Network security risk dynamic assessment and protection system based on multi-cascaded
By employing multi-cascaded data acquisition and preprocessing, dynamic data tracing graph construction, distributed security knowledge graph collaboration, and dynamic protection and closed-loop optimization modules, the problem of insufficient cross-module collaboration in network security assessment in existing technologies has been solved, enabling efficient risk assessment and precise protection for multi-cascaded architectures.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-30
- Publication Date
- 2026-04-07
AI Technical Summary
Existing network security risk dynamic assessment and protection systems lack deep cross-module collaboration mechanisms, making it difficult to adapt to the dynamic changes of multi-cascaded architectures. This results in one-sided risk assessment results, insufficient targeting and effectiveness of protection strategies, and an inability to fully defend against complex security threats.
By employing a multi-cascaded data acquisition and preprocessing module, a dynamic data traceability graph construction module, a distributed security knowledge graph collaboration module, and a dynamic protection and closed-loop optimization module, the system achieves closed-loop optimization of data traceability, knowledge collaboration, and protection strategies across the entire data chain. It also enhances the accuracy and consistency of data acquisition and knowledge synchronization through agentless technology, lightweight protocols, and authoritative cross-validation.
It significantly improves the dynamic adaptability and comprehensiveness of network security risk assessment, enhances the pertinence and dynamic optimization capabilities of protection strategies, solves the problems of data collection interference and low knowledge synchronization efficiency in existing technologies, and achieves accurate risk identification and protection for multi-cascaded network environments.
Smart Images

Figure CN121603310B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a multi-cascaded network security risk dynamic assessment and protection system. Background Technology
[0002] The dynamic risk assessment and protection system for cybersecurity provides dynamic and precise protection for cybersecurity. By adapting to changes in the network environment and new threats, it enables rapid identification and efficient prevention and control of risks, significantly reducing losses caused by cyberattacks. At the same time, it can continuously enhance the initiative and targeting of cybersecurity protection, help improve overall security protection capabilities, build a solid security barrier for the continuous and stable operation of network infrastructure, core data and various businesses, effectively avoid the interference of security risks on business operations, and ensure the security of the network ecosystem.
[0003] Currently, most network security risk dynamic assessment and protection systems rely on single-dimensional data for assessment, lacking deep cross-module collaboration mechanisms and failing to adapt to the dynamic changes of multi-cascaded architectures. Furthermore, they suffer from issues such as data collection easily interfering with the performance of business systems, low efficiency in knowledge synchronization between distributed nodes and inability to effectively resolve contradictions, risk assessments remaining at a superficial correlation analysis level, and generalized protection strategies lacking closed-loop optimization mechanisms. These problems result in one-sided risk assessment results, weak dynamic adaptability, insufficient targeting and effectiveness of protection strategies, and an inability to comprehensively defend against complex security threats in multi-cascaded network environments, making it difficult to ensure the continuous stability and security of network systems and core data.
[0004] Therefore, a multi-level network security risk dynamic assessment and protection system is proposed to solve the above problems. Summary of the Invention
[0005] The main objective of this invention is to provide a multi-cascaded dynamic network security risk assessment and protection system to address the problems mentioned in the background above.
[0006] To achieve the above objectives, the technical solution adopted by the present invention is as follows: a multi-level network security risk dynamic assessment and protection system, the system comprising a multi-level data acquisition and preprocessing module, a dynamic data tracing graph construction module, a distributed security knowledge graph collaboration module, a multi-level risk causal assessment module, and a dynamic protection and closed-loop optimization module;
[0007] The multi-cascaded data acquisition and preprocessing module is used to acquire the original data and security knowledge data of the entire data stream of each node in the multi-cascaded architecture, perform format unification, noise filtering and feature extraction on the acquired heterogeneous data, and output standardized data.
[0008] The dynamic data tracing map construction module is used to identify data entities and their relationships based on standardized data, generate initial tracing relationships, update the tracing map in real time, and perform multi-dimensional tracing path retrieval.
[0009] The distributed security knowledge graph collaboration module is used to transform unstructured security knowledge into structured knowledge units, synchronize knowledge units through a lightweight protocol, and detect and resolve knowledge contradictions between different nodes.
[0010] The multi-level risk causal assessment module is used to combine source mapping and structured knowledge to construct a structural causal model of risk propagation, and to identify core risk factors and cross-level propagation paths.
[0011] The dynamic protection and closed-loop optimization module is used to generate targeted protection strategies based on core factors and propagation paths, collect feedback data, and adjust model rules, graph update frequency, and strategy parameters.
[0012] Preferably, the multi-cascaded data acquisition and preprocessing module, when performing acquisition, is specifically used for:
[0013] Collect raw data from the entire data stream of each node using agentless technology;
[0014] Collect threat characteristics, vulnerability information, historical handling cases, and authoritative security rules for each node;
[0015] The original data and security knowledge data from the entire chain are aggregated to form a collected data set;
[0016] Perform format unification operation on heterogeneous data in the collected dataset, mapping different types of data to preset data specifications;
[0017] Perform noise filtering on the collected data after standardizing the format to remove abnormal data entries;
[0018] The noise-filtered collected data is subjected to feature extraction to extract key attribute information and output standardized data.
[0019] Preferably, the dynamic data tracing map construction module, when performing the identification of data entities and their relationships, is specifically used for:
[0020] Data entities are extracted from standardized data, and these data entities include data sources, data objects, processing components, and access subjects.
[0021] Identify the creation, transfer, transformation, and dependency relationships between data entities;
[0022] Based on data entities and their relationships, an initial tracing relationship is generated.
[0023] The entity information and relationships in the source map are updated in real time according to the preset update cycle and data change trigger conditions.
[0024] Preferably, the dynamic data tracing map construction module, when performing multi-dimensional tracing path retrieval, is specifically used for:
[0025] Set search criteria based on data object, time range, and node level;
[0026] Based on search criteria, the flow trajectory of target data is located in the source map, and the flow trajectory includes a sequence of association relationships between data entities;
[0027] Output source information, related data, and related node information of the target data to form multi-dimensional source tracing and retrieval results.
[0028] Preferably, when the distributed security knowledge graph collaboration module performs knowledge unit synchronization via a lightweight protocol, it is specifically used for:
[0029] Knowledge synchronization priority is determined based on node hierarchy, with core node knowledge units having higher synchronization priority than edge nodes.
[0030] Synchronization triggering conditions are set according to the update frequency of knowledge units. Knowledge units with high-frequency updates use real-time synchronization triggering, while knowledge units with low-frequency updates use timed synchronization triggering.
[0031] Based on synchronization priority and triggering conditions, structured knowledge units are transmitted from the initiating node to other associated nodes via a lightweight protocol;
[0032] During the synchronization process, the transmission status of knowledge units is recorded, and retry synchronization operations are performed on knowledge units that fail to be transmitted.
[0033] Preferably, when the distributed security knowledge graph collaboration module performs the detection and resolution of knowledge contradictions between different nodes, it is specifically used for:
[0034] Unstructured security knowledge is transformed into structured knowledge units through semantic parsing. The structured knowledge units include knowledge attributes, association identifiers, and source annotations.
[0035] Structured knowledge units are transmitted synchronously between nodes using a lightweight protocol.
[0036] Compare the inconsistent content in the knowledge units synchronized at different nodes;
[0037] Cross-validate inconsistent content using an authoritative database;
[0038] The verified unified statement is synchronized to all nodes to resolve knowledge contradictions.
[0039] Preferably, the multi-level risk causality assessment module, when executing the construction of a structural causal model for risk propagation, is specifically used for:
[0040] The trajectory data of the source map is associated and mapped with structured knowledge to establish the correspondence between trajectory data and knowledge units;
[0041] Establish causal relationship rules for risk propagation, wherein the rules include entity association types and risk transmission conditions;
[0042] Based on the correspondence between trajectory data and knowledge units and the causal association rules, a structural causal model is constructed.
[0043] Preferably, the multi-level risk causality assessment module, when identifying core risk factors and cross-level propagation paths, is specifically used for:
[0044] Based on structural causal models, correlations that meet preset thresholds are screened to identify core risk factors;
[0045] Tracing the initial triggering node of risk based on a structural causal model;
[0046] Tracing the risk diffusion chain along the correlation of the source map, and marking the key transfer nodes and core data objects in the diffusion chain;
[0047] Integrate the initial trigger node, key transfer node, core data objects and related relationships to form a cross-level propagation path and an affected list.
[0048] Preferably, when the dynamic protection and closed-loop optimization module generates a targeted protection strategy, it is specifically used for:
[0049] Call the preset protection strategy library, which contains protection rules corresponding to different risk types, core factors and propagation paths;
[0050] Based on the identified core risk factors and cross-level propagation paths, match the corresponding protection rules in the protection strategy library;
[0051] Bind the matched protection rules to the affected data and nodes in the affected list;
[0052] The bound protection rules are distributed to the corresponding nodes for execution according to the node hierarchy, generating targeted protection strategies.
[0053] Preferably, when the dynamic protection and closed-loop optimization module executes adjustments to model rules, graph update frequency, and strategy parameters, it is specifically used for:
[0054] Collect feedback data after the targeted protection strategy is executed. The feedback data includes threat interception records, business operation status data, and node resource usage data.
[0055] Analyze the feedback data to extract threat interception rate, business operation adaptability, and resource utilization.
[0056] Based on the extracted threat interception rate, business operation adaptability, and resource utilization, the weight of causal association rules, the update interval of the source map, and the execution threshold parameters of the protection strategy are adjusted.
[0057] The present invention has the following beneficial effects:
[0058] 1. This invention constructs an integrated collaborative architecture encompassing multi-level data acquisition and preprocessing, dynamic data tracing graph construction, distributed security knowledge graph collaboration, multi-level risk causal assessment, and dynamic protection and closed-loop optimization. It deeply integrates end-to-end data tracing capabilities and distributed security knowledge collaboration mechanisms into the risk causal assessment process. Furthermore, it continuously optimizes system operating parameters through a closed-loop feedback loop. Compared to existing technologies, this significantly improves the dynamic adaptability of network security risk assessment to multi-level architectures and the comprehensiveness of assessment results. Therefore, it addresses the problems of existing network security assessments, which largely rely on single-dimensional data, lack deep cross-module collaboration, and struggle to adapt to dynamic changes in multi-level architectures.
[0059] 2. This invention achieves low-interference acquisition of heterogeneous data and consistent synchronization of distributed secure knowledge in a multi-cascaded architecture by employing agentless data acquisition technology, a differentiated knowledge synchronization mechanism based on node hierarchy and update frequency, and an authoritative cross-validation method for resolving knowledge contradictions. Compared with existing technologies, it can improve the business compatibility of data acquisition and the timeliness and accuracy of knowledge synchronization. Therefore, it can solve the problems in existing technologies where data acquisition easily causes performance interference to business systems, the efficiency of knowledge synchronization between distributed nodes is low, and knowledge contradictions cannot be effectively resolved.
[0060] 3. This invention constructs a structural causal model of risk propagation by combining source tracing trajectory data with structured security knowledge, accurately identifying core risk drivers and cross-level propagation paths, and generating targeted protection strategies based on the assessment results. By dynamically adjusting model rules and strategy parameters through protection feedback data, compared with existing technologies, this invention can improve the accuracy of risk positioning and enhance the targeting and dynamic optimization capabilities of protection strategies. Therefore, it can solve the problems of existing technologies where network security risk assessment remains at the level of superficial correlation analysis, protection strategies are generalized, and there is a lack of effective closed-loop optimization mechanisms. Attached Figure Description
[0061] Figure 1 This is a schematic diagram of the overall system architecture of the present invention;
[0062] Figure 2 This is a schematic diagram of the multi-cascaded data acquisition and preprocessing module of the present invention;
[0063] Figure 3 This is a schematic diagram of the distributed security knowledge graph collaboration module of the present invention. Detailed Implementation
[0064] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the technical implementation details of the embodiments of the present invention. Obviously, the described embodiments belong to some embodiments of the present invention, but not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.
[0065] The terminology used in the embodiments of this invention is for the purpose of describing particular embodiments only and is not intended to limit the invention. The singular forms of system module units, etc., used in the embodiments of this invention are also intended to include the plural forms, unless the context clearly indicates otherwise.
[0066] The multi-cascaded network security risk dynamic assessment and protection system of this invention can be deployed in a distributed architecture consisting of multiple servers, edge computing nodes, and network devices. The system's implementation can be flexibly adapted to application scenarios, including integration as a stand-alone hardware device into a network gateway, deployment as a virtual machine in a cloud server cluster, or embedding as a software instance into an existing network management platform. Each module of the system can be independently deployed on different nodes, enabling cross-node calls and data interaction through standardized interfaces. It supports cluster-based horizontal scaling by adding module instances, adapting to multi-cascaded network architectures of different sizes without modifying the core program code.
[0067] In practical applications, the system's adaptation to multi-tiered networks can be flexibly adjusted according to the network topology. If the multi-tiered network is a three-layer cloud-edge-device architecture, the core system modules can be deployed on cloud servers, while data acquisition modules are distributed across edge nodes and terminal devices. For multi-tiered networks within an enterprise campus, the system can be deployed according to the core layer, aggregation layer, and access layer, ensuring localized response for data acquisition and protection strategy execution. Data is transmitted between modules via encrypted communication links, ensuring the security of internal data interaction within the system.
[0068] The following detailed description of each component module and the overall workflow of the system, using specific embodiments, is provided below.
[0069] Example 1, please refer to Figure 1 and Figure 2As shown: A multi-level network security risk dynamic assessment and protection system, which includes a multi-level data acquisition and preprocessing module, a dynamic data tracing graph construction module, a distributed security knowledge graph collaboration module, a multi-level risk causal assessment module, and a dynamic protection and closed-loop optimization module.
[0070] The multi-cascaded data acquisition and preprocessing module is used to collect raw data and security knowledge data from the entire data stream of each node in the multi-cascaded architecture, and to perform format unification, noise filtering and feature extraction on the collected heterogeneous data, and output standardized data.
[0071] The multi-cascade data acquisition and preprocessing module is specifically used for the following purposes during data acquisition:
[0072] Collect raw data from the entire data stream of each node using agentless technology;
[0073] Collect threat characteristics, vulnerability information, historical handling cases, and authoritative security rules for each node;
[0074] The original data and security knowledge data from the entire chain are aggregated to form a collected data set;
[0075] Perform format unification operation on heterogeneous data in the collected dataset, mapping different types of data to preset data specifications;
[0076] Perform noise filtering on the collected data after standardizing the format to remove abnormal data entries;
[0077] The noise-filtered collected data is subjected to feature extraction to extract key attribute information and output standardized data.
[0078] Furthermore, the multi-cascade data acquisition and preprocessing module is used to collect raw data and security knowledge data from the entire data flow of each node in the multi-cascade architecture. Through a series of standardized processing procedures, it outputs high-quality standardized data to provide reliable data support for subsequent modules.
[0079] In the data acquisition phase, the module employs agentless acquisition technology to achieve low-interference acquisition of raw data from the entire data stream link at each node. For server nodes, kernel-mode traffic capture technology based on eBPF captures TCP / UDP protocol data streams in real time without installing an agent. Captured content includes key parameters such as packet header information, data payload size, and transmission timestamps. The capture rate supports processing millions of packets per second, while keeping node CPU utilization below 5% to avoid impacting the normal operation of business systems. For network device nodes, port traffic logs and device operating status data from switches and routers are remotely obtained via the SNMPv3 protocol, and link information such as source IP, destination IP, port number, and protocol type of network traffic is collected via the NetFlow protocol. For terminal device nodes, operating system logs, application runtime logs, and user operation behavior data are obtained via WMI remote calls or the SSH protocol.
[0080] Simultaneously, the module comprehensively collects security knowledge data from each node. Threat signature data includes malicious code signatures, network attack behavior patterns, and abnormal login characteristics, which are updated in real time through integration with third-party threat intelligence platforms, with an update frequency of once per hour; vulnerability information covers known vulnerability numbers, severity levels, and remediation plans for hardware devices and operating system applications at each node, synchronized from the National Information Security Vulnerability Database (CNNVD) and the Common Vulnerability Scoring System (CVSS); historical handling cases include the triggering conditions, impact scope, handling measures, and effectiveness evaluation data of past cybersecurity incidents, stored in categories according to incident type; authoritative security rules include industry security standard compliance requirements and network access control policies, configured by security managers according to business needs and reviewed regularly.
[0081] After data collection, the module aggregates the raw data and security knowledge data from the entire data chain to form a unified collection dataset. It then proceeds to the data preprocessing stage, first performing a format standardization operation to map different data types to preset data specifications. Specifically, date and time data are uniformly converted to YYYY-MM-DDHH:MM:SS format; numerical data is uniformly represented in decimal, with units standardized to standard units such as bytes and seconds; text data is uniformly encoded in UTF-8 format; structured data is stored in JSON format; and unstructured data, such as log text, is converted into semi-structured data in key-value pair format.
[0082] After formatting is standardized, noise filtering is performed to remove outlier data entries. For numerical data, the 3σ rule is used to identify outliers: data values exceeding the mean plus or minus three standard deviations are considered outliers. For text data, regular expressions are used to filter data containing invalid characters, null values, or meaningless strings. For time-series data, data with discontinuous timestamps exceeding a preset threshold of 5 minutes is removed. Simultaneously, data integrity checks are performed to remove data lacking key fields, including data source node identifiers, timestamps, and core feature parameters.
[0083] Finally, feature extraction is performed to extract key attribute information from the data. For network traffic data, features such as source IP, destination IP, port number, protocol type, packet size, and transmission frequency are extracted; for log data, features such as event type, operation subject, operation object, and event result are extracted; for security knowledge data, features such as threat characteristics, keywords, vulnerability numbers, risk levels, and protection measures are extracted. Feature extraction employs a hybrid algorithm combining statistical filtering and deep learning: first, high-discrimination statistical features are filtered through analysis of variance, and then a lightweight CNN model is used to automatically extract latent features from the data. After the above processing, the module outputs standardized data, which is transmitted to a distributed database via a RESTful interface, supporting rapid querying and invocation by subsequent modules.
[0084] Example 2, please refer to Figure 1 As shown: The dynamic data tracing graph construction module of the multi-level network security risk dynamic assessment and protection system is used to identify data entities and their relationships based on standardized data, generate initial tracing relationships, update the tracing graph in real time, and perform multi-dimensional tracing path retrieval.
[0085] The dynamic data tracing map construction module is specifically used for identifying data entities and their relationships when performing the following tasks:
[0086] Extract data entities from standardized data. Data entities include data sources, data objects, processing components, and access subjects.
[0087] Identify the creation, transfer, transformation, and dependency relationships between data entities;
[0088] Based on data entities and their relationships, an initial tracing relationship is generated.
[0089] The entity information and relationships in the source map are updated in real time according to the preset update cycle and data change trigger conditions.
[0090] The dynamic data tracing map construction module is specifically used for: When performing multi-dimensional tracing path retrieval, it is used for:
[0091] Set search criteria based on data object, time range, and node level;
[0092] Based on search criteria, the flow trajectory of target data is located in the source map, and the flow trajectory contains a sequence of relationships between data entities;
[0093] Output source information, related data, and related node information of the target data to form multi-dimensional source tracing and retrieval results.
[0094] Furthermore, the dynamic data tracing map construction module identifies data entities and their relationships based on the standardized data output by the multi-level data acquisition and preprocessing module, generates and updates the tracing map in real time, and supports multi-dimensional tracing path retrieval, providing a visual and traceable foundation for risk transmission path analysis.
[0095] In the data entity and relationship identification stage, the module first extracts four types of core data entities from standardized data. Data source entities include database tables, message queues, topic files, storage paths, API interface addresses, etc., with each data source entity assigned a unique traceability identifier ID; data object entities include user request packets, business data streams, configuration files, data packets, etc., recording attributes such as the type, size, and creation time of the data object; processing component entities include network devices and service components such as application servers, database servers, firewalls, and load balancers, recording information such as the component's device model, deployment location, and operating status; and access subject entities include terminal IP addresses, user accounts, API interface keys, process IDs, etc., identifying the entity accessing and operating the data.
[0096] Subsequently, the module identifies four core types of relationships between data entities. Creation relationships refer to relationships where data objects are generated by a data source or processing component, such as the relationship of an application server generating business data streams; transmission relationships refer to the transmission relationships between data objects across different nodes or components, such as the relationship of a terminal device sending request data packets to a server; transformation relationships refer to relationships where data objects undergo changes in format, content, or structure during processing, such as the relationship of a firewall filtering and forwarding data packets; and dependency relationships refer to relationships where the normal operation or existence of one data entity depends on another data entity, such as the relationship where an application depends on a database table for data support. The identification of these relationships employs a combination of rule-based matching and machine learning, pre-setting a basic relationship rule base while optimizing the accuracy of relationship identification by learning entity interaction patterns from historical data.
[0097] Based on the extracted data entities and their relationships, the modules are combined to generate initial tracing relationships. A linked list of entity relationships is constructed, with each data object corresponding to a complete tracing link, encompassing its entire lifecycle of associated entities from creation, transmission, transformation to destruction. The initial tracing relationships are stored using a graph structure, where nodes represent data entities, edges represent relationships, and edge attributes include information such as association type, occurrence time, and duration.
[0098] To ensure the real-time nature of the source map, the module updates entity information and relationships in the source map in real time according to preset update cycles and data change trigger conditions. The preset update cycles are divided into three levels: 30 seconds for core nodes, 1 minute for aggregation nodes, and 5 minutes for access nodes. Data change trigger conditions include the creation of new data objects, changes in data transmission paths, updates to entity attributes, and the addition or disappearance of relationships. When such changes are detected, the corresponding graph nodes and edges are immediately updated. An incremental update mechanism is used during the update process, updating only the changed entities and relationships to avoid the resource consumption and delays caused by full updates. Simultaneously, the version information and timestamp of each update are recorded, supporting historical version backtracking of the source map with a backtracking time range of 90 days.
[0099] In the multi-dimensional tracing path retrieval stage, the module allows users to set flexible search conditions based on the time range and node level of data objects. Data object search conditions can specify specific data object IDs, file names, request IDs, etc.; time range search conditions support setting time periods accurate to the second, and can retrieve tracing paths within a maximum of 90 days; node level search conditions can select one or more levels in the core layer, aggregation layer, and access layer, or specify specific node IDs.
[0100] Based on the set search criteria, the module quickly locates the flow trajectory of target data in the source map. Through graph database index optimization techniques, it constructs multi-dimensional indexes including entity ID, timestamp, and node hierarchy, ensuring a search response time of no more than one second. The located flow trajectory contains a sequence of relationships between data entities, arranged chronologically, clearly demonstrating the complete flow process of data from creation to its current state.
[0101] Finally, the module outputs source information, associated data, and related node information of the target data, forming a multi-dimensional source tracing retrieval result. Source information includes the initial creation node, creation time, and creation entity of the data; associated data includes other data objects with transmission and transformation dependencies on the target data and their basic attributes; related node information includes the locations of all processing components accessing the target data during its flow, and the locations of related nodes. The retrieval results support visualization, presenting the source tracing path intuitively in a graph format, and can also be exported as a structured file for further analysis by security management personnel.
[0102] Example 3, please refer to Figure 1 and Figure 3 As shown: Based on a multi-level network security risk dynamic assessment and protection system, a distributed security knowledge graph collaboration module is used to transform unstructured security knowledge into structured knowledge units, synchronize knowledge units through a lightweight protocol, and detect and resolve knowledge contradictions between different nodes.
[0103] When the distributed security knowledge graph collaboration module executes the synchronization of knowledge units via a lightweight protocol, it is specifically used for:
[0104] Knowledge synchronization priority is determined based on node hierarchy, with core node knowledge units having higher synchronization priority than edge nodes.
[0105] Synchronization triggering conditions are set according to the update frequency of knowledge units. Knowledge units with high-frequency updates use real-time synchronization triggering, while knowledge units with low-frequency updates use timed synchronization triggering.
[0106] Based on synchronization priority and triggering conditions, structured knowledge units are transmitted from the initiating node to other associated nodes via a lightweight protocol;
[0107] During the synchronization process, the transmission status of knowledge units is recorded, and retry synchronization operations are performed on knowledge units that fail to be transmitted.
[0108] The distributed security knowledge graph collaboration module is specifically used for: detecting and resolving knowledge contradictions between different nodes.
[0109] Unstructured security knowledge is transformed into structured knowledge units through semantic parsing. The structured knowledge units include knowledge attributes, association identifiers, and source annotations.
[0110] Structured knowledge units are transmitted synchronously between nodes using a lightweight protocol.
[0111] Compare the inconsistent content in the knowledge units synchronized at different nodes;
[0112] Cross-validate inconsistent content using an authoritative database;
[0113] The verified unified statement is synchronized to all nodes to resolve knowledge contradictions.
[0114] Furthermore, the distributed security knowledge graph collaboration module is responsible for transforming unstructured security knowledge into structured knowledge units, achieving efficient synchronization of knowledge units between nodes through a differentiated synchronization mechanism, and resolving knowledge contradictions through authoritative cross-validation, thereby ensuring the consistency and accuracy of security knowledge in a distributed environment.
[0115] In the structured knowledge unit transformation stage, the module first performs semantic parsing on the collected unstructured security knowledge. A pre-trained language model based on a bidirectional encoder, representing the data from the converter, is used to perform word segmentation, part-of-speech tagging, entity recognition, and relation extraction on the unstructured text, extracting core conceptual attributes and related information from the text.
[0116] Subsequently, the parsed information is encapsulated into standardized structured knowledge units. Each structured knowledge unit contains three core components: knowledge attributes, association identifiers, and source annotations. Knowledge attributes include knowledge type, keywords, core parameter value range, confidence level, etc. Knowledge types are categorized as threat knowledge, vulnerability knowledge, strategy knowledge, case knowledge, etc. Association identifiers are used to mark the relationships between this knowledge unit and other knowledge units, using a unified knowledge graph node ID for association. Source annotations include the knowledge acquisition channel, publication time, and authority level, with authority levels categorized as Level 1 (national or industry standard), Level 2 (authoritative institution publication), and Level 3 (ordinary source). The structured knowledge units are stored in JSON-LD format to ensure semantic interpretability and cross-platform compatibility.
[0117] In the knowledge unit synchronization phase, the module prioritizes knowledge synchronization based on node hierarchy. The nodes in the multi-cascaded architecture are divided into three levels: core nodes, aggregation nodes, and access nodes. Core nodes include critical equipment such as network core switches, database servers, etc. Aggregation nodes include regional aggregation switches, edge computing nodes, etc., and access nodes include terminal devices and ordinary network access devices. Knowledge unit synchronization priority is highest for core nodes, followed by aggregation nodes, and lowest for access nodes. During synchronization, knowledge units from high-priority nodes are transmitted first to ensure timely synchronization of knowledge updates at critical nodes.
[0118] Simultaneously, synchronization triggering conditions are set according to the update frequency of knowledge units. Knowledge units are divided into high-frequency update categories and low-frequency update categories. High-frequency update categories include real-time threat feature intelligence, which is updated more than once a day and adopts a real-time synchronization triggering mechanism. When such knowledge units are updated, the synchronization process is immediately initiated. Low-frequency update categories include historical cases of vulnerability database security standards, which are updated less than once a day and adopt a timed synchronization triggering mechanism. The timed synchronization cycle is 2 hours for core nodes, 6 hours for aggregation nodes, and 24 hours for access nodes.
[0119] Based on synchronization priority and triggering conditions, the module transmits structured knowledge units from the initiating node to other associated nodes via a lightweight protocol. The MQTT-SN protocol is selected due to its low bandwidth consumption, low power consumption, and ease of implementation, making it suitable for the resource constraints of edge nodes in a multi-cascade architecture. During transmission, the knowledge units are compressed and encrypted to ensure transmission efficiency and data security. Simultaneously, a fragmented transmission mechanism is employed, dividing large knowledge units exceeding 1MB into fragments. Each fragment contains a checksum and sequence number to ensure the integrity and orderliness of data transmission.
[0120] During synchronization, the module records the transmission status of knowledge units in real time, including statuses such as pending transmission, successful transmission, and transmission failure. For knowledge units that fail to transmit, an exponential backoff retry mechanism is used to retry the synchronization operation. The interval between each retry doubles, with a maximum of 3 retries. If transmission still fails after 3 retries, the knowledge unit is marked as a synchronization anomaly, an anomaly log is recorded, and administrators are notified for manual handling.
[0121] In the knowledge contradiction detection and resolution phase, the module first compares inconsistencies in knowledge units synchronized across different nodes. It identifies conflicting knowledge content by comparing the association identifiers and core attributes of the knowledge units. For example, if knowledge units synchronized across different nodes label the same vulnerability as high-risk and medium-risk respectively, then a knowledge contradiction is identified.
[0122] For any identified inconsistencies, the module cross-validates them using authoritative databases. These authoritative databases include the National Vulnerability Database (CNNVD), the MITRE ATT&CK framework, and industry security standard databases. The core information of the inconsistencies is submitted to these authoritative databases for querying, obtaining their standard descriptions. For example, in cases of conflicting vulnerability severity levels, the rating from CNNVD prevails; in cases of conflicting threat characteristics, the standard feature descriptions from the MITRE ATT&CK framework are used.
[0123] After verification, the unified statement confirmed by the authoritative database is synchronized to all nodes, thus resolving the knowledge contradiction. Simultaneously, the process and results of contradiction resolution are recorded, including the unified statement used by the authoritative verification base for the nodes involved in the contradiction, forming a knowledge contradiction resolution log for administrators to trace and verify. Furthermore, the module periodically performs consistency checks on the knowledge graph weekly to comprehensively identify potential knowledge contradictions and ensure the global consistency of the distributed secure knowledge graph.
[0124] Example 4, please refer to Figure 1As shown: Based on a multi-level network security risk dynamic assessment and protection system, the multi-level risk causal assessment module is used to combine source tracing graphs and structured knowledge to build a structural causal model of risk propagation, and identify core risk factors and cross-level propagation paths;
[0125] The multi-level risk causality assessment module is specifically used when constructing a structural causal model of risk propagation, for the following purposes:
[0126] The trajectory data of the source map is associated and mapped with structured knowledge to establish the correspondence between trajectory data and knowledge units;
[0127] Establish causal relationship rules for risk propagation, including entity association types and risk transmission conditions;
[0128] Based on the correspondence between trajectory data and knowledge units and the causal association rules, a structural causal model is constructed.
[0129] The multi-level risk causality assessment module is specifically used to identify core risk factors and cross-level propagation paths when performing risk assessment.
[0130] Based on structural causal models, correlations that meet preset thresholds are screened to identify core risk factors;
[0131] Tracing the initial triggering node of risk based on a structural causal model;
[0132] Tracing the risk diffusion chain along the correlation of the source map, and marking the key transfer nodes and core data objects in the diffusion chain;
[0133] Integrate the initial trigger node, key transfer node, core data objects and related relationships to form a cross-level propagation path and an affected list.
[0134] Furthermore, the multi-level risk causal assessment module combines the trajectory data of the dynamic data tracing graph with the structured knowledge of the distributed security knowledge graph to construct a structural causal model of risk propagation, accurately identify core risk factors and cross-level propagation paths, and provide a scientific basis for the generation of targeted protection strategies.
[0135] In the structural causal model construction phase, the module first maps the trajectory data of the source tracing graph to structured knowledge, establishing a correspondence between trajectory data and knowledge units. Using the unique identifier of each data entity, the flow trajectory of data objects in the source tracing graph is associated with corresponding threat knowledge, vulnerability knowledge, and policy knowledge in the security knowledge graph. The association mapping employs a combination of rule-based and similarity-based matching methods. A pre-defined association rule base is used, and the semantic similarity between trajectory data and knowledge units is calculated. A similarity threshold is set; if the similarity exceeds the threshold, an association relationship is established.
[0136] Subsequently, the module establishes causal association rules for risk propagation, clarifying entity association types and risk transmission conditions. These causal association rules are formulated based on security expertise and historical data mining results, covering the risk transmission logic for four core association types. The risk transmission condition for creation associations is malicious behavior by the creating entity or vulnerabilities in the data source; the risk transmission condition for transmission associations is an unencrypted transmission link, security vulnerabilities in the transmission nodes, or abnormal transmission frequency; the risk transmission condition for transformation associations is tampering with the transformation component, defects in the transformation rules, or damage to data integrity during the transformation process; and the risk transmission condition for dependency associations is a security risk in the dependent entity and a dependency level exceeding a preset threshold. Each causal association rule includes parameters such as risk transmission probability, influence weight, and trigger threshold.
[0137] Based on the correspondence between trajectory data and knowledge units, and causal association rules, a structural causal model is constructed. This model employs a Bayesian network structure, with data entities as nodes and causal association rules as edges, the weights of which represent risk propagation probabilities. During model construction, the topology of the Bayesian network is first built based on the entity relationships in the source map. Then, combining the risk parameters and causal association rules from the structured knowledge, the prior probabilities and conditional probability tables for each node in the network are determined. For example, the prior probability that a server node has a high-risk vulnerability is determined based on the vulnerability occurrence rate in the vulnerability knowledge unit, and the conditional probability that an attack on this node will affect related data objects is determined based on the risk propagation probabilities in the causal association rules. After model construction, the maximum likelihood estimation method is used to train and optimize the model parameters, improving the model's prediction accuracy.
[0138] In the identification of core risk factors and cross-level propagation paths, the module uses a constructed structural causal model to filter correlations that meet preset thresholds, thus identifying core risk factors. These preset correlation thresholds filter out correlations with a risk propagation probability greater than or equal to the threshold; the entities and factors corresponding to these correlations are the core risk factors. Core risk factors include nodes with high-risk, unpatched vulnerabilities, malicious access subjects, unencrypted core data transmission links, and highly sensitive data objects. For example, a high-risk, unpatched vulnerability in a core server, terminal IP addresses frequently attempting unauthorized access, and unencrypted transmission paths for core business data are all identified as core risk factors.
[0139] Simultaneously, the initial triggering node of the risk is traced based on a structural causal model. Through the model's backward reasoning function, starting from the detected risk event nodes, the model traces back along causal relationships to pinpoint the initial source of the risk event. For example, if business data is detected to have been tampered with, backward reasoning traces back to the aggregation layer switch that was compromised during data transmission; this switch is the initial triggering node. During the tracing process, the risk contribution of each potential triggering node is recorded. The risk contribution is calculated based on the node's risk transmission probability and influence weight, and ultimately, the node with the highest risk contribution is determined as the initial triggering node.
[0140] Subsequently, the module traces the risk propagation chain along the relationships in the source map, marking key transfer nodes and core data objects in the propagation chain. Key transfer nodes refer to nodes that play a pivotal role in the risk propagation process, such as core switches and data forwarding servers; the security status of these nodes directly affects the scope and speed of risk propagation. Core data objects refer to high-value data affected during risk propagation, such as user privacy data, core business data, and configuration files. During the tracing process, the module combines the prediction results of the structural causal model to analyze the probability and path of risk propagation between nodes at different levels, marking the key paths and nodes of risk propagation.
[0141] Finally, the module integrates the core data objects and relationships of the initial trigger node, key transfer nodes, and other critical nodes to form a cross-level propagation path and an affected list. The cross-level propagation path is presented in the form of a visual graph, clearly showing the propagation trajectory of the risk from the initial trigger node, through the core transfer nodes, and between the core layer, aggregation layer, and access layer. The affected list details the nodes, devices, data objects, and business systems affected by the risk, including information such as the name, type, location, risk level, and degree of impact of the affected objects.
[0142] Example 5, please refer to Figure 1 As shown: A multi-tiered network security risk dynamic assessment and protection system, with a dynamic protection and closed-loop optimization module, is used to generate targeted protection strategies based on core factors and propagation paths, collect feedback data, and adjust model rules, graph update frequency, and strategy parameters.
[0143] The dynamic protection and closed-loop optimization module, when executing the generation of targeted protection strategies, is specifically used for:
[0144] Call the preset protection strategy library, which contains protection rules corresponding to different risk types, core factors and propagation paths;
[0145] Based on the identified core risk factors and cross-level propagation paths, match the corresponding protection rules in the protection strategy library;
[0146] Bind the matched protection rules to the affected data and nodes in the affected list;
[0147] The bound protection rules are distributed to the corresponding nodes for execution according to the node hierarchy, generating targeted protection strategies.
[0148] The dynamic protection and closed-loop optimization module, when executing adjustments to model rules, map update frequency, and strategy parameters, is specifically used for:
[0149] Collect feedback data after the targeted protection strategy is executed. The feedback data includes threat interception records, business operation status data, and node resource usage data.
[0150] Analyze the feedback data to extract threat interception rate, business operation adaptability, and resource utilization.
[0151] Based on the extracted threat interception rate, business operation adaptability, and resource utilization, the weight of causal association rules, the update interval of the source map, and the execution threshold parameters of the protection strategy are adjusted.
[0152] Furthermore, the dynamic protection and closed-loop optimization module generates targeted protection strategies and issues them for execution based on the core risk factors and cross-level propagation paths identified by the multi-level risk causal assessment module. At the same time, it collects protection effect feedback data, dynamically adjusts the update frequency of the model rule graph and strategy parameters, and forms a continuously optimized closed-loop protection system.
[0153] In the targeted protection strategy generation stage, the module first calls the preset protection strategy library, which is divided into four core rule categories according to risk type:
[0154] Vulnerability protection: rules for patching high-risk vulnerabilities, rules for regular vulnerability scanning, and rules for responding to vulnerability alerts;
[0155] Threat interception rules: malicious IP blacklist interception rules, abnormal traffic rate limiting rules, and attack behavior feature matching interception rules;
[0156] Data security related rules: rules for encrypted transmission of sensitive data, rules for data anonymization, and rules for data access auditing;
[0157] Access control rules include: role-based permission allocation rules, abnormal login blocking rules, and cross-node access authorization rules.
[0158] The protection strategy library supports administrators in adding, modifying, deleting, and approving rules. All rules include attributes such as trigger conditions, execution actions, scope of effectiveness, and priority.
[0159] Based on the identified core risk factors and cross-layer propagation paths, the module uses a rule-matching algorithm to match corresponding protection rules from the protection policy library. The matching process is divided into three levels: first, matching the corresponding policy category according to the risk type; second, matching the specific policy sub-category according to the core risk factors; and finally, matching the policy's scope of application and execution method according to the cross-layer propagation path. For example, if the risk type is vulnerability risk, the core factor is a high-risk vulnerability in the core server, and the propagation path is from the core layer to the aggregation layer, then the corresponding vulnerability patch installation rule will be matched, with the scope of application being the core server and associated aggregation layer nodes, and the execution method being immediate patch installation.
[0160] During the matching process, the matching degree of each rule with the current risk scenario is calculated. The matching degree is calculated based on the degree of fit between the rule triggering conditions and risk factors, the scope of effectiveness and the coverage of the propagation path. The top 3 rules with the highest matching degree are selected as candidate rules.
[0161] The module then binds the matched protection rules to the affected data nodes in the affected list. It clearly defines the protected objects corresponding to each protection rule, including specific node devices, data objects, and business systems. For example, a malicious IP blacklist blocking rule is bound to an affected core server node, meaning the blocking rule is only applied to access traffic to that server node; similarly, a data encryption transmission rule is bound to an affected sensitive data object, meaning encryption is only performed during the transmission of that type of sensitive data.
[0162] During the binding process, the compatibility between the rules and the protected objects is checked to avoid conflicts between protection rules. If a conflict is detected, the conflict is resolved according to the rule priority, with the rule with higher priority being executed first.
[0163] Finally, the module distributes the bound protection rules hierarchically to the corresponding nodes for execution, generating targeted protection strategies. Protection rules for core nodes are directly distributed through the cloud management platform, while those for aggregation and access nodes are forwarded through the edge gateway. During distribution, HTTPS is used between core nodes, and MQTT-SN encrypted transmission is used between edge and access nodes to ensure transmission compatibility and security across different node levels. Simultaneously, the distribution status of protection rules is recorded, including pending distribution, successful distribution, and failed distribution. Rules that fail to distribute are retried up to three times; if the retrieved rule still fails, administrators are notified for manual intervention. After receiving the protection rules, each node configures corresponding security measures as required by the rules, such as updating firewall rules, enabling encryption protocols, and adjusting access permissions, ensuring the targeted protection strategy is accurately implemented across the entire network.
[0164] In the closed-loop optimization phase, the module first collects feedback data after the targeted protection strategy is executed. This feedback data mainly includes three core types: threat interception records, including information such as the types and frequency of intercepted threats, triggering rules, etc., reported in real-time by security devices such as firewalls and intrusion detection systems; business operation status data, including CPU utilization, memory usage, network bandwidth utilization, and business response time of each node, collected periodically by the node's monitoring agent at a 1-minute interval; and node resource usage data, including CPU, memory, and network resources consumed during the execution of the protection strategy, recorded in real-time by the protection execution component. After the feedback data is collected, it is aggregated and preprocessed, abnormal data is removed, the data format is standardized, and the data is stored in the feedback database.
[0165] Subsequently, the module analyzes the feedback data and extracts three core evaluation indicators: threat interception rate, operational adaptability, and resource utilization. The formula for calculating the threat interception rate is as follows: Among them, R i N represents the threat interception rate. a N represents the actual number of threats intercepted. c This represents the expected number of threats intercepted based on the risk assessment results. Business operational adaptability is calculated comprehensively using parameters such as business response time change rate and business availability, reflecting the impact of the protection strategy on normal business operations. Resource utilization rate is the proportion of resources consumed during the execution of the protection strategy to the total resources of the node. Based on the three extracted core evaluation indicators, the module dynamically adjusts the causal relationship rule weight tracing graph update interval and the execution threshold parameters of the protection strategy.
[0166] The overall workflow of the multi-level network security risk dynamic assessment and protection system is as follows: After the system starts, the multi-level data acquisition and preprocessing module starts running. The acquisition components deployed in a distributed manner on each node acquire raw data and security knowledge data from the entire link according to the preset configuration. After preprocessing processes such as format unification, noise filtering and feature extraction, standardized data is output and transmitted to the distributed database through the RESTful interface.
[0167] The dynamic data traceability map construction module reads standardized data from a distributed database, extracts data entities and their relationships, generates an initial traceability map, and updates the map in real time according to a preset update cycle and data change trigger conditions. It also provides a multi-dimensional traceability path retrieval function, allowing managers to query the data flow trajectory.
[0168] The distributed security knowledge graph collaboration module transforms unstructured security knowledge into structured knowledge units. Through a differentiated synchronization mechanism based on node hierarchy and update frequency, the knowledge units are efficiently synchronized among nodes. At the same time, authoritative cross-validation resolves knowledge contradictions and ensures the consistency of security knowledge.
[0169] The multi-level risk causal assessment module calls upon the trajectory data of the source tracing map and structured security knowledge to construct a structural causal model of risk propagation. Through model reasoning, it filters out the core risk factors, traces the initial triggering node of the risk, tracks the cross-level propagation path, and generates a risk assessment report.
[0170] The dynamic protection and closed-loop optimization module matches targeted protection rules from the protection strategy library based on the core factors and propagation paths in the risk assessment report, binds them to the affected objects, and sends them to the corresponding nodes for execution.
[0171] During the execution of the protection strategy, the dynamic protection and closed-loop optimization module continuously collects feedback data, analyzes core evaluation indicators, and dynamically adjusts the update interval of the causal relationship rule weight tracing graph and protection strategy parameters to form a closed-loop optimization.
[0172] The above process is executed cyclically to achieve continuous dynamic assessment and protection against multi-level network security risks, ensuring that the network system maintains a high level of security protection in a dynamically changing environment.
[0173] It will be apparent to those skilled in the art that this invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from its spirit or essential characteristics. The technical solution of this invention, through the construction of a multi-tiered collaborative architecture, the design of a low-interference data acquisition and knowledge collaboration mechanism, the application of a structural causal model, and the establishment of a closed-loop optimization system, effectively solves the problems of poor adaptability, low data quality, inconsistent knowledge, inaccurate risk positioning, and generalized protection strategies in existing technologies for multi-tiered network security assessment and protection, possessing significant technical advantages and practical value.
[0174] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A multi-tiered network security risk dynamic assessment and protection system, characterized in that, The system includes a multi-cascaded data acquisition and preprocessing module, a dynamic data tracing graph construction module, a distributed security knowledge graph collaboration module, a multi-cascaded risk causal assessment module, and a dynamic protection and closed-loop optimization module. The multi-cascaded data acquisition and preprocessing module is used to acquire the original data and security knowledge data of the entire data stream of each node in the multi-cascaded architecture, perform format unification, noise filtering and feature extraction on the acquired heterogeneous data, and output standardized data. The dynamic data tracing map construction module is used to identify data entities and their relationships based on standardized data, generate initial tracing relationships, update the tracing map in real time, and perform multi-dimensional tracing path retrieval. The distributed security knowledge graph collaboration module is used to transform unstructured security knowledge into structured knowledge units, synchronize knowledge units through a lightweight protocol, and detect and resolve knowledge contradictions between different nodes. The multi-level risk causal assessment module is used to combine source mapping and structured knowledge to construct a structural causal model of risk propagation, and to identify core risk factors and cross-level propagation paths. The dynamic protection and closed-loop optimization module is used to generate targeted protection strategies based on core factors and propagation paths, collect feedback data, and adjust model rules, graph update frequency, and strategy parameters. When the distributed security knowledge graph collaboration module executes the synchronization of knowledge units via a lightweight protocol, it is specifically used for: Knowledge synchronization priority is determined based on node hierarchy, with core node knowledge units having higher synchronization priority than edge nodes. Synchronization triggering conditions are set according to the update frequency of knowledge units. Knowledge units with high-frequency updates use real-time synchronization triggering, while knowledge units with low-frequency updates use timed synchronization triggering. Based on synchronization priority and triggering conditions, structured knowledge units are transmitted from the initiating node to other related nodes via a lightweight protocol; During the synchronization process, the transmission status of knowledge units is recorded, and retry synchronization operations are performed on knowledge units that fail to be transmitted. The distributed security knowledge graph collaboration module is specifically used for: detecting and resolving knowledge contradictions between different nodes. Unstructured security knowledge is transformed into structured knowledge units through semantic parsing. The structured knowledge units include knowledge attributes, association identifiers, and source annotations. Structured knowledge units are transmitted synchronously between nodes using a lightweight protocol. Compare the inconsistent content in the knowledge units synchronized at different nodes; Cross-validate inconsistent content using an authoritative database; The verified unified statement is synchronized to all nodes to resolve knowledge contradictions. The multi-level risk causal assessment module, when executing the construction of a structural causal model for risk propagation, is specifically used for: The trajectory data of the source map is associated and mapped with structured knowledge to establish the correspondence between trajectory data and knowledge units; Establish causal relationship rules for risk propagation, wherein the rules include entity association types and risk transmission conditions; Based on the correspondence between trajectory data and knowledge units and the causal association rules, a structural causal model is constructed.
2. The network security risk dynamic assessment and protection system based on multi-cascaded architecture as described in claim 1, characterized in that, The multi-cascaded data acquisition and preprocessing module, when performing data acquisition, is specifically used for: Collect raw data from the entire data stream of each node using agentless technology; Collect threat characteristics, vulnerability information, historical handling cases, and authoritative security rules for each node; The original data and security knowledge data from the entire chain are aggregated to form a collected data set; Perform format unification operation on heterogeneous data in the collected dataset, mapping different types of data to preset data specifications; Perform noise filtering on the collected data after standardizing the format to remove abnormal data entries; The noise-filtered collected data is subjected to feature extraction to extract key attribute information and output standardized data.
3. The network security risk dynamic assessment and protection system based on multi-cascaded architecture as described in claim 1, characterized in that, The dynamic data tracing map construction module is specifically used for: identifying data entities and their relationships when performing the following tasks. Data entities are extracted from standardized data, and these data entities include data sources, data objects, processing components, and access subjects. Identify the creation, transfer, transformation, and dependency relationships between data entities; Based on data entities and their relationships, an initial tracing relationship is generated. The entity information and relationships in the source map are updated in real time according to the preset update cycle and data change trigger conditions.
4. The network security risk dynamic assessment and protection system based on multi-cascaded architecture as described in claim 1, characterized in that, The dynamic data tracing map construction module is specifically used for: When performing multi-dimensional tracing path retrieval, it is used to: Set search criteria based on data object, time range, and node level; Based on search criteria, the flow trajectory of target data is located in the source map, and the flow trajectory includes a sequence of association relationships between data entities; Output source information, related data, and related node information of the target data to form multi-dimensional source tracing and retrieval results.
5. The network security risk dynamic assessment and protection system based on multi-cascaded architecture as described in claim 1, characterized in that, The multi-level risk causality assessment module, when identifying core risk factors and cross-level propagation paths, is specifically used for: Based on structural causal models, correlations that meet preset thresholds are screened to identify core risk factors; Tracing the initial triggering node of risk based on a structural causal model; Tracing the risk diffusion chain along the correlation of the source map, and marking the key transfer nodes and core data objects in the diffusion chain; Integrate the initial trigger node, key transfer node, core data objects and related relationships to form a cross-level propagation path and an affected list.
6. The network security risk dynamic assessment and protection system based on multi-cascaded architecture as described in claim 1, characterized in that, When the dynamic protection and closed-loop optimization module generates a targeted protection strategy, it is specifically used for: Call the preset protection strategy library, which contains protection rules corresponding to different risk types, core factors and propagation paths; Based on the identified core risk factors and cross-level propagation paths, match the corresponding protection rules in the protection strategy library; Bind the matched protection rules to the affected data and nodes in the affected list; The bound protection rules are distributed to the corresponding nodes for execution according to the node hierarchy, generating targeted protection strategies.
7. The network security risk dynamic assessment and protection system based on multi-cascaded architecture as described in claim 1, characterized in that, The dynamic protection and closed-loop optimization module, when executing adjustments to model rules, graph update frequency, and strategy parameters, is specifically used for: Collect feedback data after the targeted protection strategy is executed. The feedback data includes threat interception records, business operation status data, and node resource usage data. Analyze the feedback data to extract threat interception rate, business operation adaptability, and resource utilization. Based on the extracted threat interception rate, business operation adaptability, and resource utilization, the weight of causal association rules, the update interval of the source map, and the execution threshold parameters of the protection strategy are adjusted.
Citation Information
Patent Citations
Dynamic sensitive data outbound risk assessment method and system based on multi-source risk information
CN120470590A
Combined electric appliance supply chain multi-dimensional early warning method and system based on knowledge graph
CN120672125A