are returned to the terminal side in real time in the form of structured tables, charts, and summary reports for user viewing. The agent can achieve a WYSIWYG security operation interactive experience through semantic input, improving information acquisition efficiency, lowering the usage threshold, and enhancing user perceived value.
[0074] In this embodiment, the agent runs as a service process in the terminal operating system. After startup, it loads policy rules and models; scans the system behavior log every 5 seconds to determine if there are rule hits or abnormal behaviors; if a hit is detected: it determines the threat level; executes corresponding response actions (such as kill or isolation); reports to the operations platform and waits for policy feedback. The platform can dynamically push response commands according to the policy, via MQ / HTTPS, etc., and the agent executes and records logs. After the user confirms the result, the information is sent back to the platform for model feedback and updates.
[0075] Please see Figure 2 A schematic diagram of the structure of a terminal-based threat detection and response intelligent agent security protection system provided in this embodiment of the invention. The system includes:
[0076] The real-time monitoring module is used by the threat detection and response agent deployed on the terminal to monitor the terminal's behavioral data, including processes, network, and files.
[0077] The threat detection module is used to quickly screen behavioral data based on a preset rule base and call a lightweight AI model to detect threats in dynamic behaviors.
[0078] The response decision module is used to assess the risk level of detected threats and execute graded response actions based on the assessment results. For low-risk threats, log recording or prompting is performed; for medium-risk threats, pop-up warnings are executed and user confirmation is awaited; and for high-risk threats, blocking, process termination, or network isolation is automatically performed.
[0079] The communication interface module is used to transmit the response results and user selection behavior back to the cloud security operations platform in real time after the threat detection and response agent completes a threat detection and response operation through an encrypted communication channel.
[0080] The iterative optimization module is used to iteratively optimize the lightweight AI model and rule base based on user feedback and aggregated data.
[0081] Figure 3This is a schematic diagram of a terminal-based threat detection and response intelligent agent security protection device 300 provided in an embodiment of the present invention. The terminal-based threat detection and response intelligent agent security protection device 300 can vary significantly due to different configurations or performance. It may include one or more central processing units (CPUs) 310 (e.g., one or more processors) and a memory 320, and one or more storage media 330 (e.g., one or more mass storage devices) for storing applications 333 or data 332. The memory 320 and storage media 330 can be temporary or persistent storage. The program stored in the storage media 330 may include one or more modules (not shown in the diagram), each module may include a series of instruction operations on the terminal-based threat detection and response intelligent agent security protection device 300. Furthermore, the processor 310 may be configured to communicate with the storage media 330 and execute a series of instruction operations in the storage media 330 on the terminal-based threat detection and response intelligent agent security protection device 300 to implement the method provided in the above embodiment.
[0082] The endpoint-based threat detection and response agent security protection device 300 may also include one or more power supplies 340, one or more wired or wireless network interfaces 350, one or more input / output interfaces 360, and / or one or more operating systems 331, such as Windows Server, Mac OS X, Unix, Linux, FreeBSD, etc. Those skilled in the art will understand that... Figure 3 The terminal-based threat detection and response agent security protection device structure shown does not constitute a limitation on the computer device provided by the present invention. It may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0083] The present invention also provides a computer-readable storage medium, which can be a non-volatile computer-readable storage medium or a volatile computer-readable storage medium, wherein the computer-readable storage medium stores instructions that, when executed on a computer, cause the computer to perform the various steps of the terminal-based threat detection and response intelligent agent security protection method provided in the above embodiments.
[0084] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the above-described equipment or apparatus / unit can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0085] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0086] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely preferred examples and are not intended to limit the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of the present invention is defined by the appended claims and their equivalents.
Claims
1. A security protection method for threat detection and response intelligent agents deployed on terminals, characterized in that, The method includes the following steps: The threat detection and response agent deployed on the endpoint monitors the endpoint's behavioral data, including processes, network, and files, in real time. The system quickly screens behavioral data based on a pre-defined rule base and uses a lightweight AI model to detect threats in dynamic behaviors. The system assesses the risk level of detected threats and executes tiered response actions based on the assessment results. Low-risk threats are logged or prompted, medium-risk threats are given pop-up warnings and user confirmation is required, and high-risk threats are automatically blocked, terminated, or isolated from the network. After completing a threat detection and response operation, the threat detection and response agent, through an encrypted communication channel, transmits the response results and user selection behavior back to the cloud security operations platform in real time. Based on user feedback and aggregated data, the lightweight AI model and rule base are iteratively optimized.
2. The threat detection and response intelligent agent security protection method based on terminal deployment as described in claim 1, characterized in that, The rapid screening of behavioral data based on a preset rule base includes: Feature fields are extracted from process, network, and file behavior data obtained from real-time terminal monitoring. These feature fields include process path, IP and port of network connection, and path and type of file operation. The scattered feature fields are integrated into a structured data sequence in chronological order, and a preset rule base is invoked, which includes the names of malicious processes known to threaten, hash values of suspicious files, and ranges of abnormal network ports. The structured data sequence is matched against each rule in the rule base. If data that matches the rule is found, it is marked as a suspected threat, and the matching rule number and related behavioral details are recorded.
3. The threat detection and response intelligent agent security protection method based on terminal deployment as described in claim 2, characterized in that, The process of calling a lightweight AI model to perform threat detection on dynamic behavior includes: For behavioral data that was not marked as a suspected threat after being screened by the rule base, dynamic features were extracted. These dynamic features include the changing trend of process resource usage, the fluctuation pattern of network communication traffic, the frequency of file operations, and their correlations. Dynamic features are converted into feature vectors that the model can recognize and input into a lightweight AI model. The degree of deviation is calculated by comparing the current feature vector with the baseline of normal behavior patterns. The lightweight AI model includes a One-Class SVM model and a lightweight graph model. When the deviation exceeds a preset threshold, the current dynamic behavior is determined to be abnormal, marked as a potential threat, and the abnormality confidence level is output. The system combines suspected threats identified through rapid screening using a rule-based database with potential threats identified through detection by a lightweight AI model, forming a preliminary threat detection result set.
4. The threat detection and response intelligent agent security protection method based on terminal deployment as described in claim 1, characterized in that, The process of assessing the risk level of detected threats and executing tiered response actions based on the assessment results includes: From the detected threat-related behavior data, risk features are extracted for assessment, including process behavior features, network features, file features, and CPU usage features. Each extracted risk feature dimension is assigned a corresponding weight, and the risk level is evaluated through a risk scoring function to obtain a comprehensive risk score. Based on the preset range of the comprehensive risk score, the threat is divided into three risk levels: low, medium, and high. The corresponding response action is triggered according to the risk level.
5. The threat detection and response intelligent agent security protection method based on terminal deployment as described in claim 4, characterized in that, The risk scoring function is: ; in: The overall risk score of the i-th terminal or agent; the higher the value, the greater the potential threat. The raw monitoring data of the i-th terminal includes CPU behavior, file activity, network communication, process behavior, etc. These represent risk functions based on CPU usage patterns, such as sudden increases in CPU utilization or continuous abnormal fluctuations.
6. The threat detection and response agent security protection method based on terminal deployment as described in claim 1, characterized in that, After completing a threat detection and response operation via an encrypted communication channel, the threat detection and response agent transmits the response result and user selection behavior back to the cloud security operations platform in real time, including: After completing threat detection and response operations, the threat detection and response agent automatically collects the operation data, which includes the threat detection results, the response actions performed, the execution status of the response actions, and the user's selection behavior during the response process. The agent sends an encrypted channel establishment request to the cloud security operations platform. The request includes the terminal identifier, agent version information, and encryption method negotiation parameters. After receiving the request, the cloud platform returns confirmation information for the establishment of the encrypted channel and the session key. The intelligent agent uses the encryption mechanism in the HTTPS protocol to encrypt the prepared response results and user selection behavior data. The intelligent agent sends the encrypted data to the cloud security operation platform in a preset transmission format through the established encrypted channel.
7. The threat detection and response intelligent agent security protection method based on terminal deployment as described in claim 1, characterized in that, The iterative optimization of the lightweight AI model and rule base based on user feedback and aggregated data includes: The cloud-based security operations platform receives response results and user selection behavior data from threat detection and response agents on each terminal through an encrypted channel. It categorizes these data according to data type, marking feedback data involving false alarms and false negatives as model optimization data, and marking newly emerging threat feature data as key data for supplementing the rule base. The labeled data is combined with the existing threat sample set to form a model training dataset. By adjusting the model parameters, the threshold for judging abnormal behavior and the feature weights are optimized to obtain a lightweight AI model and an optimized rule base after iterative training.
8. A threat detection and response intelligent agent security protection system based on terminal deployment, characterized in that, The system includes: The real-time monitoring module is used by the threat detection and response agent deployed on the terminal to monitor the terminal's behavioral data, including processes, network, and files. The threat detection module is used to quickly screen behavioral data based on a preset rule base and call a lightweight AI model to detect threats in dynamic behaviors. The response decision module is used to assess the risk level of detected threats and execute graded response actions based on the assessment results. For low-risk threats, log recording or prompting is performed; for medium-risk threats, pop-up warnings are executed and user confirmation is awaited; and for high-risk threats, blocking, process termination, or network isolation is automatically performed. The communication interface module is used to transmit the response results and user selection behavior back to the cloud security operations platform in real time after the threat detection and response agent completes a threat detection and response operation through an encrypted communication channel. The iterative optimization module is used to iteratively optimize the lightweight AI model and rule base based on user feedback and aggregated data.
9. A terminal-based threat detection and response intelligent agent security protection device, characterized in that, The terminal-based threat detection and response agent security protection device includes a memory and at least one processor, wherein the memory stores instructions; the at least one processor invokes the instructions in the memory to cause the terminal-based threat detection and response agent security protection device to perform each step of the terminal-based threat detection and response agent security protection method as described in any one of claims 1-7.
10. A computer-readable storage medium storing instructions thereon, characterized in that, When the instructions are executed by the processor, they implement the various steps of the terminal-based threat detection and response agent security protection method as described in any one of claims 1-7.
Citation Information
Patent Citations
Terminal threat detection and response method and engine
CN109255238A
Network security threat intelligent identification method based on generative large model
CN119921976A
Network security compliance intelligent protection system for enterprise multi-source data fusion
CN119966735A
Dynamic security risk assessment and intelligent response system and method based on AI
CN120321033A
Dynamic network security shielding system
WO2025111588A1
Cited By
Host security detection method, electronic equipment, storage medium and program product
CN121486018A