A method, apparatus, and computer-readable storage medium for network security information consistency representation based on ontology modeling.

CN121462243BActive Publication Date: 2026-09-01NO 15 INST OF CHINA ELECTRONICS TECH GRP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511503121.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-21
Publication Date
2026-09-01
Estimated Expiration
2045-10-21

AI Technical Summary

Technical Problem

[0003]在网络空间安全或其他复杂工作环境中,由于任务目标非常多样化,且有异构化、海量化的特点,网络的物理和逻辑拓扑结构、角色、系统配置、安全策略各不相同,存在复杂的因果关系、时间约束、资源限制等,缺乏统一的语义描述框架,导致策略制定时遇到共享困难、决策迷雾和实用性低的问题

Benefits of technology

[0016] The network security information consistency representation method and apparatus based on ontology modeling provided in this disclosure enables different systems to share information through standard semantic interfaces through multi-level ontology modeling and dynamic update mechanisms. At the same time, cross-level consistency verification and adversarial testing enhance the reliability and security of the ontology model, effectively solving the problem of information inconsistency. It can achieve efficient task coordination and accurate decision-making in complex environments, and has application potential and practical value, especially in highly dynamic scenarios such as network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121462243B_ABST
    Figure CN121462243B_ABST
Patent Text Reader

Abstract

This disclosure provides a method and apparatus for consistent representation of network security information based on ontology modeling. The method includes: classifying various entities involved in network security, their relationships, and attributes to construct a hierarchical ontology model; eliminating conceptual conflicts and ambiguities in multi-source data within the ontology model through context binding, multi-perspective reconstruction, and fuzzy reasoning; triggering ontology updates by injecting data in real-time from heterogeneous data sources, and updating the ontology model through a collaborative reasoning engine and an atomic update operation set; performing cross-level consistency verification on the static structure and dynamic behavior of the ontology model, and verifying the robustness of the ontology model through adversarial testing. This solution effectively addresses the heterogeneity, conflict, and dynamic changes of multi-source data in the network security field, thereby achieving more accurate and robust security management and decision-making.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments disclosed herein relate to the field of network security technology, and more specifically, to a method, apparatus, and computer-readable storage medium storing a computer program for consistent representation of network security information based on ontology modeling. Background Technology

[0002] In knowledge engineering, an ontology is a structured abstraction of domain knowledge. A key goal of ontology modeling is to ensure that data or information across different systems, teams, or organizations is consistent and interoperable. Through standardized ontology structures, coordination and planning can be based on shared understanding, avoiding information silos and improving the efficiency and accuracy of work execution.

[0003] In cyberspace security or other complex working environments, due to the highly diverse and heterogeneous nature of task objectives, the physical and logical topologies, roles, system configurations, and security policies of networks vary greatly. Complex causal relationships, time constraints, and resource limitations exist, and the lack of a unified semantic description framework leads to difficulties in sharing strategies, decision-making fog, and low practicality. To achieve information sharing in cyberspace, an ontology needs to encompass all key entities within the domain, such as units, time, objectives, resources, and tools, and determine its usage objectives and scope based on specific task requirements.

[0004] Currently, ontology modeling methods still face many challenges in handling dynamic, complex, and cross-system understanding. Therefore, improving the expressive power, reasoning ability, cross-system information integration ability, and real-time adaptability of ontology is an urgent problem to be solved. Summary of the Invention

[0005] The embodiments described herein provide a method, apparatus, and computer-readable storage medium storing computer programs for consistent representation of network security information based on ontology modeling. By constructing a unified ontology semantic framework and integrating multi-source heterogeneous data, it ensures that network security information is dynamically and consistently expressed in heterogeneous environments, enabling synchronization and sharing among multiple systems.

[0006] According to a first aspect of this disclosure, a method for consistent representation of cybersecurity information based on ontology modeling is provided, comprising: classifying various entities involved in cyberspace security, their relationships, and attributes, and constructing a hierarchical ontology model; eliminating conceptual conflicts and ambiguities in multi-source data in the ontology model through context binding, multi-perspective reconstruction, and fuzzy reasoning; triggering ontology updates by injecting data in real time through heterogeneous data sources, and updating the ontology model through a collaborative reasoning engine and an atomic update operation set; performing cross-level consistency verification on the static structure and dynamic behavior in the ontology model, and verifying the robustness of the ontology model through adversarial testing.

[0007] In some embodiments of this disclosure, the classification of various entities, their relationships, and attributes involved in cyberspace security, and the construction of a hierarchical ontology model, includes: extracting entities, relationships, and attributes from multi-source data in the cybersecurity field using natural language processing technology; classifying the extracted entities into static entities and dynamic entities, where static entities are basic entities including attackers, assets, vulnerabilities, and defense strategies, and dynamic entities are entities with time- and state-aware attributes, including attack phases and asset availability; classifying the relationships between various entities into static relationships and dynamic relationships, where static relationships are fixed interactions between entities, and dynamic relationships are relationships that change dynamically with time or state; and classifying entity attributes into core attributes and context attributes, where core attributes are unique and standardized attributes, and context attributes are variables related to a specific scenario.

[0008] In some embodiments of this disclosure, the hierarchical ontology model includes a strategic planning layer, a task decomposition layer, an operation execution layer, and a context-aware layer. The strategic planning layer defines security objectives and a compliance framework; the task decomposition layer breaks down strategic objectives into executable task chains; the operation execution layer generates atomic operation sets and schedules resources in real time; and the context-aware layer provides real-time monitoring and semantic annotation of APT attack phases and resource load status by dynamically capturing network situation. The hierarchical ontology model further classifies various entities involved in cyberspace security, their relationships, and attributes, and includes: associating entities in the operation execution layer with access control policies in the task decomposition layer; converting resource constraints in the strategic planning layer into Petri net scheduling parameters in the operation execution layer; extracting key risk indicators from the raw logs of the operation execution layer using knowledge distillation techniques; and instantiating the abstract objectives of the strategic planning layer into specific access control list rules using a neural symbolic system.

[0009] In some embodiments of this disclosure, the elimination of conceptual conflicts and ambiguities in multi-source data in the ontology model through context binding, multi-perspective reconstruction, and fuzzy reasoning includes: conflict detection based on a rule engine and visual auditing; execution of corresponding conflict resolution strategies according to different conflict types, including naming conflicts, structural conflicts, semantic coverage conflicts, and temporal conflicts; elimination of role and operational ambiguities by binding actions with related objects, organizations, and contexts; parsing events or attacks from technical, organizational, and geographical dimensions through an entity-event ontology; and using a time-related trust model to introduce a decay function to handle the credibility of historical data.

[0010] In some embodiments of this disclosure, triggering ontology updates by injecting data in real time from heterogeneous data sources and updating the ontology model through a collaborative inference engine and an atomic update operation set includes: triggering ontology updates by continuously injecting data from heterogeneous data sources in real time and by changes in network state; adjusting the ontology model based on an inference engine with two levels: multimodal inference and conflict resolution; dynamically atomic update operation sets with granularity according to ontology update triggering conditions; generating a Merkle tree hash each time the ontology changes, and storing the data in a distributed ledger using IP dynamic hiding technology.

[0011] In some embodiments of this disclosure, triggering ontology updates through continuous injection of heterogeneous data sources in real time and changes in network status includes: using a hybrid natural language processing model to extract semantic features of attack behaviors in real time, identifying new attack behaviors, and updating the corresponding attack patterns in the knowledge base in real time; designing a dynamic update engine to perform frequency statistics and threshold judgment on security events, and when the exploitation frequency of a certain type of vulnerability exceeds a preset threshold, triggering the weight adjustment of the vulnerability exploitation condition relationship in the ontology and introducing new defense strategy nodes; using a Bayesian game model to dynamically adjust the temporal attributes of attack activity classes according to different stages of APT attacks; and enabling a lightweight ontology module when facing network bandwidth or computing resource constraints. The lightweight ontology module includes core vulnerability-CVE mapping and necessary security operations and responses for emergency response strategies.

[0012] In some embodiments of this disclosure, the dynamic atomic update operation set based on the ontology update triggering conditions and execution granularity includes: updating the ontology by single entity attribute expansion when a new attack feature fingerprint is discovered; updating the ontology by multi-entity relation chain reorganization when the defense strategy coverage decreases by 15%; updating the ontology by replacing the sub-ontology as a whole when a new attack framework is detected; and dynamically adjusting the weights of the connecting edges in the ontology model when resource allocation strategies conflict.

[0013] In some embodiments of this disclosure, cross-level consistency verification of the static structure and dynamic behavior in the ontology model, and robustness verification of the ontology model through adversarial testing, include: measuring the degree of consistency of entities or relations jointly labeled by multiple experts by calculating the Kendall consistency coefficient, including: verifying the consistency between different levels and concepts of the static structure through a formal rule base and ontology alignment matrix; verifying the time constraints of the task chain using the UPPAAL tool; and verifying the robustness of the ontology model to fuzzy or anomalous inputs through adversarial testing, including: injecting fuzzy entities into the operation execution layer, detecting anomalous propagation paths in the metamodel layer, and generating an adversarial sample library. The adversarial sample library is used to generate adversarial samples by applying small perturbations to normal input data, attempting to deceive the model into making incorrect judgments.

[0014] According to a second aspect of this disclosure, a network security information consistency representation apparatus based on ontology modeling is provided. The apparatus includes at least one processor and at least one memory storing a computer program. When the computer program is executed by the at least one processor, the apparatus causes the following: classifying various entities involved in cyberspace security, their relationships, and attributes to construct a hierarchical ontology model; eliminating conceptual conflicts and ambiguities in multi-source data within the ontology model through context binding, multi-perspective reconstruction, and fuzzy reasoning; triggering ontology updates by injecting data in real-time from heterogeneous data sources, and updating the ontology model through a collaborative reasoning engine and an atomic update operation set; performing cross-level consistency verification on the static structure and dynamic behavior of the ontology model, and verifying the robustness of the ontology model through adversarial testing.

[0015] According to a third aspect of this disclosure, a computer-readable storage medium storing a computer program is provided, wherein the computer program, when executed by a processor, implements the steps of the ontology-based network security information consistency representation method according to a first aspect of this disclosure.

[0016] The network security information consistency representation method and apparatus based on ontology modeling provided in this disclosure enables different systems to share information through standard semantic interfaces through multi-level ontology modeling and dynamic update mechanisms. At the same time, cross-level consistency verification and adversarial testing enhance the reliability and security of the ontology model, effectively solving the problem of information inconsistency. It can achieve efficient task coordination and accurate decision-making in complex environments, and has application potential and practical value, especially in highly dynamic scenarios such as network security. Attached Figure Description

[0017] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the accompanying drawings of the embodiments will be briefly described below. It should be understood that the drawings described below only relate to some embodiments of this disclosure and are not intended to limit this disclosure, wherein: Figure 1 This is an exemplary flowchart of a network security information consistency representation method based on ontology modeling according to embodiments of the present disclosure; Figure 2 This is a schematic block diagram of a network security information consistency representation device based on ontology modeling according to an embodiment of the present disclosure.

[0018] It should be noted that the elements in the attached diagram are schematic and not drawn to scale. Detailed Implementation

[0019] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this disclosure. All other embodiments obtained by those skilled in the art based on the described embodiments of this disclosure without creative effort are also within the scope of protection of this disclosure.

[0020] Unless otherwise defined, all terms used herein (including technical and scientific terms) shall have the same meaning as commonly understood by one of ordinary skill in the art to which this subject matter pertains. It will be further understood that terms such as those defined in commonly used dictionaries shall be interpreted as having meanings consistent with their meanings in the context of the specification and in the relevant art, and shall not be interpreted in an idealized or overly formal form unless otherwise explicitly defined herein. Furthermore, terms such as “first” and “second” are used only to distinguish one component (or part of a component) from another component (or another part of a component).

[0021] The goal of ontology construction is to provide a shared understanding framework for cross-organizational systems. By precisely defining the relationships and attributes between different entities, it enables efficient collaboration and information sharing among different systems. Ontology construction not only helps implementers clarify key factors such as objectives, resources, and time, but also provides a foundation for decision-making reasoning and optimization. This disclosure proposes an ontology-based method for consistent representation of cybersecurity information, aiming to address the heterogeneity, conflict, and dynamic changes of multi-source data in the cybersecurity field, thereby achieving more accurate and robust security management and decision-making.

[0022] Figure 1 This is an exemplary flowchart of a consistent representation method for network security information based on ontology modeling, according to embodiments of this disclosure. Figure 1 In the method 100 shown at box S102, various entities involved in cyberspace security, their relationships and attributes are classified to construct a hierarchical ontology model.

[0023] According to one embodiment of this disclosure, natural language processing technology is used to extract entities, relationships, and attributes from multi-source data in the cybersecurity field. A hierarchical ontology architecture can be created and edited using Protege, which has a user-friendly graphical interface for designing and managing ontology concepts (classes) and their attributes and relationships. For example, in the cybersecurity field, core concepts and their interrelationships can be modeled to form a structured knowledge base. These core concepts include "attack," "vulnerability," and "defense strategy." Each entity class can have multiple attributes; for example, the "attack" class includes attributes such as "attack type" and "attack target." Concepts are interconnected through relationships; for example, the relationship between "attack" and "vulnerability" can be represented as "exploitation," while the relationship between "defense strategy" and "vulnerability" can be represented as "protection."

[0024] Ontologies can not only represent static domain knowledge but also support dynamic expansion. For example, when facing new types of cyber threats, the system can automatically expand the ontology to include new attack types, vulnerabilities, or defense strategies. Ontologies can be dynamically adjusted by introducing new concepts or modifying existing ones, and new defense strategies can be generated through reasoning based on past attack cases and defense strategies by expert systems. To ensure the scalability and maintainability of the ontology, it can be divided into multiple modules, each handling different domains or functions, facilitating independent updates and expansions. Inheritance relationships are used to organize classes in the ontology, ensuring that new concepts can be extended by inheriting from existing concepts. Version control mechanisms are employed to facilitate the management of ontology updates and revisions, ensuring compatibility between different versions.

[0025] According to one embodiment of this disclosure, the extracted entities can be divided into static entities and dynamic entities. Static entities are basic entities including attackers, assets, vulnerabilities, and defense strategies. Dynamic entities are entities with time- and state-aware attributes, including attack phases and asset availability. Static entities are fixed and immutable elements in network security. These entities are typically based on standardized data sources (such as STIX and CVE). For example, the CDO (Cyber ​​Defense Ontology) network security ontology defines the inheritance relationship between attack patterns and weaknesses through standards such as STIX and CVE to ensure the consistency of security knowledge mapping. Attackers are typically described as potential threat sources, and the types and behaviors of attackers can be summarized as attack patterns. Assets include hardware, software, and data in the network, which are targets that need to be protected. Vulnerabilities are security flaws or weaknesses existing in the system that attackers can exploit. Defense strategies are security measures and policies used to respond to and mitigate potential threats.

[0026] Dynamic entities introduce time- and state-aware attributes, reflecting changes in entities across different times and states. Dynamic entities include attack phases, exploitation, and asset availability. Different attack phases reflect the progress of an attack from preparation to actual exploitation. Asset availability reflects whether an asset is under attacker control, influencing the choice of defense strategies. Based on this, ontology can bind events and activities through timely occurrence relationships, supporting temporal reasoning and detecting the sequence and temporal relationships of cybersecurity events, thus aiding in analyzing attack patterns and the timeliness of defense strategies.

[0027] Relationships between various entities are categorized into static and dynamic relationships. Static relationships represent fixed interactions between entities, while dynamic relationships are those that change over time or with varying states. This distinction provides a more flexible description for modeling cybersecurity incidents. For example, "Exploits" indicates that an attacker exploits a vulnerability to launch an attack, while "Mitigates" indicates that a defense strategy effectively reduces the risks posed by a vulnerability. These relationships are represented by triples (e.g., attack pattern, vulnerability, countermeasure) to construct causal chains, describing the dynamic adversarial process between attackers and defenders, which helps analyze the interactions between different factors in cybersecurity incidents. Dynamic relationships, on the other hand, describe the complex interactions in a cybersecurity scenario that change over time or with varying states. For example, the "EscalatesTo" relationship describes the escalation of an attack, indicating that an attacker gradually escalates from a low-level attack to a higher-level one. The "Requires" relationship describes the preconditions for defensive actions. These dynamic relationships are represented through system dynamics models, which help to dynamically simulate and predict the evolution of attack and defense strategies, thereby supporting cybersecurity decision-making.

[0028] Entity attributes are divided into core attributes and context attributes. Core attributes are unique and standardized, while context attributes are scenario-dependent variables. Core attributes include unique identifiers (CVE-IDs) and severity scores. CVE-IDs uniquely identify vulnerabilities and attack patterns, while severity scores measure the severity of vulnerabilities, helping to determine the appropriate response strategy. Context attributes reflect the environmental characteristics of security events and defense strategies; variables such as resource availability and environmental threat levels can influence the selection and effectiveness of defense strategies. In the InfoSec entity hierarchy, service security attributes help dynamically adjust security policy weights, ensuring that policies remain effective across different network security environments.

[0029] Through the aforementioned multi-dimensional entity modeling framework, the cybersecurity ontology model can effectively integrate static and dynamic security information, describing the causal relationships and dynamic evolution processes between entities, thereby providing strong support for security analysis, decision-making, and automated defense. The hierarchical approach to entity classification, relationship modeling, and attribute design not only improves the model's accuracy but also enhances its flexibility and operability in practical cybersecurity applications.

[0030] The resulting hierarchical ontology model includes a strategic planning layer, a task decomposition layer, an operation execution layer, and a context-aware layer. The strategic planning layer is used to define security objectives and compliance frameworks; the task decomposition layer is used to break down strategic objectives into executable task chains; the operation execution layer is used to generate atomic operation sets and schedule resources in real time; and the context-aware layer is used to provide real-time monitoring and semantic annotation of APT attack phases and resource load status by dynamically capturing network situation.

[0031] Entities in the operation execution layer can be associated with access control policies in the task decomposition layer, thereby enhancing semantic richness. Resource constraints in the strategic planning layer are transformed into Petri net scheduling parameters in the operation execution layer, ensuring the system adheres to efficient constraints during execution. Knowledge distillation techniques are used to extract key risk indicators from the raw logs of the operation execution layer into those for the task decomposition layer. This compression method can achieve a data compression rate of up to 99.3% and improve data processing efficiency. A neural symbolic system is used to instantiate abstract goals from the strategic planning layer into concrete access control list rules, ensuring a smooth transition from abstract strategy to concrete implementation.

[0032] Subsequently Figure 1 At box S104, conceptual conflicts and ambiguities in the ontology model are eliminated through context binding, multi-perspective reconstruction, and fuzzy reasoning.

[0033] In multi-objective scenarios, conceptual conflicts or ambiguities often arise. For example, "defense strategy" may have different definitions or applications in different contexts. The key to resolving such conflicts is to define specific contexts for each objective or context, ensuring that concepts are not confused between different objectives, and achieving strategy synergy through ontology fusion.

[0034] According to one embodiment of this disclosure, conflict detection can be performed based on a rules engine and visual auditing. Corresponding conflict resolution strategies are executed according to different conflict types, including naming conflicts, structural conflicts, semantic coverage conflicts, and temporal conflicts. For example, if a logical contradiction such as "an unpatched vulnerability cannot be associated with a mitigated state" is detected, an alarm or suggested modification is automatically triggered. Conflict information is visualized using a graph model, with node colors and connection types used to indicate conflict levels. For example, red arrows indicate issues such as permission violations. Graphical conflict annotations can more intuitively help auditors identify and resolve potential conflicts.

[0035] Appropriate resolution strategies should be implemented for different types of conflicts. The table below details the conflict types and their solutions:

[0036] Then, ambiguity regarding roles and operations is eliminated by binding actions to relevant objects, organizations, and contexts. For example, the action of "blocking an IP" has different meanings in different contexts and needs to be determined based on the specific environment (such as intranet or extranet). Attacks are analyzed from multiple dimensions (technical, organizational, geographical, etc.) using Event-Entity Ontology. For example, malicious IPs can be associated with geographical locations via GeoIP and with their respective networks via ASN (Autonomous System Number), thus analyzing the attack source from multiple dimensions and eliminating ambiguity. A time-related trust model is used, introducing a decay function to handle the credibility of historical data. For example, for a vulnerability discovered three months ago, its threat weight will decrease by 30% according to the decay rule, thus more accurately reflecting its current threat level.

[0037] Then in Figure 1 At box S106, data is injected in real time through heterogeneous data sources to trigger ontology updates, and the ontology model is updated through a collaborative inference engine and an atomic update operation set.

[0038] According to one embodiment of this disclosure, ontology updates are triggered by continuous injection of heterogeneous data sources in real time and changes in network state. The ontology model is adjusted based on a two-layer inference engine consisting of multimodal reasoning and conflict resolution. Specifically, a hybrid natural language processing model (such as a combination of ELMo and graph neural networks) is used to extract semantic features of attack behaviors in real time, identify new attack behaviors, and update the corresponding attack patterns in the knowledge base in real time. For example, when a new type of DDoS attack is discovered, the model can automatically extract attributes such as "reflection amplification coefficient" and "protocol abuse pattern" to generate attack pattern subclass instances. By designing a dynamic update engine to perform frequency statistics and threshold judgments on security events, when the exploitation frequency of a certain type of vulnerability exceeds a preset threshold (such as 50 times within 24 hours), the weight adjustment of the vulnerability exploitation condition relationship in the ontology is triggered, and a new defense strategy node is introduced.

[0039] By linking the ontology structure with the network situation, the ontology can adjust accordingly when the network state changes. Based on a Bayesian game theory framework, the temporal attributes of attack activities are dynamically adjusted according to different stages of an APT attack (such as reconnaissance, weaponization, and penetration). When the attack enters the "lateral movement" stage, the system automatically expands the relationships between entities on the asset exposure surface and adds dependency chains such as "internal jump servers" and "database instances." This stage mapping helps reflect the attack progress in real time and optimize defense strategies. When facing network bandwidth or computing resource constraints, a lightweight ontology module is activated. This lightweight ontology module includes core vulnerability-CVE mapping and necessary security operations and responses for incident response strategies.

[0040] The inference engine architecture primarily comprises two layers: multimodal inference and conflict resolution, ensuring accurate inference and adjustment under diverse inputs and contexts. Logical constraint inference can be performed using a SWRL rule base. For example, "If the CVE-2025-XXX vulnerability is not patched, disable the relevant service ports." LSTM (Long Short-Term Memory) models are used to predict attribute change trends, such as the vulnerability's lifecycle decay curve, allowing for timely adjustments to the ontology model. A threshold-based cryptography mechanism requires 3 / 5 administrator signature confirmation for significant ontology changes. This mechanism ensures security and consistency during ontology updates. Attack path backtracking analysis identifies which defense strategy nodes require priority updates, thereby reducing potential attack risks.

[0041] Subsequently, based on the ontology update triggering conditions and the set of dynamic atomic update operations at the execution granularity, the following table shows the set of atomic update operations according to embodiments of this disclosure:

[0042] Among these, attribute appending involves adding new attributes to existing entities or concepts to supplement and enhance the expressive power of the ontology. Relationship restructuring involves adjusting, expanding, or optimizing the relationships between entities in the ontology. Hot module replacement refers to dynamically replacing parts of the ontology model without stopping system operation. Weight rebalancing involves dynamically adjusting the weights of entities such as tasks, goals, and resources in the ontology model to better reflect current environmental changes or task priorities.

[0043] When a new attack signature fingerprint is discovered, the ontology is updated by extending single-entity attributes. For example, adding a "JNDI recursive parsing depth" attribute for a Log4j vulnerability. When the coverage of a defense strategy drops by 15%, the ontology is updated by reorganizing multi-entity relationship chains. For example, establishing a mandatory verification relationship between the zero-trust policy and the API gateway entity. When a new attack framework (such as AI-generated malicious code) is detected, the entire sub-ontology is replaced. For example, replacing the traditional automated attack module with an AI-driven attack pattern sub-ontology. When resource allocation policies conflict, the weights of connection edges in the ontology model are dynamically adjusted. For example, increasing the priority of the traffic scrubbing policy to 0.9 in DDoS defense.

[0044] Security is paramount during ontology updates. According to one embodiment of this disclosure, a Merkle tree hash is generated each time the ontology changes, and the data is stored in a distributed ledger using dynamic IP hiding technology. For example, at the syntactic layer, logical contradictions in classes, attributes, and relationships are detected using an OWL 2 ELK inference engine. At the semantic layer, knowledge distillation technology is used to compare the decision differences between the old and new ontology, with a threshold set at a cosine similarity ≥ 0.85 to ensure the consistency of the updated ontology. Ontology update operations are divided into multiple sensitivity levels, allowing only administrators with specific tags to perform high-risk operations. Visualization tools allow administrators to intuitively verify the results of the updated ontology, further ensuring consistency and the accuracy of decisions.

[0045] Finally, in box S108, cross-level consistency verification is performed on the static structure and dynamic behavior in the ontology model, and the robustness of the ontology model is verified through adversarial testing.

[0046] The consistency coefficient (such as Kendall's consistency coefficient) is used to measure the degree of consistency among multiple experts in labeling entities or relationships, thereby assessing the logical consistency of the ontology model. For example, if multiple experts show high consistency in labeling entity relationships, it indicates that the ontology model design is relatively reasonable. To ensure that the structure and behavior at each layer in a cybersecurity ontology model are consistently coordinated and robust enough to withstand potential attacks and vulnerabilities, combining static structure verification, dynamic behavior verification, and adversarial testing can effectively improve the model's stability and security.

[0047] Static structure verification focuses on the consistency of structure and concepts across different levels of the ontology model. This consistency can be verified using a formal rule base and an ontology alignment matrix. The ELK inference engine can be used to perform real-time testing on the ontology model, ensuring compliance with OWL 2 EL level inference standards. OWL 2 EL is a subset of the WebOntology Language, suitable for scenarios with relatively simple inference but high processing power. The ontology alignment matrix compares different levels and concepts, assesses their similarity, and uses different mapping types (such as owl:equivalentClass and skos:closeMatch) to verify the relationships between levels. For example, the "compliance framework" of the strategic planning layer and the "control baseline" of the task decomposition layer, mapped using owl:equivalentClass, have a similarity of 0.92, indicating that their definitions in the ontology are almost identical. The "blocking action" of the operation execution layer and the "attack mitigation" of the context layer, mapped using skos:closeMatch, have a similarity of 0.78, indicating that they have some functional similarity but some differences.

[0048] Dynamic behavior verification ensures that various behaviors and task chains satisfy time and state constraints during the practical application of the ontology model, ensuring the consistency of dynamic behavior. The UPPAAL tool can be used to verify the time constraints in the task chain. UPPAAL is a model checking tool used to verify the system's temporal behavior, ensuring that the system's time constraints in various task chains are not violated, especially when facing dynamic changes.

[0049] The adversarial testing framework is used to verify the robustness of the ontology model under potential attacks. By simulating malicious attacks, it tests the model's response to uncertainty and attacks, and improves its anti-interference capability by generating an adversarial sample library. According to one embodiment of this disclosure, fuzzy entities are injected into the operation execution layer. Fuzzy entities refer to ambiguous or partially open inputs, such as semi-open network ports or incompletely validated input data. By injecting these fuzzy entities, potential security vulnerabilities or data inconsistencies can be simulated, thereby evaluating the ontology model's performance in the face of abnormal or unknown inputs. The purpose of this is to enhance the model's ability to respond to security threats.

[0050] Detecting anomaly propagation paths at the metamodel layer. The metamodel layer is where the behavior of the ontology model is abstracted and analyzed. By tracking changes in the model's internal state, the propagation paths of anomalous inputs are detected, identifying which parts are susceptible to disturbances and helping to identify potential vulnerabilities. This helps to understand how anomalies propagate and affect system behavior when the model is attacked, providing a basis for the system's security design.

[0051] Adversarial example libraries are used to generate adversarial examples by applying small perturbations to normal input data, attempting to trick the model into making incorrect decisions. For example, algorithms such as the Fast Signed Gradient Method (FGSM) or Projected Gradient Descent (PGD) can be used to generate adversarial examples. By adding these adversarial examples to the training set, the model can become more adaptable to perturbations, thereby improving overall security and robustness. The use of adversarial example libraries not only allows for the evaluation of the model's robustness during testing but also enhances the model's defense capabilities by continuously updating the examples in the library.

[0052] Ontology-based modeling provides strong support for information sharing and execution optimization in work arrangements. Through explicit entity modeling, relation definition, and instantiation, ontology not only ensures information consistency in work arrangements but also facilitates the automatic generation, reasoning, and optimization of work arrangements.

[0053] Figure 2 This is a schematic block diagram of a network security information consistency representation apparatus based on ontology modeling, according to embodiments of the present disclosure. Figure 2 As shown, the device 200 may include a processor 210 and a memory 220 storing a computer program. When the computer program is executed by the processor 210, the device 200 is made capable of performing actions such as... Figure 1 The steps of the method are shown. In one example, device 200 can classify various entities, their relationships, and attributes involved in cyberspace security, and construct a hierarchical ontology model; eliminate conceptual conflicts and ambiguities in multi-source data in the ontology model through context binding, multi-perspective reconstruction, and fuzzy reasoning; trigger ontology updates by injecting data in real time through heterogeneous data sources, and update the ontology model through a collaborative reasoning engine and an atomic update operation set; perform cross-level consistency verification on the static structure and dynamic behavior in the ontology model, and verify the robustness of the ontology model through adversarial testing.

[0054] In some embodiments of this disclosure, the device 200 can use natural language processing technology to extract entities, relationships, and attributes from multi-source data in the field of network security; the extracted entities are divided into static entities and dynamic entities, static entities are basic entities including attackers, assets, vulnerabilities, and defense strategies, and dynamic entities are entities with time and state-aware attributes, including attack phase and asset availability; the relationships between various entities are divided into static relationships and dynamic relationships, static relationships are causal chains established through triples, and dynamic relationships are relationships that change dynamically with time or state; entity attributes are divided into core attributes and context attributes, core attributes are unique and standardized attributes, and context attributes are variables related to the scenario.

[0055] In some embodiments of this disclosure, the device 200 can perform conflict detection based on a rule engine and visual auditing, and execute corresponding conflict resolution strategies according to different conflict types, including naming conflicts, structural conflicts, semantic overriding conflicts, and temporal conflicts; eliminate role and operation ambiguities by binding actions with related objects, organizations, and contexts; parse events or attacks from technical, organizational, and geographical dimensions through entity-event ontology; and use a time-related trust model to introduce a decay function to handle the credibility of historical data.

[0056] In some embodiments of this disclosure, the device 200 can trigger ontology updates through continuous injection of heterogeneous data sources in real time and changes in network state; adjust the ontology model based on a two-level inference engine of multimodal inference and conflict resolution; perform dynamic atomic update operations according to ontology update triggering conditions and execution granularity; and generate a Merkle tree hash each time the ontology changes, and store the data in a distributed ledger through IP dynamic hiding technology.

[0057] In some embodiments of this disclosure, the device 200 can employ a hybrid natural language processing model to extract semantic features of attack behaviors in real time, identify new attack behaviors, and update the corresponding attack patterns in the knowledge base in real time; by designing a dynamic update engine to perform frequency statistics and threshold judgment on security events, when the exploitation frequency of a certain type of vulnerability exceeds a preset threshold, the weight adjustment of the vulnerability exploitation condition relationship in the ontology is triggered, and a new defense strategy node is introduced; a Bayesian game model is adopted to dynamically adjust the temporal attributes of attack activity classes according to different stages of APT attacks; when facing network bandwidth or computing resource constraints, a lightweight ontology module is activated, which includes core vulnerability-CVE mapping and necessary security operations and responses for emergency response strategies.

[0058] In some embodiments of this disclosure, the device 200 can update the ontology by expanding single entity attributes when a new attack feature fingerprint is discovered; update the ontology by reorganizing multi-entity relationship chains when the defense strategy coverage decreases by 15%; update the ontology by replacing the sub-ontology as a whole when a new attack framework is detected; and dynamically adjust the weights of the connecting edges in the ontology model when resource allocation strategies conflict.

[0059] In some embodiments of this disclosure, the apparatus 200 can measure the degree of consistency of entities or relations jointly labeled by multiple experts by calculating the Kendall consistency coefficient, including: verifying the consistency between different levels and concepts of the static structure through a formal rule base and ontology alignment matrix; verifying the time constraints of the task chain using the UPPAAL tool; and verifying the robustness of the ontology model to fuzzy or anomalous inputs through adversarial testing, including: injecting fuzzy entities into the operation execution layer, detecting anomalous propagation paths in the metamodel layer, and generating an adversarial sample library, which is used to generate adversarial samples by applying small perturbations to normal input data in an attempt to deceive the model into making incorrect judgments.

[0060] In embodiments of this disclosure, processor 210 may be, for example, a central processing unit (CPU), a microprocessor, a digital signal processor (DSP), a processor based on a multi-core processor architecture, etc. Memory 220 may be any type of memory implemented using data storage technologies, including but not limited to random access memory, read-only memory, semiconductor-based memory, flash memory, disk storage, etc.

[0061] Furthermore, in embodiments of this disclosure, device 200 may also include input device 230, such as a keyboard, mouse, etc. Additionally, device 200 may also include output device 240, such as a display, etc.

[0062] In other embodiments of this disclosure, a computer-readable storage medium storing a computer program is also provided, wherein the computer program, when executed by a processor, is capable of performing the following functions: Figure 1 The steps of the ontology-based network security information consistency representation method 100 are shown.

[0063] In summary, the ontology-based network security information consistency representation method and apparatus according to the embodiments of this disclosure enables different systems to share information through standard semantic interfaces through multi-layered ontology modeling and dynamic update mechanisms. At the same time, cross-layer consistency verification and adversarial testing enhance the reliability and security of the ontology model, effectively solving the problem of information inconsistency. It can achieve efficient task coordination and accurate decision-making in complex environments, and has application potential and practical value, especially in highly dynamic scenarios such as network security.

[0064] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatuses and methods according to various embodiments of the present disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of an instruction, which contains one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0065] Unless otherwise expressly indicated by the context, the singular form of words used herein and in the appended claims includes the plural form, and vice versa. Thus, when referring to the singular, the plural form of the corresponding term is generally included. Similarly, the terms “comprising” and “including” shall be interpreted as including rather than exclusively. Likewise, the terms “including” and “or” shall be interpreted as including unless such interpretation is expressly prohibited herein. Where the term “example” is used herein, particularly when it follows a set of terms, “example” is merely exemplary and illustrative and should not be considered exclusive or extensive.

[0066] Further aspects and scope of adaptation become apparent from the description provided herein. It should be understood that various aspects of this application may be implemented individually or in combination with one or more other aspects. It should also be understood that the descriptions and specific embodiments herein are for illustrative purposes only and are not intended to limit the scope of this application.

[0067] Several embodiments of this disclosure have been described in detail above. However, it is obvious that those skilled in the art can make various modifications and variations to the embodiments of this disclosure without departing from the spirit and scope of this disclosure. The scope of protection of this disclosure is defined by the appended claims.

Claims

1. A method for consistent representation of network security information based on ontology modeling, characterized in that, include: Classify the various entities, their relationships, and attributes involved in cyberspace security, and construct a hierarchical ontology model; Conceptual conflicts and ambiguities in the ontology model are eliminated through context binding, multi-perspective reconstruction, and fuzzy reasoning; Ontology updates are triggered by real-time data injection from heterogeneous data sources, and the ontology model is updated through a collaborative inference engine and an atomic update operation set. This includes: triggering ontology updates through continuous real-time injection from heterogeneous data sources and changes in network state; adjusting the ontology model based on a two-tiered inference engine of multimodal inference and conflict resolution; updating the ontology by expanding single-entity attributes when a new attack signature fingerprint is discovered; updating the ontology by reorganizing multi-entity relationship chains when the defense strategy coverage decreases by 15%; updating the ontology by replacing the entire sub-ontology when a new attack framework is detected; dynamically adjusting the weights of connecting edges in the ontology model when resource allocation strategies conflict; and generating a Merkle tree hash for each ontology change and storing the data in a distributed ledger using dynamic IP hiding technology. as well as Cross-level consistency verification is performed on the static structure and dynamic behavior in the ontology model, and the robustness of the ontology model is verified through adversarial testing.

2. The method for consistent representation of network security information based on ontology modeling according to claim 1, characterized in that, The classification of various entities, their relationships, and attributes involved in cyberspace security, and the construction of a hierarchical ontology model, includes: Utilize natural language processing technology to extract entities, relationships, and attributes from multi-source data in the field of cybersecurity; The extracted entities are divided into static entities and dynamic entities. The static entities are basic entities including attackers, assets, vulnerabilities, and defense strategies. The dynamic entities are entities with time and state-aware attributes, including attack phase and asset availability. The relationships between various entities are divided into static relationships and dynamic relationships. Static relationships are established through causal chains using triples, while dynamic relationships are relationships that change dynamically with time or state. Entity attributes are divided into core attributes and context attributes. The core attributes are unique and standardized attributes, while the context attributes are variables related to the scenario.

3. The method for consistent representation of network security information based on ontology modeling according to claim 1, characterized in that, The hierarchical ontology model comprises a strategic planning layer, a task decomposition layer, an operation execution layer, and a context-aware layer. The strategic planning layer defines security objectives and a compliance framework; the task decomposition layer breaks down strategic objectives into executable task chains; the operation execution layer generates atomic operation sets and schedules resources in real time; and the context-aware layer provides real-time monitoring and semantic annotation of APT attack phases and resource load status by dynamically capturing network situational awareness. The classification of various entities, their relationships, and attributes involved in cyberspace security, and the construction of a hierarchical ontology model, also includes: Associate entities in the operation execution layer with access control policies in the task decomposition layer, and convert resource constraints in the strategic planning layer into Petri net scheduling parameters in the operation execution layer. Knowledge distillation technology is used to extract key risk indicators from the raw logs of the operation execution layer into the task decomposition layer. By using a neural symbol system, the abstract goals of the strategic planning layer are instantiated into specific access control list rules.

4. The method for consistent representation of network security information based on ontology modeling according to claim 1, characterized in that, The elimination of conceptual conflicts and ambiguities in the ontology model through context binding, multi-perspective reconstruction, and fuzzy reasoning includes: Conflict detection is performed based on a rule engine and visual auditing. Corresponding conflict resolution strategies are executed according to different conflict types, including naming conflicts, structural conflicts, semantic coverage conflicts, and temporal conflicts. Eliminate ambiguity in roles and operations by binding actions to relevant objects, organizations, and contexts; Analyzing events or attacks from technical, organizational, and geographical dimensions through entity-event ontology; and By utilizing a time-related trust model, a decay function is introduced to handle the credibility of historical data.

5. The method for consistent representation of network security information based on ontology modeling according to claim 1, characterized in that, The method of triggering ontology updates through continuous injection of real-time heterogeneous data sources and changes in network state includes: A hybrid natural language processing model is used to extract semantic features of attack behaviors in real time, identify new attack behaviors, and update the corresponding attack patterns in the knowledge base in real time. By designing a dynamic update engine to perform frequency statistics and threshold judgment on security events, when the exploitation frequency of a certain type of vulnerability exceeds the preset threshold, the weight adjustment of the vulnerability exploitation condition relationship in the ontology is triggered, and a new defense strategy node is introduced. A Bayesian game theory model is used to dynamically adjust the temporal attributes of attack activity classes according to different stages of APT attacks. When faced with limited network bandwidth or computing resources, a lightweight ontology module is activated. This lightweight ontology module includes the necessary security operations and responses for core vulnerability-CVE mapping and incident response strategies.

6. The method for consistent representation of network security information based on ontology modeling according to claim 1, characterized in that, The cross-level consistency verification of the static structure and dynamic behavior in the ontology model, and the verification of the robustness of the ontology model through adversarial testing, include: Kendall's consistency coefficient is used to measure the degree of consistency among multiple experts in jointly annotating entities or relations. This includes: verifying consistency between different levels and concepts of the static structure using a formal rule base and ontology alignment matrix; validating the time constraints of the task chain using the UPPAAL tool; and... The robustness of the ontology model to fuzzy or anomalous inputs is verified through adversarial testing, which includes: injecting fuzzy entities into the operation execution layer, detecting anomalous propagation paths in the metamodel layer, and generating an adversarial sample library. The adversarial sample library is used to generate adversarial samples by applying small perturbations to normal input data, in an attempt to deceive the model into making incorrect judgments.

7. A network security information consistency representation device based on ontology modeling, characterized in that, The device includes: At least one processor; and At least one memory storing a computer program; When the computer program is executed by the at least one processor, the device performs the steps of the network security information consistency representation method based on ontology modeling according to any one of claims 1 to 6.

8. A computer-readable storage medium storing a computer program, characterized in that, When executed by a processor, the computer program implements the steps of the network security information consistency representation method based on ontology modeling according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Multi-source heterogeneous network security knowledge graph construction and application method

    CN111163086A

  • Construction method for network security-oriented space knowledge graph

    CN115455206A