Intelligent decision-making method and device for coping with network attack and medium

By using multi-source network information collection and intelligent decision-making methods, and leveraging attack intent inference engines, LIME and SHAP interpreters, the problem of high-risk alarm screening in network security has been solved, enabling efficient and accurate security decisions and policy optimization.

CN121125171APending Publication Date: 2025-12-12SHANDONG INSPUR SCI RES INST CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511155417.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-18
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

The sheer volume of alerts in current network security systems, coupled with a high reliance on manual analysis, makes it difficult to efficiently filter out truly high-risk alerts, impacting response efficiency and accuracy.

Method used

By employing multi-source network information collection, an attack intent inference engine, a LIME local interpreter, and a SHAP global interpreter, network attack prediction and security decision assessment are performed to determine the optimal protection strategy.

Benefits of technology

It improves the ability to detect potential threats, accurately predicts cyberattacks, reduces false positives and false negatives, and enhances the adaptability and response efficiency of security strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125171A_ABST
    Figure CN121125171A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent decision-making method and device for coping with network attacks and a medium, belongs to the technical field of network security and artificial intelligence crossing, and is used for solving the technical problems that the number of alarm information of existing network security is large, the dependence degree of manual analysis is high, and it is difficult to efficiently screen out real high-risk-level alarm information. The method comprises the following steps: collecting network security abnormal data in multi-source network information; performing network attack prediction based on an attack intention inference engine on the network security abnormal data to determine attack behavior characteristics; performing security decision evaluation processing related to an LIME local interpreter on the attack behavior characteristics to obtain a local security index; performing security decision evaluation processing related to an SHAP global interpreter on the attack behavior characteristics to obtain a global security index; and according to the security index and the global security index, evaluating and screening the plurality of network security protection strategies to determine an optimal network security protection strategy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of interdisciplinary technology of cybersecurity and artificial intelligence, and in particular to an intelligent decision-making method, device and medium for responding to cyberattacks. Background Technology

[0002] In data security protection, security teams face a massive amount of alerts every day, and must sift through them to identify truly high-risk alerts and respond quickly. This process heavily relies on the expertise and personal experience of security analysts, but due to the increasing complexity of network environments, manual processing methods are unable to guarantee response efficiency and accuracy, thus affecting the effectiveness of the entire incident response process.

[0003] Therefore, there is an urgent need for a method to make rapid and accurate security decisions in complex network environments in order to deal with new and unknown network attacks, while reducing reliance on human resources and improving the speed and quality of incident response. Summary of the Invention

[0004] This application provides an intelligent decision-making method, device, and medium for responding to network attacks, which addresses the following technical problem: the amount of existing network security alarm information is enormous, and the reliance on manual analysis is high, making it difficult to efficiently filter out alarm information that is truly high-risk.

[0005] The embodiments of this application adopt the following technical solutions:

[0006] On one hand, embodiments of this application provide an intelligent decision-making method for responding to network attacks, including: collecting network security anomaly data from multi-source network information; performing network attack prediction based on an attack intent inference engine on the network security anomaly data to determine attack behavior characteristics; performing security decision evaluation processing on the attack behavior characteristics related to the LIME local interpreter to obtain local security indicators; performing security decision evaluation processing on the attack behavior characteristics related to the SHAP global interpreter to obtain global security indicators; and evaluating and screening various network security protection strategies based on the local security indicators and the global security indicators to determine the optimal network security protection strategy.

[0007] This application's embodiments, by collecting multi-source network information, can more comprehensively analyze network security status and improve the ability to detect potential threats. Based on the predictive capabilities of the attack intent inference engine, network attacks can be predicted more accurately, allowing for proactive preventative measures. The application of LIME and SHAP interpreters provides a deep understanding of attack behavior characteristics, contributing to greater transparency and optimization in security decision-making. Furthermore, the evaluation of local and global security indicators allows for better adaptation to different network environments and attack patterns, improving the adaptability of security strategies. Combining local and global indicators reduces false positives for normal behavior while improving the detection of false negatives for malicious behavior. Moreover, by automatically evaluating and filtering multiple security protection strategies, the optimal strategy can be quickly determined, improving the response efficiency of security incidents.

[0008] In one feasible implementation, collecting network security anomaly data from multi-source network information specifically includes: parsing and processing network traffic information for abnormal alarm data using NetFlow network layer traffic analysis technology and DPI application layer traffic analysis technology to obtain network traffic security anomaly data; identifying network terminal behavior anomaly data using EDR sensor technology; performing Syslog-based anomaly identification processing on log data from the received multi-source network information to obtain log security anomaly data; and combining the network traffic security anomaly data, the network terminal behavior anomaly data, and the log security anomaly data to obtain the network security anomaly data.

[0009] In one feasible implementation, network attack prediction based on an attack intent inference engine is performed on the network security anomaly data to determine attack behavior characteristics. Specifically, this includes: performing BERT-based threat intelligence semantic analysis on the network security anomaly data using the attack intent inference engine to obtain semantic analysis results; predicting current network attack characteristics based on the confidence levels corresponding to the network attack characteristics to obtain abnormal SWIFT message information; generating attacker profile data based on the abnormal SWIFT message information; and extracting the attack behavior characteristics related to network attack behavior from the attacker profile data.

[0010] In one feasible implementation, the attack behavior characteristics are subjected to security decision evaluation processing related to the LIME local interpreter to obtain local security indicators. Specifically, this includes: using the LIME local interpreter, randomly perturbing the network packet data object corresponding to the attack behavior characteristics, while retaining the protocol header of the network packet data object, to obtain a perturbation sample list; conducting adversarial attack tests on the perturbation sample list and pre-generated malicious traffic samples, and performing security decision evaluation based on expert-annotated benchmark features on the adversarial attack test results to obtain the local security indicators of the attack behavior characteristics.

[0011] In one feasible implementation, the attack behavior characteristics are subjected to security decision evaluation processing using the SHAP global interpreter to obtain a global security index. Specifically, this includes: using the SHAP global interpreter to group the attack behavior characteristics according to the OSI seven-layer model to obtain grouped data; sequentially calculating the contribution of each layer of the grouped data; based on the contribution and time series, performing time-series dependency analysis on each sample of the grouped data to determine the abnormal network security characteristics under the key alarm time nodes; and performing security decision evaluation processing based on DeepSHAP to quantify the characteristics of each time step to obtain the global security index.

[0012] In one feasible implementation, multiple network security protection strategies are evaluated and screened based on the local security indicators and the global security indicators to determine the optimal network security protection strategy. Specifically, this includes: querying a security response strategy library based on the local security indicators and the global security indicators to obtain security response features; wherein the security response strategy library includes: attack phase, recommended actions, and confidence thresholds; and evaluating and screening the multiple network security protection strategies based on the security response features to obtain the optimal network security protection strategy.

[0013] In one feasible implementation, before evaluating and screening the various network security protection strategies based on the security response characteristics to obtain the optimal network security protection strategy, the method further includes: dynamically adjusting the response intensity of the security response characteristics to obtain dynamic security response characteristics; wherein, the response intensity includes: network security response strength, network security observation mode, network security suppression mode, and network security elimination mode; determining a flexible decision-making mechanism based on the dynamic security response characteristics; and evaluating and screening the security response characteristics corresponding to the flexible decision-making mechanism with the various network security protection strategies.

[0014] In one feasible implementation, after evaluating and screening multiple network security protection strategies to determine the optimal network security protection strategy, the method further includes: executing the response action in the optimal network security protection strategy; blocking external FTP connections; and initiating integrity verification of network security protection data.

[0015] Secondly, embodiments of this application also provide an intelligent decision-making device for responding to network attacks, the device comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor to enable the at least one processor to execute an intelligent decision-making method for responding to network attacks as described in any of the above embodiments.

[0016] Thirdly, embodiments of this application also provide a non-volatile computer storage medium, wherein the storage medium is a non-volatile computer-readable storage medium, and the non-volatile computer-readable storage medium stores at least one program, each program including instructions, wherein when the instructions are executed by a terminal, the terminal executes an intelligent decision-making method for responding to network attacks as described in any of the above embodiments.

[0017] This application provides an intelligent decision-making method, device, and medium for responding to cyberattacks. Compared with the prior art, the embodiments of this application have the following beneficial technical effects:

[0018] 1. Enhance security analysis capabilities: By collecting network information from multiple sources, the network security situation can be analyzed more comprehensively, improving the ability to detect potential threats.

[0019] 2. Intelligent attack prediction: Based on the predictive capabilities of the attack intent reasoning engine, it can more accurately predict network attacks, thereby taking preventive measures in advance.

[0020] 3. Decision support and optimization: The application of LIME and SHAP interpreters provides the ability to gain a deep understanding of the characteristics of attack behavior, which helps to make security decisions more transparent and optimized.

[0021] 4. Improve the adaptability of security strategies: By evaluating local and global security indicators, security strategies can be better adapted to different network environments and attack patterns, thus improving their adaptability.

[0022] 5. Reduce false positives and false negatives: Combining local and global indicators can reduce false positives for normal behavior while improving the detection of false negatives for malicious behavior.

[0023] 6. Improve security response efficiency: By automatically evaluating and filtering multiple security protection strategies, the optimal strategy can be quickly determined, thereby improving the response efficiency of security incidents. Attached Figure Description

[0024] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings:

[0025] Figure 1 A flowchart illustrating an intelligent decision-making method for responding to network attacks, provided in an embodiment of this application;

[0026] Figure 2 A flowchart illustrating the execution of an intelligent decision-making system for responding to cyberattacks, provided in an embodiment of this application;

[0027] Figure 3 This is a schematic diagram of the structure of an intelligent decision-making device for responding to network attacks, provided in an embodiment of this application. Detailed Implementation

[0028] To enable those skilled in the art to better understand the technical solutions in this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this application.

[0029] It should be noted that this application provides a network security intelligent decision-making method, including: receiving and analyzing logs, traffic, or alarm information in the network through an analysis body, and outputting attack behavior characteristics; an AI intelligent decision interpretation module (e.g., a dynamic decision matrix method) evaluating the value of multiple possible protection strategies based on the output of the analysis body, and selecting the optimal strategy; and finally, an execution body executing corresponding response actions according to the optimal strategy selected by the AI ​​intelligent decision-making body.

[0030] This application provides an intelligent decision-making method for responding to network attacks, such as... Figure 1 As shown, the intelligent decision-making method for responding to cyberattacks specifically includes steps S101-S105:

[0031] S101. Collect network security anomaly data from multi-source network information.

[0032] Specifically, it is necessary to first use NetFlow network layer traffic analysis technology and DPI application layer traffic analysis technology to parse and process abnormal alarm data of network traffic information to obtain network traffic security anomaly data.

[0033] Furthermore, EDR sensor technology is needed to identify abnormal behavior of network terminals and determine abnormal behavior data of network terminals.

[0034] Furthermore, the log data from the received multi-source network information is subjected to anomaly identification processing based on Syslog standardization to obtain log security anomaly data.

[0035] Furthermore, network traffic security anomaly data, network terminal behavior anomaly data, and log security anomaly data are combined to obtain network security anomaly data.

[0036] In one embodiment, Figure 2 A flowchart illustrating the execution of an intelligent decision-making system for responding to cyberattacks, as provided in this application embodiment, is shown below. Figure 2 As shown, the NetFlow network layer traffic analysis tool is deployed to collect network traffic data in real time. First, the DPI (Deep Packet Inspection) application layer traffic analysis tool is deployed to deeply analyze application layer traffic and identify potential security threats. Then, the collected network traffic data is analyzed, and anomaly detection algorithms are used to identify abnormal traffic patterns. Based on preset security rules and thresholds, network traffic security anomaly alarm data is generated.

[0037] In one embodiment, such as Figure 2 As shown, EDR (Endpoint Detection and Response) sensors are deployed on network terminals to monitor terminal activity in real time. The terminal behavior data is then analyzed in real time, and machine learning algorithms are used to identify abnormal behavior patterns. This generates abnormal terminal behavior data, including but not limited to malware activity and abnormal login attempts.

[0038] In one embodiment, such as Figure 2 As shown, log data is collected from network devices, servers, and applications. Then, Syslog standardization tools are used to convert the log data format, ensuring data consistency. Next, log analysis tools and anomaly detection algorithms are used to identify security anomalies in the logs. Finally, network traffic security anomaly data, network terminal behavior anomaly data, and log security anomaly data are integrated. Data cleaning and deduplication are performed to ensure data accuracy and uniqueness. This results in a comprehensive network security anomaly dataset, providing a data foundation for subsequent security analysis and decision-making.

[0039] S102. Perform network attack prediction based on an attack intent reasoning engine on network security anomaly data to determine the characteristics of attack behavior.

[0040] Specifically, the attack intent inference engine is first used to perform BERT-based threat intelligence semantic analysis on network security anomaly data to obtain semantic analysis results.

[0041] Furthermore, based on the confidence level corresponding to the network attack characteristics, the semantic analysis results are processed to predict the current network attack characteristics, thereby obtaining abnormal SWIFT message information.

[0042] Furthermore, attacker profile data is generated based on abnormal SWIFT message information.

[0043] Furthermore, attack behavior characteristics related to network attack behavior are extracted from the attacker profile data.

[0044] In one embodiment, such as Figure 2 As shown, in the attack chain prediction engine, a pre-trained language model based on BERT (Bidirectional Encoder Representations from Transformers) is first selected or developed to process threat intelligence data. The BERT model is then fine-tuned to adapt to specific cybersecurity threat intelligence analysis tasks. Next, cybersecurity anomaly data, including network traffic, logs, and SWIFT messages, is collected and preprocessed. The BERT model is used to perform semantic analysis on the preprocessed data, extracting key information and contextual relationships from the text. Then, based on the semantic analysis results output by the BERT model, machine learning algorithms are used to predict network attack characteristics. A confidence score is then used to evaluate the reliability of the prediction results; predictions with high confidence are considered valid. For SWIFT messages, the prediction model is also used to identify abnormal transactions or communication patterns. Abnormal SWIFT message information is extracted from the prediction results as a basis for further analysis. Then, based on the abnormal SWIFT message information and other network anomaly data, an attacker profile is constructed. This attacker profile should include characteristics such as the attacker's behavioral patterns, attack targets, and attack methods. Finally, key network attack behavioral features are extracted from the attacker profile data. For example, analyzing characteristics such as attack frequency, attack time, and target selection can help identify the attacker's strategies and intentions.

[0045] S103. Perform security decision evaluation processing on the attack behavior characteristics related to the LIME local interpreter to obtain local security indicators.

[0046] Specifically, the LIME local interpreter performs random perturbation on the network packet data objects corresponding to the attack behavior characteristics, while retaining the protocol header of the network packet data objects, to obtain a list of perturbation samples.

[0047] Furthermore, the list of perturbation samples is subjected to adversarial attack tests against pre-generated malicious traffic samples, and the adversarial attack test results are used for security decision evaluation based on expert-annotated benchmark features to obtain local security indicators of attack behavior characteristics.

[0048] As a feasible implementation method, local security metrics can be used to evaluate the robustness of intrusion detection systems (IDS) to load disturbances during security testing; to generate malicious traffic samples that can deceive machine learning models during adversarial attacks; and to verify the ability of network devices to handle abnormal loads during protocol fuzzing tests. In other words, by retaining the protocol header and randomly perturbed loads, variants of data packets can be generated in batches, which is beneficial for network security research and testing.

[0049] In one embodiment, such as Figure 2 As shown, in the processing of the dynamic decision matrix, network traffic data, including normal and malicious traffic samples, needs to be collected first. Feature extraction techniques are used to extract attack behavior features from network packet data, such as source IP, destination IP, port number, protocol type, and packet size. Then, a classification model (such as random forest, neural network, etc.) is selected or built as the base model for identifying and classifying malicious traffic. The LIME interpreter is initialized to prepare for perturbation processing and interpreting the model's decision-making process. Next, an attack behavior feature sample is selected, and LIME is used to randomly perturb the sample's payload data. During the perturbation process, the protocol header of the network packet data object is preserved to ensure that the perturbed data still conforms to network protocol specifications. Multiple perturbation sample lists are generated, with each sample's payload data randomly modified while retaining its header information. The perturbation sample list is then input into the base model along with pre-generated malicious traffic samples. Furthermore, adversarial attack tests are conducted to observe the base model's prediction results for the perturbation samples and analyze the model's robustness. The prediction results for the perturbation samples are also evaluated based on expert-annotated baseline features (such as known attack patterns and malware characteristics). By comparing the prediction results of the model before and after the perturbation, the impact of attack behavior characteristics on model decision-making is analyzed. Finally, based on the results of adversarial attack testing and security decision evaluation, local security indicators of attack behavior characteristics are calculated. These indicators may include changes in prediction confidence, model misclassification probability, etc.

[0050] S104. Perform security decision evaluation processing on the attack behavior characteristics related to the SHAP global interpreter to obtain global security indicators.

[0051] Specifically, the attack behavior characteristics are grouped according to the OSI seven-layer model using the SHAP global interpreter to obtain grouped data.

[0052] Furthermore, the contribution of each layer of grouped data is calculated sequentially.

[0053] Furthermore, based on the contribution and time series, a time-series dependency analysis is performed on each sample of the grouped data to determine the abnormal network security characteristics based on the key time nodes of the alarm.

[0054] Furthermore, the abnormal network security characteristics are subjected to security decision evaluation processing based on DeepSHAP quantification of the characteristics at each time step to obtain global security indicators.

[0055] As a feasible implementation method, combining global security metrics, in terms of model interpretability, it's possible to understand why the model marks specific traffic as malicious and identify key time points and characteristics that trigger alarms (such as sudden port scans); in feature engineering guidance, high |SHAP| values ​​can identify important features and discover redundant features (SHAP values ​​close to zero); in model debugging, it can detect whether the model focuses on unreasonable features (such as learning timestamp noise); and in security analysis, it can locate the decisive characteristics of attack traffic (such as specific load patterns). In other words, the SHAP global interpreter can provide model interpretability for security anomaly analysis of time-series network traffic. DeepSHAP quantifies the importance of features at each time step; reveals the model's decision-making basis (such as which traffic patterns trigger alarms); requires supplementing the background parameter to define the benchmark dataset; and the output results can be used for visualization, model optimization, and security analysis.

[0056] In one embodiment, such as Figure 2As shown, in the processing of the dynamic decision matrix, network traffic data, including normal and malicious traffic samples, is first collected. Feature extraction techniques are used to extract attack behavior features from the network packet data, such as source IP, destination IP, port number, protocol type, packet size, and timestamp. Then, according to the OSI seven-layer model, the attack behavior feature data is grouped according to the physical layer, data link layer, network layer, transport layer, session layer, presentation layer, and application layer. The data in each group is preprocessed to ensure consistent data format for subsequent analysis. Next, a classification model (such as random forest or neural network) is selected or constructed as the base model for identifying and classifying malicious traffic. The SHAP interpreter is initialized to prepare for calculating feature contribution and global interpretation. The SHAP interpreter is then used to calculate the contribution of each feature to the model's prediction. The contribution of each feature is calculated separately for each OSI layer group. Finally, time series analysis is performed on each sample of each OSI layer group to identify key time points that may correspond to critical moments in network attacks. Next, based on the results of contribution and time-series dependency analysis, abnormal network security characteristics at key alarm time points are identified. It is necessary to analyze whether these characteristics are related to known attack patterns. Finally, DeepSHAP is used to quantify the characteristics at each time step and assess their impact on security decisions at different time points. Global security metrics are then calculated, reflecting the overall security status of the network at key time points.

[0057] S105. Based on local and global security indicators, evaluate and screen various network security protection strategies to determine the optimal network security protection strategy.

[0058] Specifically, the security response strategy library needs to be queried and processed based on local and global security indicators to obtain security response characteristics. The security response strategy library includes: attack phase, recommended actions, and confidence thresholds.

[0059] As a feasible implementation method, before evaluating and screening various network security protection strategies to obtain the optimal strategy, it is necessary to dynamically adjust the response intensity of the security response characteristics to obtain dynamic security response characteristics. These response intensity characteristics include: network security response strength, network security observation mode, network security suppression mode, and network security elimination mode. Then, based on the dynamic security response characteristics, a resilient decision-making mechanism is determined. Subsequently, the security response characteristics corresponding to the resilient decision-making mechanism are evaluated and screened against various network security protection strategies.

[0060] Furthermore, based on security response characteristics, various network security protection strategies are evaluated and screened to obtain the optimal network security protection strategy.

[0061] Furthermore, execute the response actions in the optimal network security protection strategy; then block external FTP connections; and finally initiate integrity verification of network security protection data.

[0062] In addition, embodiments of this application also provide an intelligent decision-making device for responding to network attacks, such as... Figure 3 As shown, the intelligent decision-making device 300 for responding to cyberattacks specifically includes:

[0063] At least one processor 301; and a memory 302 communicatively connected to the at least one processor 301; wherein the memory 302 stores instructions executable by the at least one processor 301 to enable the at least one processor 301 to execute:

[0064] Collect network security anomaly data from multi-source network information;

[0065] Based on an attack intent reasoning engine, network attack prediction is performed on network security anomaly data to determine the characteristics of attack behavior;

[0066] The attack behavior characteristics are evaluated for security decisions related to the LIME local interpreter to obtain local security indicators.

[0067] The attack behavior characteristics are evaluated for security decisions related to the SHAP global interpreter to obtain global security indicators.

[0068] Based on local and global security indicators, various network security protection strategies are evaluated and screened to determine the optimal network security protection strategy.

[0069] This application's embodiments, by collecting multi-source network information, can more comprehensively analyze network security status and improve the ability to detect potential threats. Based on the predictive capabilities of the attack intent inference engine, network attacks can be predicted more accurately, allowing for proactive preventative measures. The application of LIME and SHAP interpreters provides a deep understanding of attack behavior characteristics, contributing to greater transparency and optimization in security decision-making. Furthermore, the evaluation of local and global security indicators allows for better adaptation to different network environments and attack patterns, improving the adaptability of security strategies. Combining local and global indicators reduces false positives for normal behavior while improving the detection of false negatives for malicious behavior. Moreover, by automatically evaluating and filtering multiple security protection strategies, the optimal strategy can be quickly determined, improving the response efficiency of security incidents.

[0070] The various embodiments in this application are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the device and medium embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the description of the method embodiments.

[0071] The devices and media provided in this application are one-to-one with the methods. Therefore, the devices and media also have similar beneficial technical effects as their corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the devices and media will not be repeated here.

[0072] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0073] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0074] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0075] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0076] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0077] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0078] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0079] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0080] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of this specification.

Claims

1. An intelligent decision-making method for responding to cyberattacks, characterized in that, The method includes: Collect network security anomaly data from multi-source network information; The network security anomaly data is used to perform network attack prediction based on an attack intent reasoning engine to determine the characteristics of attack behavior; The attack behavior characteristics are subjected to security decision evaluation processing related to the LIME local interpreter to obtain local security indicators; The attack behavior characteristics are subjected to security decision evaluation processing related to the SHAP global interpreter to obtain global security indicators; Based on the local security indicators and the global security indicators, various network security protection strategies are evaluated and screened to determine the optimal network security protection strategy.

2. The intelligent decision-making method for responding to network attacks according to claim 1, characterized in that, Collecting network security anomaly data from multi-source network information, specifically including: By using NetFlow network layer traffic analysis technology and DPI application layer traffic analysis technology, abnormal alarm data of network traffic information is parsed and processed to obtain network traffic security abnormal data. By using EDR sensor technology, abnormal behavior of network terminals can be identified and processed to determine abnormal data of network terminal behavior. The log data from the received multi-source network information is subjected to anomaly identification processing based on Syslog standardization to obtain log security anomaly data; The network traffic security anomaly data, the network terminal behavior anomaly data, and the log security anomaly data are combined to obtain the network security anomaly data.

3. The intelligent decision-making method for responding to network attacks according to claim 1, characterized in that, The network security anomaly data is used to perform network attack prediction based on an attack intent inference engine to determine attack behavior characteristics, specifically including: The attack intent inference engine is used to perform BERT-based threat intelligence semantic analysis on the network security anomaly data to obtain semantic analysis results. Based on the confidence level corresponding to the network attack characteristics, the semantic analysis results are processed to predict the current network attack characteristics, thereby obtaining abnormal SWIFT message information. Based on the abnormal SWIFT message information, attacker profile data is generated; Extract the attack behavior features related to network attack behavior from the attacker profile data.

4. The intelligent decision-making method for responding to network attacks according to claim 1, characterized in that, The attack behavior characteristics are subjected to security decision evaluation processing related to the LIME local interpreter to obtain local security indicators, specifically including: The LIME local interpreter performs random perturbation processing on the network packet data object corresponding to the attack behavior characteristics, and retains the protocol header of the network packet data object to obtain a perturbation sample list. The list of disturbance samples is subjected to adversarial attack tests against pre-generated malicious traffic samples. The adversarial attack test results are then used for security decision evaluation based on expert-annotated benchmark features to obtain the local security index of the attack behavior features.

5. The intelligent decision-making method for responding to network attacks according to claim 1, characterized in that, The attack behavior characteristics are subjected to security decision evaluation processing related to the SHAP global interpreter to obtain global security indicators, specifically including: The attack behavior characteristics are grouped according to the OSI seven-layer model using the SHAP global interpreter to obtain grouped data. The contribution of the grouped data at each level is calculated sequentially; Based on the contribution and time series, a time-series dependency analysis is performed on each sample of the grouped data to determine the abnormal network security characteristics based on the key time nodes of the alarm. The abnormal network security characteristics are subjected to security decision evaluation processing based on DeepSHAP quantization of the characteristics at each time step to obtain the global security index.

6. The intelligent decision-making method for responding to network attacks according to claim 1, characterized in that, Based on the local security indicators and the global security indicators, various network security protection strategies are evaluated and screened to determine the optimal network security protection strategy, specifically including: Based on the local security indicators and the global security indicators, the security response strategy library is queried to obtain security response features; wherein, the security response strategy library includes: attack phase, recommended actions, and confidence thresholds; Based on the security response characteristics, the various network security protection strategies are evaluated and screened to obtain the optimal network security protection strategy.

7. The intelligent decision-making method for responding to network attacks according to claim 6, characterized in that, Before evaluating and screening the various network security protection strategies based on the security response characteristics to obtain the optimal network security protection strategy, the method further includes: The security response characteristics are dynamically adjusted in terms of response intensity to obtain dynamic security response characteristics; wherein, the response intensity includes: network security response intensity, network security observation mode, network security suppression mode, and network security elimination mode; Based on the aforementioned dynamic security response characteristics, a flexible decision-making mechanism is determined; The security response characteristics corresponding to the elastic decision-making mechanism are evaluated and screened in conjunction with the various network security protection strategies.

8. The intelligent decision-making method for responding to network attacks according to claim 1, characterized in that, After evaluating and screening various network security protection strategies to determine the optimal network security protection strategy, the method further includes: Execute the response action in the optimal network security protection strategy; Block external FTP connections; Initiate integrity verification of network security protection data.

9. An intelligent decision-making device for responding to cyberattacks, characterized in that, The device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor to enable the at least one processor to execute an intelligent decision-making method for responding to network attacks according to any one of claims 1-8.

10. A non-volatile computer storage medium, characterized in that, The storage medium is a non-volatile computer-readable storage medium that stores at least one program, each program including instructions that, when executed by a terminal, cause the terminal to perform an intelligent decision-making method for responding to network attacks according to any one of claims 1-8.

Citation Information

Patent Citations

  • Method, system and device for generating interpretable threat intelligence

    CN116962047A

  • Intelligent intrusion detection method and system based on interpretable intrusion detection network

    CN118337427A

  • Multi-interpretation fusion algorithm for intrusion detection feature analysis

    CN118885966A

  • Multi-class network security threat perception and active and passive cooperative response processing system and method

    CN120223394A