Intelligent control system of network security data storage device

By synchronously collecting and analyzing the operating parameters and network environment data of storage devices, and combining policy matching and instruction parsing, the control policy is dynamically optimized. This solves the problems of insufficient accuracy in anomaly identification and policy matching and chaotic instruction execution in existing technologies, and achieves efficient network security data storage device control.

CN121530633AInactive Publication Date: 2026-02-13ANHUI UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511563251.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-30
Publication Date
2026-02-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The control systems of existing network security data storage devices lack accuracy in anomaly identification and policy matching, making them unable to effectively cope with complex security scenarios. Furthermore, the command execution and policy optimization processes are chaotic and static, making them difficult to adapt to dynamic network threats.

Method used

An anomaly labeling module synchronously collects operational parameters and network environment data. A policy matching module generates control policies by combining anomaly types with associated contexts. An instruction parsing module reconstructs the topology network and sorts action nodes. An effect feedback module adjusts access control and encryption levels. A status assessment module quantifies the security baseline offset. An optimization control module dynamically updates the policy library.

Benefits of technology

It significantly improves the accuracy and effectiveness of security control for storage devices, forming a closed-loop security protection mechanism, continuously adapting to network threats, and providing reliable data storage security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530633A_ABST
    Figure CN121530633A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of control systems, and discloses an intelligent control system for network security data storage equipment, which comprises an exception labeling module, a strategy matching module, an instruction analysis module, an effect feedback module, a state evaluation module and an optimization control module, identifying abnormal identification data of the operation parameters and the network environment data in the storage device; based on a network data security policy library, performing policy matching on the abnormal identification data to obtain a control policy; performing multi-level instruction analysis on a composite control rule in the control strategy to obtain an executable instruction sequence; according to the executable instruction sequence, adjusting the access control authority and the data encryption level to obtain control effect data; based on the control effect data, evaluating the security state of the storage device to obtain a security baseline offset; dynamically updating a network data security policy library based on the security baseline offset to obtain an optimization control policy; according to the invention, the efficiency of electrical automatic plasma welding can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of control systems, in particular to an intelligent control system for network security data storage equipment. BACKGROUND

[0002] In the field of control of network security data storage equipment, the existing technology is insufficient in precision of abnormality identification and strategy matching. When the traditional system identifies the abnormality of the storage equipment, only a single dimension of the running parameters or network environment data is detected, and the synchronous collection and collaborative comparison of the two are not realized, resulting in one-sided abnormality identification data, which is easy to miss potential security risks. When matching the security strategy, only the basic strategy is searched according to the simple abnormal type, and the instantiation adjustment and feasibility verification are not combined with the abnormal associated context, so the generated control strategy is easy to be out of touch with the actual running state of the equipment, which cannot effectively cope with complex security scenarios and reduces the security protection effect of the storage equipment.

[0003] The existing technology has obvious defects in the aspects of instruction execution and strategy optimization. When analyzing the control strategy, the logical dependency relationship of the composite control rule is not restructured by a topology network, and an executable instruction sequence is not generated according to the action node priority, which is easy to cause confusion or logical conflict in instruction execution. In the stage of control effect feedback and strategy updating, only the permission adjustment and encryption level change are simply recorded, and the device security state is not evaluated based on the security event data and the security baseline offset is not quantified, which cannot dynamically optimize the network data security strategy library, so that the control system is in a static protection mode for a long time, which is difficult to adapt to the dynamic changes of network security threats and cannot provide continuous and reliable security protection for the storage equipment. SUMMARY

[0004] The present application provides an intelligent control system for network security data storage equipment to solve the problems raised in the background art.

[0005] To achieve the above-mentioned purpose, the intelligent control system for network security data storage equipment provided by the present application is characterized in that the abnormality labeling module, the strategy matching module, the instruction analysis module, the effect feedback module and the state of the abnormality labeling module are used to identify the abnormal mode of the running parameters and the network environment data of the storage equipment, and the abnormal identification data of the storage equipment is obtained. The strategy matching module is used to match the abnormal identification data based on the network data security strategy library, and the control strategy of the storage equipment is obtained. The instruction analysis module is used to analyze the composite control rule in the control strategy by multiple levels of instructions, and the executable instruction sequence of the storage equipment is obtained. The effect feedback module is configured to adjust, according to the executable instruction sequence, an access control permission and a data encryption level of the storage device, to obtain control effect data of the storage device. The state evaluation module is configured to evaluate, based on the control effect data, a security state of the storage device, to obtain a security baseline offset of the storage device. The optimization control module is configured to dynamically update, based on the security baseline offset, the network data security policy library, to obtain an optimized control policy of the storage device.

[0006] In a preferred embodiment, the anomaly labeling module is configured to identify an abnormal mode of a running parameter and network environment data in the storage device, to obtain anomaly identification data of the storage device, specifically for: synchronously collecting the running parameter and the network environment data in the storage device; performing a step-by-step abnormal comparison between the running parameter and a normal running range of the storage device, to obtain an abnormal identification of the running parameter of the storage device; performing a step-by-step abnormal screening on the network environment data, to obtain an abnormal identification of the network environment of the storage device; combining the abnormal identification of the running parameter and the abnormal identification of the network environment into the anomaly identification data of the storage device.

[0007] In a preferred embodiment, the policy matching module is configured to perform, based on the network data security policy library, a policy matching on the anomaly identification data, to obtain a control policy of the storage device, specifically for: parsing the anomaly identification data to determine an abnormal type and an abnormal associated context of the storage device; merging the abnormal type and the abnormal associated context into an abnormal analysis result of the storage device; performing a policy retrieval matching on the abnormal analysis result based on the network data security policy library, to obtain a candidate policy of the storage device; performing a context adaptation adjustment on the candidate policy, to obtain a preliminary policy of the storage device; verifying a feasibility between the preliminary policy and the running parameter, to obtain a verification passed policy of the storage device; outputting the verification passed policy as the control policy of the storage device.

[0008] In a preferred embodiment, the policy matching module is configured to perform, based on the network data security policy library, a policy retrieval matching on the anomaly analysis result, to obtain a candidate policy of the storage device, specifically for: parsing the exception analysis result to obtain an exception type identifier and a context parameter of the exception analysis result; selecting a basic policy in the network data security policy library according to the exception type identifier; instantiating and adjusting the basic policy based on the context parameter to obtain an adaptive policy of the storage device; taking the adaptive policy as a candidate policy of the storage device.

[0009] In a preferred embodiment, the instruction parsing module performs multi-level instruction parsing on the composite control rule in the control policy to obtain an executable instruction sequence of the storage device, specifically for: performing structural decomposition on the composite control rule in the control policy to obtain a rule decomposition result of the control policy; topology network reconstruction based on the logical dependency relationship between the action clause and the condition clause in the composite control rule to obtain an action dependency network of the composite control rule; priority sequencing of the action nodes in the action dependency network to obtain a target priority sequence of the action nodes; dynamic topology sequencing of the action clause based on the target priority sequence to obtain an executable instruction sequence of the storage device.

[0010] In a preferred embodiment, the instruction parsing module performs priority sequencing of the action nodes in the action dependency network to obtain a target priority sequence of the action nodes, specifically for: identifying the feature dimensions of the number of direct predecessor nodes and the number of direct successor nodes in the action nodes according to the action dependency network to obtain topology feature data of the action nodes; nonlinearly weighting and fusing the number of direct predecessor nodes and the number of direct successor nodes according to the topology feature data to obtain a criticality index of the action nodes; comprehensive sequencing of the action nodes based on the criticality index to obtain an initial priority sequence of the action nodes; adjusting the initial priority sequence according to the urgency of the condition clause to obtain a target priority sequence of the action nodes.

[0011] In a preferred embodiment, the effect feedback module adjusts the access control permission and the data encryption level of the storage device according to the executable instruction sequence to obtain control effect data of the storage device, specifically for: parsing the executable instruction sequence to obtain an access control adjustment instruction and a data encryption adjustment instruction of the storage device; updating an access control rule of the storage device based on the access control adjustment instruction to obtain an updated access control permission of the storage device; modifying a data encryption parameter of the storage device based on the data encryption adjustment instruction to obtain a modified data encryption level of the storage device; synthesizing the updated access control permission and the modified data encryption level into control effect data of the storage device.

[0012] In a preferred embodiment, the state evaluation module, in execution, evaluates a security state of the storage device based on the control effect data to obtain a security baseline offset of the storage device, specifically for: extracting an access control permission adjustment record and a data encryption level change information of the storage device according to the control effect data; normalizing the access control permission adjustment record and the data encryption level change information into security event data of the storage device; performing multi-dimensional index classification on the security event data to obtain a security event classification result of the storage device; determining a security baseline standard of the storage device according to the security event classification result; performing dynamic consistency analysis on the security state of the storage device based on the security baseline standard to obtain a security state consistency degree of the storage device; performing difference quantification on a target security state of the storage device based on the security state consistency degree to obtain the security baseline offset of the storage device.

[0013] In a preferred embodiment, the state evaluation module, in execution, performs difference quantification on a target security state of the storage device based on the security state consistency degree to obtain the security baseline offset of the storage device, specifically for: extracting a number of abnormal access patterns and a number of encryption vulnerability indexes in the storage device according to the security event classification result; performing multi-dimensional evaluation on the target security state of the storage device to obtain a target security state consistency requirement of the storage device; performing difference quantification on the target security state based on the security state consistency degree to obtain the security baseline offset of the storage device, wherein the formula for calculating the security baseline offset is as follows: ; In the formula, n represents the number of abnormal access patterns, m represents the number of encryption vulnerability indexes, and k represents the target security state consistency requirement. This is the safety baseline offset. The degree of consistency of the security state. The target security state consistency requirement. The number of the abnormal access patterns. The number of the aforementioned cryptographic vulnerability indicators. It is a logarithmic function.

[0014] In a preferred embodiment, the optimization control module dynamically updates the network data security policy library based on the security baseline offset to obtain an optimization control policy for the storage device, specifically for: Based on the safety baseline offset, determine the adjustment type and adjustment range of the control strategy; Based on the adjustment type and the adjustment magnitude, the access control rules and data encryption rules in the network data security policy library are mapped to collaborative revision instructions of the network data security policy library; Based on the collaborative revision instructions, the network data security policy library is collaboratively updated to obtain the target network data security policy library of the storage device. Based on the target network data security policy library, the real-time data environment of the storage device is re-matched to obtain the optimized control policy for the storage device.

[0015] Compared with the prior art, the present invention has the following beneficial effects: 1. This invention, through its intelligent control system for network security data storage devices, significantly improves the accuracy and effectiveness of security control for storage devices. The system uses an anomaly labeling module to simultaneously collect operating parameters and network environment data, generating comprehensive anomaly identification data through hierarchical comparison and layer-by-layer filtering to ensure no potential security risks are overlooked. A policy matching module combines anomaly type and associated context analysis results to retrieve candidate policies from a network data security policy library, performing context adaptation and feasibility verification to generate control policies that fit the actual operating state of the device. An instruction parsing module reconstructs the topology of the composite control rules, sorting them according to the criticality indicators and urgency of conditions of action nodes to generate an executable instruction sequence, avoiding chaotic instruction execution and making the generation and execution of security control instructions more scientific.

[0016] 2. This invention offers significant advantages in control effect feedback and dynamic strategy optimization. The effect feedback module precisely adjusts access control permissions and data encryption levels based on the executable instruction sequence, forming complete control effect data. The status evaluation module organizes security events and quantifies the security baseline offset based on this data, accurately reflecting the difference between the device's security status and the target through a formula. The optimization control module determines the direction of strategy adjustment based on the offset, dynamically updates the network data security policy library, and re-matches the real-time data environment to obtain an optimized control strategy. The entire system forms a closed loop of "anomaly identification – policy matching – instruction execution – effect evaluation – strategy optimization," continuously improving the security protection capabilities of storage devices and providing reliable protection for data storage security. Attached Figure Description

[0017] Figure 1 A system architecture diagram of an intelligent control system for a network security data storage device provided in an embodiment of the present invention; The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0018] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments belong to some, but not all, embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0019] The terminology used in the embodiments of this invention is for the purpose of describing particular embodiments only and is not intended to limit the invention. The singular forms “said” and “the” as used in the embodiments of this invention and the appended claims are also intended to include the plural forms, and “multiple” generally includes at least two unless the context clearly indicates otherwise.

[0020] Depending on the context, the word "if" or "if" as used here can be interpreted as "when," "when," "in response to determination," or "in response to detection." Similarly, depending on the context, the phrase "if determination" or "if detection (of the stated condition or event)" can be interpreted as "when determination," "in response to determination," "when detection (of the stated condition or event)," or "in response to detection (of the stated condition or event)."

[0021] Furthermore, the timing of the steps in the following method embodiments is merely an example and not a strict limitation.

[0022] In practice, the server-side equipment deployed in the intelligent control system of a network security data storage device may consist of one or more devices. The aforementioned intelligent control system for a network security data storage device can be implemented as: a business instance, a virtual machine, or hardware devices. For example, the intelligent control system can be implemented as a business instance deployed on one or more devices in a cloud node. Simply put, the intelligent control system can be understood as software deployed on a cloud node, used to provide each user terminal with an intelligent control system for the network security data storage device. Alternatively, the intelligent control system can also be implemented as a virtual machine deployed on one or more devices in a cloud node. This virtual machine contains application software for managing each user terminal. Or, the intelligent control system can also be implemented as a server composed of numerous identical or different types of hardware devices, with one or more hardware devices configured to provide each user terminal with an intelligent control system for the network security data storage device.

[0023] In terms of implementation, the intelligent control system and user terminal of a network security data storage device are mutually compatible. That is, if the intelligent control system of a network security data storage device is implemented as an application installed on a cloud service platform, then the user terminal is implemented as a client that establishes a communication connection with the application; or if the intelligent control system of a network security data storage device is implemented as a website, then the user terminal is implemented as a webpage; or if the intelligent control system of a network security data storage device is implemented as a cloud service platform, then the user terminal is implemented as a mini-program in an instant messaging application.

[0024] like Figure 1 The diagram shown is a system architecture diagram of an intelligent control system for a network security data storage device according to an embodiment of the present invention.

[0025] The intelligent control system 100 for a network security data storage device described in this invention can be located in a cloud server. In terms of implementation, it can function as one or more service devices, or as an application installed in the cloud (e.g., a mobile service operator's server, server cluster, etc.), or it can be developed into a website. Depending on the functions implemented, the intelligent control system 100 for a network security data storage device may include an anomaly labeling module 101, a policy matching module 102, an instruction parsing module 103, an effect feedback module 104, a status evaluation module 105, and an optimization control module 106. The modules described in this invention can also be referred to as units, which are a series of computer program segments that can be executed by the processor of an electronic device and can perform a fixed function, stored in the memory of the electronic device.

[0026] In this embodiment of the invention, in an intelligent control system for a network security data storage device, each of the above-mentioned modules can be implemented independently and can call other modules. Here, "calling" can be understood as a module connecting to multiple modules of another type and providing corresponding services to those connected modules. In the intelligent control system for a network security data storage device provided by this embodiment of the invention, without modifying the program code, the applicability of the intelligent control system architecture of a network security data storage device can be adjusted by adding modules and directly calling them, achieving cluster-based horizontal expansion to quickly and flexibly expand the intelligent control system of a network security data storage device. In practical applications, the above-mentioned modules can be set in the same device or different devices, or they can be set in a virtual device, such as a service instance in a cloud server.

[0027] The following describes, with reference to specific embodiments, the various components and specific workflows of an intelligent control system for a network security data storage device: The anomaly labeling module is used to identify anomaly patterns in the operating parameters and network environment data of the storage device, and obtain anomaly identification data of the storage device. In this embodiment of the invention, the anomaly labeling module identifies abnormal patterns in the operating parameters and network environment data of the storage device to obtain anomaly identification data for the storage device, specifically for: Synchronously collect operating parameters and network environment data from storage devices; The operating parameters are compared step by step with the normal operating range of the storage device to obtain the abnormal operating parameter identifier of the storage device. The network environment data is filtered layer by layer for anomalies to obtain the network environment anomaly identifier of the storage device. The abnormal operating parameters and the abnormal network environment are combined to form the abnormal identification data of the storage device.

[0028] Specifically, when synchronously collecting operating parameters and network environment data from storage devices, a dedicated data acquisition device is first connected to the hardware interface of the storage device. This device must be fully compatible with the communication protocol of the storage device to ensure accurate reading of the internal data. After starting the acquisition device, operating parameters and network environment data of the storage device are acquired simultaneously at preset fixed time intervals. The operating parameters include key information generated by the storage device itself during operation, such as read / write speed, cache utilization, hardware temperature, and data transmission latency. The network environment data includes network-related data such as bandwidth utilization, network latency, packet loss rate, and network connection stability of the network to which the storage device is connected. The operating parameters and network environment data collected each time are stored in a dedicated data storage module in chronological order of collection time, ensuring that each set of data can be clearly traced back to the specific collection time, providing complete and time-consistent raw data for subsequent anomaly identification.

[0029] Furthermore, the operating parameters are compared step by step with the normal operating range of the storage device. When an abnormality is detected in the operating parameters of the storage device, the pre-set normal operating range is retrieved from the system parameter library of the storage device. This normal operating range is determined based on the hardware specifications, design standards and historical data of long-term stable operation of the storage device, and covers the reasonable fluctuation range of all operating parameters.

[0030] Furthermore, for each operating parameter, a step-by-step comparison is performed according to the importance and scope of influence of the parameter. First, core operating parameters such as read / write speed and hardware temperature are compared. The actual values ​​of the collected read / write speeds are compared with the read / write speed range in the normal operating range. If the actual value exceeds the range, it is marked as an abnormal read / write speed. Then, secondary operating parameters such as cache utilization and data transmission latency are compared. Similarly, the actual values ​​are compared with the corresponding normal range. If they exceed the range, the corresponding parameter is marked as abnormal.

[0031] Furthermore, after comparing all operating parameters, all marked abnormal parameter information is summarized and organized to form identification information that includes the abnormal parameter name, the time of abnormal occurrence, and the deviation of the actual value from the normal range. This identification information is the abnormal operating parameter identifier of the storage device.

[0032] Furthermore, when performing layer-by-layer anomaly screening on network environment data to obtain network environment anomaly identifiers for storage devices, an anomaly screening hierarchy system for network environment data is first constructed. This system is divided into a basic layer, a transport layer, and an application layer according to the degree of direct impact of the network environment on the operation of the storage device. The basic layer corresponds to network connection stability data, the transport layer corresponds to bandwidth utilization and network latency data, and the application layer corresponds to packet loss rate data.

[0033] Furthermore, anomaly screening is performed layer by layer starting from the basic layer. First, network connection stability data is checked. By continuously monitoring the connection status between the storage device and the network, if connection interruptions or frequent disconnections occur within a preset time, it is marked as a network connection stability anomaly. Next, transport layer data is screened, comparing the actual bandwidth utilization value with the normal bandwidth utilization range. If it exceeds the range, it is marked as a bandwidth utilization anomaly. At the same time, the actual network latency value is compared with the normal network latency range. If it exceeds the range, it is marked as a network latency anomaly. Finally, application layer data is screened, comparing the actual packet loss rate with the normal packet loss rate range. If it exceeds the range, it is marked as a packet loss rate anomaly. The anomaly information screened at each layer is summarized to form identification information containing the type of abnormal network data, the time period of the anomaly, and the difference between the actual value and the normal range. This identification information is the network environment anomaly identifier for the storage device.

[0034] Furthermore, when combining the abnormal operation parameter identifier and the abnormal network environment identifier into the abnormal identifier data of the storage device, a structured format for the abnormal identifier combination is first established. This format includes three core fields: abnormal identifier category, abnormal details, and abnormal occurrence timestamp. The abnormal identifier category is divided into two types: abnormal operation parameter and abnormal network environment.

[0035] Furthermore, the various anomaly information in the operational parameter anomaly identifiers are filled in according to a structured format, clearly indicating the anomaly category as operational parameter anomaly, and detailing the anomaly parameter name, deviation from the normal range, and other anomaly details, along with the timestamp of each anomaly occurrence. Simultaneously, the various anomaly information in the network environment anomaly identifiers are also filled in according to the same structured format, indicating the anomaly category as network environment anomaly, and detailing the anomaly data type, difference from the normal range, and the corresponding timestamp. After completing the formatting of all anomaly information, the structured data of the two types of anomaly identifiers are integrated into a complete dataset. This dataset is the anomaly identifier data for the storage device, which can be directly used for subsequent analysis of storage device anomaly causes and troubleshooting.

[0036] In summary, synchronously collecting operational parameters and network environment data avoids the limitations of traditional single-dimensional detection, reduces the risk of missing overlapping scenarios due to data asynchrony, and provides a complete data foundation for anomaly identification. By comparing operational parameters level by level, focusing on key parameters according to a "core-to-secondary" logic, and determining the normal range in conjunction with equipment standards, the accuracy of operational parameter anomaly identification is improved, and anomaly details are clarified.

[0037] In summary, network environment data is filtered layer by layer, and anomalies are located according to the "basic layer - transport layer - application layer," avoiding the limitations of a "one-size-fits-all" approach and enhancing the scenario adaptability of network environment anomaly identification. Combining two types of anomaly identifiers and integrating anomaly category, details, and timestamps creates a complete anomaly profile, aiding in accurate subsequent judgment of anomaly relationships and providing a comprehensive basis for strategy matching.

[0038] The policy matching module is used to perform policy matching on the abnormal identification data based on the network data security policy library to obtain the control policy of the storage device. In this embodiment of the invention, the policy matching module performs policy matching on the abnormal identification data based on a network data security policy library to obtain the control policy for the storage device, specifically for: The anomaly identification data is parsed to determine the anomaly type and anomaly association context of the storage device. The exception type and the exception association context are combined into the exception resolution result of the storage device; Based on the network data security policy library, the anomaly parsing results are used to perform policy retrieval and matching to obtain candidate policies for the storage device. The candidate strategies are adapted to the context to obtain the initial strategy for the storage device. Verify the feasibility between the preliminary strategy and the operating parameters to obtain the verification pass strategy for the storage device; The verification pass policy is output as the control policy for the storage device.

[0039] The policy matching module performs policy retrieval and matching on the anomaly parsing results based on the network data security policy library to obtain candidate policies for the storage device, specifically for: Parse the anomaly parsing result to obtain the anomaly type identifier and context parameters of the anomaly parsing result; Based on the anomaly type identifier, select the basic policy from the network data security policy library; Based on the context parameters, the basic strategy is instantiated and adjusted to obtain the adaptation strategy for the storage device; The adaptation strategy is used as a candidate strategy for the storage device.

[0040] Specifically, when parsing anomaly identification data to determine the anomaly type and associated context of the storage device, a dedicated data parsing tool is first launched. This tool must be fully compatible with the structured format of the anomaly identification data to ensure that all information in the data can be completely read. The specific content corresponding to the operational parameter anomaly identifier and the network environment anomaly identifier is extracted from the anomaly identification data. For the operational parameter anomaly identifier, the specific category of the abnormal operational parameter is identified, such as read / write speed anomaly, hardware temperature anomaly, etc. These categories are the anomaly types of the storage device. Simultaneously, information such as the timestamp of each anomaly occurrence, the duration of the anomaly, and the task being executed by the storage device at the time of the anomaly are extracted. For the network environment anomaly identifier, information such as the timestamp of the specific category of abnormal network data occurrence, the number of network-connected devices during the anomaly duration, and the specific direction of data transmission are extracted. These time, task, and device connection information directly related to the anomaly are integrated to form the anomaly associated context of the storage device.

[0041] Furthermore, when merging the exception type and exception association context into the storage device's exception resolution result, a standardized document structure for the exception resolution result is first established. This structure includes two core parts: an exception type field and an exception association context field. The identified exception types are sequentially filled into the exception type field according to their categories, such as explicitly recording specific details like read / write speed anomalies, hardware temperature anomalies, and network latency anomalies. Then, the organized exception association context is filled into the exception association context field according to chronological order and association logic, ensuring that each exception type corresponds to its specific context information at the time of occurrence. For example, read / write speed anomalies correspond to the timestamp of occurrence and the large data write task being executed at the time; network latency anomalies correspond to the timestamp of occurrence and the number of devices connected to the network at the time. After completing the field filling, the document is formatted to ensure no information is missing or formatted incorrectly. The final standardized document is the storage device's exception resolution result.

[0042] Furthermore, when performing policy retrieval and matching based on the anomaly analysis results using the network data security policy library to obtain candidate policies for the storage device, the retrieval function of the network data security policy library is first activated. This policy library pre-stores security control policies corresponding to various anomaly scenarios, and each policy is labeled with the applicable anomaly type and anomaly context conditions. The anomaly analysis results are input into the policy library retrieval system as retrieval conditions. The retrieval system first filters out all policies in the library related to the anomaly type in the anomaly analysis results, and then performs a secondary matching on the filtered policies in combination with the anomaly association context. For example, if the anomaly type is network latency anomaly and the anomaly association context shows that the number of network connected devices is too high when the anomaly occurs, the retrieval system will filter out policies in the library that are for network latency anomalies and are suitable for the "too many connected devices" scenario. All policies that pass the secondary matching are extracted and sorted from high to low according to the matching degree to form a list containing multiple suitable policies. This list is the candidate policy for the storage device.

[0043] Furthermore, when adjusting the candidate strategies to adapt to the context and obtain the initial strategy for the storage device, each candidate strategy in the candidate strategy list is extracted one by one. For each candidate strategy, its preset applicable context conditions are compared with the abnormal association context of the storage device to identify the details where there are differences. For example, in a scenario where a candidate strategy is preset to apply to "too many device connections", the preset threshold for the number of devices is a fixed value. However, if the abnormal association context shows that the actual number of device connections is higher than this threshold, then the control parameters related to the number of device connections in the strategy are adjusted according to the difference between the actual number of device connections and the preset threshold. For example, "limit the number of new device connections to five" in the strategy is changed to "limit the number of new device connections to three" to adapt to the actual device connection situation. If the preset abnormal duration response plan in the candidate strategy does not match the duration of the actual abnormal association context, then the corresponding processing steps in the strategy are adjusted according to the actual duration. For example, "disconnect some non-critical connections after ten minutes of continuous abnormality" is changed to "disconnect some non-critical connections after five minutes of continuous abnormality". After completing the context adaptation adjustment for each candidate strategy, the strategy with the highest matching degree and the best adaptation is selected, which is the initial strategy of the storage device.

[0044] Furthermore, to verify the feasibility between the initial strategy and the operating parameters, when the storage device passes the verification strategy, the current operating parameters of the storage device are first obtained, including real-time data such as read / write speed, cache utilization, and hardware temperature. The control operations involved in the initial strategy are compared and analyzed one by one with the current operating parameters to determine whether executing the control operations in the initial strategy will cause the operating parameters to exceed the normal operating range. For example, if the initial strategy includes the operation of "reducing read / write speed to reduce hardware load," the theoretical value of the reduced read / write speed is calculated and compared with the read / write speed range within the normal operating range of the storage device. If the theoretical value is within the normal range, the operation is feasible in terms of read / write speed. If the initial strategy includes the operation of "increasing cache usage to improve data processing efficiency," the theoretical value of the increased cache utilization is calculated and compared with the normal cache utilization range to confirm whether it is within a reasonable range. After the feasibility verification of all control operations in the preliminary strategy is completed, if the theoretical operating parameters corresponding to all operations are within the normal range, it indicates that the preliminary strategy is feasible and the preliminary strategy is the verification pass strategy of the storage device. If the theoretical operating parameters corresponding to a certain operation exceed the normal range, return to the previous step to readjust the candidate strategy for context adaptation until a feasible verification pass strategy is obtained.

[0045] Furthermore, when the output verification pass policy is used as the control policy for the storage device, the verification pass policy is first standardized by documenting it. The control operation steps, execution time points, and monitoring requirements during execution are organized according to a preset control policy document format to ensure clear content, unambiguous steps, and no vague or unclear statements. The policy output function is then activated, transmitting the standardized verification pass policy document to the storage device's control module. Encryption is used during transmission to ensure the policy document is not tampered with or leaked. Upon receiving the policy document, the control module performs integrity verification. If no data loss is confirmed, the document is marked as the control policy currently being executed by the storage device. The policy reception time and effective time are recorded, completing the output process. At this point, the verification pass policy officially becomes the control policy for the storage device.

[0046] Specifically, when parsing the anomaly resolution results to obtain the anomaly type identifier and context parameters, a data parsing program is first started. This program can recognize the standardized document structure of the anomaly resolution results. Specific anomaly categories, such as network latency anomalies and hardware temperature anomalies, are extracted from the anomaly type field of the anomaly resolution results. Each category is assigned a unique identifier, which serves as the anomaly type identifier. Simultaneously, specific information related to the anomaly is extracted from the anomaly association context field, such as the time range of the anomaly occurrence, the load on storage devices during the anomaly period, and the number of network-connected devices. This information is converted into specific numerical or descriptive content that can be directly used for policy matching; this content constitutes the context parameters.

[0047] Furthermore, when selecting basic policies from the network data security policy library based on anomaly type identifiers, the index system of the network data security policy library is first opened. Each basic policy in this system is associated with a corresponding anomaly type identifier. The obtained anomaly type identifier is input into the index system, which then performs a precise search within the policy library based on the identifier to find all basic policies that perfectly match that identifier. For example, if the anomaly type identifier corresponds to network latency anomalies, the index system will filter out all basic policies in the library that are explicitly marked as applicable to network latency anomalies. These policies are general handling solutions for this type of anomaly and do not include adaptation details for specific scenarios. These filtered policies are the selected basic policies.

[0048] Furthermore, when instantiating and adjusting the basic policies based on context parameters to obtain the adaptation policy for the storage device, each selected basic policy is first opened one by one to analyze the variable parts that need to be adjusted according to the actual scenario. The context parameters are matched with the variable parts of the basic policies. For example, if a basic policy states "limit new device access based on the number of network connected devices," and the context parameters show that the current number of connected devices is a specific value, then the statement is adjusted to "limit the number of new devices accessing to a certain percentage of the current number of connected devices," and the specific value is substituted. If the context parameters include the duration of an anomaly, then the statement in the basic policy "execute a certain operation after the anomaly lasts for a period of time" is adjusted to "execute a certain operation after the anomaly lasts for a specific duration," specifying the specific duration. After adjusting all the variable parts of the basic policies, the policy content is fully adapted to the actual context parameters, and the adjusted policy is the adaptation policy for the storage device.

[0049] Furthermore, when considering adaptation strategies as candidate strategies for storage devices, each strategy undergoes a format check to ensure that the operational steps, applicable conditions, and other details are clearly and unambiguously described, conforming to the document specifications for candidate strategies. After passing the check, all adaptation strategies are sorted according to their adjusted adaptation degree, with strategies having higher adaptation degrees appearing first, forming an ordered strategy list. This list is marked as a candidate strategy for the storage device and stored in the temporary storage area of ​​the strategy matching module. Simultaneously, the strategy's generation time and corresponding anomaly resolution results are recorded for subsequent steps and traceability. At this point, the adaptation strategy officially becomes a candidate strategy for the storage device.

[0050] In summary, parsing anomaly identification data determines the anomaly type and associated context, avoiding identification bias caused by relying on only a single anomaly, and providing an accurate basis for subsequent strategy matching. Merging anomaly types and associated contexts to form anomaly parsing results integrates key information, ensuring that strategy retrieval and matching comprehensively considers the anomaly scenario.

[0051] In summary, the system retrieves and matches candidate policies from the policy library, then filters and adapts policies based on anomaly analysis results, reducing the filtering of invalid policies and improving matching efficiency. Adapting and adjusting candidate policies yields preliminary policies that align with the actual anomaly context of the device, preventing them from becoming out of touch with real-world scenarios.

[0052] In summary, the feasibility of the initial strategy and operating parameters is verified, strategies that may affect the normal operation of the equipment are eliminated, and the security and applicability of the control strategy are ensured. The output verification uses the strategy as a control policy to ensure that the final executed strategy is accurate and feasible, effectively improving the security protection of the storage device.

[0053] In summary, parsing the anomaly analysis results yields anomaly type identifiers and context parameters, accurately extracting key matching information and providing a clear direction for strategy retrieval, thus avoiding matching bias. Based on the anomaly type identifier, a basic strategy is selected, directly locating a general strategy in the strategy library that is suitable for the anomaly category, reducing invalid searches and improving strategy selection efficiency.

[0054] In summary, adapting the basic strategy based on contextual parameters ensures that the strategy aligns with the actual abnormal scenarios of the device, preventing a disconnect between general strategies and real-world conditions. Using these adapted strategies as candidate strategies ensures their scenario adaptability, laying the foundation for generating precise control strategies in the future.

[0055] The instruction parsing module is used to perform multi-level instruction parsing on the composite control rules in the control strategy to obtain the executable instruction sequence of the storage device. In this embodiment of the invention, the instruction parsing module performs multi-level instruction parsing on the composite control rules in the control strategy to obtain the executable instruction sequence of the storage device, specifically for: The composite control rules in the control strategy are structurally decomposed to obtain the rule decomposition result of the control strategy; Based on the rule decomposition results, the logical dependencies between action clauses and condition clauses in the composite control rule are reconstructed into a topological network to obtain the action dependency network of the composite control rule. The action nodes in the action-dependent network are prioritized to obtain the target priority sequence of the action nodes. Based on the target priority sequence, the action clauses are dynamically topologically sorted to obtain the executable instruction sequence of the storage device.

[0056] The instruction parsing module performs priority sorting on the action nodes in the action dependency network at the execution root, obtaining the target priority sequence of the action nodes, specifically for: Based on the action dependency network, the feature dimensions of the number of direct predecessor nodes and the number of direct successor nodes in the action node are identified to obtain the topological feature data of the action node. Based on the topological feature data, the number of direct predecessor nodes and the number of direct successor nodes are nonlinearly weighted and fused to obtain the key indicators of the action node. Based on the aforementioned key indicators, the action nodes are comprehensively sorted to obtain an initial priority sequence of the action nodes; Based on the urgency of the conditional clauses, the initial priority sequence is adjusted to obtain the target priority sequence of the action node.

[0057] Specifically, when structurally decomposing the composite control rules in the control strategy to obtain the rule decomposition results, the rule structure parsing tool is activated to read the composite control rule text line by line. By identifying logical connectors, the rules are split into independent parts, and then the split parts are classified into action clauses and condition clauses. The action clauses are the operations to be performed, and the condition clauses are the prerequisites for triggering the actions. Finally, the rules are organized into a structured table labeled with the clause type, content, and position according to the original logical order. This table is the rule decomposition result.

[0058] Furthermore, when reconstructing the topological network of the logical dependencies between action clauses and condition clauses in the composite control rule based on the rule decomposition results to obtain the action dependency network of the composite control rule, the triggering condition clauses corresponding to each action clause are first sorted out to clarify the dependency relationship. Then, the action clauses and condition clauses are treated as independent nodes, and directional lines are used to indicate the dependency from the condition clause node to the action clause node. If multiple condition clauses trigger the same action clause, they are all connected to the action clause node. If one condition clause triggers multiple action clauses, they are connected separately. The constructed visual network structure is the action dependency network.

[0059] Furthermore, when prioritizing action nodes in the action-dependent network to obtain the target priority sequence of action nodes, the action nodes are first divided into three levels—core impact, important impact, and general impact—based on the degree of impact of the action clauses on the safe operation of the storage device, and initial priorities are assigned. The core impact level is the highest. Then, the triggering order of the action nodes is combined. If node A is a prerequisite for the execution of node B, then node A has a higher priority than node B. All action nodes are sorted by combining the two factors to form a list of nodes from high to low priority. This list is the target priority sequence.

[0060] Furthermore, when dynamically sorting the action clauses based on the target priority sequence to obtain the executable instruction sequence of the storage device, the action clauses corresponding to each action node are extracted and the execution content and object are clarified. The action clauses are checked according to the target priority sequence to see if there are any pre-dependent actions. If there are no dependencies, they are directly added to the list to be executed. If there are dependencies, they are added after the pre-dependent actions are added. During the process, conflicting action clauses are verified and eliminated. Finally, the list to be executed is arranged into an ordered instruction text according to the order of addition. This text is the executable instruction sequence.

[0061] Specifically, when obtaining the topological feature data of action nodes based on the feature dimensions of the number of direct predecessor nodes and direct successor nodes in the action dependency network, each action node in the action dependency network is selected one by one. For each action node, directly connected conditional clause nodes or action nodes are found along the lines pointing to that node in the network. These nodes are the direct predecessor nodes of that action node, and the total number of these nodes is counted to obtain the number of direct predecessor nodes. At the same time, other directly connected action nodes are found along the lines originating from that node. These nodes are the direct successor nodes of that action node, and the total number of these nodes is counted to obtain the number of direct successor nodes. The number of direct predecessor nodes and the number of direct successor nodes for each action node are recorded accordingly to form a dataset containing these two quantities of information for each action node. This dataset is the topological feature data of the action nodes.

[0062] Furthermore, when obtaining the criticality index of an action node by non-linearly weighting and fusing the number of direct predecessor nodes and direct successor nodes based on topological feature data, the weight allocation of the number of direct predecessor nodes and direct successor nodes in the fusion process is first determined. The weight of the number of direct successor nodes is higher than that of the number of direct predecessor nodes because a larger number of direct successor nodes indicates that the action node has a greater impact on the execution of subsequent actions, and therefore is more critical. For each action node, the number of its direct predecessor nodes is first amplified according to their corresponding weights, and then the number of its direct successor nodes is amplified according to their corresponding weights. The amplification method is to adjust the proportion of the quantities in the fusion result according to their weights, with higher-weighted quantities having a larger proportion in the fusion result. The two amplified quantities are then added together to obtain a comprehensive value, which is the criticality index of the action node. The higher the value, the stronger the criticality of the action node in the entire network.

[0063] Furthermore, when comprehensively ranking action nodes based on key indicators to obtain the initial priority sequence of action nodes, the key indicators of all action nodes are first summarized and organized, and the action nodes are arranged in descending order of indicator values. If two action nodes have the same key indicator value, their number of direct successor nodes is compared, and the action node with more direct successor nodes is ranked first; if the number of direct successor nodes is also the same, their number of direct predecessor nodes is compared, and the action node with fewer direct predecessor nodes is ranked first, because such nodes are less constrained by other nodes and can be executed first. After sorting all action nodes according to this rule, an ordered list of action nodes is formed, which is the initial priority sequence of action nodes.

[0064] Furthermore, when adjusting the initial priority sequence based on the urgency of the conditional clauses to obtain the target priority sequence of the action nodes, the trigger conditional clauses corresponding to each action node are first analyzed to evaluate the urgency of the situation described by the conditional clauses. The urgency is divided into three levels: urgent, moderately urgent, and normal. Among them, the situation that may lead to data loss or hardware damage to the storage device is urgent, the situation that may affect the device performance but will not cause serious consequences is moderately urgent, and the other situations are normal.

[0065] Furthermore, for each action node in the initial priority sequence, if its corresponding conditional clause is urgent, the action node's position in the sequence is moved forward, increasing its priority; if the urgency is moderate, the action node's position in the sequence is moved backward, decreasing its priority; if it is relatively urgent, its position in the initial priority sequence remains unchanged. After adjusting the positions of all action nodes, a new ordered list of action nodes is formed, which is the target priority sequence of action nodes.

[0066] In summary, the decomposition of complex control rules clearly separates actions and conditional clauses, avoiding logical confusion and laying the foundation for subsequent parsing. The logical dependencies between actions and conditional clauses are reconstructed into an action dependency network, visually presenting the relationships and preventing conflicts in instruction execution logic.

[0067] In summary, prioritizing action nodes clarifies the order of instruction execution, preventing security failures due to delays in critical actions. Sequencing action clauses yields a sequence of executable instructions, ensuring orderly and consistent instruction execution and improving the accuracy of storage device security control.

[0068] In summary, identifying topological features of action nodes and accurately capturing node dependency characteristics provides objective data support for priority ranking, avoiding subjective judgment bias. The key indicators of nonlinear weighted fusion highlight the impact of direct successor nodes on subsequent actions, accurately quantifying node importance and ensuring a scientific ranking basis.

[0069] In summary, the initial sequence is arranged based on key indicators to clarify the basic priority of nodes, avoid chaotic execution order, and ensure that core actions are handled first. The target sequence is adjusted according to the urgency of conditions to make the priority match the actual abnormal and urgent scenarios, thereby improving the timeliness and security of instruction execution.

[0070] The effect feedback module is used to adjust the access control permissions and data encryption level of the storage device according to the executable instruction sequence, so as to obtain the control effect data of the storage device. In this embodiment of the invention, the effect feedback module, when executing the executable instruction sequence to adjust the access control permissions and data encryption level of the storage device to obtain control effect data of the storage device, is specifically used for: Parse the executable instruction sequence to obtain the access control adjustment instruction and data encryption adjustment instruction of the storage device; Based on the access control adjustment instruction, update the access control rules of the storage device to obtain the updated access control permissions of the storage device. Based on the data encryption adjustment instruction, the data encryption parameters of the storage device are modified to obtain the modified data encryption level of the storage device; The updated access control permissions and the modified data encryption level are combined to form the control effect data of the storage device.

[0071] Specifically, when parsing the executable instruction sequence to obtain the access control adjustment instructions and data encryption adjustment instructions for the storage device, the instruction parsing program is started to read the executable instruction sequence line by line, and the instructions containing keywords such as "access" and "permission" are selected as access control adjustment instructions, and the instructions containing keywords such as "encryption" and "key" are selected as data encryption adjustment instructions, ensuring that each instruction clearly corresponds to a specific adjustment object, forming two independent instruction sets.

[0072] Furthermore, when updating the access control rules of the storage device based on the access control adjustment instructions and obtaining the updated access control permissions of the storage device, the current access control rule document is retrieved, and the rules are modified according to each access control adjustment instruction, such as prohibiting temporary users from performing data deletion operations or allowing administrators to perform batch imports. After modification, the integrity of the document is verified, and it is set as the new effective rule. The permission settings in the document are the updated access control permissions.

[0073] Furthermore, when modifying the data encryption parameters of the storage device based on the data encryption adjustment instructions to obtain the modified data encryption level of the storage device, open the data encryption configuration interface, modify the parameters according to each data encryption adjustment instruction, such as changing the encryption algorithm for sensitive user data or expanding the encryption scope to the temporary cache, start the encryption level detection program after modification, and the generated encryption security level report is the modified data encryption level.

[0074] Furthermore, when combining the updated access control permissions and the modified data encryption level into the control effect data of the storage device, a standardized document containing sections on "access control permissions" and "data encryption level" is constructed. The former records specific permissions according to user groups, while the latter records encryption algorithms, coverage, and security levels. The complete document formed after unifying the format is the control effect data.

[0075] In summary, analyzing the two types of adjustment commands in the instruction sequence accurately separates access control and data encryption-related operations, avoiding command confusion and providing a clear direction for subsequent targeted adjustments. Based on the access control adjustment command update rules, the results of device permission changes are clearly defined, ensuring that permission management aligns with security requirements and preventing unauthorized access risks.

[0076] In summary, modifying parameters according to data encryption adjustment instructions enhances the data encryption protection level, ensures data storage security, and addresses potential data leakage threats. The combined results of these two types of data constitute the control effect data, comprehensively recording permission and encryption adjustment details, providing a complete basis for subsequent assessments of equipment security status.

[0077] The status assessment module is used to assess the security status of the storage device based on the control effect data, and obtain the security baseline offset of the storage device. In this embodiment of the invention, the state assessment module, based on the control effect data, assesses the security status of the storage device and obtains the security baseline offset of the storage device, specifically for: Based on the control effect data, extract the access control permission adjustment records and data encryption level change information of the storage device; The access control permission adjustment records and the data encryption level change information are organized into security event data for the storage device; The security event data is classified using multi-dimensional indicators to obtain the security event classification results for the storage device. Based on the security incident classification results, the security baseline standard for the storage device is determined; Based on the security baseline standard, a dynamic consistency analysis is performed on the security status of the storage device to obtain the degree of consistency of the security status of the storage device. Based on the degree of consistency of the security status, the difference of the target security status of the storage device is quantified to obtain the security baseline offset of the storage device.

[0078] The state assessment module, based on the degree of security state consistency, performs differential quantification on the target security state of the storage device to obtain the security baseline offset of the storage device, specifically for: Based on the security event classification results, extract the number of abnormal access patterns and the number of encryption vulnerability indicators in the storage device; A multi-dimensional assessment of the target security status in the storage device is performed to obtain the target security status consistency requirements of the storage device. Based on the degree of consistency of the security state, the difference of the target security state is quantified to obtain the security baseline offset of the storage device, wherein the formula for calculating the security baseline offset is as follows: ; In the formula, This is the safety baseline offset. The degree of consistency of the security state. The target security state consistency requirement. The number of the abnormal access patterns. The number of the aforementioned cryptographic vulnerability indicators. It is a logarithmic function.

[0079] Specifically, when extracting access control permission adjustment records and data encryption level change information of storage devices based on the control effect data, the control effect data document is opened, the specific content of permission modification is extracted from the "Access Control Permissions" section, and organized into access control permission adjustment records by time. At the same time, the encryption parameter change information is extracted from the "Data Encryption Level" section to form data encryption level change information. Each piece of information includes the status before and after the change and the time.

[0080] Furthermore, when organizing access control permission adjustment records and data encryption level change information into security event data for storage devices, access control permission adjustment records are converted into event entries labeled "access control permission adjustment" and data encryption level change information is converted into event entries labeled "data encryption level change" according to a unified format of event type, change content, change time, and scope of impact. All entries are then integrated by time to form security event data.

[0081] Furthermore, when classifying security incident data using multi-dimensional indicators to obtain the security incident classification results for storage devices, each security incident entry is labeled with a classification tag according to three dimensions: the scope of impact, risk level, and incident type, such as global impact, high risk, access control permission adjustment, etc. Then, the events are grouped by the tags to form the security incident classification results.

[0082] Furthermore, when determining the security baseline standard for storage devices based on the security incident classification results, events with global impact and high risk are selected, their adjustment targets and post-change status are analyzed, and in conjunction with device design security standards and industry specifications, standard documents containing core security requirements such as access control and data encryption are formulated, which are the security baseline standards.

[0083] Furthermore, based on the security baseline standard, a dynamic consistency analysis of the security status of the storage device is performed to obtain the security status consistency degree of the storage device. The current security status of the device is obtained and compared with the security baseline standard one by one. The proportion of consistent elements is counted. Combined with the severity of inconsistent elements, the degree of conformity between the current security status and the baseline standard is evaluated, which is the security status consistency degree.

[0084] Furthermore, based on the degree of consistency of security status, the target security status of the storage device is quantified to obtain the security baseline offset of the storage device. The state that fully complies with the security baseline standard is taken as the target. The degree of consistency of security status is compared to find the differences. The differences are quantified according to the number and severity of the deviation elements. The values ​​are added together to obtain the value representing the overall degree of deviation, which is the security baseline offset.

[0085] Specifically, based on the security event classification results, the number of abnormal access patterns and the number of encryption vulnerability indicators in the storage device are extracted. High- and medium-risk access control permission adjustment events are screened from the security event classification results. Unique access patterns that do not conform to the security baseline standards are identified and their total number is counted, which is the number of abnormal access patterns. At the same time, high- and medium-risk data encryption level change events are screened, encryption protection defects are identified and their total number is counted, which is the number of encryption vulnerability indicators.

[0086] Furthermore, a multi-dimensional assessment of the target security status in the storage device is conducted to obtain the target security status consistency requirements of the storage device. Evaluation standards are formulated from three dimensions: access control compliance, data encryption integrity, and security policy enforcement. For example, access control compliance requires that user permissions are not exceeded, and data encryption integrity requires that core data encryption meets the standards. These are combined to form a clear requirement document, which is the target security status consistency requirement.

[0087] Furthermore, when quantifying the differences in the target security state based on the degree of security state consistency to obtain the security baseline offset of the storage device, the degree of security state consistency is compared with the target security state consistency requirements to identify the specific differences in each dimension. These differences are then quantified according to their importance and severity. The total value obtained by summing up the quantified values ​​of all differences is the security baseline offset.

[0088] Specifically, the degree of security status consistency comes from dynamic consistency analysis of the security status of storage devices based on security baseline standards. During the analysis, the current security status information of the device is obtained, compared with the security baseline standards, the proportion of consistent elements is statistically analyzed, and the severity of inconsistent elements is combined to obtain a comprehensive result.

[0089] Furthermore, the requirement for consistency in the target security state stems from a multi-dimensional assessment of the device's target security state. Standards are established across three dimensions: access control compliance, data encryption integrity, and security policy enforcement, culminating in a comprehensive and explicit requirement document. The number of anomalous access patterns is derived from security event classification results. High- and medium-risk access control permission adjustment events are filtered out, and unique access patterns that do not conform to the security baseline standards are identified. The total number of these patterns is then calculated.

[0090] Furthermore, the number of encryption vulnerability indicators comes from the security event classification results. High- and medium-risk data encryption level change events are filtered out to identify encryption protection flaws, and the total number of these flaws is accumulated.

[0091] Furthermore, the formula means that it comprehensively considers the difference between the current security status of the storage device and the target security status, as well as the impact of abnormal access and encryption vulnerabilities on the security status, and calculates a value that reflects the degree to which the security status deviates from the target security baseline.

[0092] Furthermore, the calculation first calculates the absolute difference between the degree of security state consistency and the target security state consistency requirement, then divides it by the target security state consistency requirement to obtain the relative difference. At the same time, the logarithm of the sum of the number of abnormal access patterns and the number of encryption vulnerability indicators is calculated. The relative difference is multiplied by the logarithm plus one to obtain the security baseline offset.

[0093] Furthermore, the security baseline offset decreases when the security state consistency level approaches the target security state consistency requirement; conversely, the security baseline offset increases when the security state consistency level deviates significantly from the target security state consistency requirement. The security baseline offset increases when the number of abnormal access patterns or encryption vulnerability indicators increases; and decreases when the number of abnormal access patterns or encryption vulnerability indicators decreases.

[0094] In summary, extracting permission adjustment records and encrypted change information allows for the accurate acquisition of core data on control effectiveness, providing a reliable basis for security assessments and preventing assessments from being divorced from actual operations. Organizing information into security event data and standardizing data formats ensures that security-related information is clearly structured, facilitating subsequent classification and analysis.

[0095] In summary, the classification results of multidimensional security events provide a precise reference for determining security baseline standards by analyzing event characteristics from multiple dimensions. Establishing security baseline standards based on the classification results ensures that the baseline aligns with the actual security scenarios of the equipment, avoiding standards that are out of touch with reality.

[0096] In summary, dynamic consistency analysis assesses the degree of consistency between the current security state and the baseline, determining the alignment between the current security state and the baseline in real time and promptly identifying deviations. Quantifying the security baseline offset provides a clear visual representation of the degree of security state deviation, offering a clear direction for subsequent optimization strategies.

[0097] In summary, extracting abnormal access patterns and the number of encryption vulnerability indicators allows for the precise identification of device security risks, providing crucial risk data support for differential quantification. A multi-dimensional assessment of the consistency requirements of target security status clarifies security target standards and avoids inaccurate differential judgments due to ambiguous targets.

[0098] In summary, by quantifying the difference using formulas to obtain the safety baseline offset, and by comprehensively considering the safety status fit and the number of risks, the degree of deviation is presented intuitively, providing a precise basis for strategy optimization.

[0099] The optimization control module is used to dynamically update the network data security policy library based on the security baseline offset to obtain the optimization control policy for the storage device.

[0100] In this embodiment of the invention, the optimization control module dynamically updates the network data security policy library based on the security baseline offset to obtain the optimization control policy for the storage device, specifically for: Based on the safety baseline offset, determine the adjustment type and adjustment range of the control strategy; Based on the adjustment type and the adjustment magnitude, the access control rules and data encryption rules in the network data security policy library are mapped to collaborative revision instructions of the network data security policy library; Based on the collaborative revision instructions, the network data security policy library is collaboratively updated to obtain the target network data security policy library of the storage device. Based on the target network data security policy library, the real-time data environment of the storage device is re-matched to obtain the optimized control policy for the storage device.

[0101] Specifically, the differences reflected by the security baseline offset are analyzed. If the offset is mainly due to access control permissions not meeting the target requirements, the adjustment type is determined to be an access control rule revision. If the offset is mainly due to insufficient data encryption protection, the adjustment type is determined to be a data encryption rule revision. If there are significant differences in both, the adjustment type is a joint revision of access control and data encryption rules. At the same time, the adjustment range is determined based on the size of the offset. A large offset indicates that the current policy is significantly different from the target state and requires a large adjustment. A small offset indicates that the difference is slight and only a small adjustment is needed.

[0102] Furthermore, for the determined adjustment type, the corresponding access control rules or data encryption rules are extracted from the network data security policy library. According to the adjustment range requirements, specific revision content is formulated for the extracted rule entries. All revision content is organized into instructions in a unified format, clarifying the rule entry, revision method and specific content corresponding to each instruction. These instructions are the collaborative revision instructions of the network data security policy library.

[0103] Furthermore, the revision function of the network data security policy library is activated, and the revision operation is executed one by one according to the order of the collaborative revision instructions. During the execution, the location of the rule entry corresponding to each instruction is first located, and deletion, modification or addition operations are performed according to the instruction requirements. After the revision is completed, it is checked whether there are any conflicts between the revised rules. If conflicts are found, they are coordinated and processed according to the priority of the collaborative revision instructions to ensure that all rules are logically consistent. After all revisions and conflict handling are completed, the updated network data security policy library is saved. This updated policy library is the target network data security policy library of the storage device.

[0104] Furthermore, the system collects real-time data environment information of the storage device and matches this information with rules in the target network data security policy library to identify access control rules and data encryption rules applicable to the current environment. Based on the matched rules, specific control measures are formulated, clarifying the permission restrictions for different users, the encryption requirements for different data, and the triggering conditions for executing these measures. These control measures are then organized into a structured policy document to ensure that each measure directly corresponds to the specific scenario in the real-time data environment. This document constitutes the optimized control strategy for the storage device.

[0105] In summary, the adjustment type and magnitude are determined based on the security baseline offset, accurately identifying the direction of policy optimization, avoiding blind adjustments, and ensuring that policy updates align with device security requirements. Mapping rules serve as collaborative revision instructions, clearly defining the revision content of the policy library, ensuring synchronized optimization of access control and data encryption rules, and avoiding rule conflicts.

[0106] In summary, collaborative updates to the policy library and target library enable dynamic iteration of the policy library, overcoming the limitations of static protection and adapting to changes in security threats.

[0107] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0108] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.

[0109] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. An intelligent control system for a network security data storage device, characterized in that, The abnormality marking module, the strategy matching module, the instruction analysis module, the effect feedback module, the state evaluation module and the optimization control module, wherein: The abnormality marking module is configured to identify abnormal patterns of the running parameters and the network environment data in the storage device, and obtain abnormal identification data of the storage device. The strategy matching module is configured to perform strategy matching on the abnormal identification data based on a network data security policy library, and obtain a control strategy of the storage device. The instruction analysis module is configured to perform multi-level instruction analysis on the composite control rules in the control strategy, and obtain an executable instruction sequence of the storage device. The effect feedback module is configured to adjust the access control permission and the data encryption level of the storage device according to the executable instruction sequence, and obtain control effect data of the storage device. The state evaluation module is configured to evaluate the security state of the storage device based on the control effect data, and obtain a security baseline offset of the storage device. The optimization control module is configured to dynamically update the network data security policy library based on the security baseline offset, and obtain an optimized control strategy of the storage device.

2. The intelligent control system of a network security data storage device of claim 1, wherein, The abnormality marking module is configured to identify abnormal patterns of the running parameters and the network environment data in the storage device, and obtain abnormal identification data of the storage device. The running parameters and the network environment data in the storage device are synchronously collected. The running parameters are compared with normal running ranges of the storage device to obtain running parameter abnormality identification of the storage device. The network environment data is screened layer by layer to obtain network environment abnormality identification of the storage device. The running parameter abnormality identification and the network environment abnormality identification are combined to obtain the abnormal identification data of the storage device.

3. The intelligent control system of a network security data storage device of claim 1, wherein, The strategy matching module is configured to perform strategy matching on the abnormal identification data based on a network data security policy library, and obtain a control strategy of the storage device. The abnormality identification data is analyzed to determine the abnormal type and the abnormal associated context of the storage device. The abnormal type and the abnormal associated context are combined to obtain an abnormal analysis result of the storage device. The abnormal analysis result is matched based on the network data security policy library to obtain a candidate strategy of the storage device. The candidate strategy is context-adapted to obtain a preliminary strategy of the storage device. The feasibility between the preliminary strategy and the running parameters is verified to obtain a verified strategy of the storage device. The verified strategy is output as the control strategy of the storage device.

4. The intelligent control system of a network security data storage device of claim 3, wherein, The strategy matching module is configured to perform strategy matching on the abnormal identification data based on a network data security policy library, and obtain a control strategy of the storage device. The abnormal analysis result is analyzed to obtain an abnormal type identification and a context parameter of the abnormal analysis result. The network data security policy library is selected based on the abnormal type identification. The network data security policy library is selected based on the abnormal type identification. Based on the context parameter, the base strategy is instantiated and adjusted to obtain an adaptive strategy of the storage device; The adaptive strategy is taken as a candidate strategy of the storage device.

5. The intelligent control system of a network security data storage device of claim 1, wherein, The instruction analysis module performs multi-level instruction analysis on the composite control rule in the control strategy to obtain an executable instruction sequence of the storage device, specifically for: performing structural decomposition on the composite control rule in the control strategy to obtain a rule decomposition result of the control strategy; based on the rule decomposition result, topological network reconstruction is performed on the logical dependency relationship between the action clause and the condition clause in the composite control rule to obtain an action dependency network of the composite control rule; performing priority sorting on the action nodes in the action dependency network to obtain a target priority sequence of the action nodes; based on the target priority sequence, dynamically topologically sorting the action clauses to obtain an executable instruction sequence of the storage device.

6. An intelligent control system for a network security data storage device as described in claim 5, wherein, The instruction analysis module performs root priority sorting on the action nodes in the action dependency network to obtain a target priority sequence of the action nodes, specifically for: According to the action dependency network, identify the feature dimensions of the number of direct predecessor nodes and the number of direct successor nodes in the action nodes to obtain the topological feature data of the action nodes; According to the topological feature data, the number of direct predecessor nodes and the number of direct successor nodes are nonlinearly weighted and fused to obtain the criticality index of the action nodes; based on the criticality index, the action nodes are comprehensively sorted to obtain an initial priority sequence of the action nodes; According to the urgency of the condition clause, adjust the initial priority sequence to obtain the target priority sequence of the action nodes.

7. The intelligent control system of a network security data storage device of claim 1, wherein, The effect feedback module executes the executable instruction sequence to adjust the access control permission and the data encryption level of the storage device to obtain control effect data of the storage device, specifically for: Parse the executable instruction sequence to obtain access control adjustment instructions and data encryption adjustment instructions of the storage device; based on the access control adjustment instructions, update the access control rules of the storage device to obtain the updated access control permissions of the storage device; based on the data encryption adjustment instructions, modify the data encryption parameters of the storage device to obtain the modified data encryption level of the storage device; The updated access control permissions and the modified data encryption level are combined into the control effect data of the storage device.

8. The intelligent control system of a network security data storage device of claim 1, wherein, The state evaluation module executes based on the control effect data, evaluates the security state of the storage device to obtain the security baseline offset of the storage device, specifically for: According to the control effect data, extract the access control permission adjustment record and the data encryption level change information of the storage device; The access control permission adjustment record and the data encryption level change information are regularized into security event data of the storage device; performing multi-dimensional index classification on the security event data to obtain a security event classification result of the storage device; According to the security event classification result, a security baseline standard of the storage device is determined; Based on the security baseline standard, dynamic consistency analysis is performed on the security state of the storage device to obtain a security state consistency degree of the storage device; Based on the security state consistency degree, a target security state of the storage device is subjected to difference quantification to obtain a security baseline offset of the storage device.

9. The intelligent control system of a network security data storage device of claim 8, wherein, The state evaluation module, in performing difference quantification on the target security state of the storage device based on the security state consistency degree to obtain the security baseline offset of the storage device, is specifically configured to: According to the security event classification result, the number of abnormal access patterns and the number of encryption vulnerability indicators in the storage device are extracted; The target security state of the storage device is subjected to multi-dimensional evaluation to obtain a target security state consistency requirement of the storage device; Based on the security state consistency degree, the target security state is subjected to difference quantification to obtain the security baseline offset of the storage device, wherein the formula for calculating the security baseline offset is as follows: ; wherein is the security baseline offset, is the security state consistency degree, is the target security state consistency requirement, is the number of abnormal access patterns, is the number of encryption vulnerability indicators, is a logarithm function.

10. The intelligent control system of a network security data storage device of claim 1, wherein, The optimization control module, in performing dynamic updating of the network data security policy library based on the security baseline offset to obtain the optimization control strategy of the storage device, is specifically configured to: According to the security baseline offset, the adjustment type and adjustment amplitude of the control strategy are determined; According to the adjustment type and the adjustment amplitude, access control rules and data encryption rules in the network data security policy library are mapped into a collaborative revision instruction of the network data security policy library; Based on the collaborative revision instruction, the network data security policy library is subjected to collaborative updating to obtain a target network data security policy library of the storage device; According to the target network data security policy library, the real-time data environment of the storage device is re-matched to obtain the optimization control strategy of the storage device.