Security configuration information updating method and electronic equipment

By acquiring threat assessment results and resource load weights from the server, the security policy parameters of the server are dynamically adjusted, solving the problem that traditional static security policies are difficult to deal with complex network threats. This enables efficient and flexible security configuration updates and improves the server's security protection capabilities.

CN121530772APending Publication Date: 2026-02-13INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202610059393.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-16
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

Traditional static security configuration strategies are insufficient to cope with emerging risks such as advanced persistent threats and internal anomalous behaviors that are constantly evolving. Existing server architectures are inadequate in terms of dynamic security policy adjustments, making it difficult to achieve flexible adjustments and efficient protection in complex network environments.

Method used

By obtaining the threat assessment results of the server, the initial security policy parameters are determined according to the threat type and severity, and adapted in combination with resource load weights. The target security policy parameters are optimized using a swarm intelligence optimization algorithm, and the server's security configuration information is dynamically updated.

Benefits of technology

It achieves accurate matching and efficient response to current threats, improves the targeting and effectiveness of threat response, avoids deploying high-overhead security measures in high-load scenarios, and ensures business performance and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530772A_ABST
    Figure CN121530772A_ABST
Patent Text Reader

Abstract

The invention discloses a security configuration information updating method and electronic equipment, and particularly relates to the field of network security, and the method comprises the steps: obtaining a threat evaluation result of a server; determining an initial security policy parameter of the server according to the threat type and severity in the threat assessment result; determining a target security policy parameter of the server based on the initial security policy parameter and a resource load weight of the server; and updating the security configuration information of the server according to the target security policy parameter, so that the problem that novel risks such as continuously evolved advanced persistent threats and internal abnormal behaviors are difficult to deal with by adopting a static rule or a manual preset policy in the prior art can be solved, and the technical effect of dynamically adjusting the security configuration information of the server is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and particularly relates to a security configuration information updating method and an electronic device. BACKGROUND

[0002] With the wide application of cloud computing, big data and Internet of Things technologies, the security threats faced by servers in complex network environments are increasingly complex, diversified and dynamic. Traditional security configuration information usually adopts static rules or manually preset strategies, which are difficult to cope with new risks such as continuously evolving advanced persistent threats and internal abnormal behaviors. SUMMARY

[0003] The present application provides a security configuration information updating method and an electronic device to at least solve the problem that the traditional static security configuration strategy in the related art is difficult to cope with new risks such as continuously evolving advanced persistent threats and internal abnormal behaviors.

[0004] The present application provides a security configuration information updating method, comprising: obtaining a threat assessment result of a server; determining initial security policy parameters of the server according to a threat type and a severity in the threat assessment result; determining target security policy parameters of the server based on the initial security policy parameters and a resource load weight of the server; updating security configuration information of the server according to the target security policy parameters.

[0005] Optionally, the obtaining of the threat assessment result of the server comprises: obtaining running state data of the server; performing feature extraction on the running state data to obtain feature vector data of the server; performing anomaly detection on the feature vector data to obtain a target anomaly score corresponding to the running state data; in response to the target anomaly score being not less than an anomaly score threshold, determining the threat assessment result of the server according to the target anomaly score.

[0006] Optionally, the performing of anomaly detection on the feature vector data to obtain the target anomaly score corresponding to the running state data comprises: determining a window size and a step length of a sliding window; performing segmentation processing on the feature vector data based on the window size and the step length to obtain a plurality of local vector data of the server; performing anomaly detection on the feature vector data and the local vector data to obtain a first anomaly score and a plurality of second anomaly scores corresponding to the running state data; According to the first anomaly score and the plurality of second anomaly scores, a target anomaly score corresponding to the running state data is determined.

[0007] Optionally, according to the threat type and the severity in the threat assessment result, an initial security policy parameter of the server is determined, including: According to the threat type and the severity in the threat assessment result, a candidate security policy parameter of the server is determined. The priority of the plurality of parameters in the candidate security policy parameter is sorted from high to low to obtain the initial security policy parameter of the server.

[0008] Optionally, before determining the target security policy parameter of the server based on the initial security policy parameter and the resource load weight of the server, the method provided by the present disclosure includes: Obtaining a resource load condition in the server, the resource load condition at least including a usage rate of a processor, an occupancy rate of a memory and a read-write rate of a disk; According to the type of the service carried by the server, weights corresponding to the usage rate of the processor, the occupancy rate of the memory and the read-write rate of the disk are determined respectively; Based on the usage rate of the processor, the occupancy rate of the memory and the read-write rate of the disk and the weights, a resource load weight of the server is determined.

[0009] Optionally, determining the target security policy parameter of the server based on the initial security policy parameter and the resource load weight of the server includes: Based on the initial security policy parameter and the resource load weight, an adapted security policy parameter is determined; The adapted security policy parameter is processed by a target algorithm to obtain the target security policy parameter of the server, the target algorithm being a group intelligence optimization algorithm.

[0010] Optionally, before updating the security configuration information of the server according to the target security policy parameter, the method provided by the present disclosure includes: The target security policy parameter is processed for verification to obtain a verification result corresponding to the target security policy parameter; In response to the verification result meeting a target verification condition, the target security policy parameter is converted into a parameter update instruction; The security configuration information of the server is updated according to the target security policy parameter, including: The security configuration information of the server is updated according to the parameter update instruction.

[0011] Optionally, after updating the security configuration information of the server according to the target security policy parameter, the method provided by the present disclosure includes: Obtaining a health condition of the server, the health condition at least including a running stability condition, a response speed and a security condition; In response to the health condition not meeting the target health condition, obtaining an update number of security configuration information of the server; In response to the update number of the security configuration information being less than a target update number, updating a target security policy parameter, and adjusting the security configuration information of the server based on the updated target security policy parameter.

[0012] Optionally, the updating the target security policy parameter comprises: determining an update step of the target security policy parameter based on the health condition; updating the target security policy parameter according to the update step.

[0013] The application further provides a security configuration information updating device, comprising: an obtaining unit configured to obtain a threat assessment result of a server; a first determining unit configured to determine an initial security policy parameter of the server according to a threat type and a severity in the threat assessment result; a second determining unit configured to determine a target security policy parameter of the server based on the initial security policy parameter and a resource load weight of the server; an updating unit configured to update security configuration information of the server according to the target security policy parameter.

[0014] The application further provides an electronic device, comprising a memory configured to store a computer program, and a processor configured to execute the computer program to implement the steps of any of the above methods.

[0015] The application further provides a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the steps of any of the above methods.

[0016] The application further provides a computer program product, comprising a computer program, and the computer program is executed by a processor to implement the steps of any of the above methods.

[0017] The security configuration information updating method and the electronic device provided by the application comprise the following steps: obtaining a threat assessment result of a server; determining an initial security policy parameter of the server according to a threat type and a severity in the threat assessment result, which can accurately match the current threat and improve the pertinence and effectiveness of threat response; introducing a resource load weight to adapt the initial security policy parameter and determine a target security policy parameter of the server, which avoids deploying high-overhead security measures in a high-load scenario and thus guarantees business performance; and updating security configuration information of the server according to the target security policy parameter to dynamically adjust the security configuration information of the server. BRIEF DESCRIPTION OF DRAWINGS

[0018] In order to more clearly illustrate the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments. Obviously, the drawings described in the following embodiments are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort based on these drawings.

[0019] Figure 1 The flowchart of the security configuration information updating method provided by the embodiments of the present application is shown in the figure. Figure 2 The structure diagram of the security configuration information updating device provided by the embodiments of the present application is shown in the figure. Figure 3 The architecture diagram of the security configuration information updating system provided by the embodiments of the present application is shown in the figure. Figure 4 The flowchart of the processing of the threat perception module provided by the embodiments of the present application is shown in the figure. Figure 5 The flowchart of the processing of the load adaptation module provided by the embodiments of the present application is shown in the figure. Figure 6 The flowchart of the processing of the control parameter optimization module provided by the embodiments of the present application is shown in the figure. Figure 7 The flowchart of the security configuration information updating method provided by the embodiments of the present application is shown in the figure. DETAILED DESCRIPTION

[0020] The technical solutions in the embodiments of the present application will be clearly and completely described in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative effort fall within the protection scope of the present application.

[0021] It should be noted that, in the description of the present application, the terms "comprise", "contain" or any other variant thereof are intended to cover non-exclusive inclusion, so that the process, method, article or equipment comprising a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or equipment. The terms "first", "second" and the like in the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence.

[0022] With the rapid development of server technology, dynamic security policy adjustment systems are increasingly important in enhancing server security and adapting to complex network environments. However, existing server architectures and functional designs still have many shortcomings in implementing dynamic security policy adjustments, making it difficult to fully meet the needs of modern data centers for efficient and intelligent security protection.

[0023] Two schemes for updating security configuration information in related technologies are briefly introduced below: The first scheme discloses a server that realizes hot-plug and blind-plug functions of node modules and PCIE devices by setting node supports and PCIE supports, thereby reducing the need for power-off during server maintenance and ensuring business continuity.

[0024] The second scheme discloses a server and a method for controlling its channel switch, which realizes testing and monitoring functions of I2C devices through the design of a baseboard management controller and a multi-channel switch, ensuring the stability and reliability of internal communication in the server.

[0025] In the above schemes, the following defects exist: The first scheme mainly focuses on the physical connection and maintenance convenience of hardware modules and does not involve the adjustment mechanism of server dynamic security policy. Its real-time security threat perception and dynamic response capabilities are limited, and it is difficult to flexibly adjust the security policy according to the actual running state when facing complex network security environments, which may limit the server's security protection capabilities.

[0026] The second scheme only focuses on the channel control and data monitoring of specific hardware devices and fails to provide dynamic adjustment support for the overall security policy of the server. Its security mechanism is relatively static and lacks the ability to integrate and respond to real-time threat intelligence. In the face of external attack behavior or internal abnormal state, it is difficult to dynamically adjust the security policy, which may exhibit low adaptability and protection effect in high-risk environments.

[0027] To solve the technical problems in related schemes, the threat assessment result of the server is obtained. According to the threat type and severity in the threat assessment result, the initial security policy parameters of the server are determined, which can accurately match the current threat and improve the pertinence and effectiveness of threat response. By introducing resource load weights to adapt the initial security policy parameters, the target security policy parameters of the server are determined, avoiding the deployment of high-overhead security measures in high-load scenarios, thereby ensuring business performance. The security configuration information of the server is updated according to the target security policy parameters, realizing the dynamic adjustment of the security configuration information of the server.

[0028] The security configuration information updating method provided by the embodiments of the present disclosure can be applied to cloud computing and data center security operation and maintenance, business system adaptive protection, edge computing and Internet of Things device security management, and the like. The execution subject of the method can be an intelligent network card or a security management platform, such as a security agent program deployed locally on a server.

[0029] In order for those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0030] Figure 1 A flowchart of a security configuration information updating method provided by an embodiment of the present disclosure.

[0031] As shown in Figure 1 The security configuration information updating method comprises the following steps: Step 101, obtaining a threat assessment result of a server; In some embodiments, the threat assessment result is a quantitative or qualitative judgment result of the security risks currently faced by the server, and at least includes a threat type and a severity level. The threat type can include a Distributed Denial of Service (DDoS) attack, malware, abnormal login, etc., and the severity level can be divided into high, medium and low, or can be divided into a score between 0 and 100.

[0032] In some embodiments, the threat assessment result can be obtained by analyzing the collected server running state data to identify whether there is an abnormal or attack behavior. The server running state data includes but is not limited to network traffic packets, system logs such as syslog, auditd logs, process lists, hardware monitoring indicators such as CPU temperature, fan speed, file access records, etc.

[0033] Step 102, determining initial security policy parameters of the server according to the threat type and the severity level in the threat assessment result; In some embodiments, the initial security policy parameters of the server are determined from a pre-set policy library according to the threat type and the severity level in the threat assessment result.

[0034] In some embodiments, the initial security policy parameters of the server can be determined from a pre-set policy library according to the threat type and the severity level in the threat assessment result.

[0035] Step 103, determining target security policy parameters of the server based on the initial security policy parameters and resource load weights of the server; In some embodiments, the resource load weight is a load adaptation factor determined based on current CPU usage, memory occupancy, disk I / O rate, and other resource consumption conditions of the server, reflecting a value of overall load pressure of the system, and used to adjust the strength or granularity of the security policy parameter.

[0036] In some embodiments, the target security policy parameter is a security policy parameter that is adapted and optimized based on the resource load, and used for updating the security configuration information.

[0037] In some embodiments, the initial security policy parameter is adapted, such as degraded, throttled, delayed execution, or enhanced, such as full detection, real-time blocking, in combination with the current system load status, to generate a final executable optimized policy, and then the target security policy parameter of the server is determined.

[0038] For example, if the resource load weight is greater than 0.8, the log recording frequency in the initial security policy parameter is reduced from 100% to 30%.

[0039] In step 104, the security configuration information of the server is updated according to the target security policy parameter.

[0040] In some embodiments, the security configuration information is all software and hardware settings on the server that affect its security status, including but not limited to firewall rules, access control lists, user permissions, service start / stop status, encryption policies, log levels, network bandwidth limits, and other information.

[0041] In some embodiments, the target security policy parameter can be converted into specific configuration instructions and executed through an operating system or hardware interface to update the security configuration information of the server, such as calling the iptables command of Linux to update the firewall in the security configuration information.

[0042] In some embodiments, the security configuration information at the hardware level can also be directly modified through a baseboard management controller or an intelligent network card firmware interface.

[0043] By obtaining the threat assessment result of the server, and determining the initial security policy parameter of the server according to the threat type and severity in the threat assessment result, the current threat can be accurately matched, and the pertinence and effectiveness of threat response can be improved. By introducing the resource load weight to adapt the initial security policy parameter, the target security policy parameter of the server is determined, which avoids deploying high-overhead security measures in a high-load scenario, thereby ensuring business performance. According to the target security policy parameter, the security configuration information of the server is updated to dynamically adjust the security configuration information of the server.

[0044] In some embodiments, the threat assessment result of the server is obtained, including: The running state data of the server is obtained. In some embodiments, the running state data of the server is raw data generated by the server during operation, reflecting its current working state. It includes the aforementioned network traffic packets, system logs such as syslog, auditd logs, process lists, hardware monitoring indicators such as CPU temperature, fan speed, file access records, etc.

[0045] In some embodiments, the running state data of the server can be obtained by reading network statistics, memory or log information, or by pulling CPU, memory, disk and other performance counters from the remote server through the standard management protocol.

[0046] Feature extraction is performed on the running state data to obtain feature vector data of the server. In some embodiments, deep learning models can be used for anomaly detection on feature vector data, or rule-based methods related to anomaly detection can be used for anomaly detection on feature vector data. Among them, the deep learning model can be isolated forest, autoencoder, etc. The target anomaly score represents the numerical result of the degree of current running state anomaly. The higher the value of the target anomaly score, the more likely it is to be attacked or fail.

[0047] Anomaly detection is performed on the feature vector data to obtain a target anomaly score corresponding to the running state data. In response to the target anomaly score being not less than an anomaly score threshold, a threat assessment result of the server is determined according to the target anomaly score.

[0048] In some embodiments, feature extraction on running state data refers to the process of extracting features with discriminative and representative characteristics from running state data. Feature vector data is a numerical vector obtained after feature extraction, used to represent the running state of the server at a certain time or period, such as an average packet length of 1500, a CPU usage rate of 75%, etc.

[0049] In some embodiments, the anomaly score threshold is a pre-set critical value. When the target anomaly score is greater than the threshold, it is determined that there is an effective threat in the server, and a threat assessment result needs to be generated, otherwise it is considered as normal fluctuation.

[0050] In some embodiments, the mapping relationship between the target anomaly score and the threat can be determined. For example, a target anomaly score less than 60 corresponds to no threat; a target anomaly score between 60 and 80 corresponds to medium risk; and a target anomaly score greater than 80 corresponds to high risk.

[0051] In some embodiments, the feature vector data is subjected to anomaly detection to obtain a target anomaly score corresponding to the running state data, comprising: determining the window size and step length of the sliding window; In some embodiments, the sliding window refers to sliding forward at a certain interval on the data stream by a fixed-length window, and each time a continuous data segment is intercepted for analysis. The window size refers to the number of data points or time length covered by the sliding window, such as 10 seconds or 100 samples. The step length of the sliding window refers to the distance the window advances each time.

[0052] In some embodiments, the window size and step length of the sliding window can be pre-configured or automatically adjusted according to the current network traffic rate. When the traffic rate is high, the window size is increased to smooth the noise. When the traffic rate is low, the window size is reduced to improve sensitivity.

[0053] The feature vector data is segmented based on the window size and step length to obtain a plurality of local vector data of the server; In some embodiments, the local vector data is a feature sub-sequence representing the running state of the server in a short period of time obtained after segmentation by the sliding window.

[0054] The feature vector data and the local vector data are subjected to anomaly detection to obtain a first anomaly score and a plurality of second anomaly scores corresponding to the running state data; According to the first anomaly score and the plurality of second anomaly scores, a target anomaly score corresponding to the running state data is determined.

[0055] In some embodiments, the first anomaly score is the score obtained by anomaly detection on the entire feature vector data, reflecting long-term or overall abnormal trends. The second anomaly score is the score obtained by anomaly detection on each local vector data. There are multiple second anomaly scores, which are used to capture short-term sudden anomalies such as instantaneous DDoS pulses.

[0056] In some embodiments, the target anomaly score is the final anomaly score obtained by combining the first anomaly score and the plurality of second anomaly scores, taking into account global stability and local suddenness, and is more robust and sensitive.

[0057] In some embodiments, the first anomaly score and the plurality of second anomaly scores are weighted and summed to obtain the target anomaly score. The weight can be an empirical value or dynamically adjusted according to actual conditions.

[0058] In some embodiments, the same anomaly detection model can be used to perform anomaly detection on the feature vector data and the local vector data respectively, to obtain the first anomaly score and the plurality of second anomaly scores corresponding to the running state data, and the anomaly detection model is a deep learning model such as Isolation Forest. Different structures of anomaly detection models can also be used to perform anomaly detection on the feature vector data and the local vector data to obtain the first anomaly score and the plurality of second anomaly scores corresponding to the running state data.

[0059] In some embodiments, the window size and the step size of the sliding window are determined, the feature vector data is segmented based on the window size and the step size to obtain a plurality of local vector data of the server, anomaly detection is performed on the feature vector data and the local vector data to obtain the first anomaly score and the plurality of second anomaly scores corresponding to the running state data, and the target anomaly score corresponding to the running state data is determined according to the first anomaly score and the plurality of second anomaly scores. The stability of the global trend and the sensitivity of the local mutation can be effectively combined, and the detection capability for slow penetration attacks or intermittent abnormal behaviors can be improved.

[0060] In some embodiments, the initial security policy parameters of the server are determined according to the threat type and the severity in the threat assessment result, including: The candidate security policy parameters of the server are determined according to the threat type and the severity in the threat assessment result. In some embodiments, the threat type refers to the specific category of a security event, which is used to distinguish the nature of an attack or abnormal behavior. For example, distributed denial of service, malware, illegal access, etc. The severity refers to the quantitative evaluation of the potential harm of a threat, which is usually divided into three levels of high, medium and low, or represented by a value of 0-100. It reflects the possibility of damage to the availability, integrity or confidentiality of the server.

[0061] In some embodiments, the candidate security policy parameters can be one or more sets of security policy parameter sets that may be applicable, which are preliminarily screened from a preset policy library according to the current threat type and severity. Or it can be predicted by a machine learning model, such as the threat assessment result being a threat type WebShell upload and a high severity, determining the candidate security policy parameters of the server to block HTTP POST large files, isolate the Web directory, and enable file integrity monitoring.

[0062] The priority of the plurality of parameters in the candidate security policy parameters is sorted from high to low to obtain the initial security policy parameters of the server.

[0063] In some embodiments, the priority refers to the importance and urgency of each security policy parameter when executed, and a high-priority policy should be deployed first because it is more critical to contain threats or has lower execution cost. The initial security policy parameter is a security policy parameter that has been prioritized, representing the order in which the policy should be executed in an ideal state.

[0064] In some embodiments, a fixed priority can be bound to each security policy parameter in the preset policy library, such as 1 to 10, and the priority is read directly during prioritization, such as a priority of 9 for blocking malicious Internet Protocol (IP) and a priority of 3 for logging.

[0065] In some embodiments, the candidate security policy parameters of the server are determined according to the threat type and severity in the threat assessment result; the priorities of multiple parameters in the candidate security policy parameters are sorted in descending order to obtain the initial security policy parameters of the server. Multiple policies may act on the same resource, such as limiting IP and closing port at the same time. The priority mechanism ensures that high-value policies take effect and low-value policies are suppressed or delayed, avoiding policy conflicts and redundancy, and ensuring that the most critical security measures are prioritized and executed.

[0066] In some embodiments, before determining the target security policy parameters of the server based on the initial security policy parameters and the resource load weight of the server, the security configuration information updating method comprises: Obtaining the resource load condition in the server, the resource load condition at least including the usage rate of the processor, the occupancy rate of the memory and the read-write rate of the disk; In some embodiments, the resource load condition in the server refers to the usage state of the current hardware resources of the server, which is used to reflect the system running pressure. The resource load condition in the server can be obtained in real time by calling the hardware monitoring interface of the operating system, such as the proc file system, or can be obtained by hardware sensor driver acquisition.

[0067] According to the type of business carried by the server, determining the weight corresponding to the usage rate of the processor, the occupancy rate of the memory and the read-write rate of the disk, respectively; In some embodiments, the type of business carried by the server refers to the application or service category carried by the server, and different businesses have different sensitivities to resources. For example, web services belong to CPU-intensive type, databases belong to I / O-intensive type, and cache services belong to memory-intensive type.

[0068] In some embodiments, according to the type of service carried by the server, the weights corresponding to the processor usage, memory occupancy and disk read-write rate are determined, including: the weights corresponding to the processor usage, memory occupancy and disk read-write rate can be determined according to the preset mapping relationship between the type of service and the weights, or the weights corresponding to the processor usage, memory occupancy and disk read-write rate can be obtained by training a machine model such as support vector machine or random forest according to the historical resource usage mode.

[0069] Based on the processor usage, memory occupancy and disk read-write rate and the weights, the resource load weight of the server is determined.

[0070] In some embodiments, the resource load weight of the server is a value calculated by weighting the processor usage, memory occupancy and disk read-write rate and their corresponding weights, which is used to quantify the overall load pressure of the server at present.

[0071] In some embodiments, by obtaining the resource load situation in the server, the resource load situation at least includes the processor usage, memory occupancy and disk read-write rate; according to the type of service carried by the server, the weights corresponding to the processor usage, memory occupancy and disk read-write rate are determined; based on the processor usage, memory occupancy and disk read-write rate and the weights, the resource load weight of the server is determined, and the weights corresponding to the type of service are introduced to dynamically allocate, so that the evaluation of the resource load is more in line with the actual business scenario, and a more accurate load basis is provided for the adaptation of the security policy.

[0072] In some embodiments, based on the initial security policy parameters and the resource load weight of the server, the target security policy parameters of the server are determined, including: Based on the initial security policy parameters and the resource load weight, the adapted security policy parameters are determined. In some embodiments, the adapted security policy parameters are the preliminary adjustment results obtained by combining the initial security policy parameters and the resource load weight. For example, reducing the log frequency, limiting the number of concurrent detection threads, etc. under high load.

[0073] In some embodiments, based on the initial security policy parameters and the resource load weight, the adapted security policy parameters can be determined by using linear scaling, or can be determined according to the strategy grading mapping method, i.e. each strategy is preset with multiple grades including high, medium and low, and the adapted security policy parameters are automatically switched according to the resource load weight. For example, the initial security policy parameters are: log level = DEBUG, concurrent scanning threads = 10, and the resource load weight Lf is 0.85, and the adapted security policy parameters are obtained, i.e. the log level is ERROR and the concurrent scanning threads are 2.

[0074] The adapted security policy parameters are optimized by using a target algorithm to obtain target security policy parameters of the server, and the target algorithm is a swarm intelligence optimization algorithm.

[0075] In some embodiments, the swarm intelligence optimization algorithm can be one or a combination of algorithms such as a genetic algorithm, a particle swarm optimization, an ant colony algorithm, and the like, and the target security policy parameters are final security policy parameters optimized by the swarm intelligence algorithm.

[0076] In some embodiments, the optimization of the adapted security policy parameters by using the target algorithm refers to taking the adapted policy parameters as initial solutions, searching for better solutions in the policy space by the swarm intelligence algorithm, and the target is to maximize the security benefit and minimize the performance loss, so as to finally obtain the target security policy parameters.

[0077] In some embodiments, the adapted security policy parameters are determined based on the initial security policy parameters and the resource load weight, and the adapted security policy parameters are optimized by using the target algorithm to obtain the target security policy parameters of the server, and the target algorithm is a swarm intelligence optimization algorithm, which can automatically find a near-optimal configuration scheme under complex security and performance constraints, thereby improving the scientificity and effectiveness of the adjustment of the security policy parameters.

[0078] In some embodiments, before updating the security configuration information of the server according to the target security policy parameters, the security configuration information updating method comprises: checking the target security policy parameters to obtain a checking result corresponding to the target security policy parameters; in response to the checking result meeting a target checking condition, converting the target security policy parameters into a parameter update instruction; updating the security configuration information of the server according to the target security policy parameters, comprising: updating the security configuration information of the server according to the parameter update instruction.

[0079] In some embodiments, the checking of the target security policy parameters refers to checking the target security policy parameters in terms of legality, security, compatibility, and the like, to ensure that they can be safely deployed on the server. The checking result is usually a Boolean value, pass, fail, or structured information containing error codes.

[0080] In some embodiments, the target checking condition is a preset checking pass standard, such as the parameters being within the allowed range, not conflicting with existing configurations, meeting the operating system security policy, and the like.

[0081] In some embodiments, the target security policy parameters are converted into parameter update instructions to translate abstract security policy parameters into specific commands or configuration instructions recognizable and executable by the operating system or hardware.

[0082] In some embodiments, the target security policy parameters can be converted into parameter update instructions by using a predefined instruction template such as Jinja2, or by a compiler.

[0083] In some embodiments, the generated instructions are actually issued and applied to the hardware and software components of the server to update the security configuration information of the server. Specifically, the security configuration information of the server can be updated through container / K8s policy injection or through command line execution.

[0084] In some embodiments, before performing the security configuration update, the target security policy parameters are checked and converted, and the consistency of the optimized target security policy parameters is checked. The checking content includes but is not limited to checking whether the parameter value is within the range allowed by the server hardware specifications, such as whether the number of firewall rules exceeds the chip entry limit, and whether the parameter logic is compatible with the current operating system version and installed security software. The checking result is used to determine whether it meets the preset target checking condition, i.e., no conflict and executable. Only when the checking result meets the condition, the target security policy parameters are converted into specific parameter update instruction sequences recognizable by the underlying hardware or operating system driver according to the predefined instruction mapping rule. Finally, the security configuration information of the server is updated according to the parameter update instructions, rather than the original policy parameters, such as updating the firewall rules by calling the iptables command or updating the mandatory access control policy by configuring the selinux policy module.

[0085] In some embodiments, by updating the security configuration information of the server according to the parameter update instructions, the system instability or security function failure caused by parameter errors or incompatibility is effectively prevented, and the reliability and security of the update operation are ensured.

[0086] In some embodiments, after updating the security configuration information of the server according to the target security policy parameters, the security configuration information updating method comprises: obtaining the health condition of the server, the health condition at least including the running stability condition, the response speed and the security condition; in response to the health condition not meeting the target health condition, obtaining the update times of the security configuration information of the server; In response to the number of times of updating the security configuration information being less than the target number of times of updating, a target security policy parameter is updated, and the security configuration information of the server is adjusted based on the updated target security policy parameter.

[0087] In some embodiments, the health status of the server is used to comprehensively evaluate a set of indicators of the overall running state of the server after the security configuration is updated. The running stability can be determined according to whether the server frequently crashes, services are interrupted, or processes crash; the response speed can be determined according to performance indicators such as request processing delay, throughput, and Application Programming Interface (API) response time; and the security status can be determined according to indicators such as whether there are still threats, whether the policy is effective, and whether there are new abnormal behaviors.

[0088] In some embodiments, the health status of the server can be obtained by using an external monitoring system, or by using a security agent, or by using a log analysis platform.

[0089] In some embodiments, the number of times of updating the security configuration information refers to the cumulative number of times of adjusting the security configuration of the server since the current threat response started, and the target number of times of updating is a preset maximum allowed number of adjustments, such as 6 times, which is a hard boundary condition for exiting the feedback adjustment.

[0090] In some embodiments, the number of times of updating the security configuration information of the server can be obtained from a database or a local file.

[0091] In some embodiments, updating the target security policy parameter refers to modifying the policy parameter when the current policy does not achieve the expected effect, such as enhancing / weakening the intensity, and generating a new round of security policy parameters.

[0092] In some embodiments, updating the target security policy parameter includes: determining an update step of the target security policy parameter based on the health status; updating the target security policy parameter according to the update step.

[0093] In some embodiments, the update step of the target security policy parameter is the magnitude or increment of each change when adjusting the target security policy parameter, which determines whether the policy adjustment is fine-tuning or significant change. The step size can be a fixed value, an adaptive value, or a value dynamically calculated by the health status, such as using a small step size for cautious adjustment if the health status deteriorates seriously, or using a more precise step size to approach the optimum if the target is close.

[0094] In some embodiments, by deploying performance probes and security sensors, indicators reflecting server health conditions are continuously obtained, and the health conditions are compared with preset target health conditions. If the measured conditions do not meet the target requirements, the system queries the number of updates of security configuration information in the current strategy adjustment period. If the number of updates is less than the preset target number of updates, a strategy parameter fine-tuning mechanism is triggered. The fine-tuning mechanism quantitatively determines the update step of the target security strategy parameter based on the gap between the current health condition and the target value. For example, if the response delay is too high, the depth of flow inspection is adjusted downward by a smaller step. The target security strategy parameter is finely adjusted according to the update step. Finally, based on the fine-tuned target security strategy parameter, the security configuration information of the server is adjusted again to gradually approach the optimal configuration, thereby improving the final effect of security policy adjustment and the robustness of the system.

[0095] In summary, the scheme provided by the present disclosure has the following advantages: By obtaining the threat assessment result of the server, and determining the initial security strategy parameter of the server according to the threat type and severity in the threat assessment result, the current threat can be accurately matched, and the pertinence and effectiveness of threat response can be improved. By introducing the resource load weight to adapt the initial security strategy parameter, the target security strategy parameter of the server is determined, which avoids deploying high-overhead security measures in a high-load scenario, thereby ensuring business performance. The security configuration information of the server is updated according to the target security strategy parameter, and the security configuration information of the server is dynamically adjusted.

[0096] To implement the security configuration information updating method provided by the embodiments of the present disclosure, the embodiments of the present disclosure further provide a security configuration information updating device, as shown in Figure 2 The security configuration information updating device provided by the embodiments of the present disclosure has the following advantages: Figure 2 A structural schematic diagram of the security configuration information updating device provided by the embodiments of the present disclosure is shown in FIG. 2. The security configuration information updating device 200 comprises: An obtaining unit 201, configured to obtain a threat assessment result of a server; A first determining unit 202, configured to determine an initial security strategy parameter of the server according to a threat type and severity in the threat assessment result; A second determining unit 203, configured to determine a target security strategy parameter of the server based on the initial security strategy parameter and a resource load weight of the server; An updating unit 204, configured to update security configuration information of the server according to the target security strategy parameter.

[0097] In an embodiment, the obtaining unit 201 is specifically configured to: Obtain running state data of the server; Perform feature extraction on the running state data to obtain feature vector data of the server; The feature vector data is subjected to anomaly detection to obtain a target anomaly score corresponding to the running state data; In response to the target anomaly score being not less than an anomaly score threshold, a threat assessment result of the server is determined according to the target anomaly score.

[0098] In an embodiment, the obtaining unit 201 is specifically configured to: determine a window size and a step length of the sliding window; segment the feature vector data based on the window size and the step length to obtain a plurality of local vector data of the server; subject the feature vector data and the local vector data to anomaly detection to obtain a first anomaly score corresponding to the running state data and a plurality of second anomaly scores; determine a target anomaly score corresponding to the running state data according to the first anomaly score and the plurality of second anomaly scores.

[0099] In an embodiment, the first determining unit 202 is specifically configured to: determine candidate security policy parameters of the server according to the threat type and the severity in the threat assessment result; sort priorities of a plurality of parameters in the candidate security policy parameters in descending order to obtain initial security policy parameters of the server.

[0100] In an embodiment, the first determining unit 202 is specifically configured to: obtain resource load conditions in the server, the resource load conditions at least including a usage rate of a processor, an occupancy rate of a memory, and a read-write rate of a disk; determine weights corresponding to the usage rate of the processor, the occupancy rate of the memory, and the read-write rate of the disk respectively according to a business type carried by the server; determine a resource load weight of the server based on the usage rate of the processor, the occupancy rate of the memory, and the read-write rate of the disk and the weights.

[0101] In an embodiment, the second determining unit 203 is specifically configured to: determine adapted security policy parameters based on the initial security policy parameters and the resource load weight; perform optimization processing on the adapted security policy parameters by using a target algorithm to obtain target security policy parameters of the server, the target algorithm being a swarm intelligence optimization algorithm.

[0102] In an embodiment, the security configuration information updating apparatus 200 further includes a conversion unit configured to: perform verification processing on the target security policy parameters to obtain a verification result corresponding to the target security policy parameters; In response to the check result meeting the target check condition, the target security policy parameter is converted into a parameter update instruction; In an embodiment, the updating unit 204 is specifically configured to: update the security configuration information of the server according to the parameter update instruction.

[0103] In an embodiment, the updating unit 204 is specifically configured to: obtain the health condition of the server, the health condition at least including a running stability condition, a response speed, and a security condition; in response to the health condition not meeting the target health condition, obtain an update frequency of the security configuration information of the server; in response to the update frequency of the security configuration information being less than a target update frequency, update the target security policy parameter, and adjust the security configuration information of the server based on the updated target security policy parameter.

[0104] In an embodiment, the updating unit 204 is specifically configured to: determine an update step of the target security policy parameter based on the health condition; update the target security policy parameter according to the update step.

[0105] It should be noted that the foregoing explanation and description of the method embodiments are also applicable to the device of the present embodiment, and the principles are the same, which will not be limited herein in the present embodiment.

[0106] The features of the embodiments corresponding to the security configuration information updating device can be seen from the related description of the embodiments corresponding to the security configuration information updating method, which will not be repeated herein.

[0107] The present disclosure provides a security configuration information updating system, such as Figure 3As shown, including threat perception module 1, policy generation module 2, load adaptation module 3, control parameter optimization module 4 and execution module 5, work together to realize the dynamic adjustment of server security policy. Specifically, the threat perception module 1 is the core data input end of the whole system, which includes a multi-source data acquisition unit 6 and an abnormal behavior analysis unit 7. The multi-source data acquisition unit 6 is responsible for collecting network traffic data, system log data and hardware monitoring data from the server running environment. These data are transmitted to the abnormal behavior analysis unit 7 for further processing. The abnormal behavior analysis unit 7 first performs feature extraction on the collected data, extracts the key features that can reflect the server running state, and converts these features into a feature vector sequence. Subsequently, a deep learning model 9 is used to detect anomalies in the feature vector sequence. In this process, the weight parameters of the deep learning model 9 are initialized, and the feature vector sequence is input into the model to obtain a preliminary anomaly score. In order to improve the detection accuracy, the sliding window technique is used to segment the feature vector sequence, calculate the local anomaly score of each segment, and weight the local anomaly score and the preliminary anomaly score to obtain the final anomaly score. The final anomaly score is compared with the preset anomaly score threshold, if it exceeds the threshold, it is determined that there is a potential threat and a threat assessment result is generated. The threat assessment result is then output to the policy generation module 2; the policy generation module 2 receives the threat assessment result from the threat perception module 1, and based on the result, matches the corresponding initial security policy parameters from the preset policy library. The preset policy library contains multiple security policy templates, each template corresponds to different threat types and severity. The policy generation module 2 selects the most appropriate strategy template according to the threat assessment result, and generates the corresponding initial security policy parameters. In order to ensure the efficiency of subsequent processing, the policy generation module 2 prioritizes the initial security policy parameters and generates a priority queue. The initial security policy parameters in the priority queue are then output to the load adaptation module 3; the load adaptation module 3 obtains the current resource load state of the server through the hardware monitoring interface 8, including CPU usage C, memory occupancy M and disk I / O rate D. The load adaptation module 3 calculates the load adaptation factor based on the above resource load state using the weighted average algorithm, that is, the aforementioned resource load weight Lf. The calculation formula of the load adaptation factor Lf is where and are the corresponding weight coefficients, and satisfy. The weight coefficients are set according to the actual application scenario and resource importance of the server, for example, in network-intensive applications, the value of can be appropriately increased to increase the weight of CPU usage. The calculated load adaptation factor Lf is combined with the initial security policy parameters to generate the adapted security policy parameters. The adapted security policy parameters are then output to the control parameter optimization module 4; the control parameter optimization module 4 receives the adapted security policy parameters output by the load adaptation module 3, and optimizes them based on the genetic algorithm 10.The genetic algorithm 10 simulates the natural selection process to find the optimal solution by encoding, crossing, mutating, etc. the security policy parameters. In this process, the control parameter optimization module 4 performs consistency check on the optimized security policy parameters to ensure that these parameters meet the compatibility requirements of the server hardware and software. The content of the consistency check includes checking whether the parameters exceed the hardware performance limit, whether they conflict with the operating system interface specification, etc. The security policy parameters that pass the consistency check are converted into execution instructions and output to the execution module 5; the execution module 5 includes a hardware interface unit and a software driver unit, which respectively communicate with the server hardware components through the physical bus and interact with the server software components through the operating system interface. The execution module 5 adjusts the security configuration of the server according to the optimized security policy parameters. For example, at the hardware level, the hardware interface unit may adjust the firewall rules or modify the bandwidth limit of the network interface; at the software level, the software driver unit may update the access control list or enable specific security services. After completing the security configuration adjustment, the system verifies the effectiveness of the adjusted security configuration. The verification process includes testing the running stability, response speed and security indicators of the server under the new configuration to see if they meet the preset standards. If the verification result does not meet the preset standards and the maximum adjustment times have not been reached, the control parameter optimization module 4 fine-tunes the security policy parameters based on the verification result and returns the execution module 5 to re-execute the adjustment process. If the verification result meets the preset standards or the maximum adjustment times have been reached, the current security policy adjustment task is completed.

[0108] As shown in Figure 4 , the processing flow of the threat perception module 1 consists of multiple steps. The multi-source data acquisition unit 6 first acquires network traffic data, system log data and hardware monitoring data, and transmits these data to the abnormal behavior analysis unit 7. The abnormal behavior analysis unit 7 extracts features from the data, extracts key features and generates a feature vector sequence. Then, the deep learning model 9 performs anomaly detection on the feature vector sequence, generates a preliminary anomaly score, segments the feature vector sequence by sliding window technology, calculates the local anomaly score of each segment, and sums the local anomaly score and the preliminary anomaly score to obtain the final anomaly score. The final anomaly score is compared with the preset threshold value, and if it exceeds the threshold value, it is determined that there is a potential threat and a threat assessment result is generated.

[0109] As shown in Figure 5 , the processing flow of the load adaptation module 3 includes three main steps of resource load state acquisition, load adaptation factor calculation and adapted security policy parameter generation. The hardware monitoring interface 8 acquires the current CPU usage C, memory occupancy M and disk I / O rate D of the server, and transmits these data to the load adaptation module 3. The load adaptation module 3 calculates the load adaptation factor based on the weighted average algorithm, and combines Lf with the initial security policy parameters to generate the adapted security policy parameters.

[0110] As shown in Figure 6 the processing flow of the control parameter optimization module 4 includes two main steps of security policy parameter optimization based on the genetic algorithm 10 and consistency verification, the genetic algorithm 10 finds the optimal solution by encoding, crossing, mutating and other operations on the security policy parameters, and then performs consistency verification on the optimized security policy parameters to ensure that they meet the compatibility requirements of the server hardware and software.

[0111] As shown in Figure 7 the overall flow of the server dynamic security policy adjustment method includes multiple steps from threat assessment to security configuration adjustment and effectiveness verification, the threat perception module 1 generates a threat assessment result, the policy generation module 2 generates initial security policy parameters, the load adaptation module 3 generates adapted security policy parameters, the control parameter optimization module 4 generates optimized security policy parameters, and the execution module 5 adjusts the security configuration of the server according to the optimized security policy parameters and verifies the adjustment result. If the verification result does not meet the preset standard and the maximum adjustment number is not reached, the control parameter optimization module 4 is returned to fine-tune the parameters and re-execute the adjustment process.

[0112] Embodiments of the present application also provide an electronic device comprising a memory and a processor, the memory storing a computer program, and the processor being configured to run the computer program to perform the steps in any of the above security configuration information updating method embodiments.

[0113] Embodiments of the present application also provide a computer readable storage medium storing a computer program, wherein the computer program is configured to perform the steps in any of the above security configuration information updating method embodiments when running.

[0114] In an example embodiment, the above computer readable storage medium can include, but is not limited to, a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic or optical disk, and various media that can store computer programs.

[0115] Embodiments of the present application also provide a computer program product comprising a computer program, the computer program being executed by a processor to implement the steps in any of the above security configuration information updating method embodiments.

[0116] The embodiment of the present application further provides another computer program product, comprising a nonvolatile computer readable storage medium, the nonvolatile computer readable storage medium storing a computer program, the computer program being executed by a processor to implement the steps in any of the above security configuration information updating method embodiments.

[0117] Those skilled in the art will further appreciate that the units and algorithm steps of the examples described in connection with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, various components have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends on the particular application and design constraints imposed on the overall system. Skilled persons can implement the described functionality in varying ways for each particular application, but such implementation does not depart from the scope of the present application.

[0118] The above has introduced in detail a security configuration information updating method and an electronic device provided by the present application. The principles and implementation manners of the present application are described herein by applying specific examples, and the above description of the embodiments is only for helping to understand the method of the present application and its core idea. It should be noted that, for those skilled in the art, some improvements and modifications can be made to the present application without departing from the principles of the present application, and these improvements and modifications also fall within the protection scope of the claims of the present application.

Claims

1. A method for updating security configuration information, characterized in that, include: Obtain the threat assessment results for the server; Based on the threat type and severity in the threat assessment results, determine the initial security policy parameters for the server; Based on the initial security policy parameters and the server's resource load weight, the target security policy parameters for the server are determined. Update the server's security configuration information according to the target security policy parameters.

2. The security configuration information update method according to claim 1, characterized in that, The threat assessment results obtained from the server include: Obtain server running status data; Feature extraction is performed on the running status data to obtain the feature vector data of the server; Anomaly detection is performed on the feature vector data to obtain a target anomaly score corresponding to the running status data; In response to the target anomaly score being not less than the anomaly score threshold, the threat assessment result of the server is determined based on the target anomaly score.

3. The security configuration information update method according to claim 2, characterized in that, The step of performing anomaly detection on the feature vector data to obtain a target anomaly score corresponding to the running status data includes: Determine the window size and step size of the sliding window; The feature vector data is segmented based on the window size and stride to obtain multiple local vector data of the server. Anomaly detection is performed on the feature vector data and the local vector data to obtain a first anomaly score and multiple second anomaly scores corresponding to the running status data; Based on the first anomaly score and the plurality of second anomaly scores, a target anomaly score corresponding to the running status data is determined.

4. The security configuration information update method according to claim 1, characterized in that, The step of determining the initial security policy parameters of the server based on the threat type and severity in the threat assessment results includes: Based on the threat type and severity in the threat assessment results, candidate security policy parameters for the server are determined; The initial security policy parameters of the server are obtained by sorting the priority of multiple parameters in the candidate security policy parameters from high to low.

5. The security configuration information update method according to claim 1, characterized in that, Before determining the target security policy parameters of the server based on the initial security policy parameters and the server's resource load weight, the method includes: Obtain the resource load information of the server, which includes at least the processor utilization rate, memory usage rate, and disk read / write speed; Based on the type of service carried by the server, determine the weights corresponding to the processor utilization, memory usage, and disk read / write speed, respectively. The resource load weight of the server is determined based on the processor utilization, memory occupancy, disk read / write speed, and the weights.

6. The security configuration information update method according to claim 1, characterized in that, The process of determining the target security policy parameters for the server based on the initial security policy parameters and the server's resource load weight includes: Based on the initial security policy parameters and the resource load weight, the adapted security policy parameters are determined; The adapted security policy parameters are optimized using a target algorithm to obtain the target security policy parameters for the server. The target algorithm is a swarm intelligence optimization algorithm.

7. The security configuration information update method according to claim 1, characterized in that, Before updating the server's security configuration information according to the target security policy parameters, the method includes: The target security policy parameters are verified to obtain a verification result corresponding to the target security policy parameters. In response to the verification result meeting the target verification conditions, the target security policy parameters are converted into parameter update instructions; The step of updating the server's security configuration information according to the target security policy parameters includes: Update the server's security configuration information according to the parameter update command.

8. The security configuration information update method according to claim 1, characterized in that, After updating the server's security configuration information according to the target security policy parameters, the method includes: Obtain the health status of the server, which includes at least its operational stability, response speed, and security status. In response to the health status not meeting the target health status, the number of times the server's security configuration information has been updated is obtained; In response to the fact that the number of updates to the security configuration information is less than the target number of updates, the target security policy parameters are updated, and the security configuration information of the server is adjusted based on the updated target security policy parameters.

9. The security configuration information update method according to claim 8, characterized in that, The updating of the target security policy parameters includes: Based on the health status, determine the update step size of the target security policy parameters; Update the target security policy parameters according to the specified update step size.

10. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the security configuration information update method according to any one of claims 1-9.

Citation Information

Patent Citations

  • Network security dynamic defense method and device based on edge computing

    CN119182571A

  • Method and device for configuring firewall of baseboard management controller, and medium

    CN120151081A

  • Dual-channel anomaly detection method and system based on local entropy and isolated forest

    CN120873918A

  • Method and system for automatically executing network security policy based on artificial intelligence large model

    CN121056220A

  • Threat index based WLAN security and quality of service

    US20190021004A1