Network connection intelligent scheduling method and system based on multi-dimensional dynamic reputation evaluation and cooperative joint defense

By using multi-dimensional behavioral sequence analysis and dynamic reputation modeling, the problem of identifying low-frequency, slow attacks in existing technologies has been solved, enabling real-time and flexible protection of communication entities and improving the efficiency of network protection and resource utilization.

CN121000474APending Publication Date: 2025-11-21王嘉宏
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511227089.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-29
Publication Date
2025-11-21

AI Technical Summary

Technical Problem

Existing network protection solutions lack continuous tracking and analysis of the behavioral sequences of communication entities. The reputation assessment mechanism is static and singular, lacking the ability to integrate multi-source intelligence. The scheduling mechanism lacks flexibility and real-time performance, and lacks cross-device policy linkage capabilities, resulting in difficulty in identifying low-frequency, slow attacks and excessive resource consumption.

Method used

It employs multi-dimensional behavioral sequence analysis and dynamic reputation modeling, intercepts communication requests in real time, extracts multi-dimensional features, establishes a dynamic reputation database, integrates historical behavior with the current request anomaly level, calculates reputation scores using a recursive penalty algorithm, and achieves dynamic scheduling through multi-source threat intelligence fusion and policy mapping table, supporting cross-device policy linkage.

Benefits of technology

It achieves efficient identification and protection against low-frequency, slow attacks, reduces resource consumption, improves the real-time nature and flexibility of protection, and ensures unimpeded flow of critical business traffic.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure FT_2
    Figure FT_2
  • Figure FT_3
    Figure FT_3
Patent Text Reader

Abstract

The invention discloses a network protection method and system based on multi-dimensional behavior sequence analysis and dynamic reputation modeling. The method comprises the following steps: intercepting a connection request in real time at a network access point and extracting features; establishing a historical behavior sequence of a dynamic reputation library storage communication entity; a recursive penalty algorithm based on a time decay factor is adopted, and a historical reputation score, external threat intelligence and other dimensions are fused to generate a real-time dynamic reputation score; matching a strategy mapping table according to a preset matching strategy; implementing a push-back coverage mechanism on the requests which are not passed immediately; an overall implementation scheme of cooperative joint defense is used; through an innovative push-back coverage mechanism, the state and the number of queue items maintained for each abnormal communication entity in the system are constant and decoupled from the total attack request amount, the expandability and the anti-pressure ability are extremely high, the cost for resisting flood attacks of any scale can be substantially reduced theoretically, and the method is suitable for popularization and application. And the protection effect on persistent malicious behaviors is obviously improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of computer networks and network security technology, and in particular to a network connection intelligent scheduling method and system based on multi-dimensional behavior analysis and dynamic reputation assessment. The method and system are deployed at the network boundary to perform real-time analysis, reputation assessment, and proactive scheduling of requests during the connection establishment phase. This efficiently addresses various network resource abuse behaviors, including distributed denial-of-service (DDoS) attacks and low-frequency slow attacks, while ensuring unimpeded flow of critical business traffic. Background Technology

[0002] With the rapid development of internet technology, cyberattacks have become increasingly complex and frequent. Distributed Denial-of-Service (DDoS) attacks, credential stuffing attacks, malicious web crawlers, and vulnerability scanning threats continue to challenge network security defenses. The core objective of these attacks is to exhaust the target's connection, computing, or bandwidth resources, causing service unavailability.

[0003] Existing protection solutions, such as static rule-based access control lists (ACLs), rate limiting based on simple thresholds, and centralized traffic scrubbing centers, all have significant limitations: rigid rules, lack of intelligent differentiation capabilities, extremely high construction and operation costs, and the fact that each security component typically operates independently, forming "security silos" and lacking effective intelligence sharing and coordination mechanisms. More importantly, existing solutions lack the ability to analyze the historical behavioral sequences of communication entities from multiple dimensions, making it difficult to identify well-disguised low-frequency, slow attacks, and their resource consumption is often proportional to the attack traffic, easily leading to performance bottlenecks.

[0004] Therefore, there is an urgent need in this field for a forward protection solution that can achieve real-time accurate assessment, proactive intelligent scheduling, decoupling of resource consumption, and cross-domain collaborative defense, so as to intervene at the TCP / IP connection establishment stage, transforming passive cleaning into proactive modulation, and efficiently responding to various resource abuse attacks. Summary of the Invention

[0005] In the field of cybersecurity, especially against persistent malicious behaviors such as Distributed Denial-of-Service (DDoS) attacks, web scraping, and brute-force attacks, traditional protection methods mostly rely on single-request feature matching or static rule bases, lacking the ability to analyze and model the long-term behavioral sequences of communication entities (such as source IPs). The inventors, through research and practice, have discovered the following prominent problems with existing technologies:

[0006] (1) Lack of continuous tracking and analysis of the behavior sequence of communication entities: Existing systems usually only perform feature matching on a single request, and cannot identify communication entities that seem normal in a single request but exhibit obvious malicious behavior in the long term.

[0007] (2) Static and simple credit assessment mechanism: Most systems adopt a fixed credit scoring mechanism, which cannot dynamically adjust the credit value according to the real-time network situation and changes in entity behavior, leading to misjudgment or omission.

[0008] (3) Lack of multi-source intelligence fusion capability: Local detection results and external threat intelligence (such as global IP reputation database and collaborative defense platform) are not effectively integrated, and decision-making lacks a global perspective.

[0009] (4) The scheduling mechanism lacks flexibility and real-time performance: Traditional delayed processing mechanisms cannot efficiently manage a large number of pending requests, especially for multiple requests to the same entity, which lack state coverage and priority scheduling capabilities.

[0010] (5) Lack of cross-device policy linkage capability: protection policies are often limited to a single device and cannot be linked with downstream firewalls, load balancers and other devices, resulting in limited protection effect.

[0011] To address the aforementioned technical problems, this invention proposes a method and system for multi-dimensional behavioral sequence analysis and dynamic reputation modeling, which features continuous learning, dynamic adjustment, multi-source fusion, and collaborative linkage.

[0012] Therefore, this invention provides a method for multi-dimensional behavioral sequence analysis and dynamic reputation modeling, the method comprising the following:

[0013] At the network access point, connection requests from communication entities are intercepted in real time and metadata is extracted. Extracted features include at least the source IP address, timestamp, protocol type, message length, TCP flags, TLS SNI, HTTP User-Agent, request URI, and geographic location. A dynamic reputation database is established to persistently store the historical behavioral state sequence of each communication entity, including but not limited to historical access frequency time series, behavioral entropy value, protocol compliance index, geographic spatiotemporal anomaly indicators, and historical reputation score. A recursive penalty algorithm based on a time decay factor is used to quantify the behavioral deviation of the communication entity. The mathematical expression of the algorithm is: Current behavioral deviation = α × (Historical behavioral deviation × γ^(-Δt) + β × The current request anomaly score is calculated by a pre-trained anomaly detection model. It integrates historical reputation scores, current behavior deviation, and long-term behavior baselines to generate a real-time dynamic reputation score for the communication entity through a non-linear function. The latest behavior indicators and reputation scores are updated to the dynamic reputation database in real time to ensure consistency and timeliness of the status.

[0014] Preferably, the attenuation coefficient γ in the recursive penalty algorithm can be dynamically adjusted according to the network environment threat level. When the threat level is high, γ is reduced to enhance the memory of historical behavior, and when the threat level is low, γ is increased to accelerate reputation recovery.

[0015] Preferably, the current request anomaly degree can be calculated using machine learning models such as isolated forest, autoencoder, or LSTM network to identify the abnormal characteristics of a single request.

[0016] Preferably, the dynamic reputation database adopts a time-series database structure, which supports high-frequency writing and complex aggregation queries.

[0017] Preferably, the long-term behavioral baseline is calculated using a sliding window statistical method, and the window size can be adaptively adjusted according to the business type.

[0018] This invention also provides a method for multi-source threat intelligence fusion and integrated decision-making, the method comprising the following:

[0019] The system queries external multi-source threat intelligence sources in real time, including but not limited to global IP reputation databases, WAF event logs, SIEM system alarms, and intelligence shared by collaborative defense nodes. It then obtains an external threat index for the communication entity from these sources. An adaptive weighted fusion model is used to fuse the local real-time dynamic reputation score with the external threat index to generate a comprehensive threat level. The weight coefficients of the fusion model can be dynamically adjusted based on factors such as entity type, business importance, and real-time attack posture. A dynamically adjustable policy mapping table is maintained, defining the control policies and parameters corresponding to different comprehensive threat levels. The policy set includes immediate allow, soft drop, hard drop, delayed forwarding, bandwidth limiting, connection limit, redirection to a challenge page, and synchronization to a global blacklist. The system queries the policy mapping table based on the comprehensive threat level to generate the final control policy.

[0020] Preferably, the policy mapping table can dynamically adjust policy parameters and execution priorities based on the system's real-time load rate, CPU / memory usage, and global attack situation, or it can be manually set by the administrator.

[0021] Preferably, the external threat intelligence can be obtained in an encrypted manner through a standard API interface to ensure the security of data transmission.

[0022] Preferably, the fusion model is implemented using fuzzy logic or Bayesian networks to handle uncertainty and conflict intelligence.

[0023] Preferably, the policy mapping table supports hot loading, allowing policy logic to be updated without restarting the system.

[0024] The present invention also provides a method for push-over and dynamic scheduling based on reputation queuing, the method comprising the following:

[0025] A reputation priority queue is established to sort requests for processing from highest to lowest based on their real-time reputation score. Requests requiring delayed processing are placed in this reputation queue, with high-reputation requests processed first and low-reputation requests remaining in the queue. When a new request from the same communication entity arrives and the policy decision still requires delayed processing, the system checks if a pending entry for that entity already exists. If it does, the new request's status information (including updated reputation score, timestamp, etc.) overwrites the existing entry, and it is re-inserted into the reputation queue based on the new arrival time. If it does not exist, a new entry is created and inserted into the queue according to its reputation value. This overwriting mechanism does not rely on a fixed time period; each overwriting occurs immediately whenever a new request adds an old request that is already in the queue, ensuring the system always schedules entities with the latest status. Through this mechanism, entities with consistently low reputation due to high-frequency or long-term low-frequency requests will remain in the queue, while high-reputation entities will receive priority processing.

[0026] Preferably, the reputation queue is implemented using an array queue structure to ensure the efficiency of insertion, deletion, and overwrite operations.

[0027] Preferably, the scheduling strategy can dynamically adjust the queue processing rate according to the real-time system load, and automatically reduce the processing priority of low-reputation requests when the load is high.

[0028] Preferably, the queue supports a priority preemption mechanism, allowing high-reputation requests to interrupt the processing flow of low-reputation requests.

[0029] Preferably, the overlay mechanism supports state persistence, allowing unfinished queued tasks to be recovered after a system restart.

[0030] This invention also provides a method for global collaborative defense and intelligence sharing, the method comprising the following:

[0031] A global collaborative agent module is established to communicate with the central collaborative defense platform. Information on communication entities identified locally as high-threat (including behavioral characteristic sequences, reputation scores, and associated malware hashes) is encrypted and anonymized for privacy, and then synchronized to the platform in near real-time. The module subscribes to global high-risk entity intelligence reported by other nodes from the platform. The received global intelligence is incorporated into the fusion decision-making process as a high-priority, high-weight factor during local decision-making. For entities obtained through global intelligence, their reputation score recovery rate locally is lower than that of entities discovered purely locally, thus achieving a longer period of continuous blocking.

[0032] Preferably, the synchronization mechanism employs incremental update and compressed transmission technology to reduce network bandwidth consumption.

[0033] Preferably, the platform supports blockchain-based threat intelligence storage and tracing to ensure the credibility and immutability of the intelligence.

[0034] Preferably, the collaborative agent supports a multi-center architecture to avoid single points of failure.

[0035] The present invention also provides a method for downstream strategy linkage and execution, the method comprising the following:

[0036] The comprehensive threat level or final decision policy is converted into standardized network control commands; the commands adopt open industry standard models and protocols; the commands are sent to policy execution points in the network in real time through the policy delivery interface; downstream devices perform precise forwarding, dropping, rate limiting or remarking operations on the data stream matching the entity according to the commands.

[0037] Preferably, the instruction includes a security level identifier, which downstream devices can dynamically adjust the inspection intensity and depth of the security policy based on the identifier.

[0038] Preferably, the strategy linkage supports bidirectional communication, and downstream devices can feed back the execution results to the upstream decision-making module to form a closed-loop optimization.

[0039] Preferably, the instruction issuance supports a transaction mechanism to ensure the atomicity and consistency of strategy execution.

[0040] Preferably, the linkage interface supports multiple communication protocols to adapt to different device environments. Attached Figure Description

[0041] The specific embodiments of the present invention will be further described in detail below with reference to the accompanying drawings;

[0042] Figure 1 This is a schematic diagram of the system architecture provided in Embodiment 1 of the present invention.

[0043] Figure 2 This is a sequence diagram of the execution of the overlay mechanism provided in Embodiment 2 of the present invention.

[0044] Figure 3 This is a flowchart of mutual reputation assessment provided in Embodiment 3 of the present invention.

[0045] Figure 4 This is the human-machine authentication and reputation restoration provided in Embodiment 4 of the present invention.

[0046] Figure 5 This is the collaborative defense data flow diagram provided in Embodiment 5 of the present invention. Detailed Implementation

[0047] Example 1:

[0048] This embodiment proposes a method and system for multi-dimensional behavioral sequence analysis and dynamic reputation modeling, such as Figure 1 As shown, the method and system include the following steps:

[0049] Step S101: Deploy high-performance processing equipment at the network access point and configure network parameters.

[0050] Step S102: Initialize each functional module of the software system using a layered strategy.

[0051] Step S103: Construct a dynamic reputation database storage structure that supports efficient querying.

[0052] Step S104: Extract multi-dimensional features from network traffic and perform standardization processing.

[0053] Step S105: Calculate dynamic reputation score based on multi-factor weighted model.

[0054] Step S106: Collect threat intelligence data from multiple sources.

[0055] Step S107: Use a fusion algorithm to comprehensively evaluate the reputation score.

[0056] Step S110: Construct a policy mapping table structure that supports hot reloading.

[0057] Step S111: Implement the intelligent overlay management mechanism for the pushback queue.

[0058] Step S112: Establish a two-way intelligence synchronization communication mechanism.

[0059] This embodiment provides the overall architecture and implementation framework of the system, applicable to various network environments. The system adopts a modular design, possessing good scalability and adaptability, and can meet the security protection needs of networks of different sizes.

[0060] In step S101, the system hardware deployment needs to fully consider network throughput processing capabilities. Devices should support line-rate traffic processing to adapt to network environments of different sizes. Network configuration must ensure perfect compatibility with existing network equipment and support multiple network topologies.

[0061] In step S102, the software initialization adopts a layered modular design to ensure that each component can run, upgrade, and maintain independently. The kernel layer is responsible for underlying packet processing and traffic scheduling, the user-mode management layer is responsible for system resource configuration, status monitoring, and fault recovery, and the application layer components provide rich security functions.

[0062] In step S103, the dynamic reputation database design prioritizes query performance and data consistency, employing an optimized storage structure to support fast access. The database supports multiple data types and can completely record the historical behavior of each communication entity.

[0063] In step S104, feature extraction covers protocols at all network layers, providing a comprehensive foundation for behavioral analysis. Basic features are extracted at the network layer, connection state information is analyzed at the transport layer, and high-level protocol features are deeply analyzed at the application layer.

[0064] In step S105, the reputation scoring model employs a multi-factor weighted algorithm, comprehensively considering factors across multiple dimensions. The historical behavior baseline score reflects the entity's long-term behavioral trends, the current request anomaly is calculated in real-time by a machine learning model, and the long-term behavioral pattern analysis identifies slowly changing threat behaviors through sliding window statistics.

[0065] In step S106, the intelligence gathering system supports multi-source data acquisition, providing comprehensive threat awareness capabilities. Data sources include commercial threat intelligence services, open-source threat intelligence, and industry information sharing platforms.

[0066] In step S107, the fusion algorithm employs advanced data fusion technology to provide accurate reputation assessment results.

[0067] In step S110, the policy mapping table adopts a flexible hierarchical structure, supporting multiple policy configuration methods. The mapping table contains multiple reputation score ranges, each corresponding to a specific processing policy and parameter settings.

[0068] In step S111, the overlay mechanism implements intelligent queue management to ensure the effective utilization of system resources. Based on the latest state principle, the overlay mechanism always retains the latest request state of the same entity, avoiding the processing of outdated request information.

[0069] In step S112, the two-way intelligence synchronization mechanism establishes a comprehensive information sharing system. The synchronization mechanism supports both real-time and batch synchronization modes, allowing the selection of an appropriate synchronization method based on the importance and urgency of the data.

[0070] Example 2:

[0071] This embodiment proposes a complete protection process against SYN Flood attacks, such as... Figure 2 As shown, the protection process includes the following steps:

[0072] Step S201: Capture the incoming data packet and parse the source IP information.

[0073] Step S202: Calculate the recursive penalty value for extremely short time intervals.

[0074] Step S203: Execute the pushback processing strategy based on the credit score decline result.

[0075] Step S204: Enable the overwrite mechanism to maintain the latest task status in the queue.

[0076] This embodiment provides a complete protection process against SYN Flood attacks. For example... Figure 2 As shown, the execution sequence of the coverage mechanism includes steps such as client request sending, connection interceptor feature extraction, policy decision-maker decision, pushback queue management, and policy executor processing.

[0077] In step S201, the system captures the incoming data packet and parses the source IP information.

[0078] In step S202, a recursive penalty algorithm is used for precise behavior evaluation. Due to the extremely high frequency of SYN Flood attacks and the extremely short time difference Δt (γ^Δt ≈ 1), FP_curr rises sharply in a short period of time.

[0079] In step S203, the intelligent threshold mechanism dynamically adjusts the threshold parameters based on the network environment and workload. When the reputation score drops below the threshold, the policy decision-maker automatically upgrades the processing policy to more stringent protection measures.

[0080] The overwrite mechanism in step S204 ensures efficient utilization of system resources. For each attacking IP, the system retains only the most recent task item in the queue, preventing the queue from being overwhelmed by duplicate attack packets.

[0081] Example 3:

[0082] This embodiment proposes a method specifically designed to address low-frequency, slow-speed attack scenarios. For example... Figure 3 As shown, the protection process includes the following steps:

[0083] Step S301: Capture the incoming data packet and parse the source IP information.

[0084] Step S302: Monitor the slow downward trend of the credit score over time.

[0085] Step S303: Upgrade the processing strategy when the reputation value drops to the threshold.

[0086] Step S304: Enable the overlay mechanism to achieve optimized resource allocation.

[0087] This embodiment is specifically designed to address low-frequency, slow-speed attack scenarios. For example... Figure 3 As shown, the credit assessment process includes steps such as data input, data preprocessing, time decay processing, weight allocation, data fusion, and credit score output.

[0088] In step S301, the system captures the incoming data packet and parses the source IP information.

[0089] In step S302, although the single Δt of the low-frequency attack is large, resulting in a significant decay of γ^Δt, FP_curr still maintains a slow but continuous increase through the δ parameter and the recursive calculation mechanism.

[0090] In step S303, the intelligent threshold mechanism dynamically adjusts the threshold parameters based on the network environment and workload. When the reputation score drops below the threshold, the policy decision-maker automatically upgrades the processing policy to more stringent protection measures.

[0091] The overwrite mechanism in step S304 ensures efficient utilization of system resources. For each attacking IP, the system retains only the most recent task in the queue, reducing the impact of low-frequency, slow attacks on the system.

[0092] Example 4:

[0093] This embodiment proposes a mechanism for providing human-machine authentication and reputation restoration, such as... Figure 4 As shown, the protection process includes the following steps:

[0094] Step S401: Generating and distributing challenge questions.

[0095] Step S402: Response verification and reputation reset.

[0096] This embodiment provides a human-machine authentication and reputation restoration mechanism. For example... Figure 4 As shown, when the reputation score of a communication entity is lower than a preset threshold, the system automatically triggers the human-machine authentication process.

[0097] In step S401, the system generates challenge levels of corresponding difficulty based on the reputation score. For entities with reputation scores slightly below the threshold, a simple JavaScript challenge is used; for entities with significantly low reputation scores, a graphical CAPTCHA verification is used; and for entities with extremely low reputation scores, a multi-factor authentication method is used. The challenge content is distributed to the client through a secure channel to ensure the security of the transmission process.

[0098] Step S402 employs a three-level verification mechanism to ensure the accuracy of authentication. The first level of verification checks the compliance of the response format, excluding obviously invalid responses. The second level verifies the correctness of the answer, employing a fault-tolerance mechanism to handle common input errors. The third level of verification analyzes response time patterns to detect automated attack behaviors. Upon successful verification, the system resets the reputation score of the communicating entity to a preset benign value and clears relevant historical penalty records, restoring its normal network access permissions.

[0099] The entire authentication process is automated, requiring no manual intervention, which ensures both security and a good user experience. The system also records various metrics during the authentication process for subsequent behavior analysis and model optimization.

[0100] Example 5:

[0101] This embodiment proposes an overall implementation plan for collaborative defense. For example... Figure 5 As shown, the implementation scheme includes the following steps:

[0102] Step S501: Develop a standardized threat intelligence sharing protocol.

[0103] Step S502: Establish a distributed credit assessment information system.

[0104] Step S503: Implement a rapid emergency response and joint handling mechanism.

[0105] This embodiment provides an overall implementation plan for collaborative defense. For example... Figure 5 As shown, the collaborative defense data flow includes nodes reporting threat intelligence, platform aggregation and analysis, intelligence data distribution, local decision-making integration, and effect feedback.

[0106] In step S501, the system establishes a comprehensive threat intelligence sharing protocol to ensure the effective exchange of security information between different systems. The protocol defines a unified data format and exchange standard, supporting various types of threat information.

[0107] In step S502, a distributed credit evaluation system is constructed to support information synchronization and collaborative analysis among multiple nodes. The system employs distributed database technology to achieve real-time synchronization and consistency maintenance of credit data.

[0108] Step S503 establishes a rapid emergency response mechanism to ensure timely protective measures are taken when a security threat is detected. The response mechanism includes a complete process: threat detection, analysis and confirmation, decision-making, measure implementation, and effectiveness evaluation.

[0109] When node a reports threat intelligence, the platform aggregates and analyzes the data, then distributes the intelligence data to nodes b and c. Nodes b and c then perform local decision-making and integration to reduce the threat posed by the attack sources from node a to nodes b and c.

[0110] The above description is only a preferred embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structural or procedural transformations made based on the content of the present invention specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of the present invention.

Claims

1. A network connection intelligent scheduling method and system based on multi-dimensional dynamic reputation assessment and collaborative defense, applied to network entry devices, characterized in that, The method includes the following steps: During the network connection establishment phase, intercept connection request packets and parse and extract their source IP addresses as communication entity identifiers; Query a dynamic reputation database to obtain the historical status information corresponding to the communication entity identifier. The historical status information includes the last request time, the last internal behavior reputation value, and the last frequency penalty value. Calculate the time difference between the current request time and the previous request time; The current frequency penalty value is calculated using a recursive penalty algorithm, the mathematical expression of which is: Current frequency penalty value = Amplification factor × max(0, previous frequency penalty value - recovery factor^time difference + correction value); Calculate the current internal behavioral reputation score based on the frequency of updates, penalty values, and other behavioral indicators; The current request time, the current internal behavior reputation value, and the current frequency penalty value are immediately updated to the dynamic reputation database; Obtain an external threat score for the communication entity from an external security component; By combining the current internal behavior reputation score with the external threat score, a comprehensive reputation evaluation score is generated; According to a predefined policy mapping table, an active connection scheduling policy is matched for the comprehensive reputation evaluation value. The policy set includes, but is not limited to: immediate release, discard, pushback processing, connection rate limit, setting a maximum concurrent connection limit based on the reputation interval, and returning a challenge to the client. Execute the matched strategy; among which, for the pushback processing strategy, implement the task overwrite mechanism: when a new connection request of the same communication entity arrives and needs to be pushed back, replace any old tasks that already exist in the pushback queue with its new pushback task, and re-queue according to the arrival time of the new task. The dynamic strategy decision-making mechanism is not limited to a single strategy, but dynamically adjusts the strategy type, parameters and execution priority in the strategy mapping table based on multi-dimensional information such as real-time system load, reputation distribution and threat intelligence.

2. The intelligent network connection scheduling method according to claim 1, characterized in that, The parameters in the recursive penalty algorithm are defined as follows: Amplification factor: a constant greater than 0, controlling the amplification intensity of the penalty; Recovery coefficient: a constant greater than 1, controlling the rate at which the penalty value decays over time; Correction value: a constant used to adjust the baseline intensity of the penalty; The algorithm ensures that even if a communicating entity initiates requests at a low frequency, its frequency penalty value will still recursively accumulate and increase as long as the interval between its requests remains shorter than the time required for the penalty value to decay naturally.

3. The intelligent network connection scheduling method according to claim 1, characterized in that, The strategy of returning a challenge to the client can be triggered at any time when the communication entity is not immediately allowed and is in the back-queue stage. The client will receive a prompt message such as "queuing for connection or perform human verification to connect immediately" or similar.

4. The intelligent network connection scheduling method according to claim 1, characterized in that, The method further includes a step of implementing an intelligent reputation recovery mechanism, which includes: Time decay recovery: When a communication entity has no new requests within a preset time window, its reputation value for the next access will automatically recover to a default reputation value based on the time decay factor. Active authentication recovery: For entities whose reputation value has been reduced due to abnormal behavior, a challenge is returned to them; if the human-machine verification is successful, the internal behavior reputation value and frequency penalty value of the communication entity in the dynamic reputation database are reset to the preset good state value in one go.

5. The intelligent network connection scheduling method according to claim 1, characterized in that, The method further includes a step: To achieve IP reputation sharing and collaborative defense, the steps include: According to the first preset cycle, the IP address information of the device whose comprehensive reputation evaluation value is lower than a reporting threshold will be encrypted and reported to a central reputation sharing platform. According to the second preset cycle, a global list of low-reputation IPs is retrieved from the central reputation sharing platform; The global list of low-reputation IPs obtained from platform synchronization will be used as an external threat intelligence source and incorporated into the fusion calculation step. For low-reputation IPs obtained through synchronization, their corresponding platform reputation score decays over time at a rate slower than that of local reputation recovery.

6. The intelligent network connection scheduling method according to claim 1, characterized in that, The method further includes a step: linking downstream security components, which includes: The comprehensive credit rating value is mapped to a security level identifier; Generate a security instruction that includes the connection quintuple information and the security level identifier; The security instructions are sent to downstream network security components in real time. Downstream network security components dynamically adjust the strength and depth of security policy checks on the connection request based on the received security level identifier.

7. The intelligent network connection scheduling method according to claim 1, characterized in that, The strategy of "setting the maximum concurrent connection limit based on the reputation interval" is as follows: different maximum concurrent connection thresholds are configured for different comprehensive reputation evaluation value ranges, and the value of the threshold is positively correlated with the value of the comprehensive reputation evaluation value.

8. The intelligent network connection scheduling method according to claim 4, characterized in that, The challenge is a JavaScript computation task, a CAPTCHA image verification, or another method that enables the communicating entity to prove that it is not malicious.

9. A network connection intelligent scheduling system, used to implement the method described in any one of claims 1-8, characterized in that, The system includes: The connection interception module is used to intercept connection request packets and parse metadata during the network connection establishment phase. A dynamic reputation database is used to store historical and real-time status information of communication entities; The behavior quantification engine is used to perform reputation assessment calculations, and it has a built-in implementation of the recursive penalty algorithm. The intelligence fusion center is used to integrate external threat intelligence and perform fusion computing. The strategy decision-maker has a built-in strategy mapping table, which is used to output scheduling strategies based on the comprehensive credit evaluation value. A policy executor for executing the scheduling policy, which includes a push queue manager that implements the task coverage mechanism; A reputation recovery manager is used to implement the intelligent reputation recovery mechanism. Reputation sharing agent is used to enable communication and data synchronization with the central reputation sharing platform; The policy linkage mechanism is used to generate security commands and send them to downstream security components.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method as described in any one of claims 1 to 8.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 8.