Network adaptive management system based on dynamic network security
By introducing behavior monitoring and security analysis modules, the short-term behavior of network users can be monitored in real time and evaluated in multiple dimensions. This solves the problem of linear tracking that is not possible in existing technologies, achieves more accurate identification of security and risk characteristics, and improves the comprehensiveness and timeliness of network security management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUANGZHOU SIYUN DATA TECH CO LTD
- Filing Date
- 2026-02-04
- Publication Date
- 2026-04-17
AI Technical Summary
Existing technologies cannot perform linear tracking from the perspective of the operating user, nor can they conduct an overall risk assessment of the short-term behavior of the same network user, resulting in low comprehensiveness and timeliness of network security early warnings.
The network adaptive management system based on dynamic network security includes a behavior monitoring module, a security analysis module, and a risk analysis module. It monitors network behavior in real time, extracts event elements from historical events, generates permission, privacy, and fluctuation data sets, and conducts security assessments and risk characteristic analyses.
It enables refined and weighted assessment of network behavior, improves the accuracy of security judgments and the effectiveness of decision-making, and significantly enhances the pertinence and efficiency of network security management.
Smart Images

Figure CN121644237B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of network security management and involves data analysis technology, specifically a network adaptive management system based on dynamic network security. Background Technology
[0002] The network adaptive management system is an intelligent network security protection system that can perceive changes in the network environment and threat situation in real time, automatically adjust security strategies and defense measures, and achieve continuous protection, dynamic response and intelligent optimization of network security.
[0003] The invention patent with publication number CN119172100B discloses a network security processing method and system based on dynamic networks. This method performs network security processing based on comprehensive security impact scores and dynamic IP update results. It solves the technical problem of inaccurate network risk identification and untimely protection under traditional static IP address management. Through dynamic and real-time network security processing, it achieves the technical effect of improving network security protection capabilities. However, this method cannot perform linear tracking from the perspective of the operating user, conduct overall risk assessment of the short-term behavior of the same network user, or identify risk characteristics based on the distribution of event risk factors, resulting in low comprehensiveness and timeliness of network security early warning.
[0004] To address the aforementioned technical problems, this application proposes a solution. Summary of the Invention
[0005] The purpose of this invention is to provide a network adaptive management system based on dynamic network security, which solves the problem that existing technologies cannot perform linear tracking from the perspective of operating users and conduct overall risk assessment of the short-term behavior of the same network user;
[0006] The technical problem that this invention aims to solve is: how to provide a network adaptive management system based on dynamic network security that can linearly track from the perspective of the operating user and conduct an overall risk assessment of the short-term behavior of the same network user.
[0007] The objective of this invention can be achieved through the following technical solutions:
[0008] A network adaptive management system based on dynamic network security includes a behavior monitoring module, a security analysis module, and a risk analysis module that are sequentially connected in communication. The behavior monitoring module, security analysis module, and risk analysis module are all connected in communication with a database.
[0009] The behavior monitoring module is used to monitor network behavior in real time: after detecting network behavior, it retrieves the behavior trajectory of the user who performed the network behavior after logging in and marks the historical network behavior in the behavior trajectory as historical event i, extracts the event element i of historical event i, i=1,2,...,n, where n is a positive integer; and sends the event element i of all historical events i corresponding to the network behavior to the security analysis module.
[0010] The security analysis module is used to analyze the security of network behavior: it generates a permission set e, a privacy set e, and a fluctuation set e based on the event element i of historical event i; it randomly selects a data point from the permission set e, the privacy set e, and the fluctuation set e and performs random traversal and combination to obtain several combination elements, obtains the security coefficient of the combination elements, sums up the security coefficients of all combination elements and takes the average value to obtain the security assessment value of the network behavior, and determines whether the security of the network behavior meets the requirements based on the security assessment value.
[0011] The risk analysis module is used to analyze the risk characteristics of network behavior.
[0012] Furthermore, event element i includes permission data i, privacy data i, and fluctuation data i. Permission data i is the difference between the lowest permission level corresponding to the attribute of historical event i and the permission level of the executing user; privacy data i is the file privacy level corresponding to historical event i.
[0013] Furthermore, the process of acquiring fluctuation data i includes: marking L1 seconds after the completion of historical event i as the monitoring period, acquiring the network latency, jitter, and packet loss rate during the monitoring period, marking the network fluctuation level during the monitoring period based on the network latency, jitter, and packet loss rate, and marking the fluctuation level as fluctuation data i.
[0014] Furthermore, the generation process of the permission set e, privacy set e, and fluctuation set e includes: selecting the m largest data from the permission data i, privacy data i, and fluctuation data i corresponding to all historical events i of the network behavior, and obtaining the permission data e, privacy data e, and fluctuation data e, e=1,2,...,m, where m is a positive integer and m<n; the permission data e, privacy data e, and fluctuation data e are respectively composed of the permission data e, privacy data e, and fluctuation data e.
[0015] Furthermore, the process of obtaining the security coefficient of the combined elements includes: forming an analysis data row vector HX from the permission data e, privacy data e, and fluctuation data e in the combined elements, where HX = [permission data e, privacy data e, fluctuation data e], and generating a weight column vector QX for the analysis data row vector, where QX = [k1, k2, k3]. TThe safety factor of the combined elements is obtained by performing a dot product calculation on the row vector HX of the analysis data and the column vector QX of the weights.
[0016] Furthermore, the specific process for determining whether the security of network behavior meets the requirements includes: retrieving the security assessment threshold from the database, comparing the security assessment value of the network behavior with the security assessment threshold; if the security assessment value is less than the security assessment threshold, the network behavior is determined to meet the security requirements; if the security assessment value is greater than or equal to the security assessment threshold, the network behavior is determined to not meet the security requirements, a risk analysis signal is generated, and the risk analysis signal is sent to the risk analysis module.
[0017] Furthermore, the specific process of the risk analysis module to analyze the risk characteristics of network behavior includes: marking the permission data e, privacy data e, and volatility data e in the combined elements as permission risk data, privacy risk data, and volatility risk data, respectively; marking the event element i in historical event i that contains permission risk data, privacy risk data, or volatility risk data as a latent element; marking the ratio of the number of latent elements to n as the latent risk coefficient; marking the risk characteristics of network behavior through the latent risk coefficient; and sending the risk characteristics of network behavior to the mobile terminal of the administrator.
[0018] Furthermore, the specific process of marking the risk characteristics of online behavior includes: retrieving the implicit risk threshold from the database, comparing the implicit risk coefficient with the implicit risk threshold; if the implicit risk coefficient is less than the implicit risk threshold, it is determined that the historical event risk elements of the online behavior are concentrated, and the risk characteristics of the online behavior are marked as explicit risks; if the implicit risk coefficient is greater than or equal to the implicit risk threshold, it is determined that the historical event risk elements of the online behavior are dispersed, and the risk characteristics of the online behavior are marked as implicit risks; and sending the risk characteristics of the online event to the mobile terminal of the administrator.
[0019] The present invention has the following beneficial effects:
[0020] The quantification methods for permission data i and privacy data i are clearly defined, enabling the behavior monitoring module to extract more targeted and quantifiable data. This detailed definition of event elements provides the security analysis module with multi-dimensional and high-precision input information, greatly enhancing the depth and breadth of security analysis. Specifically, permission data i can effectively identify potential risks of permission abuse or unauthorized operations; privacy data i can accurately assess the potential impact of data leakage; and fluctuation data i can reflect anomalies in the network environment, assisting in determining whether attack behavior exists. The combined effect of these specific data allows the system to more comprehensively and accurately assess the security of network behavior, significantly improving the ability to identify and warn of complex network threats. This provides a more reliable basis for decision-making in the network adaptive management system, effectively reducing security risks caused by incomplete information or inaccurate assessments.
[0021] By setting a monitoring period L1 seconds after the historical event i is executed, and acquiring network latency, jitter, and packet loss rate in real time during this period, the system can objectively and accurately reflect the immediate state of the network environment after a specific event occurs. This fluctuation level labeling based on actual network performance indicators enables the security analysis module to obtain more convincing and real-time fluctuation data i when performing network behavior security analysis, thereby significantly improving the accuracy and reliability of network behavior security assessment. This helps the system to identify network performance anomalies or potential risks caused by network behavior more promptly and accurately, providing a solid data foundation for subsequent security decisions.
[0022] This application enables a refined, weighted quantitative assessment of the security of each composite element. This assessment method fully considers the differentiated impact of different security attributes such as permissions, privacy, and network fluctuations on network behavior security, making the final calculated security coefficient of the composite element more representative and accurate. This not only improves the reliability of the security assessment of individual composite elements, but also provides a more solid data foundation for the subsequent calculation of the overall security assessment value of network behavior, thereby significantly improving the accuracy of network behavior security judgment and the effectiveness of decision-making in the network adaptive management system based on dynamic network security.
[0023] 4. This application overcomes the limitations of existing technologies, which can only determine whether network behavior security meets requirements but cannot deeply reveal specific risk characteristics. This solution marks the permission data e, privacy data e, and fluctuation data e in the combined elements as permission risk data, privacy risk data, and fluctuation risk data, respectively. Furthermore, it identifies implicit elements in historical events i and calculates implicit risk coefficients, thereby enabling more detailed and accurate marking of the risk characteristics of network behavior. This marking can not only distinguish the type of risk, whether it is explicit or implicit, but also quantify the prevalence of potential risks. By promptly sending this information with clear risk characteristic markings to the mobile terminals of administrators, administrators can quickly understand the nature of the risks and thus take more precise and effective risk response strategies, avoiding blind handling or omission of potential threats, and significantly improving the pertinence and efficiency of network security management. Attached Figure Description
[0024] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1 This is a system block diagram of Embodiment 1 of the present invention;
[0026] Figure 2 This is a flowchart of the method in Embodiment 2 of the present invention. Detailed Implementation
[0027] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0028] Traditional network security management systems lack a linear tracking mechanism for short-term user behavior, making it impossible to assess the risk of a single user's post-login behavior as a whole. Furthermore, the risk feature identification process fails to consider the distribution characteristics of event risk factors, limiting the comprehensiveness and timeliness of network security early warnings. Specifically, the real-time response capability and accuracy of risk prediction in network security protection are affected, as the system cannot dynamically analyze historical network behavior data related to permission changes, privacy levels, and network fluctuations, resulting in fragmented risk identification.
[0029] For example, in an enterprise intranet environment, when a user logs into the system and continuously performs file access, permission changes, and data transfer operations, the existing system only makes independent judgments on individual network behaviors and fails to treat historical events in the behavioral trajectory as a sequence as a whole. Furthermore, when a user accesses a high-privacy-level file and immediately performs a permission escalation operation, the system cannot extract permission data, privacy data, and fluctuation data from historical events for correlation analysis. As a result, the distribution characteristics of risk factors are ignored, and risk warnings are missed or delayed.
[0030] If the above problems are not addressed, the network security protection system will struggle to identify the cumulative effects of risks in complex network attacks. The dispersed nature of event risk factors may mask critical threats. Consequently, the network environment's ability to provide continuous protection is weakened, the reliability of dynamic response processes is reduced, and the accuracy of security policy adjustments is affected.
[0031] Example 1: As Figure 1 As shown, the network adaptive management system based on dynamic network security includes a behavior monitoring module, a security analysis module, and a risk analysis module that are connected in sequence. All three modules are connected to a database.
[0032] For ease of understanding, the following explains some key terms in this embodiment:
[0033] Network Adaptive Management System: This system is an intelligent network security protection system designed to perceive changes in the network environment and threat situation in real time, and to automatically adjust security policies and defense measures to achieve continuous protection, dynamic response and intelligent optimization of network security.
[0034] Database: This database is configured to store various types of data required for system operation, such as user behavior trajectories, historical event information, security assessment thresholds, and risk analysis-related parameters, and supports data retrieval and storage operations by various modules.
[0035] Network behavior: This term refers to all operations performed by a user in a network environment, such as file access, program execution, data transfer, system configuration changes, etc.
[0036] Behavioral trajectory: This term refers to a sequence of network behaviors performed by a user after logging into the system, which includes information such as the time, type, and target of the user's actions.
[0037] Historical event i: This term refers to a single or group of network behaviors with specific significance identified in the behavioral trajectory. The subscript "i" indicates the event number, i = 1, 2, ..., n, where n is a positive integer.
[0038] Event Element i: This term refers to the key data points extracted from historical event i that describe the characteristics of the event. These elements are used for subsequent security analysis and risk assessment.
[0039] Combination element: This term refers to a data unit formed by randomly selecting and combining data from the permission set e, privacy set e, and fluctuation set e, which is used to calculate the security coefficient.
[0040] Security factor: This term refers to the numerical value obtained after evaluating a single composite element, which reflects the security level of the network behavior segment represented by that composite element.
[0041] Security assessment value: This term refers to the value obtained by summing and averaging the security coefficients of all combined elements, which represents the overall security level of the entire network behavior.
[0042] The behavior monitoring module is used to monitor network behavior in real time. After detecting network behavior, it retrieves the behavior trajectory of the user who performed the network behavior after logging in and marks the historical network behavior in the behavior trajectory as historical event i. It extracts the event element i of historical event i, i = 1, 2, ..., n, where n is a positive integer. Event element i includes permission data i, privacy data i, and fluctuation data i. Permission data i is the difference between the lowest permission level corresponding to the attribute of historical event i and the permission level of the user who performed the behavior. Privacy data i is the file privacy level corresponding to historical event i. The process of obtaining fluctuation data i includes: marking L1 seconds after the completion of historical event i as the monitoring period, obtaining the network latency, jitter, and packet loss rate during the monitoring period, marking the network fluctuation level during the monitoring period according to the network latency, jitter, and packet loss rate, and marking the fluctuation level as fluctuation data i; and sending the event elements of all historical events corresponding to the network behavior to the security analysis module.
[0043] Event element i is a dataset used to describe and quantify historical network behavior characteristics. It serves as the fundamental input for the security analysis module to conduct network behavior security assessments, and its comprehensiveness and accuracy directly impact the validity of the assessment results. Event element i can contain data from multiple dimensions, such as information related to permissions, privacy, and network status, aiming to characterize the potential risks of network behavior from different perspectives.
[0044] Permission data *i* is a key indicator for measuring the risk level of historical event *i* at the permission level. It is reflected by quantifying the difference between the minimum permissions required for historical event *i* and the permissions actually possessed by the user executing it. For example, if the minimum permission level for an event is set to "administrator," while the permission level for the executing user is "regular user," then permission data *i* will reflect the risk of this permission mismatch. Permission data *i* can be calculated in various ways, including differences, ratios, and level mappings, but its core purpose is to reflect the degree of permission matching or the possibility of permission abuse. The minimum permission level corresponding to the attribute of historical event *i* refers to the minimum operational permissions or access level necessary to complete a specific historical event *i*. For example, for a historical event *i* of "modifying system configuration," its minimum permission level might be set to "system administrator"; for a historical event *i* of "accessing a regular document," its minimum permission level might be set to "regular user." This level is usually predefined by the system administrator or security policy and is associated with the sensitivity or importance of the event. The permission level of the executing user refers to the permission level possessed by the user actually executing historical event *i* in the current system. This permission level is typically determined by the authentication system upon user login and may be dynamically adjusted based on the user's role, group, or specific authorization. For example, a user might be assigned permission levels such as "Regular User," "Advanced User," or "Administrator." The difference is a quantitative comparison method used to calculate the difference between two values. Here, it specifically refers to the numerical difference between the lowest permission level corresponding to the historical event attribute i and the permission level of the executing user. By calculating the difference, the degree of matching between the executing user's permissions and the permissions required for the event can be intuitively reflected, thus providing a quantitative basis for permission risk assessment. For example, permission levels can be numerically denoted, such as "Regular User" as 1, "Advanced User" as 2, and "Administrator" as 3, and then subtraction can be performed.
[0045] Privacy data *i* is an indicator used to assess the impact of historical event *i* on data privacy. It directly reflects the sensitivity of the documents or data involved in historical event *i*. For example, if historical event *i* involves accessing a database containing personally identifiable information (PII), its privacy data *i* level will be higher; if it involves accessing publicly available, non-sensitive documents, its privacy data *i* level will be lower. The assignment of privacy data *i* can be based on preset privacy classification standards, such as "public," "internal," "confidential," and "top secret," and quantified into numerical values. Document privacy level is a classification or rating of the sensitivity of documents or data. This level is usually defined by an organization's security policy or data classification standards, aiming to identify the potential harm caused by the leakage or unauthorized access of different types of data. For example, document privacy levels can be divided into "public," "internal," "restricted," and "confidential," and each level can be assigned a corresponding numerical value to facilitate system quantification and risk assessment.
[0046] Fluctuation data i, as part of event element i, is used to reflect the stability or anomalies of the network environment when historical event i occurred. Although the specific acquisition process will be further described in subsequent implementations, its role here is to provide an indicator of network transmission quality or environmental anomalies, such as network latency, jitter, or packet loss rate. These indicators may foreshadow network attacks, resource exhaustion, or other abnormal behaviors, thus providing an additional risk dimension for security analysis.
[0047] The security analysis module is used to analyze the security of network behavior: It selects the m largest values from the permission data i, privacy data i, and fluctuation data i corresponding to all historical events i of the network behavior, obtaining permission data e, privacy data e, and fluctuation data e, where e = 1, 2, ..., m, m is a positive integer, and m < n; permission set e, privacy set e, and fluctuation set e are formed from the permission data e, privacy set e, and fluctuation set e, respectively; a data point is randomly selected from the permission set e, privacy set e, and fluctuation set e, and randomly combined to obtain several combination elements; the permission data e, privacy data e, and fluctuation data e in the combination elements form the analysis data row vector HX, HX = [permission data e, privacy data e, fluctuation data e], and a weight column vector QX is generated for the analysis data row vector, QX = [k1, k2, k3]. T The safety coefficient of the combined elements is obtained by performing a dot product calculation on the row vector HX and the weight column vector QX of the analysis data. The safety coefficients of all combined elements are summed and averaged to obtain the safety assessment value of the network behavior. The safety assessment threshold is retrieved from the database and compared with the safety assessment threshold. If the safety assessment value is less than the safety assessment threshold, the network behavior is determined to meet the safety requirements. If the safety assessment value is greater than or equal to the safety assessment threshold, the network behavior is determined to not meet the safety requirements. A risk analysis signal is then generated and sent to the risk analysis module.
[0048] Specifically, L1 seconds represents the length of time the network environment needs to be continuously monitored after historical event i has been executed. This time parameter is set to capture any instantaneous or short-term network performance fluctuations that may occur after the event. L1 seconds can be flexibly configured according to the actual network environment, event type, and risk sensitivity requirements. For example, for highly sensitive operations, L1 seconds can be set to a shorter time (e.g., 1 or 2 seconds) to quickly respond to instantaneous fluctuations; for operations that require observation of subsequent impacts, L1 seconds can be set to a longer time (e.g., 5 or 10 seconds) to comprehensively assess network stability. The monitoring period refers to the time window during which the system continuously monitors network performance within L1 seconds after historical event i has been executed. During this period, the system actively or passively collects various indicators related to network status. Setting the monitoring period ensures that fluctuation data is acquired in the immediate network environment after a specific event, thus more accurately reflecting the potential impact of the event on network performance. Network latency, jitter, and packet loss rate are key indicators for measuring network service quality (QoS). Latency refers to the time required for a data packet to travel from the source to the destination, reflecting the network's response speed. Jitter refers to the variation in data packet latency, reflecting the stability of network transmission. Packet loss rate refers to the proportion of data packets lost during transmission out of the total number of transmitted data packets, reflecting the reliability of network transmission. These metrics can be obtained in various ways, such as real-time packet capture analysis using a network protocol analyzer, data collection through integration of network performance monitoring tools into network devices, or periodic sending of test data packets and measurement of transmission performance by deploying probes or agents in the network. Fluctuation level is a quantitative indicator derived from a comprehensive evaluation of network latency, jitter, and packet loss rate obtained during the monitoring period. It aims to simplify complex network performance data into an easily understandable and comparable level to reflect the stability or anomaly of the network environment. Fluctuation level labeling can employ various methods. For example, multiple level ranges (such as low, medium, and high) can be preset and divided based on a weighted average of latency, jitter, and packet loss rate or a specific threshold; alternatively, machine learning models can be used to automatically identify and label different fluctuation levels by training on historical network performance data.
[0049] The following is a concrete example to illustrate this. Suppose the behavior monitoring module detects a certain network behavior and identifies 10 historical events i (n=10) from the user's post-login behavior trajectory. Each historical event i contains permission data i, privacy data i, and fluctuation data i. To generate the permission set e, privacy set e, and fluctuation set e, the security analysis module can set the value of m to 3. In practice, the security analysis module will first collect all permission data i corresponding to these 10 historical events i, for example, [5, 8, 2, 9, 4, 7, 1, 6, 3, 10]. Then, the system will select the 3 data with the largest values from these 10 permission data i (i.e., m=3) to obtain permission data e, for example, [10, 9, 8]. Similarly, a similar operation will be performed for privacy data i and fluctuation data i, selecting the 3 data with the largest values respectively to obtain privacy data e and fluctuation data e. For example, privacy data e might be [9.5, 9.2, 8.8], and fluctuation data e might be [0.8, 0.7, 0.6]. Ultimately, these filtered permission data e, privacy data e, and fluctuation data e will form permission set e, privacy set e, and fluctuation set e, respectively, for use in subsequent security assessments. In practice, this data filtering process can be completed by a dedicated data processing unit within the security analysis module. For example, it can quickly sort and truncate the data using an efficient sorting algorithm, or it can utilize streaming processing technology to obtain the largest m data points in real time by maintaining a fixed-size min-heap as the data is input.
[0050] Through the above technical solution, when generating the permission set e, privacy set e, and fluctuation set e, the security analysis module no longer blindly uses the event elements i of all historical events i. Instead, it selectively selects the m largest data values from the permission data i, privacy data i, and fluctuation data i corresponding to all historical events i of the network behavior. This streamlined and focused data processing method allows subsequent security analysis to concentrate on the key factors that have the most significant impact on network behavior security. This not only significantly reduces the amount of data that the security analysis module needs to process when performing random traversal combinations, thereby improving computational efficiency, but also avoids interference from unimportant or low-impact data on the security assessment results, enabling the security assessment value of network behavior to more accurately and realistically reflect its potential security risks. Therefore, this solution can effectively improve the response speed and decision-making quality of the entire network adaptive management system in making security judgments, enabling it to provide more timely and accurate protection in the face of complex and ever-changing network threats.
[0051] The risk analysis module is used to analyze the risk characteristics of online behavior: It labels the permission data e, privacy data e, and volatility data e in the combined elements as permission risk data, privacy risk data, and volatility risk data, respectively. It labels the event element i in historical events i that contains permission risk data, privacy risk data, or volatility risk data as a latent element. It labels the ratio of the number of latent elements to n as the latent risk coefficient. It retrieves the latent risk threshold from the database and compares the latent risk coefficient with the latent risk threshold: if the latent risk coefficient is less than the latent risk threshold, the historical event risk elements of the online behavior are considered concentrated, and the risk characteristics of the online behavior are labeled as explicit risks; if the latent risk coefficient is greater than or equal to the latent risk threshold, the historical event risk elements of the online behavior are considered dispersed, and the risk characteristics of the online behavior are labeled as latent risks. The risk characteristics of the online behavior are then sent to the administrator's mobile terminal.
[0052] The terms "permission risk data," "privacy risk data," and "volatility risk data" are redefinitions of permission data (e), privacy data (e), and volatility data (e) in the combined elements, aiming to highlight their potential threats from a risk management perspective. Permission risk data reflects potential security vulnerabilities related to user permissions, privacy risk data reveals the possibility of sensitive information leakage, and volatility risk data indicates potential security risks caused by network instability. This data can be identified by adding specific risk labels or type identifiers to the raw data items in the data processing flow. For example, adding a field to the data structure to store its marker as risk data, or classifying it into a dedicated risk data set during data transmission or storage. Latent elements refer to those event elements i in historical event i that, while not directly causing the security assessment value to exceed limits, contain permission risk data, privacy risk data, or volatility risk data. These elements represent potential, easily overlooked risks that may foreshadow deeper security problems. Identification of latent elements can be achieved by traversing each event element i of historical event i and checking whether it contains any of the above types of risk data. If included, event element i is marked in the database or memory, for example, by setting a Boolean flag "is_implicit_risk_element" to true, or by adding it to a dedicated "implicit element list". The implicit risk coefficient is a quantitative indicator used to measure the proportion of event elements i marked as implicit elements among all historical events i. This coefficient reflects the prevalence or distribution of potential risks in network behavior, where n represents the total number of all historical events i. The implicit risk coefficient can be calculated by counting the total number of event elements i marked as implicit elements and then dividing it by the total number of historical events n. This calculation can be performed internally within the risk analysis module, and the result can be stored as a floating-point number or a percentage. Risk characteristic labeling classifies or qualitatively describes the risk type of network behavior based on the magnitude of the implicit risk coefficient. This helps managers quickly understand the nature of the risk—whether it is explicit and easily discovered, or implicit and requires in-depth investigation. Specific labels can be compared using preset thresholds. For example, if the latent risk coefficient is below a certain threshold, it is marked as "explicit risk"; if it is above or equal to the threshold, it is marked as "latent risk". The label can be a string tag, such as "explicit risk" or "latent risk", or a corresponding enumerated value. Sending the risk characteristics of network behavior to the mobile terminals of administrators is a notification mechanism for risk analysis results, ensuring that administrators can promptly obtain and process risk information about network behavior. Mobile terminals, as convenient receiving devices, can achieve real-time or near real-time risk alerts, thereby improving response efficiency.This sending process can be implemented through various communication protocols and technologies. For example, by integrating an SMS gateway, risk characteristic information can be sent to a designated mobile phone number in the form of a text message; or if the administrator has installed a specific mobile application, risk notifications can be sent to their mobile terminal through an application push service; or risk characteristic information can be sent to the administrator's mobile email address via email notification.
[0053] The following example will provide a more detailed explanation of the above technical solution:
[0054] Suppose that in a corporate network environment, user A performs a series of network operations within a short period of time, including accessing sensitive files, attempting to install unauthorized software, and transferring large amounts of data. Traditional network security systems might only perform static rule checks on each individual operation; for example, if accessing sensitive files requires specific permissions, the system would check whether user A has those permissions. However, this approach cannot assess user A's short-term behavior as a whole, nor can it identify potential risk patterns underlying these behaviors.
[0055] The network adaptive management system based on dynamic network security in this embodiment is deployed in the enterprise network. When user A performs the above network operation:
[0056] First, the behavior monitoring module is activated to monitor user A's online behavior in real time. This module continuously records all of user A's actions after logging in, forming a behavioral trajectory. For example, user A accessing a sensitive file is marked as historical event 1, attempting to install software is marked as historical event 2, and a large amount of data transfer is marked as historical event 3.
[0057] Secondly, after receiving these event elements, the security analysis module begins to analyze the security of user A's network behavior. Based on the event elements of historical events 1, 2, and 3, this module generates a permission set e, a privacy set e, and a fluctuation set e. For example, the permission set e might contain all permission levels involved in user A's operations; the privacy set e might contain the privacy level information of all files or data involved in these operations; and the fluctuation set e might contain network status information such as network connection latency and jitter during these operations. Subsequently, the security analysis module randomly selects data from these sets and combines them to form multiple combined elements. For example, a combined element might consist of "permission levels when accessing sensitive files," "data types of privacy involved when installing software," and "network jitter during data transmission." For each combined element, the security analysis module calculates its security coefficient. For example, a preliminary security coefficient can be obtained by simply weighting and summing the original values of each element in the combined element. After calculating the security coefficients of all combined elements, the security analysis module sums these security coefficients and takes the average to obtain the comprehensive security assessment value of user A's current network behavior. Assume this security assessment value is calculated to be 75. The security analysis module then compares the security assessment value with the preset security requirements.
[0058] Finally, since the security analysis module determines that user A's network behavior does not meet security requirements, the risk analysis module is activated to analyze the risk characteristics of this network behavior. The risk analysis module can label user A's network behavior as a risk based on the security assessment value provided by the security analysis module and the combined factors that led to the unsatisfactory assessment value. For example, if the high security assessment value is mainly due to a significant contribution from permission-related factors in the behavior of "attempting to install unauthorized software," the risk analysis module may label this network behavior as "permission abuse risk." This labeling helps administrators quickly locate the root cause of the risk and take targeted measures, such as immediately restricting user A's permissions or conducting a security audit.
[0059] As can be seen from the above examples, this system continuously tracks user behavior and extracts event elements through the behavior monitoring module, comprehensively evaluates multi-dimensional event elements through the security analysis module, and identifies risk characteristics through the risk analysis module. This enables the system to perform an overall security assessment and risk characteristic analysis of a series of network behaviors of users in a short period of time, thus providing a more comprehensive and timely network security early warning capability than traditional static rule checks.
[0060] Based on the above examples, the overall technical concept of this embodiment demonstrates a significant technical contribution. Existing technologies, such as the invention patent with publication number CN119172100B, primarily focus on network security processing based on comprehensive security impact scores and dynamic IP update results, solving the problem of inaccurate network risk identification under traditional static IP address management. However, this existing technology has limitations at the user behavior level; it cannot perform linear tracking from the perspective of the operating user, conduct overall risk assessment of the short-term behavior of the same network user, or identify risk characteristics based on the distribution of event risk factors, resulting in low comprehensiveness and timeliness of network security early warnings.
[0061] The system in this embodiment, by introducing a behavior monitoring module, can monitor and track the behavior trajectory of a user after logging in in real time, and mark historical network behaviors as historical events i, extracting event elements i. This allows the system to linearly track and record a series of operations performed by user A in a short period of time, such as accessing sensitive files, installing software, and transferring data, from the user's perspective, overcoming the shortcomings of existing technologies that cannot perform linear tracking from the user's perspective.
[0062] Example 2: Figure 2 As shown, the network adaptive management method based on dynamic network security includes the following steps:
[0063] Step S1: Real-time monitoring of network behavior: After detecting network behavior, retrieve the behavior trajectory of the user who performed the network behavior after logging in and extract historical events i and event elements i;
[0064] Step S2: Analyze the security of network behavior: Generate element combinations and obtain the security coefficient of the element combinations, and determine the security of network behavior based on the security factors of all element combinations;
[0065] Step S3: Analyze the risk characteristics of network behavior: Obtain the implicit risk coefficient of network behavior and mark the risk characteristics of network behavior through the implicit risk coefficient.
[0066] The network adaptive management system based on dynamic network security, when working, after detecting network behavior, retrieves the behavior trajectory of the user who performed the network behavior after logging in and extracts historical events i and event elements i; generates element combinations and obtains the security coefficient of the element combinations, judges the security of network behavior based on the security elements of all element combinations; obtains the implicit risk coefficient of network behavior, and marks the risk characteristics of network behavior through the implicit risk coefficient.
[0067] The above description is merely an example and illustration of the structure of the present invention. Those skilled in the art can make various modifications or additions to the specific embodiments described, or use similar methods to replace them, as long as they do not deviate from the structure of the invention or exceed the scope defined in the claims, all of which should fall within the protection scope of the present invention.
[0068] In the description of this specification, references to terms such as "an embodiment," "example," "specific example," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0069] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to any specific implementation. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.
Claims
1. A network adaptive management system based on dynamic cyber security, characterized in that, It includes a behavior monitoring module, a security analysis module, and a risk analysis module that are connected in sequence via communication. The behavior monitoring module, the security analysis module, and the risk analysis module are all connected in communication with a database. The behavior monitoring module is used to monitor network behavior in real time: after detecting network behavior, it retrieves the behavior trajectory of the user who performed the network behavior after logging in and marks the historical network behavior in the behavior trajectory as historical event u, extracts the event element i of historical event u, i=1,2,...,n, where n is a positive integer; and sends the event element i of all historical events u corresponding to the network behavior to the security analysis module. The security analysis module is used to analyze the security of network behavior: it generates a permission set M1, a privacy set M2, and a fluctuation set M3 based on the event element i of historical event u. Randomly select one data point from the permission set M1, privacy set M2, and fluctuation set M3, and randomly traverse and combine them to obtain several combination elements. Obtain the security coefficient of the combination elements, sum and average the security coefficients of all combination elements to obtain the security assessment value of the network behavior, and use the security assessment value to determine whether the security of the network behavior meets the requirements. The risk analysis module is used to analyze the risk characteristics of network behavior; Event element i includes permission data Sj1, privacy data Sj2, and fluctuation data Sj3. Permission data Sj1 is the difference between the lowest permission level corresponding to the historical event u attribute and the permission level of the executing user. Privacy data Sj2 represents the file privacy level corresponding to historical event u; The process of acquiring fluctuation data Sj3 includes: marking L1 seconds after the historical event u is completed as the monitoring period, acquiring the network latency, jitter and packet loss rate during the monitoring period, marking the network fluctuation level during the monitoring period based on the network latency, jitter and packet loss rate, and marking the fluctuation level as fluctuation data Sj3. The generation process of permission set M1, privacy set M2, and fluctuation set M3 includes: selecting the m largest data from the permission data Sj1, privacy data Sj2, and fluctuation data Sj3 corresponding to all historical events u of the network behavior, and obtaining permission index data Sy1, privacy index data Sy2, and fluctuation index data Sy3, e=1,2,…,m, where m is a positive integer and m<n; and forming permission set M1, privacy set M2, and fluctuation set M3 from permission index data Sy1, privacy index data Sy2, and fluctuation index data Sy3 respectively. The process of obtaining the safety coefficient of the combined elements includes: forming an analysis data row vector HX from the permission index data Sy1, privacy index data Sy2, and volatility index data Sy3 in the combined elements, where HX = [permission index data Sy1, privacy index data Sy2, volatility index data Sy3]; generating a weight column vector QX for the analysis data row vector, where QX = [k1, k2, k3]T; and calculating the safety coefficient of the combined elements by performing a dot product between the analysis data row vector HX and the weight column vector QX.
2. The network adaptive management system based on dynamic network security according to claim 1, characterized in that, The specific process for determining whether the security of network behavior meets the requirements includes: retrieving the security assessment threshold from the database, comparing the security assessment value of the network behavior with the security assessment threshold; if the security assessment value is less than the security assessment threshold, the network behavior is determined to meet the security requirements; if the security assessment value is greater than or equal to the security assessment threshold, the network behavior is determined to not meet the security requirements, a risk analysis signal is generated, and the risk analysis signal is sent to the risk analysis module.
3. The network adaptive management system based on dynamic network security according to claim 2, characterized in that, The specific process of analyzing the risk characteristics of network behavior by the risk analysis module includes: marking the permission index data Sy1, privacy index data Sy2, and volatility index data Sy3 in the combined elements as permission risk data, privacy risk data, and volatility risk data, respectively; marking the event element i in the historical event u that contains permission risk data, privacy risk data, or volatility risk data as a latent element; marking the ratio of the number of latent elements to n as the latent risk coefficient; marking the risk characteristics of network behavior through the latent risk coefficient; and sending the risk characteristics of network behavior to the mobile terminal of the administrator.
4. The network adaptive management system based on dynamic network security according to claim 3, characterized in that, The specific process of marking the risk characteristics of online behavior includes: retrieving the implicit risk threshold from the database, comparing the implicit risk coefficient with the implicit risk threshold; if the implicit risk coefficient is less than the implicit risk threshold, it is determined that the historical event risk elements of the online behavior are concentrated, and the risk characteristics of the online behavior are marked as explicit risks; if the implicit risk coefficient is greater than or equal to the implicit risk threshold, it is determined that the historical event risk elements of the online behavior are dispersed, and the risk characteristics of the online behavior are marked as implicit risks; and sending the risk characteristics of the online event to the mobile terminal of the administrator.
Citation Information
Patent Citations
Network security processing method and system based on dynamic network
CN119172100B
Intelligent terminal security risk assessment system and method
CN118828514A
Risk assessment and prediction method based on network security situation awareness system
CN119324822A