Network security guarantee strategy dynamic optimization method, system, equipment and medium
By standardizing the processing of enterprise security operation data and applying dynamic policy adjustment functions, the problems of real-time perception and dynamic adjustment of network threats have been solved. Stable fusion of multi-source data and auditable policy optimization have been achieved, forming a positive incentive mechanism for security practices and improving the robustness and response efficiency of network security.
Patent Information
- Application Number
- CN202511564506.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-30
- Publication Date
- 2026-02-06
AI Technical Summary
Existing technologies struggle to achieve real-time perception and dynamic adjustment of network threats. They are difficult to integrate multi-source heterogeneous data, are sensitive to noise leading to policy jitter, lack auditable decision-making loops and positive incentive mechanisms, and lack end-to-end, quantifiable, and interpretable dynamic policy optimization solutions.
By collecting security operation data from target enterprises, preprocessing and standardizing indicators, setting weights, using dynamic adjustment functions to calculate and generate dynamic optimization schemes, and introducing adjustment cooling-off periods and external threat intelligence, an auditable strategy adjustment closed loop is formed, and evidence packages are generated for human-machine collaborative confirmation.
It improves the timeliness and accuracy of dynamic risk assessment, builds an auditable and explainable closed loop for strategy adjustment, forms a positive incentive mechanism for improving security practices, and enhances the robustness and anti-interference ability of the system.
Smart Images

Figure CN121485976A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, specifically to a method, system, device, and medium for dynamically optimizing network security protection strategies. Background Technology
[0002] Modern organizations face high-frequency, rapidly evolving, and complex cyber threats, urgently requiring a technological mechanism capable of real-time security posture awareness and dynamic adjustment of protection strategies. Current mainstream Security Operations Centers (SOCs) or Security Information and Incident Management (SIEM) systems typically rely on periodic manual assessments, making it difficult to respond promptly to incidents such as sudden vulnerability exploits and persistent intrusions.
[0003] In recent years, with the increasing demand for cybersecurity risk governance, new service models such as cybersecurity assurance services have gradually emerged, relying on the continuous, objective, and quantitative assessment of the security posture of the protected organization. In such scenarios, cybersecurity assurance service providers need to dynamically assess the risk level of the protected organization based on its real-time security data and adjust their assurance strategies accordingly. This further highlights the urgent need for automated, explainable, and auditable dynamic risk assessment and strategy optimization technologies.
[0004] However, existing technologies still have significant bottlenecks: (1) Difficulty in integrating multi-source heterogeneous data: Security data is scattered across heterogeneous systems such as firewalls, EDR, asset lists, patch management systems, identity authentication platforms, and external threat intelligence. The formats, granularities, and time windows vary, and there is a lack of a unified standardization and fusion computing framework; (2) Noise sensitivity and policy jitter: Instantaneous alarms or short-term business fluctuations (such as a surge in promotional traffic) are easily misjudged as risk events. If policy adjustments are directly triggered, it will lead to frequent and unreasonable changes in protection parameters. There is a lack of effective smoothing and cooling-off period control mechanisms; (3) Lack of auditable decision-making loop: The policy adjustment process often lacks a complete chain of evidence, making it difficult to trace the original data, calculation logic, and decision basis. There is also a lack of human-machine collaborative confirmation, which is not conducive to compliance auditing and dispute resolution; (4) Lack of positive incentive feedback mechanism: Existing systems are mostly one-way monitoring, which fails to effectively map the continuous improvement of security practices (such as vulnerability repair and configuration hardening) to the optimization of protection strategies. It is difficult to form an adaptive security loop of "monitoring-evaluation-response-incentive".
[0005] Although the concept of Adaptive Security Architecture has been widely accepted, emphasizing the use of continuous monitoring, assessment, and policy adjustments to address dynamic threats, in practice, especially in scenarios requiring high-credibility decision-making (such as network security assurance services and managed security services), there is still a lack of an end-to-end, quantifiable, explainable, and auditable dynamic policy optimization technology solution. Summary of the Invention
[0006] In view of this, embodiments of this application provide a method, system, device, and medium for optimizing network security protection strategies for dynamic risk assessment, so as to achieve timely and accurate response to rapid changes in the enterprise's security posture and to form a positive incentive mechanism for network security risk management.
[0007] This application provides the following technical solution: a method for dynamically optimizing network security protection strategies, including: Collect and preprocess the safety operation data of the target enterprise, extract multi-dimensional monitoring indicators from the preprocessed safety operation data, and perform indicator standardization and indicator standardization score smoothing on the multi-dimensional monitoring indicators to obtain the indicator smoothing standard score corresponding to each monitoring indicator. Weights are assigned to the multi-dimensional monitoring indicators, and the smoothed standard scores of each monitoring indicator are weighted according to their respective weights to obtain a comprehensive indicator factor. The comprehensive indicator factor is then matched with a set threshold. If the match is successful, a risk review mechanism is triggered. The comprehensive factor of the index is substituted into the set dynamic adjustment function of the strategy for calculation, and the dynamic optimization scheme of the current network security protection strategy is obtained in the preset network security protection strategy mapping table based on the calculation result. The dynamic adjustment function of the strategy is as follows:
[0008] In the formula, This represents the initial baseline index factor set. This represents the current comprehensive factor of the aforementioned indicators. This represents the calculation result of the dynamic adjustment function of the strategy.
[0009] According to one embodiment of this application, the method further includes: setting an adjustment cooling-off period; after obtaining the comprehensive index factor, determining whether the current time has passed the adjustment cooling-off period based on the timestamp of the previous strategy optimization; if the adjustment cooling-off period has passed, matching the comprehensive index factor with a set threshold.
[0010] According to one embodiment of this application, the method further includes: Mandatory high-risk triggering rules are formulated for each monitoring indicator in the multi-dimensional monitoring indicators. The smoothed standard score of each monitoring indicator is matched with the high-risk triggering rules. If the match is successful, the risk review mechanism is triggered. The system monitors external threat intelligence data in real time. If a serious security threat is identified based on the external threat intelligence data, the risk review mechanism is triggered.
[0011] According to one embodiment of this application, the method further includes: After obtaining the current network security protection strategy dynamic optimization plan, a complete suggestion and evidence package is generated. The suggestion and evidence package is pushed and displayed to the security service provider and the target enterprise respectively. After the current network security protection strategy dynamic optimization plan is verified and evaluated, both parties confirm the implementation and change of the network security protection strategy. The recommendations and evidence package information includes risk review trigger rule entries, trigger indicators and their corresponding standardized scores, indicator smoothing standard scores, indicator comprehensive factors, initial baseline indicator factors, calculation results of the dynamic adjustment function of this network security protection strategy, mapping table references, corresponding original security log indexes and their hash digests.
[0012] According to one embodiment of this application, collecting and preprocessing the security operation data of a target enterprise includes: The system employs methods including deploying probe systems, integrating API interfaces, custom SDK development, and periodic importing of files or logs to collect security operation data from target enterprises. This security operation data includes traffic data from the target enterprise's local / cloud network security devices, security event logs, asset and configuration management data, and external threat intelligence data.
[0013] According to one embodiment of this application, the multi-dimensional monitoring indicators are subjected to indicator standardization and indicator standardization score smoothing processing, including: The multi-dimensional monitoring indicators are standardized on a percentage scale using a linear scaling algorithm to obtain standardized scores. The standardized scores are then smoothed using an exponential moving average algorithm to obtain smoothed standardized scores for each monitoring indicator.
[0014] This application also provides a dynamic optimization system for network security protection strategies, including: The data acquisition and indicator extraction module is used to collect the security operation data of the target enterprise and preprocess it. It extracts multi-dimensional monitoring indicators from the preprocessed security operation data, and performs indicator standardization and indicator standardization score smoothing on the multi-dimensional monitoring indicators to obtain the indicator smoothing standard score corresponding to each monitoring indicator. The risk review and judgment module is used to assign weights to the multi-dimensional monitoring indicators, weight the smoothed standard scores of each monitoring indicator according to their corresponding weights to obtain a comprehensive indicator factor, and match the comprehensive indicator factor with a set threshold. If the match is successful, the risk review mechanism is triggered. The adjustment scheme generation module is used to substitute the comprehensive factor of the indicator into the set dynamic adjustment function of the strategy for calculation, and obtain the current network security protection strategy dynamic optimization scheme in the preset network security protection strategy mapping table based on the calculation result.
[0015] This application also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that the processor implements the above-mentioned dynamic optimization method for network security protection strategies when executing the computer program.
[0016] This application also provides a computer-readable storage medium, characterized in that the computer-readable storage medium stores a computer program that performs the above-described dynamic optimization method for network security protection strategies.
[0017] Compared with the prior art, the beneficial effects that at least one technical solution adopted in the embodiments of this specification can achieve include at least: (1) Improve the timeliness and accuracy of dynamic risk assessment: By integrating multi-source heterogeneous security data and introducing smoothing algorithms, the risk assessment results can more stably and realistically reflect the current security situation; (2) Construct an auditable and interpretable closed loop for policy adjustment: Generate a complete evidence package containing the original log index and hash digest, supporting human-machine collaborative confirmation and compliance audit; (3) Form a positive incentive mechanism for improving security practices: The continuous optimization of security indicators is automatically mapped to the enhancement of protection strategies or the expansion of service scope, which is applicable to scenarios such as network security services that require long-term risk management; (4) Enhance system robustness and anti-interference capability: Balance automation efficiency and strategy stability through multiple mechanisms such as cooling-off period, high-risk forced triggering, and external intelligence linkage. Attached Figure Description
[0018] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is a schematic diagram of the dynamic optimization method for network security protection strategy of the present invention; Figure 2 This is a first schematic diagram of the dynamic optimization method for network security protection strategy according to an embodiment of the present invention; Figure 3 This is a second schematic diagram of the dynamic optimization method for network security protection strategy according to an embodiment of the present invention; Figure 4 This is a schematic diagram of the network security protection strategy dynamic optimization system of the present invention; Figure 5 This is a schematic diagram of a network security protection strategy dynamic optimization system according to an embodiment of the present invention; Figure 6 This is a schematic diagram of the structure of the computer device of the present invention. Detailed Implementation
[0020] The embodiments of this application will now be described in detail with reference to the accompanying drawings.
[0021] The following specific examples illustrate the implementation of this application. Those skilled in the art can easily understand other advantages and effects of this application from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. This application can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this application. It should be noted that, in the absence of conflict, the following embodiments and features in the embodiments can be combined with each other. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0022] The terms used in the embodiments of this invention are explained as follows: Target organization or organization: refers to an entity whose network and information systems are protected by the security strategy described in this invention, such as an enterprise, institution, or government department.
[0023] Security service provider: An organization that provides professional technical services such as risk assessment, risk management, security testing, incident response, and event evaluation for network security assurance services.
[0024] A cybersecurity assurance policy refers to a dynamically adjustable set of security control parameters, including but not limited to security response strength, protection coverage, monitoring frequency, and alarm thresholds. In business scenarios such as cybersecurity assurance services, this policy can be further mapped to protection scope, service level, or risk-sharing parameters, but the core of this invention lies in the technical mechanism of policy generation itself.
[0025] like Figure 1 As shown, this embodiment of the invention provides a method for dynamically optimizing network security protection strategies, including: S101. Collect the safety operation data of the target enterprise and preprocess it. Extract multi-dimensional monitoring indicators from the preprocessed safety operation data. Perform indicator standardization and indicator standardization score smoothing on the multi-dimensional monitoring indicators respectively to obtain the indicator smoothing standard score corresponding to each monitoring indicator. S102. Set weights for the multi-dimensional monitoring indicators, weight the smoothing standard scores of each monitoring indicator according to the corresponding weights to obtain a comprehensive indicator factor, match the comprehensive indicator factor with a set threshold, and if the match is successful, trigger a risk review mechanism. S103. Substitute the comprehensive factor of the index into the set dynamic adjustment function of the strategy for calculation, and obtain the current dynamic optimization scheme of the network security protection strategy in the preset network security protection strategy mapping table according to the calculation result.
[0026] In one embodiment of the present invention, the method further includes: after obtaining the current dynamic optimization scheme of the network security protection strategy, generating complete suggestion and evidence package information, pushing and displaying the suggestion and evidence package information to the security service provider and the target enterprise respectively, and after the current dynamic optimization scheme of the network security protection strategy is verified and evaluated, the two parties confirm the execution and change of the network security protection strategy; wherein, the suggestion and evidence package information includes risk review trigger rule entries, trigger indicators and the corresponding indicator standardized score, indicator smoothing standard score, indicator comprehensive factor, initial baseline indicator factor, and the calculation result of the dynamic adjustment function of this network security protection strategy. Mapping table references, corresponding original security log indexes and their hash digests.
[0027] This invention proposes a dynamic optimization method for network security assurance strategies to address shortcomings in existing technologies, such as lagging security situation awareness, difficulties in multi-source data fusion, and a lack of interpretability and positive incentive loops in strategy adjustments. This solution includes the following technical contents: 1. Data Acquisition: Data is obtained from multiple channels, including the target enterprise's security devices (such as firewalls and intrusion detection systems), security event logs (such as SIEM logs), and external threat intelligence interfaces. It supports both real-time API / SDK integration and periodic file or log imports to ensure comprehensive security operation data collection.
[0028] 2. Data Preprocessing and Indicator Extraction: The collected raw security data is cleaned, formatted, and normalized to eliminate redundancy and noise. Then, multi-dimensional monitoring indicators are extracted, such as the frequency of security incidents, average remediation time, number of exposed vulnerabilities, and number of abnormal network traffic events. These "monitoring indicators" can objectively reflect the security posture characteristics of the target enterprise.
[0029] 3. Dynamic Optimization Model for Network Security Assurance Strategies: Based on various extracted monitoring indicators, dynamic strategy optimization suggestions are calculated. Specifically, the optimization engine sets weights or rules for different indicators, comprehensively evaluates the current risk status through decision-making logic, and determines the appropriate direction for adjusting response strength and protection coverage.
[0030] 4. Human-Computer Interaction Confirmation Mechanism: To ensure the controllability and rationality of adjustments, the system provides an interactive interface for security service providers and target companies to view adjustment suggestions. Both parties can confirm, negotiate, or appeal the suggested results on the interface, and can supplement new security information for reassessment, thus forming a verifiable feedback loop.
[0031] 5. Final Adjustment and Implementation: After confirmation by both parties, the system automatically sends the new policy parameters to security systems such as SOC, EDR, and firewall, and records the version and historical information for future reference and compliance audit.
[0032] To avoid frequent adjustments to the protection strategy due to changes in the security risk situation, in one embodiment of the present invention, the method further includes: setting an adjustment cooling-off period; after obtaining the comprehensive index factor, determining whether the current time has passed the adjustment cooling-off period based on the timestamp of the previous protection strategy adjustment; if the adjustment cooling-off period has passed, matching the comprehensive index factor with a set threshold.
[0033] In one embodiment of the present invention, the method further includes: formulating mandatory high-risk triggering rules for each monitoring indicator in the multi-dimensional monitoring indicators; matching the smoothing standard score of each monitoring indicator with the high-risk triggering rules; if the matching is successful, triggering the risk review mechanism; and monitoring external threat intelligence data in real time. If a serious security threat is determined to exist based on the external threat intelligence data, triggering the risk review mechanism.
[0034] In practical implementation, the purpose of this embodiment is to automatically or semi-automatically generate network security protection strategy adjustment suggestions based on the target enterprise's multi-source network and security data, and then execute them after confirmation. The overall data flow is as follows: Data source → Data acquisition and access module → Raw data warehouse → Preprocessing module → Indicator extraction module → Indicator standardization and smoothing module → Comprehensive factor calculation module → Trigger judgment and mapping module (dynamic adjustment engine) → Suggestion and evidence package generation → User interaction / manual confirmation → Strategy management and execution → Audit log archiving.
[0035] The dynamic adjustment process of the network security protection strategy in this embodiment is as follows: Figure 2 , Figure 3 As shown: 1. Data Acquisition and Access. Metadata from sources including but not limited to the following is collected through methods such as deploying probe systems, integrating API interfaces, custom SDK development, and periodic file or log imports: (1) Local / cloud network security devices: event / traffic logs of firewalls, protection gateways, IDS / IPS, WAF, etc.
[0036] (2) SIEM / Log Management System: Security events, alarms, and audit logs.
[0037] (3) Asset and configuration management: asset list, port / service exposure list, patch / configuration status.
[0038] (4) Login anomalies and permission change records of Identity and Access Management (IAM).
[0039] (5) Business system events: critical system offline, communication interruption, etc.
[0040] (6) External intelligence sources: vulnerability databases, threat intelligence subscription interfaces (such as CVE notifications, malicious activity intelligence, etc.).
[0041] 2. Data warehouse storage and preprocessing: (1) The collected data is used in a time series database or document database for high-throughput writing and fast retrieval, and an index table is built for fast statistics.
[0042] (2) Data preprocessing mainly includes the following steps: a. Time unification: Considering the differences in the sources of multi-source data (such as domestic and foreign threat intelligence), the raw data should be uniformly converted to the system standard UTC time and the time zone should be recorded.
[0043] b. Deduplication: If the same security threat alert occurs multiple times in a short period of time, it should be integrated and deduplicated, treated as the same event, and the highest threat level field should be retained.
[0044] c. Field Mapping: Standardize the mapping of different fields from multiple data sources to facilitate unified processing and analysis later. For example, firewalls use src_ip to represent source IPs, and SIEM systems use src_address to represent source IPs; both should be uniformly mapped to source_ip.
[0045] d. Handling missing values: Due to the complexity of multi-source data, it is difficult to avoid the situation of missing fields during dynamic analysis and adjustment. A uniform default value should be set to replace it.
[0046] e. Outlier labeling: If the volume of a single data entry far exceeds the historical statistical value (such as a sudden surge in the number of log entries), outlier labeling will be performed and noise reduction or manual troubleshooting will be triggered.
[0047] 3. Selection of monitoring indicators: (1) Predefine a pool of monitoring indicators and extract indicators for use. These indicators can be formulated from multiple dimensions, including security incidents, assets, defense capabilities, and external threat intelligence. Common indicators include, but are not limited to: frequency of high-risk security incidents in the past 24 hours, average number of risk handling incidents, number of internet-exposed visible assets in the past 30 days, number of abnormal authentication incidents (such as high-frequency brute-force logins, a large number of different IPs using a single account to log in, etc.), percentage of assets that have not been security-hardened, number of historical network traffic anomaly incidents, number of open high-risk ports, and endpoint detection deployment rate, etc.
[0048] (2) Standardized scores for indicators: To eliminate the influence of different units of measurement, a linear scaling to a 0–100 score scale is adopted. For example, for the indicator "number of abnormal identity verification events", if the number of occurrences in the past 7 days is X=12, then the standardization to a percentage scale (0-100) is performed according to the following linear scaling algorithm: Set valuation limits for X The metric is set to [0, 50] (meaning that for the "number of abnormal authentication events" metric, a maximum of 50 occurrences can be considered to have triggered the highest risk level). like Then the standardized value S = 0; like Then the standardized value S = 100; otherwise, For this example metric, the standardized value S=24.
[0049] (3) Standardized score smoothing: To suppress misleading decisions caused by instantaneous fluctuations (e.g., during business promotions or other activities, a surge in user traffic may be mistakenly interpreted as a DDoS attack), the linearly standardized values need to be processed using the exponential moving average (EMA) algorithm. The formula is as follows: ,in The smoothing coefficient is the default value. =0.2; Taking the aforementioned indicator "Number of Abnormal Authentication Events" as an example, the previous value of EMA (EMA) is saved and maintained separately by the system for each monitoring indicator for each policy. Upon first observation of the standardized score S, the system can choose to initialize the EMA to S (instant initialization), i.e. = S = 24.
[0050] (4) Combining multiple indicators into a comprehensive factor: combining the various indicators from the previous step Values according to their weights Weighting is then applied to obtain a comprehensive indicator factor, which is the judgment and mapping value required to trigger dynamic network security protection strategy adjustments. The weights are... It is subjectively defined by the security service provider or the target company based on factors such as actual protection needs and risk tolerance.
[0051] For example, in a company's cybersecurity risk management plan, three monitoring indicators were selected, with smoothed standard values S1 = 24, S2 = 9, and S3 = 18, and weights of 0.4, 0.4, and 0.2 respectively. The comprehensive factor for these indicators is: .
[0052] After providing security services, security service providers typically conduct risk assessments and require security remediation measures from target companies. Therefore, it is essential to clearly define initial baseline indicator factors as core reference parameters for adjusting subsequent dynamic cybersecurity assurance strategies. .
[0053] 4. Trigger determination and mapping for dynamic network security protection policy adjustments: The dynamic network security protection policy adjustment engine has three main functions: (1) Triggering rules: include the following three categories.
[0054] a. Comprehensive Threshold Trigger. When the comprehensive factors of the indicators in the previous step reach a certain predetermined threshold range, a risk review is triggered. This comprehensive threshold is mainly defined by the security service provider or the target company based on its own risk model, industry security situation, and other factors.
[0055] b. Mandatory Triggering of Individual Indicators. In addition to threshold triggering based on comprehensive factors, mandatory high-risk triggering rules should be established for individual indicators to meet regulatory compliance requirements with lower risk tolerance. For example, if the standard score for the indicator "number of unpatched high-risk vulnerabilities" is not 0, a risk review should be triggered, requiring manual intervention to investigate the risk situation.
[0056] c. External threat intelligence trigger. When a new and serious security threat emerges externally, a risk review is triggered, and manual intervention is required to investigate the risk. Examples include security threat incidents such as Windows EternalBlue and the Log4j remote command execution vulnerability, which have a wide-ranging impact on the industry and are extremely harmful.
[0057] (2) Adjustment cooling-off period: In order to avoid frequent adjustments to network security protection strategies due to changes in the security risk situation, an adjustment cooling-off period should be set up to avoid multiple executions of dynamic adjustments during this period.
[0058] (3) Dynamic network security protection strategy adjustment function: After each adjustment cooling-off period, a decision is made on whether to adjust the network security protection strategy based on the difference between the current new comprehensive indicator factor value and the initial baseline indicator factor. That is, the dynamic adjustment function for the network security protection strategy is:
[0059] In the formula, This represents the initial baseline index factor set. This represents the current comprehensive factor of the aforementioned indicators. This represents the calculation result of the dynamic adjustment function of the network security protection strategy.
[0060] The preset network security protection policy adjustment policy mapping table is shown in the table below:
[0061] 5. Recommendation and Evidence Package Generation: Changes in security posture and adjustments to cybersecurity strategies should not be fully automated throughout the entire process. A complete recommendation and evidence package should be generated and presented to both the security service provider and the target enterprise. After thorough verification and evaluation, both parties should confirm the implementation and changes to the cybersecurity strategy. The basic fields of the evidence package should include: risk review trigger rule entries, trigger indicators and their corresponding standardized scores, indicator smoothing standard scores, indicator comprehensive factors, initial baseline indicator factors, and the calculation results of the dynamic adjustment function for this cybersecurity strategy. Mapping table references, corresponding original security log indexes and their hash digests.
[0062] 6. Implementation, version control and audit records of network security protection strategies: Detailed version records should be kept for every adjustment to network security protection strategies for traceability and auditing, in accordance with the basic compliance requirements of relevant laws and regulations.
[0063] like Figure 4 As shown, this application also provides a network security protection strategy dynamic optimization system 200, including: The data acquisition and indicator extraction module 201 is used to collect the safety operation data of the target enterprise and preprocess it. It extracts multi-dimensional monitoring indicators from the preprocessed safety operation data, and performs indicator standardization and indicator standardization score smoothing on the multi-dimensional monitoring indicators to obtain the indicator smoothing standard score corresponding to each monitoring indicator. The risk review and judgment module 202 is used to set weights for the multi-dimensional monitoring indicators, weight the smoothing standard scores of each monitoring indicator according to the corresponding weights to obtain a comprehensive indicator factor, and match the comprehensive indicator factor with a set threshold. If the match is successful, the risk review mechanism is triggered. The adjustment scheme generation module 203 is used to substitute the comprehensive factor of the indicator into the set dynamic adjustment function of the strategy for calculation, and obtain the current network security protection strategy dynamic optimization scheme in the preset network security protection strategy mapping table according to the calculation result.
[0064] In specific implementation, the risk review and judgment module 202 is also used to set an adjustment cooling-off period, and after obtaining the comprehensive factor of the indicator, determine whether the current time has passed the adjustment cooling-off period based on the timestamp of the previous network security protection strategy adjustment. If the adjustment cooling-off period has passed, the comprehensive factor of the indicator is matched with the set threshold.
[0065] In specific implementation, the risk review and judgment module 202 is also used to formulate mandatory high-risk triggering rules for each monitoring indicator in the multi-dimensional monitoring indicators, match the smoothing standard score of each monitoring indicator with the high-risk triggering rules, and if the match is successful, trigger the risk review mechanism; monitor external threat intelligence data in real time, and if it is determined that a serious security threat has occurred based on the external threat intelligence data, trigger the risk review mechanism.
[0066] In specific implementation, such as Figure 5 As shown, this embodiment also includes a suggestion and evidence package generation module 204, which is used to generate complete suggestion and evidence package information after obtaining the current network security protection strategy dynamic optimization scheme, push and display the suggestion and evidence package information to the security service provider and the target enterprise respectively, and after the current network security protection strategy dynamic optimization scheme is verified and evaluated, the two parties confirm the execution and change of the network security protection strategy.
[0067] In one embodiment, a computer device is provided, such as Figure 6 As shown, it includes a memory 301, a processor 302, and a computer program stored on the memory 301 and executable on the processor 302. When the processor 302 executes the computer program, it implements the above-mentioned dynamic optimization method for network security protection strategy.
[0068] Specifically, the computer device can be a computer terminal, a server, or a similar computing device.
[0069] In this embodiment, a computer-readable storage medium is provided, which stores a computer program that performs the above-described dynamic optimization method for network security protection strategies.
[0070] Specifically, computer-readable storage media, including both permanent and non-permanent, removable and non-removable media, can store information using any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer-readable storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable storage media does not include transient media, such as modulated data signals and carrier waves.
[0071] Obviously, those skilled in the art should understand that the modules or steps of the above-described embodiments of the present invention can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. Optionally, they can be implemented using computer-executable program code, thereby storing them in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those presented here, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, the embodiments of the present invention are not limited to any particular hardware and software combination.
[0072] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for dynamically optimizing network security protection strategies, characterized in that, include: Collect and preprocess the safety operation data of the target enterprise, extract multi-dimensional monitoring indicators from the preprocessed safety operation data, and perform indicator standardization and indicator standardization score smoothing on the multi-dimensional monitoring indicators to obtain the indicator smoothing standard score corresponding to each monitoring indicator. Weights are assigned to the multi-dimensional monitoring indicators, and the smoothed standard scores of each monitoring indicator are weighted according to their respective weights to obtain a comprehensive indicator factor. The comprehensive indicator factor is then matched with a set threshold. If the match is successful, a risk review mechanism is triggered. The comprehensive factor of the index is substituted into the set dynamic adjustment function of the strategy for calculation, and the dynamic optimization scheme of the current network security protection strategy is obtained in the preset network security protection strategy mapping table based on the calculation result. The dynamic adjustment function of the strategy is as follows: In the formula, This represents the initial baseline index factor set. This represents the current comprehensive factor of the aforementioned indicators. This represents the calculation result of the dynamic adjustment function of the strategy.
2. The method for dynamically optimizing network security protection strategies according to claim 1, characterized in that, The method further includes: After setting an adjustment cooling-off period and obtaining the comprehensive factor of the indicator, the system determines whether the current time has passed the adjustment cooling-off period based on the timestamp of the previous strategy optimization. If the adjustment cooling-off period has passed, the comprehensive factor of the indicator is matched with a set threshold.
3. The method for dynamically optimizing network security protection strategies according to claim 1, characterized in that, The method further includes: Mandatory high-risk triggering rules are formulated for each monitoring indicator in the multi-dimensional monitoring indicators. The smoothed standard score of each monitoring indicator is matched with the high-risk triggering rules. If the match is successful, the risk review mechanism is triggered. The system monitors external threat intelligence data in real time. If a serious security threat is identified based on the external threat intelligence data, the risk review mechanism is triggered.
4. The method for dynamically optimizing network security protection strategies according to claim 1, characterized in that, The method further includes: After obtaining the current network security protection strategy dynamic optimization plan, a complete suggestion and evidence package is generated. The suggestion and evidence package is pushed and displayed to the security service provider and the target enterprise respectively. After the current network security protection strategy dynamic optimization plan is verified and evaluated, both parties confirm the implementation and change of the network security protection strategy. The recommendations and evidence package information includes risk review trigger rule entries, trigger indicators and their corresponding standardized scores, indicator smoothing standard scores, indicator comprehensive factors, initial baseline indicator factors, calculation results of the dynamic adjustment function of this network security protection strategy, mapping table references, corresponding original security log indexes and their hash digests.
5. The method for dynamically optimizing network security protection strategies according to claim 1, characterized in that, Collect and preprocess the target company's security operation data, including: The system employs methods including deploying probe systems, integrating API interfaces, custom SDK development, and periodic importing of files or logs to collect security operation data from target enterprises. This security operation data includes traffic data from the target enterprise's local / cloud network security devices, security event logs, asset and configuration management data, and external threat intelligence data.
6. The method for dynamically optimizing network security protection strategies according to claim 1, characterized in that, The multi-dimensional monitoring indicators are standardized and their standardized scores are smoothed, including: The multi-dimensional monitoring indicators are standardized on a percentage scale using a linear scaling algorithm to obtain standardized scores. The standardized scores are then smoothed using an exponential moving average algorithm to obtain smoothed standardized scores for each monitoring indicator.
7. A dynamic optimization system for network security protection strategies, characterized in that, include: The data acquisition and indicator extraction module is used to collect the security operation data of the target enterprise and preprocess it. It extracts multi-dimensional monitoring indicators from the preprocessed security operation data, and performs indicator standardization and indicator standardization score smoothing on the multi-dimensional monitoring indicators to obtain the indicator smoothing standard score corresponding to each monitoring indicator. The risk review and judgment module is used to assign weights to the multi-dimensional monitoring indicators, weight the smoothed standard scores of each monitoring indicator according to their corresponding weights to obtain a comprehensive indicator factor, and match the comprehensive indicator factor with a set threshold. If the match is successful, the risk review mechanism is triggered. The adjustment scheme generation module is used to substitute the comprehensive factor of the indicator into the set dynamic adjustment function of the strategy for calculation, and obtain the current network security protection strategy dynamic optimization scheme in the preset network security protection strategy mapping table based on the calculation result.
8. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the network security protection strategy dynamic optimization method as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that executes the dynamic optimization method for network security assurance strategy according to any one of claims 1 to 6.
Citation Information
Patent Citations
Network security operation method based on security policy
CN117081868A
Dust removal system risk dynamic assessment and grading early warning method based on Internet of Things monitoring
CN117670028A
Security policy automatic arrangement and optimization method based on multi-dimensional evaluation model
CN119254457A
Accounting insurance information integrated management system
CN120125043A
Self-adaptive data security management and risk early warning system based on intelligent analysis under cloud platform
CN120358082A