Social engineering adaptive dynamic protection method based on post risk assessment

By constructing a knowledge graph and risk baseline model for power positions, and combining multimodal feature fusion and real-time anomaly detection, personalized safety control rules are generated. This solves the problem of poor generalization of existing power grid industry protection measures and enables dynamic risk assessment and personalized protection of employee behavior.

CN121581618APending Publication Date: 2026-02-27ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511466897.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-14
Publication Date
2026-02-27

AI Technical Summary

Technical Problem

Existing technologies lack dynamic evolution modeling capabilities, cross-modal correlation identification capabilities, and personalized security strategy recommendations in the power grid industry, making it difficult to cope with complex social engineering attacks, resulting in poor generalization and weak response capabilities of protection measures.

Method used

An adaptive dynamic protection method based on job risk assessment is adopted. By constructing a knowledge graph of power jobs, establishing a job risk baseline model, and designing a job-specific feature extractor, multimodal feature fusion and real-time anomaly detection are achieved, generating personalized safety control rules.

Benefits of technology

It enables dynamic risk assessment and personalized protection of employee behavior, improves the safety resilience and defense intelligence level of the power grid system, and can accurately identify potential risks and generate efficient protection strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121581618A_ABST
    Figure CN121581618A_ABST
Patent Text Reader

Abstract

The invention discloses a social engineering self-adaptive dynamic protection method based on post risk assessment, relates to the technical field of network security, and solves the problem that in the prior art, the aspects of employee security awareness modeling, multi-modal data fusion and personalized security policy recommendation still have obvious deficiencies. The method comprises the following steps: firstly, constructing an electric power post knowledge graph, and carrying out structured modeling on four entities of posts, permissions, assets and vulnerabilities and association relationships thereof to form a global semantic network; secondly, a post risk baseline model is established, a normal behavior mode is defined by quantifying inherent risks of posts and analyzing historical operation logs, and a static and dynamic combined risk reference is formed; and finally, designing a post exclusive feature extractor, fusing personal behavior data of the employees with semantic constraints and risk baselines of the knowledge graph, and generating highly personalized feature vectors, thereby laying a foundation for subsequent real-time monitoring of abnormal behaviors of the employees, quantification of safety consciousness and providing of differentiated protection.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and particularly relates to a social engineering adaptive dynamic protection method based on post risk assessment. BACKGROUND

[0002] With the rapid development of digital power grids, the network security protection system of the power industry gradually evolves from traditional physical isolation and rule control to an active defense mechanism based on personnel behavior and situation awareness. The operation behavior of core posts such as power grid dispatching, equipment operation and maintenance, and remote control has become an important breakthrough for network attackers. In particular, under the background of frequent attacks such as social engineering attacks, supply chain attacks and disguised instructions, the safety awareness level of employees has a key influence on the overall system security.

[0003] At present, the existing technology mainly adopts a safety awareness evaluation method based on a static scoring mechanism. Generally, according to indicators such as the violation record, login frequency or training score of employees, a fixed safety scoring model is constructed. This kind of method can reflect the long-term performance of employees to some extent, but it generally ignores the characteristics of the evolution of safety awareness over time, and cannot depict the periodic influence of factors such as periodic training, work fatigue and high-pressure dispatching on employee alertness. In addition, these methods usually rely on structured operation log data and lack the ability to identify unstructured signals such as employee physiological state and psychological changes, making it difficult to accurately capture potential emotional abnormalities and induced risks.

[0004] Some existing technical solutions attempt to introduce deep learning-based behavior modeling methods, such as using recurrent neural networks (RNN) or long short-term memory networks (LSTM) to analyze employee operation sequences and predict the probability of abnormal behavior. Some research also explores joint modeling of operation behavior and physiological signals (such as heart rate and skin galvanic response), but often only involves simple splicing at the data level, lacking the ability to model cross-temporal alignment and implicit causal relationships between multiple modalities, which can easily cause data fusion bias. In addition, existing methods generally use a unified safety strategy, lacking personalized protection mechanisms and post-attack adaptation strategies. In particular, in scenarios where post samples are sparse and new attacks are frequent, the generalization of protection measures is poor, the response ability is weak, and it is difficult to form an efficient closed-loop security defense system.

[0005] In summary, the existing technology still has obvious deficiencies in employee safety awareness modeling, multi-modal data fusion and personalized safety strategy recommendation, and it is difficult to meet the complex security threat situation faced by the current power grid industry. Therefore, there is an urgent need for a new technical solution that has dynamic evolution modeling capability, cross-modal correlation recognition capability and post adaptation recommendation capability to improve the security resilience and defense intelligence level of the overall power grid system. SUMMARY

[0006] In view of the obvious deficiencies in the modeling of employee safety awareness, multi-modal data fusion and personalized safety strategy recommendation in the prior art, which are difficult to meet the complex security threat situation faced by the current power grid industry, the present application provides a social engineering adaptive dynamic protection method based on post risk assessment, which can form a complete protection closed loop of "safety awareness quantification-risk calculation-decision recommendation" through a three-stage progressive technical solution, and the three-stage technology forms a layer-by-layer deepening protection chain: spatiotemporal modeling reveals the evolution law of safety awareness, providing a dynamic baseline for the system; multi-modal fusion expands the evaluation dimension, accurately identifies hidden risks; and post feature analysis converts abstract risks into executable defense strategies. The specific technical solution is as follows: A social engineering adaptive dynamic protection method based on post risk assessment, comprising the following steps: Construction of power post portrait and risk benchmark modeling based on multi-modal feature fusion: according to post information, access strategy, asset list and historical operation data, a directed heterogeneous graph is constructed, risk scores are calculated according to the heterogeneous graph, an employee post risk baseline model is constructed, post exclusive features are extracted, and a post portrait is made; Real-time monitoring and abnormal evaluation of post behavior based on multi-modal time series analysis: multi-modal feature fusion is performed on the collected operation logs, access data and context information, the fused features are mapped into the post baseline model, it is judged whether it is abnormal operation, and the dynamic risk score is calculated; Adaptive dynamic protection strategy generation and optimization for social engineering attacks: based on the real-time dynamic risk score of the post and the post portrait feature vector, an executable safety control rule set is output.

[0007] Preferably, the process of obtaining the dynamic risk score is as follows: Message passing is performed on the post knowledge graph G = (V, E) to obtain the context vector and is fused with ; is input into the time series model for reconstruction or prediction to obtain the fitting error, wherein is the context-enhanced representation; The original score is calculated, specifically as follows: wherein is the reconstruction error score, is the prediction error score; According to the extracted context vector related to the current user / post, the Figure One ​The consistency score is used to verify, as shown below: wherein, is the context vector or its reduced dimension representation; , is the mean and covariance of the historical context vector; is a scalar, representing the degree of deviation of the current context from the historical distribution; The three scores , , are normalized and fused to obtain the final comprehensive anomaly score, as shown below: wherein, represents the normalized score of the j class, represents the fusion weight; Finally, the dynamic risk score function is defined, as follows: ; wherein, is the normalized comprehensive anomaly score; is the post-specific feature; , is the weight coefficient.

[0008] Preferably, the acquisition process of the executable security control rule set is as follows: By defining a risk-policy mapping function, a preliminary protection policy set is obtained, as shown below: wherein, represents the user's real-time risk score; represents the post portrait feature vector; represents the normal baseline behavior model output probability sequence of the employee; represents the mapping function; A strategy weight mechanism is introduced to output a weighted dynamic strategy set; The weighted strategy set is normalized, as shown below: ; When there is a conflict, if the two strategies are mutually exclusive, the strategy with a higher score is selected for execution; if they can be combined, a composite strategy is generated through:

[0009] Preferably, the strategy weight is based on the user's real-time risk score, and the higher the user's real-time risk score, the lower the strategy weight.

[0010] ​A computer readable storage medium comprising a stored program, wherein the computer readable storage medium is caused to perform the social engineering adaptive dynamic protection method based on post risk assessment as described above when the program is run.

[0011] A processor for running a program, wherein the processor is caused to perform the social engineering adaptive dynamic protection method based on post risk assessment as described above when the program is run.

[0012] Compared with the prior art, the present application has the following beneficial effects: The present application establishes a dynamic risk portrait for each employee post through a three-stage process: first, a power post knowledge graph is constructed, four types of entities, i.e., posts, permissions, assets and vulnerabilities, and their associated relationships are structured modeled to form a global semantic network; second, a post risk baseline model is established, the inherent risk of the post (such as permission sensitivity and risk exposure) is quantified, and historical operation logs are analyzed to define normal behavior patterns, forming a risk benchmark that combines static and dynamic; finally, a post-specific feature extractor is designed, the employee's personal behavior data is fused with the semantic constraints of the knowledge graph and the risk baseline, and a highly personalized feature vector is generated, thereby laying a foundation for subsequent real-time monitoring of employee behavior anomalies, quantifying safety awareness and providing differentiated protection. BRIEF DESCRIPTION OF DRAWINGS

[0013] In order to more clearly illustrate the specific embodiments of the present application or the technical solutions in the prior art, the drawings needed in the specific embodiments or prior art description will be briefly introduced below. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, the elements or parts are not necessarily drawn according to the actual proportions.

[0014] Figure 1 A diagram for inherent risk scoring for each post; Figure 2 A ROC curve graph for complete model anomaly detection; Figure 3 A diagram for the influence of model components on performance in ablation experiments; Figure 4 A diagram for comparison of anomaly detection performance of different models; Figure 5 A diagram for inherent risk scoring for each post; Figure 6 A ROC curve diagram; Figure 7 An ablation experiment diagram; Figure 8 A ROC curve diagram in model comparison; Figure 9Figure 1 is a schematic diagram of the overall process architecture of the present application; Figure 10 Figure 4 is a flowchart of the power post portrait construction and risk benchmark modeling process based on multi-modal feature fusion; Figure 11 Figure 5 is a flowchart of the real-time monitoring and abnormality evaluation of post behavior based on time series analysis; Figure 12 Figure 6 is a flowchart of the adaptive dynamic protection strategy generation and optimization for social engineering attacks; Figure 13 Figure 7 is a flowchart of the overall method of the present application. DETAILED DESCRIPTION

[0015] In one embodiment of the present application, a social engineering adaptive dynamic protection method based on post risk assessment is provided.

[0016] As shown in Figure 9 , Figure 13 , the complete implementation process is as follows: Phase 1: Power post risk benchmark modeling based on multi-modal feature fusion, as shown in Figure 10 : This phase aims to build an intelligent protection framework for social engineering attacks on power systems. The core is to establish a dynamic risk portrait for each employee post through a three-stage process. First, a power post knowledge graph is constructed to structurally model four types of entities, namely posts, permissions, assets, and vulnerabilities, and their associated relationships, forming a global semantic network. Second, a post risk baseline model is established to define normal behavior patterns by quantifying the inherent risks of the post (such as permission sensitivity and risk exposure) and analyzing historical operation logs, forming a static and dynamic combined risk benchmark. Finally, a post-specific feature extractor is designed to integrate employee personal behavior data with semantic constraints from the knowledge graph and risk baseline, generating highly personalized feature vectors, thereby laying the foundation for subsequent real-time monitoring of employee behavior anomalies, quantifying safety awareness, and providing differentiated protection.

[0017] 1.1 Construction of power post knowledge graph In the power system, different posts have complex relationships with the permissions, operation objects, and potential vulnerabilities they involve. It is difficult to fully depict the risk characteristics of the post relying solely on traditional text descriptions or access control lists. Therefore, this phase studies the use of knowledge graphs to structurally model four types of entities, namely posts, permissions, assets, and vulnerabilities, and their relationships, thereby forming a power post knowledge graph, providing semantic support and data-level support for subsequent risk baseline modeling and behavior monitoring.

[0018] The input data for constructing the power position knowledge graph includes the following four types: position responsibility specification, which describes the skills and responsibilities required for the employee's position; access control policy, which contains the mapping relationship between employee positions and position permissions; system asset list, which describes the type and importance of assets; and vulnerability library data, which contains known vulnerability information corresponding to assets. Constructing the power position knowledge graph can be preliminarily formalized as a directed heterogeneous graph, and the specific construction formula is as follows: (1) where, : Node set, including position node , permission node , asset node , and vulnerability node . : Edge set, representing the relationship between nodes (i.e., entities). : Relationship type set, mainly including the following relationships: position-permission relationship : Position requirement for permission; permission-asset relationship : Accessible assets corresponding to permission; asset-vulnerability relationship : Asset-related vulnerability information.

[0019] To achieve unified expression of multi-modal information of power employees, different types of data need to be pre-processed, and the processed data needs to be unified into a vector format and then embedded into the same vector space. The vector representation of the position node is obtained from the power position responsibility specification text, and the obtaining method is as follows: (2) where, : Vector representation of the position . : Text encoding function based on pre-trained language BERT model.

[0020] The vector representations of the permission node , asset node , and vulnerability node are mapped from the access control policy, asset attributes, and vulnerability library data, respectively, and the specific formula is as follows: (3) (4) (5) Then, the vectors obtained from the above four types of data are embedded into the corresponding nodes of the graph, and the entire graph structure is modeled through a graph neural network, and the specific formula is as follows: (6) in, : No. l Layer Time Node i The vector representation of . :node i The set of neighboring nodes. : No. l Layer weight matrix. : ReLU activation function.

[0021] Through the above technical process, a knowledge graph of power industry positions is finally obtained, providing semantic and data support for the subsequent modeling of job risk baselines and monitoring of employee behavior.

[0022] 1.2 Job Risk Baseline Model Building In the context of social engineering attacks on power systems, profiling power system employees' job roles relies not only on their historical operational behaviors but also on in-depth analysis of the correlation between job roles and permissions, assets, and vulnerabilities. This allows for a more accurate baseline modeling of the risk of power system employees' job roles in the context of social engineering attacks. A power job knowledge graph provides a globally structured representation of employee roles and external system resources, while the employee job risk baseline model characterizes the inherent risks of employee roles through temporal behavior modeling and risk quantification. These two can be coupled through graph constraints and risk mapping to achieve a comprehensive and in-depth risk characterization and security protection against social engineering attacks on power systems.

[0023] The power industry job knowledge graph provides contextual constraints on employee roles in terms of permissions, assets, and vulnerabilities through a structured representation of nodes and edges. Specifically, the following mapping relationships exist: Job-permission mapping: The "job-permission" relationship in the knowledge graph is used to calculate the permission sensitivity of a job. The specific formula for calculating permission sensitivity is as follows: (7) in, This represents the set of permission vectors possessed by a job position. The permission-asset-vulnerability link mapping associates job positions with assets through permissions, which in turn map to potential vulnerabilities, thus affecting risk exposure. The specific formula for calculating risk exposure is as follows: (8) in, This represents the set of asset vectors accessible to the position. This represents the set of vulnerability vectors existing on asset a. This indicates the risk level of vulnerability v. The job-organizational structure relationship mapping uses organizational hierarchy edges in the knowledge graph to calculate business impact. The specific formula for calculating business impact is as follows: , represents the position of the post in the organizational structure, represents a business impact mapping function, for example, the weight of a core scheduling post is higher than that of a general maintenance post.

[0024] For the modeling of the power system employee post risk baseline model, the permission sensitivity, risk exposure and business impact calculated above can be used for joint calculation, and then the employee post risk score is obtained, and the calculation formula is as follows: (9) For the processing of the employee's historical operation log, the high probability operation sequence of the post under normal conditions is obtained by modeling the time sequence behavior, so as to realize the full description of the typical behavior mode of the post. The specific process is as follows: First, the historical operation log L of the post is sequenced, and the log of a certain post is represented as: (10) wherein, represents the specific operation behavior of the post at time step t, and T is the length of the historical log sequence. Then the behavior sequence is modeled by using the time sequence convolution network, and the modeling formula is as follows: (11) wherein, the behavior hidden vector of the post at time step t. The benchmark high probability operation distribution of the employee post can be represented as: (12) wherein, represents the operation probability distribution of the post under the benchmark model.

[0025] Through the above technical process, the time sequence behavior benchmark sequence distribution of the normal operation of the employee and the employee post risk score can be obtained. The risk baseline model of the post can be jointly represented by the time sequence behavior distribution and the post risk score, and the specific formula is as follows: (13) wherein, is the risk baseline model of the post; is the normal behavior sequence distribution of the post; is the inherent risk score of the post.

[0026] The risk baseline model of the post not only describes the behavior dynamic characteristics of the post, but also provides a static risk benchmark value, which provides a basis for comparison for subsequent real-time anomaly detection.

[0027] 1.3 Post-specific feature extraction After constructing the power post knowledge graph and the post risk baseline model, in order to realize the differentiated modeling of different post employees in the face of social engineering attacks, it is necessary to design a post-specific feature extractor for extracting the exclusive features of different post employees. The goal of this module is to extract the multi-dimensional features highly related to the post role from the input set In the graph relationship, multi-dimensional features highly related to the post role are extracted to support subsequent dynamic security awareness quantification and risk prediction.

[0028] Employee Belonging to the post , the original input set is defined as: (14) Where, represents the behavior or environmental feature vector related to the post (such as operation log features, email interaction features, safety training history, etc.), d is the dimension of a single feature vector.

[0029] In order to reflect the characteristics of the post, the input set needs to be mapped to the post-specific feature space using the adjacency information and attribute information of the nodes in the post knowledge graph. The mapping function is defined as: (15) Where, represents the exclusive feature matrix of employee u in post p , m is the number of extracted features, d′ is the dimension of the transformed features.

[0030] Post-specific features not only come from the employee's own behavior input set, but also are constrained by the topological relationship between posts and the risk baseline. The adjacency set of the post node is: (16) The aggregation of post features can be represented as: (17) Where, represents the attribute vector of the post node ; represents the attribute vector of the adjacent post node ; represents the feature transformation weight matrix; represents the ReLU activation function; represents the hidden representation of the post role, which is used to constrain the post-specific feature extraction of the employee.

[0031] Finally, according to the above calculation results, the post-specific feature extraction output calculation formula is: (18) wherein, represents the post-specific feature vector of the employee under the post; represents the feature matrix extracted based on the input set; is the post graph hidden representation, reflecting the semantic constraints between posts; is the post risk baseline, which guides the bias direction of feature extraction as a regularization term; is the feature fusion function, which uses weighted splicing and multi-layer perception (MLP) to achieve.

[0032] Post-specific features can be passed as input to the employee real-time behavior monitoring and abnormal behavior detection model in stage two, which is used to calculate the employee's safety awareness level and attack risk exposure in the current post environment. Through this mechanism, the safety awareness evolution model has the ability of post differentiation and dynamic adaptation, which can realize the unified modeling of post role semantics-risk baseline-personal behavior features.

[0033] 2. Real-time monitoring and abnormal assessment of post behavior based on time series analysis The first stage has constructed the employee post portrait, and this paper starts from the "post" to form a safety risk baseline that is more universal and portable than "single user". It breaks through the limitation of existing methods that rely only on single-source data. Therefore, in this stage, based on the post portrait, real-time multi-modal behavior perception, abnormal detection and dynamic risk scoring of users in the organization are realized, and the detection results are fed back as executable protection strategies. As shown in Figure 11 , the specific steps are as follows: 2.1 Real-time multi-modal data collection and feature fusion In this stage, real-time multi-modal data generated by users are collected and processed. According to the research content of this study, the collected multi-modal data are operation log stream, access request stream and context information. Among them, the operation log stream mainly includes command execution, system call, data access record, etc., the access request stream includes resource access frequency, cross-system jump path, etc., and the context information refers to device identifier, geographic location, access time, network environment, etc.

[0034] Then the collected multi-modal data are timestamped and sorted, and the context risk factors are estimated by the large model according to the importance of the device to the user, which are used as a feature to construct the event stream . For each event stream, the category field is one-hot processed, the numerical field is normalized, and the time period feature is used sin / cosEncoding. The operation log, access request stream and context information are respectively statistically aggregated in time sequence to generate feature vectors of each modality. Let t Below, the data of different modalities are respectively represented as: (19) wherein, M denotes the number of modalities, denotes the feature vector of the t th modality collected at time m , such as operation command vector, network request feature, context environment variable, etc.

[0035] After obtaining the feature data of three modalities at different times, linear projection and fusion are needed to map the multi-modal features to a unified representation space.

[0036] (20) wherein, denotes the fusion feature at time t ; denotes the projection matrix of the m th modality, used to map the original feature to the public space; denotes the input feature of the t th modality at time m ; b : bias term; denotes a nonlinear activation function, such as ReLU or tanh.

[0037] Through linear projection and fusion, the fusion feature can be obtained, but the present research is aimed at real-time behavior monitoring of employees in different scenarios, and the influence of different modalities in different scenarios is different. Therefore, the attention mechanism is introduced to dynamically allocate the weight of each modality feature on this basis. The attention weight m of the th modality reflects its importance to the overall risk judgment. The calculation formula is as follows: (21) wherein, denotes the attention weight of the m th modality, reflecting its importance to the overall risk judgment; q denotes the query vector generated from the fusion feature at the current time; denotes the key vector of the m th modality; denotes the feature vector of the m th modality after projection.

[0038] Through this mechanism, the system can adaptively learn the contribution of different modalities in different scenarios, rather than using fixed weights. The relative reliable fusion features are obtained .

[0039] 2.2 Position baseline feature mapping After obtaining the real-time behavior fusion features of the employee, in order to judge whether the employee's real-time behavior is abnormal behavior, it is necessary to perform semantic alignment with the position portrait and compare the position baseline model for judgment.

[0040] On the basis of the position baseline prototype set , the following formula can be used: (22) (23) wherein represents the position baseline prototype set, segment—structure, including position responsibility text embedding (BERT) , permission vector, historical behavior prototype (cluster center), graph embedding (node2vec / GNN) , etc. K: The number of prototypes can be the number of key features of the position (such as the number of permission items and responsibility phrases), typically 10-200, adjusted according to the complexity of the position. : a linear projection matrix for cross-attention, (real-time fusion representation) and (position prototype) are projected into the same comparison space.

[0041] Through this projection, the real-time behavior fusion feature can be mapped into the position baseline space, and the matching degree between it and the position prototype is calculated. Among them is located between 0 and 1, indicating the semantic matching degree of the current behavior with the position prototype. If is too high, and represents "access to core data", indicating that the current behavior has a high permission risk. And is the behavior representation after the position. Its result is a set of vectors, whose semantics have been projected into the position baseline space, used for subsequent deviation calculation to detect abnormal behavior. This method not only ensures that the real-time behavior is aligned with the historical mode, but also consistent with the semantic consistency of the position responsibilities.

[0042] 2.3 Abnormal detection model construction For abnormal behavior, this study refers to all behavior representations with high deviation from the baseline model as abnormal behavior. In order to improve the context sensitivity of abnormal recognition, this study decides to do graph neural context enhancement method on the position knowledge graph.

[0043] On the position knowledge graphG = (V, E) Message passing to obtain context vector and fusion: (24) (25) (26) (27) where, : Post knowledge graph, node types include post, permission, system, data object, etc. Edges represent access, membership or dependency relationships. By segment - by access control list, organizational structure, system topology, etc. : Graph adjacency matrix; I is the identity matrix. D: Diagonal matrix, . : Normalized adjacency matrix, used to stabilize GCN training / inference and avoid numerical explosion. : Node initial feature matrix, each node feature can be text embedding, static importance, etc. : Graph embedding dimension. : Parameter matrix of the l-th layer of GCN. : GCN layer number, typically 2-4 layers. : Activation function ReLU. : Readout extracts the context vector related to the current user / post from . : Context-enhanced representation, obtained by concatenating and and linear transformation to get , .

[0044] In order to capture the time dependence and periodicity of abnormal behavior, time series modeling is performed to calculate the deviation degree. Abnormal behavior involves time continuity and spatial similarity. Since the encoder cannot directly extract global spatio-temporal information from raw observation data, especially features from metadata (such as log key nodes), based on this, this study introduces a spatio-temporal embedding network to focus on generating embedding features with globality and prior information from metadata, so as to better capture the overall spatio-temporal distribution trend of abnormal behavior, while reducing the impact of key position noise. The formula is as follows: Input into the time series model for reconstruction or prediction to obtain the fitting error: (28) where, , the reconstruction / prediction loss can be defined as mean square error: (29) or prediction formula: (30) where, : contextual augmentation vector for formula (27) as a temporal input. : L-th layer convolution output (TCN) with input from L-1-th layer output; final output used to generate (reconstruction) or (prediction). : k-th convolution parameter (including input / output channels) for L-th layer, shape determined by implementation. : convolution kernel width (kernel size). : dilation factor (dilation) for l-th layer, often exponentially increasing to expand receptive field. , : reconstruction / prediction output of temporal model. , : training loss (MSE) to optimize model parameters when offline or online fine-tuning. : number of samples or time steps for loss averaging.

[0045] The spatio-temporal embedding network contains two parts, time embedding and space embedding. The time embedding is captured based on the information from the metadata, while the space embedding is captured by an adaptive graph convolutional network. The two are spliced to obtain the spatio-temporal embedding of the employee's abnormal behavior in the continuous frame. In addition, this study uses causal convolution to ensure that the inference does not use future information.

[0046] Finally, the original score is calculated according to the formula (31) (32) , where is the reconstruction error score, is the prediction error score, both of which are scalars, and the larger the value indicates that the current behavior is less explainable by historical normal patterns, suspected abnormal behavior. In order to be able to accurately distinguish, according to the extracted context vector related to the current user / post, the Figure One consistency score is used to verify, the formula is as follows: (33) where, : context vector or its reduced dimension representation. , : mean and covariance of historical context vectors (grouped by post / department). : scalar, Mahalanobis distance measures the deviation of current context from the historical distribution (considering the covariance structure).

[0047] Finally, normalize and fuse the three scores 、 、 to get the final comprehensive anomaly score.

[0048] (34) where is the normalized score of the j th class (rec / pred / g) . is the fusion weight, which is trained by labeled data. The final result is the final fused anomaly score, the larger the value, the higher the possibility of abnormal operation.

[0049] 2.4 Dynamic risk score and early warning Finally, define the dynamic risk score function: (35) where : normalized comprehensive anomaly score. : post-specific features (stage one output). : contextual risk factors (uncommon equipment, unusual time period, external IP, etc.), define rules or estimate with models in advance and normalize. , , : weight coefficients (non-negative and sum to 1), reflecting the importance of real-time deviation, inherent risk of the post, and context. Recommended initial value: (give more importance to immediate abnormality); can be optimized through historical labels.

[0050] The dynamic risk score is calculated by weighting, and different thresholds are set to trigger different levels of response. Finally, the dynamic combination of "post baseline risk" and "real-time deviation" is achieved, so that risk quantification not only considers the inherent sensitivity of the post, but also has real-time dynamic response capability.

[0051] 3. Adaptive dynamic defense strategy generation for social engineering attacks On the basis of the power position image, risk baseline model and real-time anomaly detection capability constructed in the first two stages, the third stage aims to realize the generation and adaptive protection of risk-driven dynamic security strategies under social engineering attacks. By combining real-time risk scores with position semantic information, the system can automatically generate and dynamically adjust access control, operation restriction and authentication strategies, and realize active and accurate interception of potential social engineering attacks. This stage aims to build a "perception-decision-execution-feedback" integrated closed loop for social engineering attack identification and protection, with the ability to continuously optimize and adapt to the evolution of social engineering attacks.

[0052] As shown in Figure 12 , the goal of this stage is to establish a dynamic protection strategy generation system based on real-time dynamic risk scores and position image feature vectors , output executable security control rule sets , and realize the automatic mapping from risk perception to strategy execution. The system architecture includes the following modules: strategy mapping module, which maps dynamic risk scores and position images to a preliminary strategy set; strategy weighting module, which dynamically adjusts strategy strength and priority according to risk level; strategy execution module, which implements protection strategies in access control, operation audit and authentication processes.

[0053] 3.1 Strategy mapping module By defining the risk-strategy mapping function, a preliminary protection strategy set can be obtained: (36) where, represents the real-time risk score of the user output in stage two; represents the position image feature vector constructed in stage one, including permission sensitivity, business impact, risk exposure, etc.; represents the probability sequence output by the normal baseline behavior model of employees, including typical operation sequences and behavior distribution; represents the mapping function, which is realized by combining rule base and reinforcement learning model.

[0054] After this module technical operation process, the preliminary social engineering attack protection strategy rule set is generated. It is used for further optimization in the strategy weighting module to adapt to different social engineering attack scenarios.

[0055] 3.2 Strategy weighting module In order to make the social engineering attack protection strategy rule set generated by the previous module adapt to different social engineering attack risk situations and better cope with attacks, a strategy weight mechanism is introduced: (37) where, To the candidate policy library Y The first policy in the policy library; The policy weight is calculated by the following formula: (38) The policy weight adjustment example is as follows: low risk ( <0.3): ω 日志 ≈0.8,ω 认证 ≈0.2; high risk ( >0.7) ω 权限限制 ≈0.6, ω 多因子 ≈0.4.

[0056] 3.3 Policy execution module The policy execution module aims to convert the weighted dynamic policy set output by the policy weighting module: , into implementable security control actions, and to realize conflict and priority coordination, business impact control, and execution result monitoring and feedback in the actual execution process. This module is a key link in the "perception-decision-execution-feedback" closed loop. Its design goals include: ensuring the standardization and consistency of policy actions; resolving conflicts between policies and reasonably ordering them; implementing policy security delivery through cross-system adapters; providing idempotency and transaction rollback mechanisms to reduce execution risk; and outputting a quantifiable execution feedback vector to provide optimization signals for subsequent feedback learning.

[0057] Before execution, the weighted policy set needs to be normalized to ensure that it can be uniformly parsed and issued by different systems. The normalization process is defined as: (39) Each normalized policy can be represented as a five-tuple: (40) Where a represents the action type (such as permission revocation, multi-factor authentication), o represents the execution object, c represents the constraint condition, τ represents the effective time window or policy level, and r represents the rollback information. Through this normalization step, a structured policy set can be generated under the premise that the post portrait vector and the baseline behavior sequence are legal.

[0058] In the policy set, different policies may act on the same object and produce conflicts. To solve this problem, a comprehensive priority score is introduced: (41) Where is the baseline priority, Risk-driven weights, Job sensitivity.

[0059] When there is a conflict, if the two strategies are mutually exclusive, the strategy with a higher score is selected for execution; if they can be combined, a composite strategy is generated through: to ensure the coherence of the system execution logic.

[0060] 4. Experimental verification The first stage experiment simulates the generation of knowledge graph data (post-privilege-asset-vulnerability relationship) and employee historical operation sequence for 5 power positions (dispatcher P0, operation and maintenance engineer P1, information security officer P2, customer service representative P3, and database administrator P4). The complete model is used for training to obtain the inherent risk score of each position and the anomaly detection model.

[0061] The first stage experiment outputs the inherent risk score of each position, calculates the anomaly score of the model on the test set (including normal and abnormal operation sequences), draws the ROC curve and calculates the AUC value. The results show that the risk scores of the dispatcher (P0) and the database administrator (P4) are the highest (>8.5), and the score of the customer service representative (P3) is the lowest (3.0). The results are consistent with the common sense of power system position risk; the ROC curve of the complete model is much higher than the diagonal line, and the AUC value reaches 0.95, indicating that the model has excellent ability to distinguish between normal and abnormal behavior; removing any key component will cause the AUC performance to decrease, w / o KG (remove the knowledge graph) performance decreases most significantly (AUC decreases to 0.82), proving the core importance of multi-modal information fusion, w / o TCN (remove the time series modeling) and w / o Risk Baseline performance also decreased significantly, proving the effectiveness of behavior sequence modeling and risk prior guidance; the ROC curve of the complete model (Our Full Model) proposed by us is closest to the upper left corner, and the AUC value is the highest, LSTM-Autoencoder and GNN-only deep learning methods are superior to traditional Isolation Forest, our model surpasses these baseline methods, proving that integrating knowledge graph, risk baseline, and time series behavior modeling is feasible and effective. The experimental results are shown in Figure 1-4 ​Due to the confidentiality of real power system operation data, the second stage experiment adopts a highly simulated simulation data generation strategy to build the Electric-Sec simulation dataset. The knowledge graph is constructed as follows: node types: post, employee, permission, system / asset (such as SCADA, DMS, customer service system), data table, vulnerability. Relationship types: affiliation (employee-post), possession (post-permission), accessibility (permission-asset), inclusion (asset-data table), existence (asset-vulnerability). Generation process: build different graph structures for 5 key posts (dispatcher P0, operation and maintenance engineer P1, information security officer P2, customer service representative P3, database administrator P4). For example, the dispatcher (P0) node is directly connected to the SCADA system, real-time control permission, and high-risk vulnerability node, while the customer service representative (P3) node is only connected to the customer service system and query permission. Operation sequence generation: generate 30-day operation sequences for each employee to simulate their normal operation behavior (such as dispatchers issuing instructions, and operation and maintenance personnel executing inspection scripts). Based on the post permission, inject pre-defined abnormal operation sequences (such as customer service representatives attempting to access the SCADA system, and operation and maintenance engineers bulk downloading data tables at non-working hours) as positive samples (abnormal samples).

[0062] The second stage experiment runs the complete model on the test set, calculates the AUC and draws the ROC curve, and the results show that the inherent risk scores of the database administrator (DBA, P4) and the dispatcher (P0) are the highest (9.1 and 8.7), and the risk score of the customer service representative (P3) is the lowest (3.0). The results are consistent with the consensus of power industry safety management, and the DBA and the dispatcher directly control the core system and data, with the highest inherent risk, proving the effectiveness of the post portrait in stage one; remove the KG, Risk Baseline, and TCN components to evaluate the degree of performance degradation. Removing the knowledge graph (w / o KG) results in the most severe performance degradation (AUC drops to 0.82), and removing TCN and Risk Baseline drops to 0.85 and 0.88, respectively. The multi-modal relationship information provided by the knowledge graph is the core of the model, and time series modeling and risk prior guidance are also key components to improve performance. Run all baseline methods and compare their performance with the complete model. Our complete model (AUC=0.95) significantly outperforms LSTM-Autoencoder (0.86), GNN-only (0.83), and IsolationForest (0.72), proving the success of the multi-modal fusion architecture, which organically combines time series behavior patterns, global relationship semantics, and post safety priors to achieve the best results. As shown in Figure 5-8

[0063] ​The core goal of the third stage experiment is to verify the performance of the proposed dynamic protection strategy generation system under different methods. The experiment mainly includes data and environment, the experimental data comes from the job behavior log and historical risk events, and the job portrait vector is extracted through feature engineering, including permission sensitivity, business impact, risk exposure and other dimensions, the risk baseline model comes from the output of stage two, including real-time risk score and baseline behavior distribution, the experimental environment is Python3.10, and the deep learning and machine learning framework uses TensorFlow 2.11 and Scikit-learn; Complete method: dynamic protection strategy generation system based on real-time dynamic risk score and portrait feature vector, using risk-strategy mapping, strategy weighting and conflict coordination mechanism, by comparing the complete method with logistic regression, support vector machine (SVM), random forest and other methods, the performance of different methods in protection strategy generation is comprehensively evaluated.

[0064] The experimental results show that the dynamic protection strategy generation system proposed in this paper is significantly better than traditional methods in dealing with social engineering attacks, not only can provide high-precision strategy recommendation, but also can balance real-time and system robustness, providing a feasible solution for social engineering security protection of power positions.

Claims

1. A social engineering adaptive dynamic protection method based on job risk assessment, characterized in that, Includes the following steps: Power Job Profile Construction and Risk Benchmark Modeling Based on Multimodal Feature Fusion: A directed heterogeneous graph is constructed based on job information, access strategies, asset lists, and historical operation data. Risk scores are calculated based on the heterogeneous graph, an employee job risk baseline model is constructed, and job-specific features are extracted to create a job profile. Real-time monitoring and anomaly assessment of job behavior based on multimodal time series analysis: Multimodal feature fusion is performed on the collected operation logs, access data and context information to be detected, and the fused features are mapped to the job baseline model to determine whether it is an abnormal operation and calculate dynamic risk score. Generate and optimize adaptive dynamic protection strategies against social engineering attacks: Based on real-time dynamic risk scores and job profile feature vectors, output a set of executable security control rules.

2. The social engineering adaptive dynamic protection method based on job risk assessment according to claim 1, characterized in that, The construction of power job profiles and risk benchmark modeling based on multimodal feature fusion includes the following steps: Construct a knowledge graph for power positions, and structurally model four types of entities—positions, permissions, assets, and vulnerabilities—and their relationships to form a global semantic network; Establish a job risk baseline model, define normal behavior patterns by quantifying the inherent risks of the job and analyzing historical operation logs, and form a risk benchmark that combines static and dynamic elements. The inherent risks include at least authority sensitivity and risk exposure. Design a job-specific feature extractor that integrates employee personal behavioral data with the semantic constraints and risk baseline of the knowledge graph to generate personalized feature vectors.

3. The social engineering adaptive dynamic protection method based on job risk assessment according to claim 1, characterized in that, The process of multimodal feature fusion is as follows: The collected multimodal data is timestamped, standardized, and sorted to construct an event stream. The operation logs, access request streams, and context information are statistically aggregated according to time series to generate feature vectors for each modality. calculate m Attention weights for each modality The fused features are obtained based on attention weights, and the calculation formula is as follows: in, Indicates the first m The attention weight of each modality reflects its importance to the overall risk assessment. q This represents the query vector, generated from the fused features at the current time. Indicates the first m The key vector of each modality; Indicates the first m The feature vectors of each mode after projection Indicates time t The fusion feature representation; Indicates the first m Projection matrix of each mode; Indicates time t The m Modal input features.

4. The social engineering adaptive dynamic protection method based on job risk assessment according to claim 1, characterized in that, The process of mapping the fused features to the job baseline model is as follows: In the job baseline prototype set Based on this, the following formula is adopted: in, This represents the set of baseline prototypes for job positions. K indicates Number of prototypes; All are linear projection matrices used for cross-attention; For real-time fusion representation; This is a prototype for the job position.

5. The social engineering adaptive dynamic protection method based on job risk assessment according to claim 1, characterized in that, The process of obtaining dynamic risk scores is as follows: Job knowledge graph G = (V, E) Message passing is performed to obtain the context vector. and Integration; Will The input time series model is reconstructed or predicted to obtain the fitting error, where, This is a context-enhanced representation; The raw score is calculated as follows: in, To score the reconstruction error, The prediction error score; The graph consistency score is recalculated based on the extracted context vectors related to the current user / position for verification, as shown below: in, It is a context vector or its reduced-dimensional representation; , The mean and covariance of the historical context vector; is a scalar representing the degree of deviation of the current context from the historical distribution; Three scoring methods , , After normalization and fusion, the final comprehensive anomaly score is obtained, as shown below: in, Indicates the first j The normalized score for the class. Indicates the fusion weights; Finally, the dynamic risk scoring function is defined as follows: ; in, The normalized composite anomaly score; Features specific to the job position; , These are the weighting coefficients.

6. The social engineering adaptive dynamic protection method based on job risk assessment according to claim 1, characterized in that, The process of obtaining the set of executable security control rules is as follows: By defining a risk-strategy mapping function, a preliminary set of protection strategies is obtained, as follows: in, This indicates the user's real-time risk score; Represents the feature vector of a job profile; This represents the probability sequence output by the employee's normal baseline behavior model; Represents a mapping function; Introduce a strategy weighting mechanism to output a weighted dynamic strategy set; The weighted strategy set is normalized and represented as follows: ; When a conflict exists, if the two strategies are mutually exclusive, the strategy with the higher score is selected for execution; if they can be combined, then: Generate composite strategies.

7. The social engineering adaptive dynamic protection method based on job risk assessment according to claim 6, characterized in that, The strategy weight is derived from the user's real-time risk score; the higher the user's real-time risk score, the lower the strategy weight.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored program, wherein, when the program is executed, it controls the device containing the computer-readable storage medium to perform the social engineering adaptive dynamic protection method based on job risk assessment as described in any one of claims 1 to 7.

9. A processor, characterized in that, The processor is used to run a program, wherein the program executes the social engineering adaptive dynamic protection method based on job risk assessment as described in any one of claims 1 to 7.

Citation Information

Cited By

  • Engineering supervision full-life-cycle digital management and control platform integrating multiple systems

    CN121920969A