Network security attack and defense strategy generation method, system and device fusing knowledge graph and medium

By constructing a knowledge graph based on multi-source data, attack feature data is collected and evaluated in real time. Combined with attack and defense objective functions and dynamic Bayesian network optimization strategies, the dynamic adaptability and strategy bias problems in the generation of network security attack and defense strategies in existing technologies are solved, and efficient and real-time defense strategy generation and optimization are achieved.

CN121098535APending Publication Date: 2025-12-09GUIZHOU POWER GRID CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511101737.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-07
Publication Date
2025-12-09

AI Technical Summary

Technical Problem

Existing cybersecurity attack and defense strategy generation technologies suffer from problems such as unsystematic knowledge integration, insufficient dynamic adaptability, lack of data quality assessment, limited coverage of strategy generation scenarios, delayed feedback and adjustment, and reliance on manual intervention for optimization, resulting in strategy bias and insufficient adaptability.

Method used

A knowledge graph is constructed based on multi-source data from publicly available vulnerability databases. Attack feature data is collected in real time, preprocessed and quality assessed, and candidate strategies are generated by combining attack and defense objective functions. Genetic algorithms and dynamic Bayesian networks are used to optimize the strategy, and a real-time feedback adjustment mechanism is established to dynamically update the knowledge graph and discover high-frequency attack-defense patterns.

Benefits of technology

It has enabled the dynamic and intelligent development of network security defense strategies, improved the accuracy, adaptability and real-time performance of strategy generation, ensured the effectiveness of defense and the efficiency of resource utilization, and formed a closed-loop mechanism of strategy-feedback-optimization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121098535A_ABST
    Figure CN121098535A_ABST
Patent Text Reader

Abstract

The invention discloses a network security attack and defense strategy generation method, system and device fused with a knowledge graph and a medium, and belongs to the technical field of network security attack and defense strategies, and the method comprises the steps: dynamically constructing a network security knowledge graph containing an attack path and vulnerability association relationship based on multi-source data of a public vulnerability library, dynamic mapping of real-time asset change information and a graph entity is realized through an entity link mechanism, and consistency verification is performed on a mapping relation by using a graph neural network model so as to filter anomalies; structured and unstructured attack feature data are collected in real time from channels such as network traffic, and preprocessing is completed through regular cleaning, feature selection and data quality evaluation; real-time data and a knowledge graph are subjected to multi-dimensional matching, an attack and defense target function of a defense cost target is combined, a candidate strategy set is generated through a genetic algorithm, an incomplete information game model is introduced to calculate sub-game perfect Nash equilibrium to determine an optimal strategy, and a dynamic Bayesian network is utilized to update a strategy transition probability based on historical data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security attack and defense strategy technology, specifically to a method, system, device, and medium for generating network security attack and defense strategies that integrates knowledge graphs. Background Technology

[0002] The cybersecurity field is currently facing the challenges of increasingly complex attack methods and continuously escalating offensive and defensive confrontations. With the expansion of network asset scale and dynamic expansion of attack surface, how to efficiently integrate multi-source security data and build an offensive and defensive strategy system with dynamic adaptability has become a key issue in improving network defense effectiveness. As a structured knowledge representation method, knowledge graphs are gradually showing the potential to integrate the correlation of attack elements and support strategy generation in the cybersecurity field. However, existing technologies still have problems in practical applications, such as unsystematic knowledge integration, insufficient dynamic adaptability, and the need to improve strategy reliability.

[0003] Existing network security attack and defense strategy generation technologies suffer from the following structural problems: First, during knowledge graph construction, the integration of attack paths and vulnerability relationships relies heavily on static rules or a single data source, lacking systematic correlation modeling of multi-source vulnerability databases, resulting in insufficient structured knowledge support for attack and defense strategies. Second, the synchronization mechanism between asset change information and knowledge graph entities is imperfect, easily leading to a disconnect between the knowledge graph and the actual state due to dynamic adjustments to network assets, thus causing strategy deviations. Third, the support for unstructured data is limited during the collection of multi-source heterogeneous data; the methods for noise filtering and key feature screening in the preprocessing stage are simplistic, and data quality assessment is lacking, affecting the reliability of subsequent strategy inputs. Fourth, the strategy generation process does not fully integrate attack characteristics, knowledge associations, and defense cost constraints, resulting in limited coverage of candidate strategies and a lack of simulation capabilities for scenarios with information asymmetry between attackers and defenders, leading to insufficient adaptability of the strategies. Fifth, the quantitative evaluation of strategy execution effectiveness relies heavily on subjective indicators, lacking objective and comprehensive evaluation methods, and the feedback adjustment mechanism is lagging, failing to respond promptly to changes in execution effectiveness. Sixth, knowledge graph optimization relies on manual intervention or static updates, lacking a closed-loop optimization mechanism, with weak high-frequency attack-defense pattern mining capabilities, making it difficult to continuously integrate the latest attack and defense experience, thus limiting the overall improvement of strategy capabilities. To address these issues, a method and system for generating cybersecurity attack and defense strategies that integrates knowledge graphs is proposed. Summary of the Invention

[0004] In view of the above-mentioned problems, the present invention is proposed.

[0005] Therefore, the purpose of this invention is to solve the problem of how to generate and optimize dynamic and intelligent network security defense strategies to cope with real-time changing network attack methods.

[0006] To address the aforementioned technical problems, this invention provides the following technical solution: a method for generating network security attack and defense strategies integrating knowledge graphs, comprising,

[0007] Based on multi-source data from publicly available vulnerability databases, a knowledge graph is constructed through an entity linking mechanism, and the mapping relationships between entities in the graph are dynamically verified. Real-time attack feature data is collected and preprocessed. The real-time attack feature data is matched with the knowledge graph in multiple dimensions, and an attack and defense objective function is set to generate a set of candidate strategies to determine the optimal attack and defense strategy. The optimal attack and defense strategy is pushed to the defense device for execution, and the effect is quantitatively evaluated through hierarchical analysis. A real-time feedback adjustment mechanism is set up to dynamically adjust the strategy priority. The knowledge graph is updated according to the feedback adjustment mechanism, and attack and defense modes are added.

[0008] As a preferred embodiment of the network security attack and defense strategy generation method integrating knowledge graphs described in this invention, the construction of the knowledge graph includes:

[0009] Based on multi-source data from publicly available vulnerability databases, network security entities are extracted through entity identification, and an entity-relationship model is constructed through relation extraction.

[0010] Set up an entity linking mechanism to dynamically map the entity-relationship model and construct a knowledge graph;

[0011] Perform consistency checks on the mapped knowledge graph and filter out abnormal mapping results.

[0012] As a preferred embodiment of the network security attack and defense strategy generation method integrating knowledge graphs described in this invention, the preprocessing includes:

[0013] Obtain real-time attack signature data from network traffic channels;

[0014] Analyze and process real-time attack signature data;

[0015] Perform data cleaning to remove invalid data and extract key features;

[0016] The quality of key features after preprocessing is verified by combining data quality assessment indicators.

[0017] The beneficial effects of the preferred technical solution in the embodiments of the present invention are as follows: by evaluating the data quality of multi-dimensional indicators, the reliability and consistency of multi-source heterogeneous data are effectively improved, providing a high-quality data foundation for subsequent attack and defense strategies.

[0018] As a preferred embodiment of the network security attack and defense strategy generation method integrating knowledge graphs described in this invention, the step of determining the optimal attack and defense strategy includes:

[0019] The real-time attack feature data that has passed quality verification will be matched with the knowledge graph in multiple dimensions.

[0020] A pre-defined attack and defense objective function is used, and a set of candidate strategies is generated using a genetic algorithm.

[0021] Calculate the perfect Nash equilibrium of the subgame to determine the optimal offensive and defensive strategy in the candidate strategy set;

[0022] The optimal offensive and defensive strategies are dynamically verified and adjusted based on the updated strategy transition probabilities using historical data.

[0023] The beneficial effects of the preferred technical solution in the embodiments of the present invention are as follows: the attack and defense strategy transition probability is trained and updated based on historical data, and the network node parameters are adjusted through real-time feedback, so that the dynamic Bayesian network can better fit the actual attack and defense scenario and improve the dynamic adaptability and accuracy of the attack and defense strategy.

[0024] As a preferred embodiment of the network security attack and defense strategy generation method integrating knowledge graphs described in this invention, the dynamic adjustment of strategy priority includes:

[0025] Push the optimal attack and defense strategy to the defense equipment for execution, and collect attack blocking rate indicators;

[0026] A comprehensive evaluation score is generated by calculating the attack blocking rate index using the analytic hierarchy process.

[0027] A real-time feedback and adjustment mechanism is established, which uses the changes in statistical indicators through a sliding window to dynamically adjust the strategy priority.

[0028] The preferred technical solution in this embodiment of the invention has the following advantages: by dynamically adjusting the size of the sliding window and monitoring the attack blocking rate in real time, it can quickly respond to changes in attack patterns, adjust strategy priorities in a timely manner, and push backup strategies to ensure the effectiveness of the defense.

[0029] As a preferred embodiment of the network security attack and defense strategy generation method integrating knowledge graphs as described in this invention, the updated knowledge graph includes:

[0030] Entity attributes are updated based on execution feedback, and incremental learning is used to optimize the graph subset;

[0031] Set a confidence threshold for entity relationships; if the confidence level falls below the threshold, manual review will be triggered.

[0032] Add the Apriori algorithm to discover high-frequency attack-defense patterns and supplement the association rule base.

[0033] As a preferred embodiment of the network security attack and defense strategy generation method integrating knowledge graphs described in this invention, the Apriori algorithm includes, in the process of mining high-frequency attack-defense patterns using the Apriori algorithm, setting association rules as follows:

[0034] In the association rule base of knowledge graph closed-loop optimization and anomaly handling, the Apriori algorithm sets the minimum support to 0.2 and the minimum confidence to 0.5.

[0035] The extracted attack-defense pattern must satisfy the association relationship of three entity types: attack method, defense measure, and asset type.

[0036] The beneficial effects of the preferred technical solution in the embodiments of the present invention are as follows: by setting reasonable minimum support and confidence, and requiring the attack-defense mode to include key entity types, it is possible to effectively extract association rules with practical significance, optimize the closed-loop optimization process of the knowledge graph, and improve the accuracy of anomaly handling.

[0037] Another objective of this invention is to provide a network security attack and defense strategy generation system that integrates knowledge graphs.

[0038] To address the aforementioned technical problems, this invention provides the following technical solution: a network security attack and defense strategy generation system integrating knowledge graphs, comprising:

[0039] The knowledge graph construction module builds an entity-relationship model containing attack paths and vulnerability associations based on public vulnerability databases and internal network asset data. It has a preset entity linking mechanism to realize the dynamic mapping of network asset change information and knowledge graph entities. The entity linking mechanism adds a dynamic entity relationship verification submodule, which uses a graph neural network model to perform consistency verification on the mapped entity relationships and filter out abnormal mapping results.

[0040] The real-time data acquisition module obtains real-time attack characteristic data from network traffic and system logs. The preset data preprocessing submodule performs noise filtering and standardization. The preprocessing submodule adds a data quality assessment submodule, which quantifies and scores the cleaned data through integrity, timeliness and consistency indicators, and retains data that is above the threshold.

[0041] The strategy generation module matches real-time data with knowledge graphs in multiple dimensions, combines attack and defense objective functions, generates a set of candidate strategies through multi-objective optimization algorithms, and introduces an incomplete information game model between the attacker and defender to determine the optimal combination of defense strategies. A dynamic Bayesian network sub-module is added to update the attack and defense strategy transition probability based on historical attack and defense interaction data.

[0042] The execution feedback module pushes candidate strategies to the defense equipment for execution, collects attack status change data, establishes a comprehensive evaluation system to generate quantitative scores, and adds a real-time feedback adjustment submodule to dynamically adjust the priority of subsequent strategies by statistically analyzing the trend of indicator changes through a sliding window.

[0043] The dynamic adjustment module updates the entity attributes of the knowledge graph based on the execution feedback data and sets a confidence threshold for entity relationships to trigger a manual review process. An automated association rule mining submodule is added, which extracts high-frequency attack-defense patterns from the feedback data using the Apriori algorithm to supplement the association rule base.

[0044] The present invention provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method for generating a network security attack and defense strategy that integrates knowledge graphs.

[0045] The present invention provides a computer-readable storage medium having a computer program stored thereon, characterized in that, when the computer program is executed by a processor, it implements the steps of the method for generating a network security attack and defense strategy that integrates knowledge graphs.

[0046] The beneficial effects of this invention are as follows: In the dynamic construction process of the network security knowledge graph, this invention constructs an entity-relationship model containing attack paths and vulnerability associations based on multi-source data from a public vulnerability database. This model can systematically integrate attack elements and associated logic, providing structured knowledge support for attack and defense strategies. The entity linking mechanism dynamically maps real-time asset change information to graph entities, ensuring that the knowledge graph is synchronized with the actual state of network assets and avoiding knowledge lag caused by asset changes. The added graph neural network model performs consistency verification on the mapping relationships and filters out abnormal results. At the same time, the dynamic verification of entity relationships in the entity linking mechanism further verifies the mapped entity relationships through the graph neural network model, effectively improving the accuracy and reliability of the knowledge graph and reducing strategy deviations caused by incorrect mappings.

[0047] In the real-time acquisition and preprocessing stage of multi-source heterogeneous data, real-time attack feature data is obtained from network traffic channels and structured and unstructured data parsing is supported. This can comprehensively cover different forms of security event data and avoid missing key attack information. In the preprocessing stage, regular expression cleaning and feature selection methods are used in combination with data quality assessment. This can effectively remove noisy data, filter key features and quantify data quality, ensuring that the data input to the policy generation module has high availability and credibility, laying a data foundation for subsequent policy optimization.

[0048] In the dynamic generation and verification of attack and defense strategies, real-time data is matched with knowledge graphs in multiple dimensions. Combined with the attack and defense objective function of defense cost, a set of candidate strategies is generated through genetic algorithms. This can comprehensively consider attack characteristics, knowledge associations, and cost constraints to generate candidate strategies covering multiple scenarios. An incomplete information game model is introduced to calculate the perfect Nash equilibrium of the subgame to determine the optimal strategy. This can simulate the strategy interaction under scenarios of information asymmetry between the attacker and defender, improving the adversarial adaptability of the strategy. The added dynamic Bayesian network updates the strategy transition probability based on historical data, enabling the strategy generation to dynamically adapt to the historical evolution of the attack and defense situation, enhancing the timeliness and targeting of the strategy.

[0049] In the strategy execution and effectiveness quantification evaluation phase, the strategy is pushed to the defense equipment for execution and the attack blocking rate index is collected. A comprehensive evaluation score is generated through the analytic hierarchy process, which can objectively quantify the actual defense effect of the strategy. A real-time feedback adjustment mechanism is designed to use a sliding window to statistically analyze changes in indicators and dynamically adjust the strategy priority. This can respond to changes in the execution effect in a timely manner, prioritize the execution of strategies with better results, and improve the utilization efficiency of defense resources.

[0050] During the closed-loop optimization and anomaly handling of the knowledge graph, entity attributes are updated based on execution feedback, and incremental learning is used to optimize graph subsets. This enables the dynamic evolution of the knowledge graph and continuously incorporates the latest attack and defense experience. Setting a confidence threshold for entity relationships to trigger manual review allows for the retention of manual intervention on top of automatic optimization, ensuring the accuracy of key entity relationships. The addition of the Apriori algorithm to mine high-frequency attack-defense patterns and supplement the association rule base can automatically extract effective defense patterns, enrich the defense strategy associations of the knowledge graph, and form a closed-loop mechanism of "strategy-feedback-optimization" to continuously improve the overall attack and defense strategy capabilities. Attached Figure Description

[0051] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0052] Figure 1 This is a flowchart illustrating the overall process of a network security attack and defense strategy generation method that integrates knowledge graphs, as provided in one embodiment of the present invention.

[0053] Figure 2 This is a module structure diagram of a network security attack and defense strategy generation system that integrates knowledge graphs, provided as an embodiment of the present invention. Detailed Implementation

[0054] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.

[0055] Example 1, referring to Figure 1 This is one embodiment of the present invention, which provides a method for generating network security attack and defense strategies by integrating knowledge graphs, including:

[0056] S100: Based on multi-source data from publicly available vulnerability databases, a knowledge graph is constructed through an entity linking mechanism, and the mapping relationship between entities in the graph is dynamically verified.

[0057] S200: Collects real-time attack characteristic data and performs preprocessing.

[0058] S300: Match real-time attack feature data with knowledge graphs in multiple dimensions, set attack and defense objective functions to generate a set of candidate strategies, and determine the optimal attack and defense strategy.

[0059] The S400 pushes the optimal attack and defense strategy to the defense equipment for execution, performs quantitative evaluation of the effect through hierarchical analysis, and establishes a real-time feedback and adjustment mechanism to dynamically adjust the strategy priority.

[0060] S500 updates the knowledge graph based on feedback adjustment mechanisms and adds attack and defense modes.

[0061] It should be noted that existing technical knowledge integration relies on static rules / single sources, resulting in insufficient strategy support; the lack of an asset change synchronization mechanism leads to graph disconnect and strategy deviation; weak unstructured data processing capabilities / lack of evaluation reduce the reliability of input data; strategy generation does not fully integrate multi-dimensional constraints and information asymmetry simulation, resulting in narrow coverage and poor adaptability; subjective effect evaluation / laggy feedback prevents timely strategy optimization; graph optimization relies on manual intervention / lacks closed-loop constraints, experience integration, and capability improvement. These shortcomings collectively lead to generated attack and defense strategies that are weak in foundation, detached from reality, have unreliable inputs, limited scenario coverage, poor adaptability, delayed response, and slow evolution, ultimately resulting in low defense effectiveness, slow response, resource waste, and persistently high security risks.

[0062] Therefore, to address the aforementioned issues, a dynamic and verifiable knowledge graph is constructed through steps S100-S500, integrating multi-source vulnerability data to lay a precise knowledge foundation. By matching attack characteristics with the knowledge graph in real-time across multiple dimensions, and combining this with an objective function, optimal attack and defense strategies are intelligently generated. After strategy execution, the effectiveness is quantitatively evaluated in real-time, and dynamic feedback adjustments are made to form a closed-loop optimization. Simultaneously, the knowledge graph is automatically updated, and new patterns are discovered, significantly improving the accuracy, adaptability, real-time performance, and continuous evolution capability of strategy generation.

[0063] Example 2, refer to Figure 1 This is one embodiment of the present invention, which provides a method for generating network security attack and defense strategies by integrating knowledge graphs, including:

[0064] In an embodiment of the present invention, step S100 involves constructing a knowledge graph based on multi-source data from a publicly available vulnerability database using an entity linking mechanism, and dynamically verifying the mapping relationships between entities in the graph. This includes the following steps S101-S103:

[0065] S101. Based on multi-source data from publicly available vulnerability databases, extract network security-related entities using entity recognition methods, and construct an entity-relationship model containing attack path information and vulnerability associations using relationship extraction methods.

[0066] S102. Set up an entity linking mechanism and add a dynamic verification step for entity relationships in the entity linking mechanism. Use a graph neural network model to verify the consistency of the mapped entity relationships and filter out abnormal mapping results with inconsistencies.

[0067] In an embodiment of the present invention, S103, dynamically verifying the mapping relationship of graph entities, that is, using a graph neural network model to verify the consistency of the mapping results of the entity linking mechanism, includes the following steps A1-A2:

[0068] A1. In the dynamic verification of entity relationships in the dynamic construction of network security knowledge graphs, the graph neural network model adopts the GraphSAGE architecture, which generates embedding vectors by aggregating entity neighbor information.

[0069] A2. Calculate the cosine similarity between the mapped entity and the original graph entity. When the similarity is lower than the preset threshold, it is judged as an abnormal mapping and relinked. Further filter out abnormal results that do not conform to the knowledge graph logic.

[0070] By aggregating neighbor information to generate embedding vectors through the GraphSAGE architecture and dynamically verifying entity relationships based on cosine similarity, abnormal mappings can be detected and corrected in a timely manner, ensuring the accuracy and real-time performance of the knowledge graph.

[0071] In an optional embodiment, the dynamic verification in S103 can be performed by using a Node2Vec model to process the knowledge graph, sampling the entity neighbor sequence through a random walk strategy, training a Skip-gram model to generate low-dimensional embedding vectors of entities, and calculating the cosine similarity between the embedded vectors of the mapped entity and the original graph entity; when the similarity is lower than a preset threshold, it is determined to be an abnormal mapping and relinked; however, Node2Vec requires pre-training and is not sensitive to dynamic graph updates, resulting in a verification lag.

[0072] In another optional embodiment, the dynamic verification in S103 can be as follows: In the dynamic verification of entity relationships, for each mapped entity, its direct neighbor set in the knowledge graph is extracted, and the Jaccard similarity coefficient between the neighbor set of the mapped entity and the neighbor set of the original graph entity is calculated; when the coefficient is lower than a preset threshold, it is determined to be an abnormal mapping and relinked; but only local structural information is relied upon while the attribute semantics are ignored.

[0073] In summary, by constructing an entity-relationship model through entity recognition and relation extraction, attack paths and vulnerability associations can be systematically integrated, providing structured knowledge support for attack and defense strategies. The entity linking mechanism can realize the dynamic mapping of real-time asset change information and knowledge graph entities, ensuring the synchronization of the knowledge graph with the actual network environment. The consistency verification of the graph neural network model can filter out abnormal mapping results, improving the accuracy and reliability of the knowledge graph.

[0074] In this embodiment of the invention, S200 involves collecting real-time attack feature data and performing preprocessing, including the following steps S201-S203:

[0075] S201. Obtain real-time attack characteristic data from network traffic channels, and support the parsing and processing of structured and unstructured data.

[0076] S202. In the preprocessing stage, the regularity cleaning method is used to remove invalid data, and the key features are extracted by the feature selection method.

[0077] In an embodiment of the present invention, S203, the key features after preprocessing are verified by combining data quality assessment indicators, including the following steps B1-B4:

[0078] B1. In the data quality assessment of real-time acquisition and preprocessing of multi-source heterogeneous data, the integrity index is calculated by statistically analyzing the missing rate of key fields.

[0079] B2. Timeliness indicators are evaluated by the difference between the data collection time and the current time;

[0080] B3. Consistency metrics are determined by comparing the differences in descriptions of the same event across different data sources.

[0081] B4. If any of the above indicators exceed the corresponding threshold, then the corresponding indicator requirements are not met.

[0082] In an optional embodiment, the quality verification in S203 can be as follows: integrity verification is performed by counting the number of missing key fields and comparing them with a preset threshold; timeliness verification is performed by calculating the difference between the data collection timestamp and the current system time and comparing it with a preset time window; consistency verification is performed by using simple text matching to calculate the number of differences for the description of the same event in different data sources; however, it relies on a fixed threshold and cannot adapt to dynamic changes in data.

[0083] In another optional embodiment, the quality verification in S203 can be: integrity verification calculates the non-empty ratio of key fields; timeliness verification assesses whether the data collection time is within the valid time range; consistency verification matches records from different data sources using event unique identifiers and counts the conflict ratio of descriptive fields; however, the rules are based on experience and are not suitable for the complexity of multi-source heterogeneous data.

[0084] In summary, it supports the parsing and processing of both structured and unstructured data, and can comprehensively cover attack feature data in network traffic; the combination of regular expression cleaning and feature selection methods with data quality assessment can effectively remove invalid data and extract key features, thereby improving the quality of the data on which subsequent strategy generation is based.

[0085] In this embodiment of the invention, step S300 involves multi-dimensional matching of real-time attack feature data with a knowledge graph, setting an attack and defense objective function to generate a candidate strategy set, and determining the optimal attack and defense strategy. This includes the following steps S301-S304:

[0086] S301. Perform multi-dimensional matching between the real-time attack feature data that has passed quality verification and the knowledge graph to extract knowledge graph information related to the current attack features;

[0087] S302. Combining the offensive and defensive objective function with the defense cost objective, a set of candidate strategies containing multiple possible solutions is generated through a genetic algorithm;

[0088] S303. Introduce an incomplete information game model, calculate the perfect Nash equilibrium of the subgame, and determine the optimal attack and defense strategy from the candidate strategy set.

[0089] In an embodiment of the present invention, S304, a dynamic Bayesian network is added to update the strategy transition probability based on historical attack and defense data, and to dynamically verify and adjust the optimal attack and defense strategy, including the following steps C1-C3:

[0090] C1. In the dynamic Bayesian network for dynamic generation and verification of attack and defense strategies, the attacker's strategy transition probability is obtained by training with historical attack path data.

[0091] C2. The probability of the defender's strategy shift is updated based on the historical defense measures' execution effect data, and the network node parameters are adjusted according to real-time feedback after each strategy interaction.

[0092] C3. Based on historical data, the attack and defense strategy transition probabilities are trained and updated, and the network node parameters are adjusted through real-time feedback, so that the dynamic Bayesian network can better fit the actual attack and defense scenario and improve the dynamic adaptability and accuracy of the attack and defense strategy.

[0093] In an optional embodiment, the dynamic verification and adjustment of the optimal strategy in S304 can be achieved by using historical attack path data and defense measure execution effect data as training sets to construct a decision tree model. The model is trained with attack and defense state features as input and the probability of the attacker's / defender's next-stage behavior as the output target. When a new attack and defense interaction occurs, the attack and defense state features of this interaction and the actual attacker / defender behavior are used as new samples. An incremental learning algorithm is used to update the decision tree model, adjusting the node splitting rules or the probability distribution of leaf nodes to reflect the latest strategy interaction results. Using the updated decision tree model, the latest attack and defense state features are input to predict the probability distribution of the attacker's possible next action and the probability distribution of the expected effects of different defense measures in the latest state. Based on the prediction results, the expected effect of the current optimal strategy in the new state is evaluated.

[0094] In another optional embodiment, the dynamic verification and adjustment of the optimal strategy in S304 can be achieved by maintaining a fixed-size sliding window, recording the key performance indicators after each execution of the optimal strategy within the window, adding the performance data of this interaction to the sliding window after each execution of the optimal strategy and obtaining real-time feedback, and removing the oldest interaction data from the window, dynamically calculating the average value, success rate, and other statistics of various performance indicators within the sliding window, setting warning thresholds for various performance indicators, periodically checking the statistics within the current sliding window, and determining that the current optimal strategy may have failed or the environment has changed if the key performance indicators are lower than the warning threshold multiple times in a row, triggering the strategy regeneration process (returning to S302), regenerating the candidate strategy set using the latest knowledge graph information and real-time attack characteristics, and selecting a new optimal strategy.

[0095] In summary, multi-dimensional matching of real-time data and knowledge graph information can fully utilize the attack paths and vulnerability associations in the knowledge graph; combining the attack and defense objective function with the defense cost target and the genetic algorithm to generate a set of candidate strategies can balance the defense effect and cost; the incomplete information game model determines the optimal strategy through subgame perfect Nash equilibrium, improving the game adaptability of the strategy; and the dynamic Bayesian network updates the strategy transition probability based on historical data, enhancing the dynamic verification capability of the strategy.

[0096] In an embodiment of the present invention, in step S400, the optimal attack and defense strategy is pushed to the defense device for execution, the effect is quantitatively evaluated through hierarchical analysis, and a real-time feedback adjustment mechanism is set to dynamically adjust the strategy priority, including the following steps S401-S403:

[0097] S401. Push the generated attack and defense decisions to the defense equipment for execution, and collect the attack blocking rate index as the basic feedback data of the execution effect;

[0098] S402. A comprehensive analysis of multiple indicators, such as attack blocking rate, is conducted using the analytic hierarchy process to generate a quantitative evaluation score.

[0099] In an embodiment of the present invention, S403, a real-time feedback adjustment mechanism is set up, which uses the changing trend of statistical indicators through a sliding window to dynamically adjust the decision priority according to the changing trend, including the following steps D1-D2:

[0100] D1. In the real-time feedback adjustment mechanism for decision execution and quantitative evaluation of results, the sliding window size is dynamically adjusted according to the response time of the business system.

[0101] D2. When the attack blocking rate is below the threshold for N consecutive windows, trigger the decision priority reordering and push the backup strategy.

[0102] By dynamically adjusting the sliding window size and monitoring the attack blocking rate in real time, it can quickly respond to changes in attack patterns, adjust decision priorities in a timely manner, and push out backup strategies to ensure the effectiveness of the defense.

[0103] In an optional embodiment, the real-time feedback adjustment mechanism in S403 can be as follows: a fixed time interval is set according to the average system response time, and the attack blocking rate data is periodically polled. At the end of each cycle, if the attack blocking rate is lower than a preset threshold, an early warning is triggered. After the cumulative number of early warnings reaches M, the priority of the current policy is automatically reduced, the policy with the highest score in the backup policy library is activated, and the new priority policy is pushed to the defense device for execution. However, the fixed cycle cannot adapt to sudden changes in traffic, resulting in response delays or resource waste.

[0104] In another optional embodiment, the real-time feedback adjustment mechanism in S403 can be to assign higher weight to the latest attack blocking rate data, gradually reduce the weight of historical data, calculate the weighted blocking rate trend value in real time, eliminate short-term fluctuation interference, and immediately start strategy reordering when the trend value is continuously lower than the threshold, select the suboptimal strategy from the candidate strategy set to replace the current strategy. It does not require waiting for a fixed window period, but the weight parameters need to be preset manually, and its adaptability is weaker than that of the sliding window.

[0105] In summary, pushing strategies to defense devices for execution and collecting attack blocking rate metrics can directly verify the actual effectiveness of the strategies; the analytic hierarchy process (AHP) generates comprehensive evaluation scores, which can quantitatively evaluate the effectiveness of the strategies from multiple dimensions; and the real-time feedback adjustment mechanism can dynamically adjust strategy priorities by statistically analyzing changes in metrics through a sliding window, thereby improving the adaptability of strategy execution.

[0106] In an embodiment of the present invention, step S500 updates the knowledge graph according to a feedback adjustment mechanism and adds an attack and defense mode, including the following steps S501-S503:

[0107] S501. Update the attribute information of relevant entities in the network security knowledge graph based on the decision execution feedback results; use incremental learning methods to optimize and update the subset of the knowledge graph involving execution feedback.

[0108] S502. Set a confidence threshold for entity relationships. When the confidence of an entity relationship falls below the threshold, a manual review process is triggered.

[0109] Add the Apriori algorithm to mine high-frequency attack-defense patterns, and supplement the mining results to the association rule base.

[0110] In the association rule base of knowledge graph closed-loop optimization and anomaly handling, the Apriori algorithm sets the minimum support to 0.2 and the minimum confidence to 0.5.

[0111] S503: Added Apriori algorithm to mine high-frequency attack-defense patterns and supplemented the association rule base.

[0112] The extracted attack-defense pattern must satisfy the association relationship of three entity types: attack method, defense measure, and asset type.

[0113] By setting reasonable minimum support and confidence levels, and requiring the attack-defense model to include key entity types, meaningful association rules can be effectively extracted, optimizing the closed-loop optimization process of the knowledge graph and improving the accuracy of anomaly handling.

[0114] In summary, updating entity attributes based on execution feedback and using incremental learning to optimize subsets of the knowledge graph enables continuous updating and optimization of the knowledge graph; triggering manual review based on entity relationship confidence thresholds can handle low-confidence anomalies; and the Apriori algorithm mines high-frequency attack-defense patterns and supplements the association rule base, enriching the knowledge foundation of attack and defense strategies.

[0115] Example 3 is an embodiment of the present invention. The above is an illustrative scheme of a method for generating network security attack and defense strategies by integrating knowledge graphs. It should be noted that the technical solution of this network security attack and defense strategy generation system integrating knowledge graphs is based on the same concept as the technical solution of the network security attack and defense strategy generation method integrating knowledge graphs described above. Details not described in detail in the technical solution of the network security attack and defense strategy generation system integrating knowledge graphs in this embodiment can be found in the description of the technical solution of the network security attack and defense strategy generation method integrating knowledge graphs described above.

[0116] This embodiment provides a network security attack and defense strategy generation system that integrates knowledge graphs, including:

[0117] Specifically, the knowledge graph construction module builds an entity-relationship model that includes attack paths and vulnerability associations based on publicly available vulnerability databases and internal network asset data;

[0118] A dynamic mapping between network asset change information and knowledge graph entities is achieved through an entity linking mechanism;

[0119] The entity linking mechanism calls the entity relationship dynamic verification submodule, which uses a graph neural network model to perform consistency verification on the mapped entity relationships and filter out abnormal mapping results.

[0120] Specifically, the real-time data acquisition module obtains real-time attack characteristic data from network traffic and system logs;

[0121] The data preprocessing submodule performs noise filtering and standardization on the acquired real-time attack feature data.

[0122] The data preprocessing submodule calls the data quality assessment submodule to quantify and score the cleaned data based on indicators of completeness, timeliness, and consistency, and retains data with scores higher than the preset threshold.

[0123] Specifically, the strategy generation module performs multi-dimensional matching between real-time data and knowledge graphs;

[0124] By combining the offensive and defensive objective functions, a set of candidate strategies is generated through a multi-objective optimization algorithm;

[0125] We introduce an incomplete information game model for both attackers and defenders to determine the optimal combination of defense strategies from the candidate strategy set;

[0126] The dynamic Bayesian network submodule is invoked to update the attack and defense strategy transition probability based on historical attack and defense interaction data.

[0127] Specifically, the execution feedback module pushes the generated optimal defense strategy combination to the defense device for execution;

[0128] Collect data on changes in the attack status after the defense equipment is activated;

[0129] Establish a comprehensive evaluation system to generate quantitative scores for attack status change data;

[0130] The real-time feedback adjustment submodule is invoked to dynamically adjust the priority of subsequent strategies by statistically analyzing the changing trends of indicators through a sliding window.

[0131] Specifically, the dynamic adjustment module updates the entity attributes of the knowledge graph based on the quantitative score data generated during the execution feedback phase;

[0132] Set a confidence threshold for entity relationships; when the confidence level of an entity relationship falls below the threshold, a manual review process will be triggered.

[0133] The automated association rule mining submodule is invoked to extract high-frequency attack-defense patterns from the feedback data using the Apriori algorithm, and the extracted high-frequency attack-defense patterns are then added to the association rule base.

[0134] It should be noted that by using the entity linking mechanism to achieve dynamic mapping between network asset change information and knowledge graph entities, and combining the graph neural network consistency verification function of the entity relationship dynamic verification submodule, the real-time performance and accuracy of the knowledge graph are effectively improved, and the problem of entity relationship failure caused by dynamic changes in network assets is avoided.

[0135] The data preprocessing submodule integrates data quality assessment functions, which quantify and score the cleaned data based on integrity, timeliness and consistency indicators, ensuring that the data input to the strategy generation module has high reliability and providing a basic guarantee for the accuracy of subsequent strategies.

[0136] A candidate strategy set is generated by a multi-objective optimization algorithm, and the optimal combination of defense strategies is determined by combining the incomplete information game model of the attacker and defender. This takes into account the multi-dimensional needs of the attacker and defender and the dynamic characteristics of the game confrontation, and improves the scientificity and adaptability of the defense strategy. The dynamic Bayesian network submodule updates the strategy transition probability based on historical attack and defense interaction data, which further enhances the dynamic evolution capability of the strategy.

[0137] A quantitative score is generated through a comprehensive evaluation system, and the sliding window statistics function of the real-time feedback adjustment submodule is used to dynamically adjust the strategy priority. This enables a rapid response to the performance of the defense equipment and strategy optimization, avoiding the problem of defense lag caused by changes in the attack status.

[0138] The system triggers a manual review process by setting a confidence threshold for entity relationships, balancing the need for automated adjustments with the need for manual intervention. The automated association rule mining submodule uses the Apriori algorithm to extract high-frequency attack-defense patterns and add them to the association rule base, enabling the system to continuously learn new attack patterns and improve long-term defense effectiveness.

[0139] In the entity relationship dynamic verification submodule of the knowledge graph construction module, the graph neural network model adopts the GraphSAGE architecture. It generates embedding vectors by aggregating entity neighbor information, calculates the cosine similarity between the mapped entity and the original graph entity, and determines an abnormal mapping when the similarity is lower than a preset threshold and relinks it.

[0140] The graph neural network model using the GraphSAGE architecture generates embedding vectors by aggregating entity neighbor information, which can more comprehensively capture the association features between entities. Combined with the cosine similarity threshold judgment mechanism, it can effectively identify abnormal mappings and dynamically adjust entity relationships, thereby improving the accuracy and real-time performance of knowledge graph construction.

[0141] In the data quality assessment submodule of the real-time data acquisition module, the completeness index is calculated by statistically analyzing the missing rate of key fields, the timeliness index is assessed by calculating the difference between the data acquisition time and the current time, and the consistency index is determined by comparing the degree of difference in the description of the same event in different data sources.

[0142] By using indicators across three dimensions—completeness, timeliness, and consistency—data quality is comprehensively evaluated from the perspectives of data field completeness, time freshness, and consistency of multi-source data. This provides a reliable data foundation for subsequent data processing and analysis, ensuring that the system operates based on high-quality data.

[0143] In the automated association rule mining submodule of the dynamic adjustment module, the Apriori algorithm is used with a minimum support of 0.2 and a minimum confidence of 0.5. The attack-defense patterns extracted during the mining process must simultaneously include the association relationships of three entity types: attack methods, defense measures, and asset types.

[0144] By setting reasonable minimum support and minimum confidence thresholds, the Apriori algorithm can effectively filter out candidate rules with low relevance, ensuring that the extracted attack-defense patterns have a complete association of three entity types: attack methods, defense measures, and asset types. This improves the practicality and relevance of the association rules and provides accurate rule support for dynamic adjustments.

[0145] This embodiment also provides an electronic device applicable to a method for generating network security attack and defense strategies that integrates knowledge graphs, comprising: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the method for generating network security attack and defense strategies that integrates knowledge graphs as proposed in the above embodiment.

[0146] This embodiment also provides a storage medium storing a computer program that, when executed by a processor, implements a network security attack and defense strategy generation method that integrates knowledge graphs as proposed in the above embodiments.

[0147] The storage medium proposed in this embodiment belongs to the same inventive concept as the method for generating a network security attack and defense strategy that integrates knowledge graphs proposed in the above embodiments. Technical details not described in detail in this embodiment can be found in the above embodiments, and this embodiment has the same beneficial effects as the above embodiments.

[0148] Based on the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.

[0149] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A method for generating cyber security attack-defense strategy based on fusion knowledge graph, characterized in that: The method comprises the following steps: Based on the multi-source data of the public vulnerability library, the knowledge graph is constructed through the entity linking mechanism, and the mapping relationship of the graph entity is dynamically verified; Collect real-time attack feature data and preprocess it; Match the real-time attack feature data with the knowledge graph in multiple dimensions, set the attack and defense target function to generate a candidate strategy set, and determine the optimal attack and defense strategy; Push the optimal attack and defense strategy to the defense equipment for execution, quantitatively evaluate the effect through hierarchical analysis, and set up a real-time feedback adjustment mechanism to dynamically adjust the strategy priority; Update the knowledge graph according to the feedback adjustment mechanism, and add attack and defense modes.

2. The network security attack-defense strategy generation method of claim 1, wherein: The construction of the knowledge graph comprises: Based on the multi-source data of the public vulnerability library, network security entities are extracted through entity recognition, and an entity-relation model is constructed through relation extraction; Set up an entity linking mechanism to dynamically map the entity-relation model to construct a knowledge graph; Consistency check is performed on the mapped knowledge graph to filter abnormal mapping results.

3. The network security attack-defense strategy generation method of claim 2, wherein: The preprocessing comprises: Obtain real-time attack feature data from network traffic channels; Parse and process the real-time attack feature data; Remove invalid data through data cleaning and extract key features; Quality verification is performed on the preprocessed key features in combination with data quality evaluation indicators.

4. The network security attack-defense strategy generation method of claim 3, wherein: The determination of the optimal attack and defense strategy comprises: Multi-dimensional matching is performed between the real-time attack feature data that passes the quality verification and the knowledge graph; A pre-set attack and defense target function is combined with a genetic algorithm to generate a candidate strategy set; The optimal attack and defense strategy in the candidate strategy set is determined by calculating the perfect Nash equilibrium of sub-games; Based on historical data, update the strategy transition probability to dynamically verify and adjust the optimal attack and defense strategy.

5. The network security attack-defense strategy generation method of claim 4, wherein: The dynamic adjustment of the strategy priority comprises: Push the optimal attack and defense strategy to the defense equipment for execution, and collect the attack blocking rate indicator; Generate a comprehensive evaluation score by calculating the attack blocking rate indicator through the hierarchical analysis method; Set up a real-time feedback adjustment mechanism to dynamically adjust the strategy priority by using a sliding window to calculate the changes in the indicators.

6. The network security attack-defense strategy generation method of claim 5, wherein: The updating of the knowledge graph comprises: Update the entity attributes according to the execution feedback, and optimize the graph subsets using incremental learning; Set an entity relationship confidence threshold, and trigger manual review when the threshold is exceeded; Add an Apriori algorithm to mine high-frequency attack-defense modes and supplement the association rule library.

7. The network security attack-defense strategy generation method of claim 6, wherein: The Apriori algorithm comprises: In the Apriori algorithm for mining high-frequency attack-defense modes, set the association rules as follows: In the association rule library in the knowledge graph closed-loop optimization and abnormal processing, the Apriori algorithm sets the minimum support to 0.2 and the minimum confidence to 0.5; 8. A network security attack-defense strategy generation system based on a knowledge graph, applying the network security attack-defense strategy generation method based on a knowledge graph according to any one of claims 1 to 7, characterized in that, The extracted attack-defense mode must satisfy the association relationship of containing attack means, defense measures, and asset type. The method comprises the following steps: A knowledge graph construction module is constructed based on the public vulnerability library and internal network asset data to construct an entity-relation model containing attack paths and vulnerability associations, and a dynamic mapping mechanism is preset to realize the dynamic mapping of network asset change information and knowledge graph entities; The entity relationship dynamic verification submodule is added to the entity linking mechanism to perform consistency check on the mapped entity relationship through a graph neural network model, and filter abnormal mapping results; The real-time data acquisition module obtains real-time attack feature data from network traffic and system logs, and a preset data preprocessing submodule performs noise filtering and standardization processing; The preprocessing submodule adds a data quality evaluation submodule, which quantitatively scores the cleaned data through integrity, timeliness and consistency indicators, and retains data higher than a threshold value; The strategy generation module matches real-time data with a knowledge graph in multiple dimensions, combines attack and defense target functions, generates a candidate strategy set through a multi-objective optimization algorithm, introduces a non-complete information game model of both attack and defense to determine an optimal defense strategy combination, adds a dynamic Bayesian network submodule, and updates attack and defense strategy transition probabilities based on historical attack and defense interaction data; The execution feedback module pushes the candidate strategy to a defense device for execution, collects attack state change data, establishes a comprehensive evaluation system, and generates a quantitative score; The real-time feedback adjustment submodule adds a sliding window to statistically analyze the trend of indicators, and dynamically adjusts the priority of subsequent strategies; The dynamic adjustment module updates the entity attributes of the knowledge graph according to the execution feedback data, sets an entity relationship confidence threshold to trigger a manual review process, and adds an automatic association rule mining submodule to extract high-frequency attack-defense patterns from feedback data through the Apriori algorithm and supplement them to the association rule library. 9.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-8 when the computer program is executed by the processor. The processor executes the computer program to realize the steps of the network security attack and defense strategy generation method based on the knowledge graph according to any one of claims 1 to 7.

10. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to realize the steps of the network security attack and defense strategy generation method based on the knowledge graph according to any one of claims 1 to 7.

Citation Information

Cited By

  • Network security attack and defense range system and method based on analogue simulation

    CN121396651A