Method and device for constructing network security management and control platform, electronic equipment and storage medium
By constructing the P-POT-PDRR security system model and intelligent multi-agent system, combined with AI intelligent analysis, the problems of insufficient collaboration in traditional network security models and the lag in manual analysis have been solved, achieving efficient threat detection and rapid response, and improving the initiative and accuracy of network security protection.
Patent Information
- Application Number
- CN202610019594.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-08
- Publication Date
- 2026-02-06
Smart Images

Figure CN121486099A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to a method and device for constructing a network security management and control platform, an electronic device and a storage medium. BACKGROUND
[0002] With the comprehensive penetration of digital technology, network attack means are becoming increasingly complex, and attack paths are becoming increasingly concealed, and the traditional network security protection system is facing severe challenges.
[0003] Existing network security models such as the PDRR (protection, detection, response, and recovery) model and the IATF framework generally have the problems of incomplete system dimensions and insufficient multi-link cooperation. For example, the traditional PDRR model focuses on the protection and response at the technical level, and does not fully integrate the security capabilities of "people" and the process specifications of "operation", resulting in a disconnection in the landing of security policies. At the same time, existing security management and control platforms rely on manual threat analysis and response decision-making, and when faced with massive security data, there are defects such as detection lag, high false alarm rate, and untimely response, making it difficult to effectively deal with complex attack behaviors such as advanced persistent threats (APTs).
[0004] With the continuous improvement of the scale, complexity, and automation level of network attacks, the traditional security operation center (SOC) that relies on manual analysis is facing structural challenges such as response delay, alarm overload, and skill gap. SUMMARY
[0005] To solve the above technical problems, the present application provides a method for constructing a network security management and control platform, which adopts the following technical solution, comprising the steps of: constructing a P-POT-PDRR security system model; based on the P-POT-PDRR security system model, constructing an intelligent multi-agent system composed of a perception agent, an analysis agent, an execution agent, and a collaborative scheduling agent, to realize distributed processing and collaboration of security tasks; through multi-source network data collection, cleaning, fusion, and asset map construction, realizing the perception of the network environment; based on the perception of the network environment, constructing an AI intelligent analysis and threat identification engine; based on the analysis results and predefined policies, realizing risk assessment, attack path prediction, and automated response decision-making, and shortening the threat disposal time; through continuous collection of execution feedback, optimizing the policy rules, and iterating the parameters of the P-POT-PDRR security system model.
[0006] Preferably, the step of constructing the P-POT-PDRR security system model specifically comprises: Define the eight core elements of the P-POT-PDRR security system model and their hierarchical logic; Establish a cross-layer coordination mechanism; Set the application paradigm of the PPP model in typical scenarios.
[0007] Preferably, based on the P-POT-PDRR security system model, an intelligent multi-agent system composed of perception agents, analysis agents, execution agents, and collaborative scheduling agents is constructed to realize distributed processing and collaboration of security tasks, and the steps specifically include: Define the responsibilities and collaboration mechanisms of perception agents, analysis agents, execution agents, and collaborative scheduling agents; Design an agent communication mechanism based on the YD_SOMN protocol; Perform dynamic scheduling and fault self-healing of the intelligent multi-agent system.
[0008] Preferably, the step of realizing network environment perception through multi-source network data collection, cleaning, fusion, and asset map construction specifically includes: Perform multi-source heterogeneous network data collection and standardized processing; Real-time draw and update network asset topology, vulnerability distribution, and configuration state to form a visual attack surface view; Perform fine-grained traffic backtracking and session analysis.
[0009] Preferably, the step of constructing an AI intelligent analysis and threat identification engine based on the perception of the network environment specifically includes: Construct user, device, and application behavior baselines to identify abnormal behaviors that deviate from the baseline; Based on the knowledge graph, perform threat correlation analysis; Use deep learning and random forest algorithms to detect unknown attacks and APTs.
[0010] Preferably, the step of realizing risk assessment, attack path prediction, and automated response decision-making based on analysis results and pre-defined strategies to shorten threat disposal time specifically includes: Combine asset value, vulnerability level, and threat intelligence multi-dimensional indicators to quantify risk levels and predict the next possible actions of attackers; Convert decision results into executable response actions to achieve cross-device and cross-system collaborative response through script orchestration; Real-time monitor response execution effect and record complete decision chain.
[0011] Preferably, the step of optimizing strategy rules by continuously collecting execution feedback and iterating parameters of the P-POT-PDRR security system model specifically includes: Based on the time control model, the task scheduling optimization is carried out. Based on the space control model, the resource scheduling optimization is carried out. Based on historical events, response effects, and environmental change data, the security policy is continuously optimized, and the P-POT-PDRR security system model and response script are analyzed.
[0012] To solve the above technical problems, the application also provides a network security management and control platform device, which adopts the following technical solutions, comprising: The construction module is used for constructing a P-POT-PDRR security system model. The multi-agent module is used for constructing an intelligent multi-agent system composed of perception agents, analysis agents, execution agents and collaborative scheduling agents based on the P-POT-PDRR security system model, realizing distributed processing and collaboration of security tasks. The fusion module is used for realizing the perception of network environment through multi-source network data acquisition, cleaning, fusion and asset map construction. The identification module is used for constructing an AI intelligent analysis and threat identification engine based on the perception of network environment. The response module is used for realizing risk assessment, attack path prediction and automatic response decision based on analysis results and predefined strategies, shortening the threat disposal time. The optimization module is used for optimizing the strategy rules by continuously collecting execution feedback, and iterating the parameters of the P-POT-PDRR security system model.
[0013] To solve the above technical problems, the application also provides an electronic device, which adopts the following technical solutions, comprising a memory and a processor, the memory stores computer readable instructions, and the processor executes the computer readable instructions to realize the steps of the network security management and control platform construction method.
[0014] To solve the above technical problems, the application also provides a computer readable storage medium, which adopts the following technical solutions, the computer readable storage medium stores computer readable instructions, and the computer readable instructions are executed by the processor to realize the steps of the network security management and control platform construction method.
[0015] Compared with the prior art, the application has the following beneficial effects: (1) The P-POT-PDRR model integrates the four basic dimensions of strategy, people, operation and technology and the four security capability dimensions, solves the defects of traditional models ignoring the people and operation dimensions, improves the collaboration of the security system, and makes the system dimension more complete. (2) Through the AI / ML model and the SOAR capability, intelligent cooperation from perception, analysis to decision, response is realized in the whole process, the threat detection efficiency and accuracy are greatly improved, the artificial dependence is reduced, and the intelligent level is higher; (3) Through the standardized interface and the automatic arrangement, the response process is quickly landed, the threat disposal time is shortened, the loss caused by the attack is reduced, and the response efficiency is better; (4) The modular architecture is adopted, various security devices and IT systems can be flexibly connected, different scale network environments can be adapted, good scalability and compatibility are possessed, and the expansibility is stronger. BRIEF DESCRIPTION OF DRAWINGS
[0016] In order to more clearly illustrate the scheme in the present application, the drawings needed in the description of the embodiments of the present application will be briefly introduced as follows. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.
[0017] Figure 1 It is a flow chart of an embodiment of the method for constructing the network security management and control platform of the present application; Figure 2 It is a definition schematic view of the P-POT-PDRR model used in the method for constructing the network security management and control platform of the present application; Figure 3 It is a message view schematic view of the security management and control network used in the method for constructing the network security management and control platform of the present application; Figure 4 It is a multi-agent communication mechanism schematic view used in the method for constructing the network security management and control platform of the present application; Figure 5 It is a YD_SOMN security management and control protocol schematic view used in the method for constructing the network security management and control platform of the present application; Figure 6 It is a three-layer protection schematic view used in the method for constructing the network security management and control platform of the present application; Figure 7 It is a structure schematic view of an embodiment of the network security management and control platform device of the present application; Figure 8 It is a structure schematic view of another embodiment of the network security management and control platform device of the present application; Figure 9 It is a structure schematic view of an embodiment of the electronic equipment of the present application. DETAILED DESCRIPTION
[0018] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs; the terminology used in the specification herein is for describing particular embodiments only and is not intended to be limiting of the application; the use herein of terms such as "comprise", "comprising", "comprises", "including", "includes" or "contain" or "containing" is to be construed in a non-exclusive sense as meaning that other steps, features or components not specifically recited are optional and can be added. The use herein of terms such as "first", "second" and the like does not imply a limitation on the number of such objects, but rather the names are used to distinguish between two or more objects.
[0019] Reference herein to "an embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the application. The appearances of the phrase "in an embodiment" in various places in the specification are not necessarily all referring to the same embodiment, nor are they necessarily all directed to the same embodiment, or to a single alternative embodiment.
[0020] For better understanding of the present application, the technical solutions of the embodiments of the present application will be described clearly and completely below with reference to the drawings.
[0021] It should be noted that the method for constructing a network security management and control platform provided by the embodiments of the present application is generally executed by a server / terminal device, and accordingly, the apparatus for constructing a network security management and control platform is generally arranged in a server / terminal device.
[0022] It should be understood that the number of terminal devices, networks and servers is merely illustrative. Any number of terminal devices, networks and servers can be provided according to implementation needs.
[0023] Embodiment one Please refer to Figure 1 , which shows a flow chart of one embodiment of the method for constructing a network security management and control platform. The method for constructing a network security management and control platform comprises the following steps: Step S1, constructing a P-POT-PDRR security system model.
[0024] In this embodiment, the electronic device (for example, a server / terminal device) on which the method for constructing a network security management and control platform runs is shown in Figure 1The server / terminal device shown) can receive a network security management platform construction request through a wired connection or a wireless connection. It should be noted that the wireless connection can include, but is not limited to, 3G / 4G / 5G connection, WiFi connection, Bluetooth connection, WiMAX connection, Zigbee connection, UWB (ultra wideband) connection, and other now known or future developed wireless connection methods.
[0025] In this embodiment, step S1 can specifically include the following steps: S11, define eight core elements of the P-POT-PDRR security system model and their hierarchical logic.
[0026] Using a dimensional classification framework, the security elements are systematically classified according to three criteria: "responsibility attribute", "value orientation" and "dependent resources". For the management and operation layer, the Policy is formally described using a strategy modeling language (such as an extension of Ponder2 or XACML) to make it machine-readable and executable. The policy is defined as a five-tuple rule containing subject, object, action, condition and obligation, and is stored in the policy library. The implementation of the People element relies on the role-based access control matrix (a combination of the RBAC model and the ABAC model), which establishes a user role directory in the platform, clearly defines the operation permissions, approval processes and responsibility boundaries of security analysts, operation administrators, policy makers and other roles, and integrates with the human resources system or AD domain to synchronize accounts and roles. The Operation element is implemented through business process modeling and notation (BPMN 2.0), which draws core security operation processes such as vulnerability handling, incident response and change management as standardized flowcharts and embeds them into the workflow engine of the SOAR platform, ensuring that each step of the process has clear inputs, outputs, responsible persons and time requirements.
[0027] S12, establish a cross-layer coordination mechanism.
[0028] RabbitMQ or Kafka is used as the underlying support for YD_SOMN protocol to ensure high throughput and message persistence. Different queues are set up for data of different priorities (such as real-time alerts and batch logs).
[0029] The policy delivery supports version control, allowing for small-scale gray release of new policies, and full-scale promotion after A / B testing and comparison of effects.
[0030] Flink or Spark Streaming is used to perform real-time aggregation analysis on feedback data and calculate key performance indicators (KPIs) such as mean time to detect (MTTD) and mean time to respond (MTTR).
[0031] S13, set the application paradigm of the PPP model in a typical scenario.
[0032] Establish the mapping relationship database of the PPP model elements and the security requirements clauses of the Equal Protection 2.0, and realize the automatic generation of the compliance self-check report.
[0033] Based on the international trusted computing organization (TCG) standard, realize the complete trusted chain transmission from the hardware to the application layer.
[0034] By using the application sandbox or micro-isolation technology, the core business work flow such as ticket selling, settlement and the like is limited to be executed in a specific and strictly authenticated computing environment and network path, and abnormal horizontal movement is blocked.
[0035] Figure 2 It is a P-POT-PDRR model definition schematic diagram used in the network security management and control platform method of the present application. As shown in the figure, Figure 2 The P-POT-PDRR (abbreviation PPP) security system model breaks the barrier of isolated operation of each link of the traditional security system through the hierarchical deployment of eight core links of Policy (policy), People (person), Operation (operation), Technology (technology), Protection (protection), Detection (detection), Response (response) and Recovery (recovery), realizes the efficient closed-loop cooperation of the management and operation layer driving the technology execution layer and the technology execution layer feeding back to the management and operation layer.
[0036] Among them, Policy, People and Operation constitute the management and operation core layer, and the rules and standards of security management and control, personnel rights and responsibilities and process specification are clear; Technology, Protection, Detection, Response and Recovery constitute the technology execution core layer, and the intelligent technology is relied on to realize the landing of the whole process of security protection. The deep integration of the two makes the system have the core advantages of active defense, intelligent cooperation and dynamic adaptation.
[0037] The purpose of the embodiment is to realize the global perception of the network environment, accurate identification of advanced threats, dynamic assessment and automatic response disposal of risks, and comprehensively improve the initiative, accuracy and efficiency of network security protection based on the innovative PPP security system model through the four core capabilities of perception intelligence, AI intelligent analysis, decision intelligence and response intelligence, and protect the safety of core business and data assets.
[0038] Step S2, based on the P-POT-PDRR security system model, an intelligent multi-agent system composed of perception agents, analysis agents, execution agents and collaborative scheduling agents is constructed, and distributed processing and cooperation of security tasks are realized.
[0039] In the present embodiment, step S2 can specifically include the steps of: S21, defining the responsibilities and collaboration mechanisms of the perception agent, analysis agent, execution agent, and collaborative scheduling agent.
[0040] The intelligent agent system is implemented using the microservice architecture concept, and each type of agent is an independent, containerized service. The perception agent is implemented as a lightweight data collector (Collector) developed in Go or Rust to ensure high performance and low resource consumption. It has built-in multiple parsing plugins (such as the grok parser for Syslog and the IPFIX decoder for NetFlow) and supports extending support for new data formats by loading dynamic link libraries (.so or.dll). Its core logic is "collection-parsing-filtering-forwarding", and the filtering rules are based on the policy library. Only security-related raw data that meets the conditions is converted into standardized events and sent to the analysis agent.
[0041] The analysis agent is implemented as a cluster of AI model services. It receives the standardized event stream and performs real-time inference using loaded machine learning models (such as models hosted by TensorFlow Serving or PyTorch Serve). To implement attack chain restoration, the analysis agent maintains an internal graph computing engine (such as an in-memory instance of JanusGraph or Neo4j) that dynamically adds entities (IP, user, file hash) and relationships (login, connection, download) from events to the knowledge graph and runs graph query algorithms (such as shortest path and community discovery) to identify potential attack sequences. The analysis results (with confidence scores) are packaged into "research and judgment conclusions" messages.
[0042] The execution agent is an automated script executor and device controller. It embeds a playbook interpreter, which is defined in YAML or JSON format and describes a series of atomic actions (such as calling firewall API to block IP) and their execution order and condition judgments. The execution agent connects with various security devices (firewalls, EDR, switches) through pre-made device adapters (Adapter), which encapsulate device-specific APIs or CLI commands. When receiving decision instructions or manually triggering the playbook, the interpreter executes atomic actions one by one and collects execution results.
[0043] The coordination scheduling agent is the "command center" of the system, composed of a group of primary and backup nodes, based on Raft or Paxos protocol to ensure high availability. It maintains a proxy registry, recording the capabilities, load and health status of all online agents. Its core is a task queue and scheduler, using improved weighted round robin or load prediction-based scheduling algorithm to dynamically allocate perception tasks, analysis tasks and execution tasks to the most suitable agent instance. When complex events require multi-agent collaboration (such as "perception-analysis-execution" chain), the scheduling agent is responsible for generating a global transaction ID and passing it between agents to ensure the entire processing process is traceable.
[0044] S22, design agent communication mechanism based on YD_SOMN protocol.
[0045] YD_SOMN protocol is a custom protocol based on Advanced Message Queuing Protocol (AMQP 1.0) with security enhancements and semantic extensions. Its message format design is as follows: { “header”: { “msg_id”: “uuid-v4”, “timestamp”: “2023-10-27T08:30:00Z”, “source”: “sensor_agent_01”, “destination”: “analyzer_pool”, “msg_type”: “event_data”, “priority”: “high”, “signature”: “BASE64(RSA-SHA256(...))” }, “body”: { “data_format”: “cef”, / / Common Event Format “payload”: {...} / / Actual data payload } } The encryption transmission mechanism uses Transport Layer Security (TLS 1.3) to provide end-to-end encryption for all communication channels between agents. Each agent applies for a digital certificate containing its unique ID from the internal Certificate Authority (CA) when starting, and all communications require mutual authentication. For sensitive fields in the message body (such as events containing personal data), additional application layer encryption is applied using the receiver agent's public key for encryption.
[0046] The message routing mechanism is based on dual routing of Topic and Tag. Each agent declares the message topics (e.g. sensor.> and tags (e.g. severity:high) it is interested in when starting up. The sender specifies the topic and tag set when publishing a message. The message bus (e.g. RabbitMQ Exchange or Kafka Topic) delivers the message to all matching subscribers according to the binding rules. For point-to-point communication (e.g. dispatch agent issuing instructions to a specific execution agent), a direct queue based on agent ID is used.
[0047] S23, dynamic scheduling and fault self-recovery of the intelligent multi-agent system are performed.
[0048] The system as a whole is deployed based on the Kubernetes (K8s) container orchestration platform. Each intelligent agent is encapsulated as an independent Docker image and defined and managed by the Deployment or StatefulSet resource object of K8s. The number of replicas (Replicas), resource requests (CPU / memory), and readiness probe (Readiness Probe) and liveness probe (Liveness Probe) of the agent are defined in the Deployment. The readiness probe periodically calls the HTTP health check interface (e.g. / health) of the agent to confirm that it is ready to receive traffic; the liveness probe checks whether the agent process is unresponsive, and if it fails, K8s will automatically restart the Pod.
[0049] Dynamic scheduling is completed by the scheduler (Scheduler) of K8s and the collaborative scheduling agent. The K8s scheduler is responsible for allocating Pods to physical nodes with sufficient resources. The collaborative scheduling agent is responsible for higher-level business load balancing: it monitors the request processing delay and queue length of each analysis agent Pod, and uses the weighted least connection algorithm to allocate new analysis tasks to the currently least busy agent instance. The scheduling strategy exists in the form of a configuration file and supports hot updates.
[0050] The fault self-recovery process is as follows: when a certain agent Pod is down due to node failure or the like, K8s detects and immediately starts a new Pod instance on its predefined node. After the new instance is started, it is automatically re-registered with the registration center of the collaborative scheduling agent. The collaborative scheduling agent reassigns the original agent's unfinished tasks (guaranteed not to be lost through the persistent message queue) to the new instance or other available instances. For stateful agents (such as analysis agents that maintain session states), state recovery is achieved by periodically saving state data to external storage such as Redis or etcd, ensuring business continuity after failover.
[0051] Figure 3 is a security management network message view diagram used in the method for constructing a network security management platform of the present application. As shown in Figure 3 , taking security policy as the cornerstone, flexible and accurate security rule setting is achieved through security policy orchestration. The security capability perception module real-time inspects the network environment, and feeds back information to the security controller, which controls and manages operations accordingly. The brain-like search engine provides powerful data retrieval and analysis capabilities, helping to quickly locate security risks. The presentation module visually displays the security situation, facilitating decision-making by managers. Host management ensures the safe operation of each host, and strictly implements security configuration requirements. Audit data records all security-related operations, providing a basis for tracing and evaluation. Security sharing with external data sources is supported, expanding the security vision. The security service module integrates various security resources to provide one-stop security protection for users.
[0052] Step S3: Network environment perception is achieved through multi-source network data collection, cleaning, fusion, and asset map construction.
[0053] In this embodiment, step S3 can specifically include the following steps: S31: Multi-source heterogeneous network data collection and standardization processing are performed.
[0054] The data collection system adopts a hierarchical distributed architecture. Lightweight data collection probes (DaemonSet) such as Fluent Bit or Vector are deployed in network key nodes and cloud environment VPC. These probes run in DaemonSet mode on all K8s nodes or are directly deployed in physical servers, responsible for collecting local system logs, container logs and network traffic (packet capture through PCAP library such as libpcap). For network devices (switches, routers) and security dedicated devices (firewalls, IDS), logs and events are sent to the centralized log collector cluster (such as Logstash nodes based on Elastic Stack) through Syslog forwarding or SNMP Trap configuration. For cloud services (AWS CloudTrail, Azure ActivityLog), write a scheduled pull task through the API / SDK provided by each cloud vendor, or configure the log direct storage service (such as AWS Kinesis Firehose) to import data into the platform.
[0055] Data standardization is processed by building a unified data model (UDM). All raw data flows into a data preprocessing pipeline composed of a series of plugins: Parsing plugins, i.e. calling corresponding parsers according to data source types. For example, use Winlogbeat module for Windows event logs, grok regular expression for Apache access logs, and directly parse JSON format API responses.
[0056] Rich plugins, i.e. adding context information to events. For example, query the internal CMDB to supplement the department and responsible person of the asset according to the IP address; query VirusTotal and other threat intelligence platforms according to the process hash value.
[0057] Normalization plugins, i.e. mapping parsed fields to standard fields of UDM. UDM uses Open Cybersecurity Framework (OCSF) or similar standards to define hundreds of general fields such as src_ip, dst_ip, user_name and event_action. For example, "sourceAddress" or "sip" in source data is mapped to src_ip.
[0058] Filtering and noise reduction plugins, i.e. applying pre-defined whitelist rules (such as ignoring periodic scanning traffic from scan managers) and frequency rules to filter out known noise-free data, significantly reducing downstream processing pressure.
[0059] S32, real-time drawing and updating network asset topology, vulnerability distribution and configuration status, forming a visual attack surface view.
[0060] Asset discovery adopts active probing, passive sensing and API synchronization. Active probing is performed by a dedicated asset discovery scanner (based on Nmap, Masscan, etc. secondary development of open source tools) regularly, which discovers the IP, open port and running service through ICMP ping, TCP SYN scan, service version identification and other means. To avoid impact on production network, the scanning task is finely scheduled in the business low peak period, and low-speed, distributed scanning strategy is adopted. Passive sensing relies on the traffic probe deployed throughout the network, which discovers assets that may be missed by active scanning (such as short-term online cloud instances) by analyzing server name indication (SNI), HTTP Host header, NetBIOS broadcast and other protocol information in network traffic. API synchronization refers to integration with configuration management database (CMDB), cloud management platform (CMP), virtualization manager (vCenter) and other systems to directly pull the recorded asset information.
[0061] The collected raw asset information is sent to the asset fusion engine. Based on entity resolution algorithm, the engine solves the problem of merging and deduplicating the same asset discovered from different sources. For example, it will determine whether IP 10.0.0.1 (open 80 port) from active scanning and IP 10.0.0.1 (host name web01 identified in HTTP traffic) from traffic analysis are the same server, and create a unified asset profile. The asset profile contains basic information, software list, network connection relationship, business system to which it belongs, etc.
[0062] The attack surface construction engine is based on asset profile and continuous vulnerability scanning and configuration checking results. It works with vulnerability scanners (such as integrated Nessus, OpenVAS API) to obtain the CVE vulnerability list and CVSS score of each asset. At the same time, it runs security baseline checking scripts to check whether the configuration of operating system, database and middleware meets the security policy. Finally, the engine uses a graph database (Neo4j) as storage, takes assets as nodes, and takes network access relationship between assets, shared vulnerabilities and affiliation as edges, to construct a dynamic and visual "asset and attack surface map". The map supports real-time query, such as "find all web servers exposed to the Internet and with high-risk vulnerabilities".
[0063] Active scanning (such as Nessus-like vulnerability scanning) and passive listening are used to discover assets. Combined with CVE vulnerability library and threat intelligence, vulnerability risk assessment is performed. The asset relationship is stored in a graph database (such as Neo4j) to support real-time query and update.
[0064] S33, fine-grained traffic backtracking and session analysis are performed.
[0065] All or key-path network traffic is copied by port mirroring (SPAN) or network tap on the network core switch and sent to a dedicated traffic collection and storage device. The device runs network monitoring tools such as Zeek (formerly Bro) or Suricata, not only for real-time intrusion detection, but more importantly, to generate rich session metadata such as connection logs (conn.log), HTTP logs (http.log), DNS logs (dns.log), etc. These structured metadata (rather than raw packets) are stored in a high-performance time-series database (such as InfluxDB) and object storage (such as Ceph) along with the index pointers of raw packets (PCAP files) after efficient compression, forming a traceable data lake.
[0066] Data aggregation and indexing are key. The system will periodically (e.g., every hour) aggregate and analyze metadata to generate multi-dimensional pre-aggregated tables. For example, aggregate total traffic size, packet count, session count by (source IP, destination IP, application protocol); aggregate access volume ranking by (destination port, region). These aggregation results are stored in Elasticsearch and inverted indexes are established to enable sub-second fast retrieval.
[0067] Build a traffic traceback database, aggregate data by IP, protocol, application, etc. Provide a visual search interface, support 2-3 level data drilling. Integrate web decoders, support HTTP / HTTPS protocol parsing.
[0068] Step S4, based on the perception of the network environment, build an AI intelligent analysis and threat identification engine.
[0069] In this embodiment, step S4 can specifically include the following steps: S41, build behavior baseline of users, devices, and applications, and identify abnormal behaviors deviating from the baseline.
[0070] The implementation of the UEBA system starts with behavior baseline modeling. For each user (User) and entity (such as host, service account Entity), the system will collect its historical normal behavior data (usually take 30-90 days as learning period), and build behavior profile from multiple dimensions: Time dimension: login time regularity (for example, employees usually log in from company IP segment from 9-18 pm on weekdays), operation active period.
[0071] Location dimension: commonly used source IP address, geographic area, VPN access point.
[0072] Resource access dimension: frequently accessed internal systems (e.g., CRM, code repository), frequently accessed file sharing paths, frequently used commands or APIs.
[0073] Number dimension: average daily login times, file download volume, database query times.
[0074] The baseline model is built using unsupervised learning algorithms. For example, the Isolation Forest algorithm is used, which is good at identifying "rare and different" instances. The system inputs the user's daily behavior feature vector (composed of the above dimensions) into the Isolation Forest model for training. The model learns the density distribution of normal behavior. In the detection phase, the new behavior feature vector is scored by the model, resulting in an anomaly score. The higher the score, the more the behavior deviates from the normal pattern.
[0075] S42, based on the knowledge graph, threat correlation analysis is performed.
[0076] Define ontology, i.e., the classification system of entity types and relationship types. Entity types include: attackers (APT organizations, malicious IPs), attack tools (malware families, exploit tools), attack methods (corresponding to MITRE ATT&CK tactics and techniques, such as T1566.001 "phishing"), vulnerabilities (CVE), assets (hosts, users, applications), indicators (IOCs such as file hashes, domain names), security events. Relationship types include: exploit (attack method exploits vulnerability), belongs to (IP belongs to an organization), infected (host infected with malware), caused (event A caused event B).
[0077] Data filling comes from multiple sources: subscribe to and parse structured intelligence reports from threat intelligence platforms (commercial such as Recorded Future, open source such as MISP), extract entities and relationships; internal asset data, vulnerability scan results, log events are included in the graph as instances; import the ATT&CK framework as a pre-set knowledge base, forming a "tactic-technology-specific case" hierarchical relationship.
[0078] The graph storage chooses a native graph database (such as Neo4j), which has a natural advantage for complex relationship queries (such as multi-hop queries, path finding). The analysis agent inserts the real-time received security events (e.g., "suspicious process P detected on host H") as temporary nodes into the in-memory graph subgraph, and runs the graph query language (such as Cypher) for correlation analysis.
[0079] Query can immediately determine whether the suspicious file matches known threat intelligence, and is associated with ATT&CK attack techniques and tactics, providing strong evidence for incident qualification. In addition, using graph neural network (GNN), embedding learning can be performed on the graph, and entities and relationships can be represented as low-dimensional vectors, so as to calculate the semantic similarity between entities and realize "similarity matching of unknown threats", for example, to determine whether a new suspicious behavior sequence is similar to a known APT attack pattern.
[0080] Define entity types (such as attackers, vulnerabilities, assets) and relationship types (such as exploitation, impact, belong to). Use graph neural network for relationship reasoning and path prediction. Integrate MITRE ATT&CK framework to realize attack phase division and association.
[0081] S43, using deep learning, random forest algorithm, detecting unknown attacks and APTs.
[0082] Anomaly detection of network traffic: using long short-term memory network (LSTM) autoencoder. The input of the model is the preprocessed network traffic time series feature vector, including the number of packets, byte number, flow number, source / destination IP entropy value (measuring IP dispersion), destination port entropy value, etc. in each time window (such as 5 minutes). After training, the LSTM autoencoder can learn the reconstruction of normal traffic patterns. During detection, the model reconstructs the input traffic and calculates the reconstruction error. If the current traffic pattern is significantly different from the historical normal pattern, the reconstruction error will be high, triggering an anomaly alert. This method has good effect on unknown attacks that do not rely on fixed features (such as new DDoS, internal data leakage).
[0083] Classification detection of host behavior: using gradient boosting decision tree (such as XGBoost or LightGBM). Feature engineering extracts hundreds of statistical and aggregated features from process creation, file operation, network connection, registry modification events collected by EDR (endpoint detection and response), such as "the number of network connections initiated by process A within 1 hour", "process tree depth", "whether to attempt to access lsass.exe memory". The model is supervised trained using a large number of labeled (malicious / benign) samples, and outputs a binary classification probability (malicious probability). This method has high detection rate for known malware variants, ransomware, mining trojans, etc.
[0084] The uncertainty quantification is achieved by ensemble model or Monte Carlo Dropout technique. For example, train multiple LSTM models with the same architecture but different initial values to form a committee. For an input sample, if the prediction results (e.g. anomaly scores) of all models are highly consistent, the confidence is high; if the divergence is large, the confidence is low. Low-confidence events are sent to the "manual review queue" for final judgment by security analysts, and the results are fed back to the model as new training samples to realize the Active Learning cycle and continuously improve the model performance.
[0085] An LSTM network is used for anomaly detection of time series data (e.g. network traffic). Random forest is used for classification of multi-dimensional features. An uncertainty quantification mechanism is introduced to output the confidence of the detection results.
[0086] Step S5, based on the analysis results and predefined strategies, risk assessment, attack path prediction and automatic response decision are realized to shorten the threat handling time.
[0087] In this embodiment, step S5 can specifically include the following steps: S51, combine asset value, vulnerability level, threat intelligence multi-dimensional indicators to quantify risk level and predict possible next actions of attackers.
[0088] The risk assessment uses a quantitative risk scoring model. The model is a function wherein: : asset criticality score. Based on the business value, data sensitivity, downtime impact of assets in CMDB, jointly evaluated by business and security departments, divided into core, important, general levels and quantified as 1-10 points. : vulnerability severity score. Directly use the CVSS 3.1 base score of the vulnerability (0-10), and adjust according to environmental factors. : threat activity score. Combine threat intelligence to judge whether the exploit code for attacking the vulnerability is public (Exploit Availability), whether there are active threats (Active Threats), and the threat level of the threat source (e.g. APT organizations are higher than ordinary hackers). : impact range score. Evaluate the number of assets, number of users affected by the vulnerability or threat, and whether it can lead to lateral movement to more core areas.
[0089] Through weighted summation or other fusion algorithms, a final risk value (0-100) is calculated and mapped to "serious", "high risk", "medium risk", "low risk" levels for sorting and response decision.
[0090] Attack path prediction uses the Attack Graph model. First, model the network: define hosts, servers, network devices as nodes; define network access permissions between nodes (e.g. firewall rules), existing vulnerabilities on nodes, user permissions on nodes, etc. as edges or node properties. Then, use the logic engine of open-source attack graph generation tools such as MulVAL to input the network model and vulnerability information. The engine will automatically reason and generate a directed graph based on a pre-defined attack rule base (e.g. "if an attacker can execute code on host A, and host A can access host B's 445 port, and host B has the MS17-010 vulnerability, then the attacker can compromise host B"). The graph shows all possible paths that an attacker can take from an initial breach point (e.g. a web vulnerability accessible from the internet) to a critical target (e.g. a domain controller, database server). The decision engine can calculate the implementation probability or attack cost of each path, thus predicting the most likely path an attacker will take and recommending the optimal defense chain-breaking point (e.g. patching a certain critical vulnerability on the path, or tightening a certain firewall rule).
[0091] Use Bayesian networks or attack graph models for path prediction. Build a risk score model that outputs a risk value between 0 and 100. Combine business impact analysis to determine response priorities.
[0092] If using the attack graph model, it can be represented as: where: : represents system state nodes (e.g. hosts, services, vulnerabilities). : represents state transition edges (e.g. exploiting vulnerabilities, escalating privileges). : represents transition probabilities, reflecting the likelihood of attack success. This model can be used to predict the possible paths an attacker takes from the initial state to the target state, providing a basis for defense decisions.
[0093] S52, convert the decision result into executable response actions, achieve cross-device, cross-system coordinated response through script arrangement.
[0094] The platform comes with a large number of integrated atomic actions with common security devices (firewall Palo Alto, Cisco; EDR CrowdStrike, SentinelOne; mailbox Office 365; ITSM ServiceNow). Each action is an independent Python function or container that encapsulates the details of calling the device REST API.
[0095] The script engine parses the YAML script, and according to the conditions and step order, it calls the functions in the action library for execution in turn. The engine needs to handle variable substitution ({{...}}), conditional branching, loops, error handling, and retry mechanisms.
[0096] A visual composer is provided for security analysts to combine pre-built action blocks and condition blocks into new scripts without writing code, greatly improving the efficiency of constructing emergency response processes.
[0097] A visual arrangement interface can be provided to support drag-and-drop script design. Standardized response scripts such as isolating hosts, blocking IPs, and disabling accounts are pre-built. Complex logic such as conditional branching and loop control is supported.
[0098] S53, real-time monitoring of response execution effect, recording complete decision chain.
[0099] Response effectiveness is verified through log collection and state feedback mechanism. Record decision input, reasoning path, execution basis, support "decision playback". Built-in GDPR, CCPA compliance check rules, automatically generate compliance report.
[0100] Step S6, through continuous collection of execution feedback, optimize strategy rules, iterate parameters of the P-POT-PDRR security system model.
[0101] In this embodiment, step S6 can specifically include the following steps: S61, based on the time division control model, task scheduling optimization is performed.
[0102] A time constraint model is established to ensure that security tasks are completed within the business tolerance time. An asynchronous task adjustment mechanism is used to achieve flexible allocation of time slots. The task execution order is dynamically adjusted by a control function.
[0103] The core constraints of the time division control model are: , , , , wherein is the security calculation time, is the security detection time, is the security response time, is the ticket business time, is the network connection time.
[0104] The process control function is: , wherein: : system state vector. : control input vector. : system matrix and control matrix. : process noise.
[0105] The model ensures the completion of security calculation within the acceptable business time by time constraints and control of security detection and response tasks, and is suitable for scenarios with extremely high real-time requirements (such as a railway ticket system).
[0106] S62, based on the space-time control model, resource scheduling optimization is performed.
[0107] Real-time perception of physical resource state (CPU, memory, network bandwidth). According to the task demand, virtual resources are dynamically allocated. A constraint satisfaction model is used to optimize the resource allocation scheme.
[0108] The constraint condition of the space-time control model is: , .
[0109] The objective function is: wherein: : physical resource set. : virtual resource set. : virtual resource demand for CPU and memory. : CPU and memory capacity of physical resources. : virtual resource placement vector on physical resources .
[0110] The model optimizes the allocation of virtual resources on physical resources to maximize resource utilization and balance the load, and is suitable for dynamic environments such as cloud computing and virtualization.
[0111] S63, based on historical events, response effects, and environmental change data, continuously optimize security policies and analyze the P-POT-PDRR security system model and response scripts.
[0112] The platform records the complete life cycle data of each security event, including: original alarm, analysis result (including model confidence), action taken (automatic or manual), final characterization of the event (true positive TP, false positive FP, true negative TN, false negative FN), disposal time consumption, business impact, etc. These data are stored in a structured manner in the data warehouse.
[0113] When a new detection rule is proposed or an existing model is updated, the system supports gray release. For example, the new rule can be applied only to 10% of the traffic, and after a period of time, the effect is scientifically evaluated through hypothesis testing (such as comparing the difference in recall rate and false alarm rate between the new and old rules). For response strategies, the MTTR (mean time to repair) of the new and old scripts can be compared.
[0114] Based on the accumulated labeled data (especially the cases that were misjudged by the model and later corrected by manual correction), trigger the incremental training or full retraining of the AI model regularly (such as every week). The training process is completed in an offline training cluster, and the new data can be used to correct the bias of the model, so that it can adapt to the latest threat trends. For rule-based detection, you can use association rule learning algorithms to automatically mine new and effective association rule patterns from historical real attack events.
[0115] The system automatically subscribes to multiple threat intelligence sources, parses unstructured threat reports through natural language processing (NLP) techniques such as named entity recognition and relationship extraction, and automatically or semi-automatically extracts new attackers, tools, vulnerabilities, and tactics as candidate entities and relationships. After being reviewed by security experts, the system can update the central knowledge graph in bulk, keeping the entire system's "knowledge base" up to date.
[0116] The data analysis module runs regularly to analyze the bottlenecks of security operations efficiency. For example, it may find that "the repair process for a certain type of vulnerability takes an average of more than SLA requirements", then automatically generate an optimization suggestion report, suggesting "consider changing the repair script for this type of vulnerability from manual approval to automatic execution", and attach risk analysis data for decision-makers to reference.
[0117] Through this whole set of automated, data-driven iterative mechanism, the entire security management and control platform evolves from a static, experience-based system to a dynamic, evidence-based, self-learning and evolving "organism", thereby continuously maintaining an advantage in attack and defense confrontation.
[0118] Figure 4 Figure 1 is a schematic diagram of the multi-agent communication mechanism used in the method for constructing a network security management and control platform of the present application. As shown in Figure 4 YD_SOMN security management and control protocol (message bus) architecture is used for communication between multi-agents to achieve high throughput and low latency message transmission. Each agent communicates through the YD_SOMN message format, and the message content includes task ID, data type, processing status, timestamp, etc. Meta information, through the message routing mechanism to realize the precise communication between agents, support broadcast, point-to-point and other communication modes. At the same time, encryption transmission and identity authentication mechanism are adopted to ensure the security and reliability of message transmission. Through the security management and control platform, centralized management and linkage control are performed on each component.
[0119] Figure 5 Figure 2 is a schematic diagram of the YD_SOMN security management and control protocol used in the method for constructing a network security management and control platform of the present application. As shown in Figure 5As shown, the F interface configuration component (SWSF) interoperates with the control center master (SOSF) protocol, configuration information instruction, alarm information, information reporting and other information. The P interface control device (SMF) / security device (SDAF) interoperates with the protocol, SMF / SDAF registration protocol / capability reporting, event reporting protocol, information collection protocol. SOSF: authentication protocol, authorization protocol; device management protocol; device control protocol; and SOSF requires SMF / SDAF to provide security service protocol. The Px interface control SMF / SDAF and network element / managed computing node interoperates with the protocol, including information collection based on SNMP / CMIP protocol, or information stealing, etc. Highly integrated with network devices, so that each network element node can be used as a security policy execution point and become part of the security protection system, which can realize the perception of security to network and service, so that security protection can timely perceive and follow the changes of network.
[0120] Figure 6 It is a three-layer protection schematic diagram used in the network security control platform construction method of the application. Figure 6 As shown, through the YD_SMON protocol, the security mechanism and security service of the security device (firewall, IDS, VPN) can be embedded and integrated in the router, switch and other network devices, and the security and service are highly coupled, the security is highly evolved in the service, the resource sharing and automatic balance are realized, and the security and service are organically integrated together to realize collaborative operation.
[0121] Implementing the embodiment has the beneficial effects that: (1) The P-POT-PDRR model integrates the four basic dimensions of strategy, person, operation and technology with the four security capability dimensions, solves the defects of ignoring the person and operation dimensions in the traditional model, improves the collaboration of the security system, and makes the system dimension more complete; (2) The AI / ML model and SOAR capability realize intelligent collaboration from perception, analysis to decision and response, greatly improve the threat detection efficiency and accuracy, reduce the dependence on manual operation, and make the intelligent level higher; (3) Through standardized interface and automatic arrangement, the response process is quickly landed, the threat disposal time is shortened, the loss caused by attack is reduced, and the response efficiency is more optimal; (4) Modular architecture is adopted, which can flexibly connect various security devices and IT systems, adapt to different scale network environments, has good scalability and compatibility, and makes the expansibility stronger.
[0122] The application is operational with numerous general purpose or special purpose computing system environments or configurations. Examples of well- known computing systems, environments, and / or configurations that can be suitable for use with the application include personal computers, server computers, handheld or laptop devices, tablet devices, multiprocessor systems, microprocessor-based systems, set top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments that include any of the above systems or devices, and the like. The application can be described in the general context of computer-executable instructions, such as program modules, being executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, and the like, that perform particular tasks or implement particular abstract data types. The application can also be practiced in distributed computing environments where tasks are performed by remote processing devices that are linked through a communications network. In a distributed computing environment, program modules can be located in both local and remote computer storage media including memory storage devices.
[0123] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing relevant hardware through computer readable instructions, and the computer readable instructions can be stored in a computer readable storage medium. When the program is executed, the processes of the above-mentioned embodiment methods can be included. The storage medium can be a non-volatile storage medium such as a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).
[0124] It should be understood that although each step in the flowchart of the accompanying drawings is displayed in sequence according to the direction of the arrow, these steps are not necessarily executed in sequence according to the direction of the arrow. Unless otherwise stated herein, the execution of these steps is not strictly limited in sequence, and they can be executed in other sequences. Moreover, at least part of the steps in the flowchart of the accompanying drawings can include multiple sub-steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution sequence is not necessarily sequential, but can be alternately or alternately executed with at least part of other steps or sub-steps or stages of other steps.
[0125] Embodiment two Further reference Figure 7 , as an implementation of the method shown in the above Figure 1 , the application provides an embodiment of a network security management and control platform device, which corresponds to the method embodiment shown in Figure 1 , and the device can be applied to various electronic devices.
[0126] As Figure 7As shown, the network security management platform device 70 of the embodiment includes a construction module 71, a multi-agent module 72, a fusion module 73, an identification module 74, a response module 75, and an optimization module 76. The construction module 71 is configured to construct a P-POT-PDRR security system model. The multi-agent module 72 is configured to construct an intelligent multi-agent system composed of a perception agent, an analysis agent, an execution agent, and a collaborative scheduling agent based on the P-POT-PDRR security system model, so as to realize distributed processing and collaboration of security tasks. The fusion module 73 is configured to realize perception of a network environment through multi-source network data acquisition, cleaning, fusion, and asset map construction. The identification module 74 is configured to construct an AI intelligent analysis and threat identification engine based on the perception of the network environment. The response module 75 is configured to realize risk assessment, attack path prediction, and automatic response decision based on analysis results and predefined strategies, so as to shorten the threat disposal time. The optimization module 76 is configured to optimize the strategy rules by continuously collecting execution feedback, and iteratively optimize the parameters of the P-POT-PDRR security system model.
[0127] The embodiment has the following beneficial effects: (1) The P-POT-PDRR model integrates the four basic dimensions of strategy, person, operation, and technology, and the four security capability dimensions, solves the defects of ignoring the person and operation dimensions in the traditional model, improves the collaboration of the security system, and makes the system dimensions more complete. (2) The AI / ML model and SOAR capability realize intelligent collaboration in the whole process from perception, analysis to decision and response, greatly improve the threat detection efficiency and accuracy, reduce the dependence on manual work, and make the intelligent level higher. (3) Through standardized interfaces and automatic arrangement, the response process is quickly landed, the threat disposal time is shortened, the loss caused by attacks is reduced, and the response efficiency is higher. (4) The modular architecture can flexibly interface various security devices and IT systems, adapt to network environments of different scales, has good scalability and compatibility, and has stronger scalability.
[0128] Embodiment Three Figure 8 is a structural schematic diagram of another embodiment of the network security management platform device of the present application. As shown in Figure 8As shown, the network security management and control platform device is a hierarchical architecture based on a PPP model, and is based on the core logic of perception-analysis-decision-execution-coordination to build a full-link system covering data collection, intelligent agent, intelligent engine, big data processing, management and control scheduling, and visual presentation.
[0129] The overall architecture of the device includes six layers (perception collection layer, intelligent agent layer, intelligent engine layer, big data processing layer, security management and control layer, and visual presentation layer), and each layer realizes data interconnection and capability loosely coupled collaboration through the YD_SOMN security management and control interface protocol, supports horizontal expansion and function iteration.
[0130] The perception collection layer serves as the data entry of the platform, responsible for the collection and standardized processing of global security data. It includes network, terminal, cloud environment, application system, and other multi-source heterogeneous security data.
[0131] The security foundation data includes multi-source heterogeneous data such as network device logs, terminal behavior data, security device alarms, application system logs, vulnerability scanning data, and threat intelligence data.
[0132] Through high-frequency data buses such as YD_SOMN, real-time collection of log, traffic, and process information, and batch import and configuration, static data such as asset information, vulnerability intelligence, and configuration information are supported, and mainstream protocols (Syslog, SNMP, API, etc.) and heterogeneous data formats are supported for access.
[0133] Through multi-element collection methods such as distributed probe deployment, API docking, and log forwarding, real-time and comprehensive data aggregation is achieved; at the same time, through data cleaning, format standardization, and feature extraction, structured and standardized security data assets are formed to provide high-quality data support for upper-layer intelligent analysis.
[0134] The intelligent agent layer is composed of various specialized intelligent agents, and realizes efficient collaborative communication between agents through the YD_SOMN security management and control protocol, ensuring smooth information flow and timely collaborative response. The core agent categories are divided into four categories, and each category not only has independent professional task processing capability, but also can realize cross-agent linkage through collaborative mechanism to form a complete security management and control closed loop: As the platform's "security tentacles," the perception agent's core responsibility is to achieve comprehensive and real-time awareness of network security posture. It collects diverse security data from the network environment (including network traffic data, device log data, application runtime data, threat intelligence data, etc.), and uses data preprocessing and feature extraction technologies to perform preliminary cleaning and filtering of the data. This allows for the accurate identification of critical information such as abnormal behavior, potential threats, and security vulnerabilities in the network. The perception results are then synchronized in real-time to the analysis agent and the collaborative scheduling agent, providing fundamental data support for subsequent analysis, decision-making, and response. The perception agent features multi-source data compatibility, real-time perception, and lightweight deployment, making it adaptable to the perception needs of different network environments.
[0135] The analysis agent is the core unit of the security brain in this embodiment. Based on the basic data transmitted by the perception agent, and combined with the security control logic of the P-POT-PDRR model, it conducts in-depth security analysis and decision-making. It integrates multiple analysis technologies such as machine learning, deep learning, and rule engines to perform correlation analysis, situation assessment, and threat tracing on perceived abnormal information and threat clues. It accurately determines the threat level, attack path, and potential security impact, and generates targeted analysis reports and handling suggestions, which are then synchronized to the execution agent and the collaborative scheduling agent.
[0136] The analysis agent has the ability to learn and evolve autonomously. It can continuously learn new threat characteristics and attack patterns, and continuously optimize the analysis model to improve the accuracy and timeliness of analysis and decision-making.
[0137] The execution agent, serving as the secure execution terminal in this embodiment, is responsible for translating the handling suggestions output by the analysis agent and the execution instructions issued by the coordination scheduling agent into specific security control actions. It supports the integration and execution of various security measures, including access control (such as blocking abnormal IPs and banning dangerous ports), vulnerability remediation (such as pushing patches and optimizing configurations), malware removal (such as virus scanning and isolation of malicious files), and emergency response (such as service restart and data recovery).
[0138] The system translates the decision-making intelligence module's output instructions into actual operations, taking over the Response and Recovery elements of the PPP model's technical execution layer. Through SOAR's automated orchestration capabilities, it achieves deep integration with various security devices such as firewalls, EDR, authentication systems, and switches (controllers), as well as IT systems like IAM and ITSM. This enables complex response operations such as isolating hosts, blocking IPs, and disabling accounts, while simultaneously supporting the rapid recovery of affected systems and services.
[0139] The execution agent has the characteristics of accurate instruction execution, operation log full-process recording, and real-time feedback of execution results, ensuring the effectiveness and traceability of the disposal action, and can cooperate with other agents to complete complex cross-link security control tasks according to the coordination instructions of the collaborative scheduling agent.
[0140] The collaborative scheduling agent is the coordination center of the intelligent agent layer, and its core responsibility is to realize the collaborative linkage of the four types of agents and other levels of the platform through YD_SOMN technology. It is responsible for the overall allocation of tasks, resource scheduling and information flow of various agents, and dynamically coordinates the collection range of the sensing agent, the analysis focus of the analysis agent, and the disposal priority of the execution agent according to the overall security control needs and real-time situation of the platform, to ensure efficient collaboration of various agents and form a combined force.
[0141] When facing complex cross-domain threats or large-scale security incidents, the collaborative scheduling agent can break down the information barriers between agents, build temporary collaborative links, and promote multi-agent joint disposal. At the same time, it synchronizes the entire collaborative process and disposal results to the upper management module of the platform to support global security decision-making. The collaborative scheduling agent has the ability of dynamic scheduling, load balancing, and fault self-healing, and is the core support for stable and efficient operation of the intelligent agent layer.
[0142] The intelligent engine layer is the core capability hub of the embodiment, integrating sensing intelligence, AI intelligent analysis, and decision-making intelligence, realizing the full-link transformation from raw data to effective information and from information research and judgment to decision output. Each engine is built based on the PPP model technology of the execution layer elements, and receives the strategy guidance of the management and operation layer. The core functions include global asset mapping, abnormal behavior detection, attack chain restoration, risk quantification evaluation, and attack path prediction.
[0143] The sensing intelligence engine belongs to the model technology support layer and the front-end module of the protection link, and its core function is to understand and perceive the network environment for self-protection. This module is not limited to log collection, but through various technical means such as asset discovery, vulnerability management, and configuration evaluation, it continuously collects network asset information, vulnerability data, device configuration information, and third-party threat intelligence (including ATT&CK, CAPEC, CVE, etc. Intelligence data), dynamically draws and updates the network asset map and attack surface, and provides comprehensive and accurate basic data support for subsequent security analysis.
[0144] The AI intelligent analysis engine attribution model technology support layer and detection link, the core function is to realize the accurate identification and depth analysis of threats. This module integrates AI / ML models, including user and entity behavior analysis (UEBA) models and knowledge graph technology, which realizes the complete restoration of attack chain and accurate identification of advanced threats through correlation analysis and anomaly detection of massive data collected by the perception intelligence module. Among them, the knowledge graph technology defines attacker, attack mode, vulnerability, attacked object and other entity categories and entity relationship, constructs a network security knowledge graph, and improves the relevance and accuracy of threat analysis.
[0145] The decision intelligence engine attribution model basic guarantee layer (Policy, People) and the front-end module of the response link, the core function is to realize risk assessment and intelligent decision-making. Based on the analysis results of the AI intelligent analysis module, combined with the pre-defined security policy (Policy), the network risk level is evaluated and the potential attack path is predicted through the risk assessment algorithm; at the same time, accurate action suggestions (such as configuration rule optimization suggestions) are provided for security personnel (People), and autonomous response decisions can be made within the pre-defined policy authorization range to generate executable configuration scripts, operation instructions, etc.
[0146] The security application service is the core interaction layer for security operation personnel, which provides visual security situation display, event analysis, policy configuration management, work order flow transfer disposal and other application services based on the output results of the intelligent engine layer.
[0147] This layer takes over the Operation element of the PPP model management and operation layer, realizes the standardization and visualization of security operation process, and supports security personnel to efficiently carry out operation work.
[0148] The big data processing layer provides storage, calculation and management capabilities for massive security data, uses distributed storage architecture (HDFS+Redis) to realize hierarchical storage of massive data, uses stream computing engine (Flink) to realize real-time data processing, uses batch processing engine (Spark) to complete offline data analysis, and provides data support for intelligent agents.
[0149] Supports the efficient operation of intelligent agents. A three-level storage architecture of "hot data-warm data-cold data" is adopted, hot data (near 7 days) is stored in Redis for real-time access, warm data (near 90 days) is stored in HDFS for fast query, and cold data (more than 90 days) is stored in object storage to reduce cost. Based on Flink, real-time processing of 100,000+ events per second is realized to ensure the timeliness of threat detection. Based on Spark, batch data mining is realized to optimize machine learning models and generate security trend reports. An enterprise security knowledge graph is constructed to integrate asset, vulnerability, threat, policy and other information to provide knowledge support for analysis agents.
[0150] The security control layer manages security policies, schedules tasks, orchestrates responses, and audits compliance. It defines agent operation boundaries and permissions through a policy engine, orchestrates response processes using an automated playbook engine, and establishes a decision tracing mechanism to ensure compliance.
[0151] Policy management provides a visual policy configuration interface, supporting the definition of agent operation boundaries, response thresholds, manual review rules, etc.
[0152] Decision tracing can record the complete decision chain, including input signals, model reasoning paths, and execution basis, and supports "decision replay" for auditing.
[0153] The compliance management system can be built into compliance inspection rules such as GDPR and CCPA, and automatically generate compliance reports to ensure that automated decisions comply with regulatory requirements.
[0154] Access control can be implemented based on the RBAC model to achieve fine-grained access control, with different roles corresponding to different operation permissions and view permissions.
[0155] The visualization layer presents the security posture through an intuitive visual interface, providing multi-dimensional human-computer interaction and operational control. It supports functions such as security posture display, event tracing, policy configuration, and agent monitoring. Personalized views are provided for different roles (security analysts, operations personnel, and management), and custom dashboards and report generation are supported.
[0156] The overall situation overview can display the overall cybersecurity situation on a large screen, including key indicators such as the number of threats, risk level distribution, and asset security status.
[0157] Event tracing supports full-process tracing of security incidents, displaying the signals associated with the incident, the analysis process, the response actions, and the handling results.
[0158] Agent monitoring can display information such as the running status, task processing volume, and resource usage of each intelligent agent, and supports agent anomaly alerts.
[0159] Custom reports allow users to define their own report templates and automatically generate various reports such as security operations and compliance audits.
[0160] The beneficial effects of implementing this embodiment are: a more complete system dimension, a higher level of intelligence, better response efficiency, and stronger scalability.
[0161] Example 4 To address the aforementioned technical problems, embodiments of the present invention also provide an electronic device. Please refer to [link / reference needed]. Figure 9 , Figure 9 This is a basic structural block diagram of the electronic device in this embodiment.
[0162] The electronic device 8 includes a memory 81, a processor 82, and a network interface 83, which are communicatively connected via a system bus. It is noted that the electronic device 8 is shown with the components memory 81, processor 82, and network interface 83, but it is understood that not all of the illustrated components are required to be implemented, and more or fewer components can be implemented instead. As understood by one skilled in the art, the electronic device is a device that is capable of automatically processing data and / or information according to pre-set or stored instructions, and the hardware thereof includes, but is not limited to, a microprocessor, an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a digital signal processor (DSP), an embedded device, etc.
[0163] The electronic device can be a desktop computer, a notebook computer, a palm computer, a cloud server, or the like. The electronic device can interact with a user through a keyboard, a mouse, a remote controller, a touchpad, a voice control device, or the like.
[0164] The memory 81 includes at least one type of readable storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory (e.g., an SD or DX memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, an optical disk, or the like. In some embodiments, the memory 81 can be an internal storage unit of the electronic device 8, such as a hard disk or a memory of the electronic device 8. In other embodiments, the memory 81 can also be an external storage device of the electronic device 8, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, or the like. Of course, the memory 81 can include both an internal storage unit and an external storage device of the electronic device 8. In this embodiment, the memory 81 is generally used to store an operating system and various application software installed in the electronic device 8, such as computer readable instructions for building a network security management platform method, etc. In addition, the memory 81 can also be used to temporarily store various data that has been output or will be output.
[0165] The processor 82 can be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip in some embodiments. The processor 82 is generally used to control the overall operation of the electronic device 8. In the present embodiment, the processor 82 is configured to run computer readable instructions or process data stored in the memory 81, for example, computer readable instructions of the method for constructing a network security management platform.
[0166] The network interface 83 can include a wireless network interface or a wired network interface, and is generally used to establish a communication connection between the electronic device 8 and other electronic devices.
[0167] The present embodiment has the advantages of more complete system dimension, higher intelligent level, more optimal response efficiency, and stronger expansibility.
[0168] Embodiment Five The present application also provides another embodiment, that is, a computer readable storage medium storing computer readable instructions, which can be executed by at least one processor to make the at least one processor perform the steps of the method for constructing a network security management platform.
[0169] The present embodiment has the advantages of more complete system dimension, higher intelligent level, more optimal response efficiency, and stronger expansibility.
[0170] From the above description of the embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by software and a general hardware platform, of course, they can also be implemented by hardware, but in many cases, the former is a better embodiment. Based on this understanding, the technical solutions of the present application or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a plurality of instructions for making a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) execute the various embodiment methods of the present application.
[0171] Obviously, the above-described embodiments are only some embodiments but not all the embodiments of the present application, the preferred embodiments of the present application are shown in the drawings, but do not limit the patent scope of the present application. The present application can be implemented in many different forms, and conversely, the purpose of providing these embodiments is to make the disclosure of the present application more thorough and comprehensive. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions recorded in the foregoing specific embodiments, or make equivalent replacements to some technical features therein. Any equivalent structure made by using the content of the present application specification and drawings, directly or indirectly applied to other related technical fields, is also within the patent protection scope of the present application.
Claims
1. A method for constructing a network security management and control platform, characterized in that, Includes the following steps: Construct a P-POT-PDRR security architecture model; Based on the P-POT-PDRR security system model, an intelligent multi-agent system is constructed, consisting of a perception agent, an analysis agent, an execution agent, and a collaborative scheduling agent, to realize the distributed processing and collaboration of security tasks. By collecting, cleaning, fusing, and constructing asset maps from multiple network sources, we can achieve awareness of the network environment. Based on the perception of the network environment, an AI intelligent analysis and threat identification engine is built; Based on the analysis results and predefined strategies, risk assessment, attack path prediction and automated response decision-making are achieved, shortening threat handling time; By continuously collecting execution feedback, the policy rules are optimized, and the parameters of the P-POT-PDRR security system model are iterated.
2. The method for constructing a network security management and control platform according to claim 1, characterized in that, The specific steps for constructing the P-POT-PDRR security system model include: Define the eight core elements of the P-POT-PDRR security architecture model and their hierarchical logic; Establish cross-level collaboration mechanisms; Establish application paradigms for the PPP model in typical scenarios.
3. The method for constructing a network security management and control platform according to claim 1, characterized in that, The steps for constructing an intelligent multi-agent system based on the P-POT-PDRR security architecture model, consisting of a perception agent, an analysis agent, an execution agent, and a collaborative scheduling agent, to achieve distributed processing and collaboration of security tasks specifically include: Define the responsibilities and collaboration mechanisms of the perception agent, analysis agent, execution agent, and collaborative scheduling agent; Design a proxy communication mechanism based on the YD_SOMN protocol; Dynamic scheduling and fault self-healing settings are implemented for the intelligent multi-agent system.
4. The method for constructing a network security management and control platform according to claim 1, characterized in that, The steps for achieving network environment awareness through multi-source network data collection, cleaning, fusion, and asset map construction specifically include: Perform multi-source heterogeneous network data acquisition and standardization processing; Real-time mapping and updating of network asset topology, vulnerability distribution, and configuration status to create a visual attack surface view; Perform fine-grained traffic backtracking and session analysis.
5. The method for constructing a network security management and control platform according to claim 1, characterized in that, The steps for building an AI-powered intelligent analysis and threat identification engine based on network environment perception specifically include: Establish behavioral baselines for users, devices, and applications, and identify abnormal behaviors that deviate from the baselines; Threat association analysis is performed based on knowledge graphs; Using deep learning and random forest algorithms, we can detect unknown attacks and APTs.
6. The method for constructing a network security management and control platform according to claim 1, characterized in that, The steps for achieving risk assessment, attack path prediction, and automated response decision-making based on analysis results and predefined strategies, thereby shortening threat handling time, specifically include: By combining multiple indicators such as asset value, vulnerability level, and threat intelligence, the risk level can be quantified and the attacker's possible next move can be predicted. Transform decision-making outcomes into actionable responses, and achieve collaborative responses across devices and systems through script arrangement; Monitor the response execution effect in real time and record the complete decision chain.
7. The method for constructing a network security management and control platform according to any one of claims 1 to 6, characterized in that, The steps of continuously collecting execution feedback, optimizing policy rules, and iterating the parameters of the P-POT-PDRR security system model specifically include: Task scheduling optimization is performed based on a time-division control model. Resource scheduling optimization is performed based on the spatial division control model. Based on historical events, response results, and environmental change data, we continuously optimize security strategies and analyze the P-POT-PDRR security system model and response scripts.
8. A device for constructing a network security management and control platform, characterized in that, include: The building block is used to construct the P-POT-PDRR security architecture model; The multi-agent module is used to construct an intelligent multi-agent system based on the P-POT-PDRR security system model, consisting of a perception agent, an analysis agent, an execution agent, and a collaborative scheduling agent, to realize the distributed processing and collaboration of security tasks. The fusion module is used to achieve network environment perception through multi-source network data acquisition, cleaning, fusion, and asset map construction; The identification module is used to build an AI-powered intelligent analysis and threat identification engine based on the perception of the network environment. The response module is used to perform risk assessment, attack path prediction, and automated response decisions based on analysis results and predefined strategies, thereby shortening threat handling time. The optimization module is used to continuously collect execution feedback, optimize policy rules, and iterate the parameters of the P-POT-PDRR security system model.
9. An electronic device, characterized in that, The system includes a memory and a processor, wherein the memory stores computer-readable instructions, and the processor executes the computer-readable instructions to implement the steps of the method for constructing a network security management platform as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the method for constructing a network security management and control platform as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Network security space surveying and mapping method, system and equipment based on multi-source data fusion
CN120415816A
Trusted management and control network platform construction method and device, electronic equipment and storage medium
CN120934918A
Network security analysis early warning system based on artificial intelligence
CN121098558A
Exposure and Attack Surface Management Using a Data Fabric
US20250233884A1
System and Method for Improving Cybersecurity of a Network
US20250317466A1
Cited By
Method and device for constructing network security operating system, electronic equipment and storage medium
CN121887549A
Communication event automation rules engine execution system and method
CN122363870A