Full lifecycle monitoring and security management system for classified carriers

By constructing a secure digital twin, the operational behavior of classified carriers can be simulated and evaluated in real time, solving the problem of insufficient dynamic modeling and risk assessment in existing technologies, and achieving efficient security risk identification and adaptive management.

CN121659312BActive Publication Date: 2026-04-21ZHILIAN INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ZHILIAN INFORMATION TECH CO LTD
Filing Date
2026-02-09
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing technologies lack the ability to dynamically model the operational status and behavior of classified carriers, making it difficult to achieve real-time simulation and risk assessment. Furthermore, they lack a probabilistic risk reasoning mechanism, resulting in limited security response effectiveness.

Method used

Construct a secure digital twin, define a normal behavior model through multi-dimensional monitoring data, simulate operational behavior in real time, perform Bayesian posterior anomaly diagnosis, generate posterior probability values ​​and type labels for abnormal risks, trigger hierarchical collaboration and inference, generate security control instructions, and perform linkage optimization through the collaboration effectiveness index.

Benefits of technology

It enables real-time simulation and post-risk assessment of the operation of classified carriers, improves the response efficiency of security risk identification, quantifies the accuracy of anomaly identification, and achieves adaptive management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121659312B_ABST
    Figure CN121659312B_ABST
Patent Text Reader

Abstract

This application provides a full-life-cycle monitoring and security management system for classified information carriers, which relates to the field of computer information security technology. By constructing a secure digital twin and a normal behavior model, synchronizing the operation behavior sequence to the secure digital twin for simulated execution to generate a behavior deviation sequence, performing posterior anomaly diagnosis on the behavior deviation sequence and the normal behavior model to obtain a posterior probability value and a type label, triggering hierarchical collaboration and deduction through the posterior probability value and the type label to obtain a security control instruction, and then executing feedback data to determine the collaborative efficiency index. Using the collaborative efficiency index to perform linkage optimization on the normal behavior model, the prior parameters in Bayesian posterior anomaly diagnosis, and the policy rules in hierarchical collaboration, this application can realize real-time simulation and risk posterior evaluation of classified information carrier operation behaviors in a secure digital twin, so as to improve the response efficiency of classified information carrier security risk identification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer information security technology, and more specifically, to a full lifecycle monitoring and security management system for classified carriers. Background Technology

[0002] With the rapid development of information technology, information data has become an important strategic resource. To prevent the leakage of classified information during storage, transmission and use, computer information security technology has emerged. By monitoring, analyzing and protecting information systems and their operating environments, it ensures the confidentiality, integrity and availability of information, and has become an important part of the information system security protection system.

[0003] As crucial objects carrying classified information, classified carriers are susceptible to security risks arising from unauthorized operations, unauthorized access, or abnormal behavior throughout their entire lifecycle, from procurement and registration to use, transfer, maintenance, and eventual disposal. Therefore, full lifecycle monitoring and security management of classified carriers is a vital technical means to ensure the security of classified information. Log auditing, rule verification, or manual inspection can monitor and manage the operational status and behavior of classified carriers. However, existing technologies primarily focus on post-hoc analysis of historical logs, lacking the ability to dynamically model the operational status and behavior of classified carriers, making it difficult to reconstruct and predict complex operational behaviors in real time. Furthermore, existing technologies generally rely on fixed thresholds or empirical rules for anomaly detection, lacking quantitative assessment of the degree of behavioral deviation and probabilistic risk reasoning mechanisms. In addition, using pre-set response strategies lacks the ability to extrapolate and evaluate the effects of different intervention strategies and the ability to adaptively optimize based on feedback results, thus limiting overall security response effectiveness. Therefore, how to achieve real-time simulation and risk post-assessment of the operation behavior of classified carriers in a secure digital twin, so as to improve the response efficiency of the identification of security risks of classified carriers, is a challenge faced by the industry. Summary of the Invention

[0004] This application provides a full lifecycle monitoring and security management system for classified carriers, which can realize real-time simulation and risk post-evaluation of the operation behavior of classified carriers in a secure digital twin, so as to improve the response efficiency of identifying security risks of classified carriers.

[0005] This application provides a full lifecycle monitoring and security management system for classified carriers, the monitoring and security management system including:

[0006] The twin monitoring module is used to construct a secure digital twin based on multi-dimensional monitoring data of classified carriers, and to define a normal behavior model in the secure digital twin;

[0007] The behavior simulation module is used to synchronize the real-time operation behavior sequence of the classified carrier to the secure digital twin for simulated execution, thereby generating a behavior deviation sequence.

[0008] The posterior anomaly diagnosis module is used to perform Bayesian posterior anomaly diagnosis on the behavioral deviation sequence and the normal behavior model to obtain the posterior probability value and type label of the abnormal risk.

[0009] The safety control feedback module is used to trigger hierarchical collaboration and inference through the posterior probability value and the type label, and then generate safety control instructions based on the inference results, and determine the collaboration efficiency index based on the execution feedback data of the safety control instructions;

[0010] The linkage optimization module is used to perform linkage optimization of the normal behavior model, the prior parameters in the Bayesian posterior anomaly diagnosis, and the strategy rules in the hierarchical collaboration using the collaborative efficiency index, so as to realize adaptive management of the security monitoring of classified carriers throughout their entire life cycle.

[0011] In this embodiment, the multi-dimensional monitoring data of the classified carrier includes: unique identifier, operation behavior events, physical state parameters, environmental temperature and humidity, and network access records; the multi-dimensional monitoring data is collected through sensor networks and business system log interfaces.

[0012] In this embodiment, constructing a secure digital twin based on multi-dimensional monitoring data of classified carriers specifically includes:

[0013] The multi-dimensional monitoring data is spatiotemporally aligned and consistency verified to obtain standardized state time-series data;

[0014] A secure digital twin is obtained by mapping the state time sequence data and the three-dimensional geometric model of the classified carrier.

[0015] In this embodiment, defining a normal behavior model in the secure digital twin specifically includes:

[0016] Feature extraction and pattern learning are performed on the compliant operational behavior sequence of the security digital twin within a historical period to obtain a behavior baseline rule base.

[0017] A normal behavior model is generated by the rule engine based on the behavior baseline rule base.

[0018] In this embodiment, the real-time operation behavior sequence of a classified carrier refers to an ordered set of operation events of the classified carrier sorted by timestamps. The real-time operation behavior sequence includes: operation subject, operation type, operation object, and operation time. The real-time operation behavior sequence is obtained by parsing the operation behavior events and network access records in the multi-dimensional monitoring data and integrating the audit logs associated with the classified carrier.

[0019] In this embodiment, synchronizing the real-time operational behavior sequence of the classified carrier to the secure digital twin for simulated execution, thereby generating a behavior deviation sequence, specifically includes:

[0020] Based on the secure digital twin, the real-time operation behavior sequence is analyzed to obtain a virtual operation instruction set;

[0021] The virtual operation instruction set is simulated and executed in the secure digital twin to obtain the simulation state result;

[0022] The simulated state results are compared with the expected state of the normal behavior model to obtain the state deviation values ​​of different operational behaviors, and then a behavior deviation sequence is generated.

[0023] In this embodiment, performing Bayesian posterior anomaly diagnosis on the behavioral deviation sequence and the normal behavior model to obtain the posterior probability value and type label of the abnormal risk specifically includes:

[0024] The Bayesian prior probability distribution is determined based on the normal behavior model and historical security event data.

[0025] Determine the likelihood probability of the behavioral deviation sequence in the Bayesian prior probability distribution;

[0026] The posterior probability value of the abnormal risk is calculated using the Bayesian prior probability distribution and the likelihood probability.

[0027] The posterior probability value is compared with a preset threshold range to obtain the type label of the abnormal risk.

[0028] In this embodiment, triggering hierarchical collaboration and inference through the posterior probability value and the type label, and then generating security control instructions based on the inference results, specifically includes:

[0029] A hierarchical response rule base is constructed, which generates a set of intervention strategies based on the type label and the posterior probability value.

[0030] Perform simulations on all intervention strategies in the set of intervention strategies to obtain the changes in the carrier state after each intervention strategy is implemented;

[0031] The effectiveness of the carrier state changes after the implementation of each intervention strategy is evaluated, and the deduction results of the effectiveness evaluation are obtained.

[0032] Based on the simulation results, a target intervention strategy is selected from the set of intervention strategies, and a safety control instruction is generated according to the target intervention strategy.

[0033] In this embodiment, determining the collaborative efficiency index based on the execution feedback data of the security control command specifically includes:

[0034] The response results and status change data of the classified carrier to the security control command are collected to obtain the execution feedback vector;

[0035] The execution feedback vector is decomposed and calculated to obtain the threat suppression rate, response time ratio, and resource utilization rate.

[0036] The threat suppression rate, response timeliness, and resource utilization rate are smoothly corrected based on the historical performance index to obtain the collaborative performance index.

[0037] In this embodiment, the collaborative effectiveness index is used to optimize the prior parameters in the normal behavior model, the Bayesian posterior anomaly diagnosis, and the strategy rules in the hierarchical collaboration, thereby achieving adaptive management of the full lifecycle security monitoring of classified carriers. Specifically, this includes:

[0038] A time-series analysis was performed on the constituent dimensions and changing trends of the collaborative effectiveness index to obtain the optimization factors;

[0039] Based on the correlation mapping relationship between the tuning factor, the normal behavior model, the prior parameters in Bayesian posterior anomaly diagnosis, and the strategy rules in hierarchical collaboration, a set of adjustment instructions for parameters and rules is generated synchronously.

[0040] The baseline threshold of the normal behavior model, the parameters of the Bayesian prior probability distribution, and the policy matching conditions in the hierarchical response rule base are updated by adjusting the instruction set to complete adaptive management within the monitoring period.

[0041] The technical solutions provided by the embodiments disclosed in this application have the following beneficial effects:

[0042] A security digital twin is constructed based on multi-dimensional monitoring data of classified carriers, and a normal behavior model is defined within the security digital twin. The real-time operational behavior sequence of the classified carriers is synchronized to the security digital twin for simulated execution, thereby generating a behavior deviation sequence. Bayesian posterior anomaly diagnosis is performed on the behavior deviation sequence and the normal behavior model to obtain the posterior probability value and type label of the anomaly risk. Hierarchical collaboration and inference are triggered by the posterior probability value and the type label, and security control instructions are generated based on the inference results. The collaboration effectiveness index is determined based on the execution feedback data of the security control instructions. The collaboration effectiveness index is used to optimize the normal behavior model, the prior parameters in the Bayesian posterior anomaly diagnosis, and the strategy rules in the hierarchical collaboration, thereby achieving adaptive management of the security monitoring of classified carriers throughout their entire lifecycle.

[0043] Therefore, this application enables real-time simulation and post-hoc risk assessment of the operational behavior of classified carriers within a secure digital twin, thereby improving the response efficiency of identifying security risks of classified carriers. Firstly, by collecting multi-dimensional monitoring data of classified carriers and constructing a secure digital twin, the physical state, operational behavior, and operating environment of the classified carriers are uniformly mapped in virtual space. A normal behavior model is defined within the secure digital twin, providing a high-fidelity, computable virtual mapping foundation for the actual operating state of the classified carriers. Secondly, by synchronizing the real-time operational behavior sequence of the classified carriers to the secure digital twin for simulation, the operational behavior can be reenacted and its state evolution analyzed in a virtual environment. By comparing the simulation results with the expected state of the normal behavior model, a behavior deviation sequence is generated, which facilitates the quantitative characterization of the degree of operational behavior deviation. Thirdly, by analyzing the behavior deviation sequence and the normal behavior model... Bayesian posterior anomaly diagnosis transforms deviations in operational behavior into posterior probability values ​​and corresponding type labels for anomaly risks. This shifts security risk assessment from qualitative judgment to quantitative analysis based on probabilistic reasoning, improving the accuracy of anomaly identification and reducing the probability of misjudgments and omissions. Then, by utilizing posterior probability values ​​and type labels to trigger hierarchical collaboration and deduction, different security intervention strategies are evaluated and deduced within a security digital twin. Security control commands are generated based on the deduction results. Simultaneously, the collaboration effectiveness index is determined through analysis of security control command execution feedback data, enabling quantitative evaluation of security response effectiveness and avoiding the problems of fixed control strategies and difficulty in assessing response effects. Finally, by using the collaboration effectiveness index to optimize the normal behavior model, the prior parameters in Bayesian posterior anomaly diagnosis, and the strategy rules in hierarchical collaboration, adaptive management of the entire lifecycle security monitoring of classified materials is achieved.

[0044] In summary, the technical solution adopted in this application can realize real-time simulation and risk post-evaluation of the operation behavior of classified carriers in a secure digital twin, so as to improve the response efficiency of identifying security risks of classified carriers. Attached Figure Description

[0045] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0046] Figure 1 This is a module structure diagram of the full lifecycle monitoring and security management system for classified carriers provided in this application;

[0047] Figure 2This is a flowchart illustrating the process of determining a sequence of behavioral deviations in some embodiments of this application;

[0048] Figure 3 This is a flowchart illustrating the process of determining the posterior probability value and type label of anomaly risk in some embodiments of this application. Detailed Implementation

[0049] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0050] This application provides a full lifecycle monitoring and security management system for classified carriers. Its core is the construction of a secure digital twin based on multi-dimensional monitoring data of the classified carrier, and the definition of a normal behavior model within the secure digital twin. The real-time operational behavior sequence of the classified carrier is synchronized to the secure digital twin for simulated execution, thereby generating a behavior deviation sequence. Bayesian posterior anomaly diagnosis is performed on the behavior deviation sequence and the normal behavior model to obtain posterior probability values ​​and type labels for abnormal risks. Hierarchical collaboration and deduction are triggered through the posterior probability values ​​and type labels, and security control commands are generated based on the deduction results. A collaboration effectiveness index is determined based on the execution feedback data of the security control commands. The collaboration effectiveness index is used to optimize the normal behavior model, the prior parameters in the Bayesian posterior anomaly diagnosis, and the strategy rules in the hierarchical collaboration, thereby achieving adaptive management of the full lifecycle security monitoring of classified carriers.

[0051] To better understand the above technical solutions, a detailed description of the technical solutions will be provided below in conjunction with the accompanying drawings and specific embodiments. (Refer to...) Figure 1 As shown in the figure, this is a module structure diagram of the full lifecycle monitoring and security management system for classified carriers provided in this application. The monitoring and security management system includes: a twin monitoring module 100, a behavior simulation module 200, a post-hoc anomaly diagnosis module 300, a security control feedback module 400, and a linkage optimization module 500, which are described below:

[0052] The twin monitoring module 100 is used to construct a secure digital twin based on multi-dimensional monitoring data of classified carriers, and to define a normal behavior model in the secure digital twin.

[0053] It should be noted that, in this application, the multi-dimensional monitoring data of classified carriers includes: unique identifiers, operational events, physical state parameters, environmental temperature and humidity, and network access records. This multi-dimensional monitoring data is collected through sensor networks and business system log interfaces. The sensor network refers to an Internet of Things (IoT) sensing layer formed by deploying various types of sensing devices in the physical storage space, circulation nodes, and usage environment of the classified carrier. The sensor network includes: electronic tag readers, temperature and humidity sensors, and physical state sensors. Electronic tag readers are used to read the unique identifiers from the electronic tags on the classified carrier; temperature and humidity sensors are used to collect environmental temperature and humidity data; and physical state sensors are used to collect physical state parameters. The business system log interface refers to a standardized data access channel provided by classified carrier management information systems, office automation systems, access control systems, network auditing systems, etc., to obtain operation and access records related to the carrier. The business system log interface can extract operational events and network access records through application programming interfaces and database connections.

[0054] In this embodiment, the construction of a secure digital twin based on multi-dimensional monitoring data of classified carriers can be carried out in the following manner:

[0055] The multi-dimensional monitoring data is spatiotemporally aligned and consistency verified to obtain standardized state time-series data;

[0056] A secure digital twin is obtained by mapping the state time sequence data and the three-dimensional geometric model of the classified carrier.

[0057] In practice, firstly, the multi-dimensional monitoring data is spatiotemporally aligned and consistency verified using timestamp alignment and data cleaning techniques. This allows the time series table, composed of all aligned and verified data items (including timestamps, carrier identifiers, and various parameter values) arranged in chronological order, to serve as standardized state time series data. Then, a predefined three-dimensional geometric model of the classified carrier is loaded. This three-dimensional geometric model is a digital three-dimensional mesh model created using 3D modeling software (such as SolidWorks) based on the actual physical dimensions and structural characteristics of the classified carrier. A dynamic mapping engine is established using digital twin technology. This dynamic mapping engine maps the standardized state time series data to the physical entity, creating a real-time, synchronous, computable, and interactive secure digital twin.

[0058] It should be noted that the standardized state time-series data in this application refers to a structured data set arranged in chronological order, formed by unifying the time of multi-source heterogeneous monitoring data, standardizing the format, and correcting the logic; a secure digital twin refers to a digital model created in a virtual information space that maintains high fidelity with the classified carrier in terms of geometric shape, physical attributes, operating rules, and real-time status. By constructing a secure digital twin, a computational basis can be provided for lossless reproduction, analysis, and prediction of the real behavior of the classified carrier in virtual space.

[0059] In this embodiment, defining the normal behavior model in the secure digital twin can be done in the following way:

[0060] Feature extraction and pattern learning are performed on the compliant operational behavior sequence of the security digital twin within a historical period to obtain a behavior baseline rule base.

[0061] A normal behavior model is generated by the rule engine based on the behavior baseline rule base.

[0062] In specific implementation, firstly, all operation records marked as "compliant" within the historical period are filtered from the historical state time-series database of the secure digital twin. Then, each operation event and its associated carrier state data are concatenated into a continuous sequence of compliant operation behaviors according to time sequence. Whether an operation record is "compliant" and the historical period can be pre-set based on the actual security management needs of the classified carrier. Next, features are extracted from each compliant operation behavior sequence using database queries, including: operation type, time period of operation, carrier physical state during operation, changes in environmental parameters before and after the operation, and statistical characteristics of the operation itself (such as average time consumption). Unsupervised pattern learning can be performed on the extracted features of all compliant operation behavior sequences using clustering algorithms (such as K-Means). Behavior sequences with similar features can be classified into the same cluster, and all clusters can be used as a baseline rule base for behavior. Then, all rules in the baseline rule base are loaded into the knowledge base of a rule engine (such as the open-source rule engine Drools). The rule engine with all rules loaded can then be used as a normal behavior model. The rule engine receives context as input, which includes the current time, the current state of the carrier, and the attributes of associated tasks. By performing rule matching in the knowledge base through the rule engine, all compliance rules triggered under the context conditions can be found.

[0063] It should be noted that the behavioral baseline rule base in this application is a set of formalized rules used to describe the standard operating modes and state change patterns that classified carriers should follow in various typical scenarios; the normal behavior model refers to a quantitative evaluation model of the expected behavioral norms of classified carriers, which is a reference standard that dynamically evolves with the carrier's state, task stage and environmental conditions, and is used to accurately compare the real-time operational behavior sequence later.

[0064] The behavior simulation module 200 is used to synchronize the real-time operation behavior sequence of the classified carrier to the secure digital twin for simulation execution, thereby generating a behavior deviation sequence.

[0065] It should be noted that, in this application, the real-time operation behavior sequence of a classified carrier refers to an ordered set of operation events of the classified carrier sorted by timestamps. The real-time operation behavior sequence includes: operation subject, operation type, operation object, and operation time. The real-time operation behavior sequence is obtained by parsing operation behavior events and network access records in multi-dimensional monitoring data and integrating the audit logs associated with the classified carrier. The audit logs associated with the classified carrier refer to event log files generated by the operating system, database system, and specific classified application software (such as document encryption system and CD burning audit system) during operation. The audit logs include: process ID, user identity, operation subject, operation type, operation result, and timestamp.

[0066] Preferred, Reference Figure 2 As shown in the figure, this is a flowchart illustrating the process of determining the behavioral deviation sequence in this embodiment. In this embodiment, the real-time operational behavior sequence of the classified carrier is synchronized to the secure digital twin for simulated execution, thereby generating the behavioral deviation sequence. This can be achieved through the following steps:

[0067] First, in step S21, the real-time operation behavior sequence is parsed based on the secure digital twin to obtain a virtual operation instruction set;

[0068] Then, in step S22, the virtual operation instruction set is simulated and executed in the secure digital twin to obtain the simulation state result;

[0069] Finally, in step S23, the simulated state results are compared with the expected state of the normal behavior model to obtain the state deviation values ​​of different operating behaviors, and then a behavior deviation sequence is generated.

[0070] In practical implementation, firstly, the real-time operation behavior sequence is a set of operation events arranged in timestamp order. Each operation event includes: operation subject, operation type, operation object, and operation time information. The real-time operation behavior sequence is parsed line by line using preset behavior parsing rules, mapping each operation event into a standardized instruction format that can be recognized and executed by the secure digital twin. For example, operation events such as "file copy," "device access," and "permission change" can be parsed into corresponding read / write instructions, interface call instructions, or status change instructions. Through the above parsing and mapping process, the real-time operation behavior sequence can be transformed into a structured set of operation instructions, which is then used as a virtual operation instruction set. Finally, each virtual operation instruction in the virtual operation instruction set can be sequentially loaded into the secure digital twin for simulation. During the simulation, state parameters can be updated based on the secure digital twin, such as the carrier's usage status, access status, connection status, or permission status. After each virtual operation instruction is executed, the state change result of the secure digital twin is recorded as the simulated state result. Finally, the expected state parameter set under the same operating conditions can be obtained based on the normal behavior model, and the expected state parameter set is compared item by item with the corresponding state parameters in the simulated state result. By calculating the difference between the simulated state parameters and the expected state parameters, including the difference in state change amplitude, execution order, and duration, the difference result corresponding to each operation behavior is quantified as a state deviation value. Then, according to the time order of the real-time operation behavior sequence, all state deviation values ​​are sorted and combined into a time series data behavior deviation sequence.

[0071] It should be noted that the virtual operation instruction set in this embodiment is a standardized set of instructions executed in the secure digital twin, which can eliminate the interface differences between the real operating environment and the virtual simulation environment; the simulated state result refers to the carrier state change data obtained by the secure digital twin after executing the virtual operation instruction set, which is used to describe the state evolution process of the classified carrier in the virtual environment; the expected state of the normal behavior model refers to the standard state change result of the classified carrier in the secure digital twin under compliant operating conditions, which is used as a benchmark for behavior comparison; the behavior deviation sequence refers to the set of state deviation values ​​arranged in the order of operation time, which is used to characterize the overall deviation of the classified carrier's operating behavior from the normal behavior model, providing a quantitative input basis for anomaly risk assessment.

[0072] The posterior anomaly diagnosis module 300 is used to perform Bayesian posterior anomaly diagnosis on the behavioral deviation sequence and the normal behavior model to obtain the posterior probability value and type label of the abnormal risk.

[0073] Preferred, Reference Figure 3As shown in the figure, this is a flowchart illustrating the process of determining the posterior probability value and type label of abnormal risk in this embodiment. In this embodiment, the Bayesian posterior anomaly diagnosis of the behavioral deviation sequence and the normal behavior model to obtain the posterior probability value and type label of abnormal risk can be achieved through the following steps:

[0074] First, in step S31, a Bayesian prior probability distribution is determined based on the normal behavior model and historical security event data.

[0075] Secondly, in step S32, the likelihood probability of the behavioral deviation sequence in the Bayesian prior probability distribution is determined;

[0076] Then, in step S33, the posterior probability value of the abnormal risk is calculated using the Bayesian prior probability distribution and the likelihood probability.

[0077] Finally, in step S34, the posterior probability value is compared with a preset threshold range to obtain the type label of the abnormal risk.

[0078] In practical implementation, firstly, the compliant operational behavior patterns recorded in the normal behavior model can be used as basic reference data, and combined with the security event records confirmed in the historical operation of classified carriers, an initial probability distribution of abnormal behavior can be constructed. Among them, the historical security event data can come from security audit logs or manually confirmed violation records. By statistically analyzing the frequency of different abnormal types in historical security events, the probability of occurrence of various abnormal risks can be obtained. Subsequently, the statistically obtained abnormal occurrence probabilities are normalized according to the form of a probability distribution function to form a probability distribution model describing the prior cognition of abnormal risks. This probability distribution model is then used as the Bayesian prior probability distribution. Secondly, the deviation values ​​in the behavioral deviation sequence can be used as input observation samples, and the observation samples can be divided into intervals according to the deviation range defined in the normal behavior model. Based on this, the probability of different anomaly hypotheses being true under the current observation conditions can be calculated by statistically analyzing the frequency of the behavioral deviation values ​​within each deviation interval. Subsequently, existing probability density function calculation methods can be used to match the behavioral deviation sequence with the Bayesian prior probability distribution to obtain the likelihood probability of the behavioral deviation sequence under each anomaly hypothesis, and the calculated probability value can be used as the likelihood probability. Then, according to Bayes' theorem, the likelihood probability can be multiplied by the corresponding Bayesian prior probability distribution, and the calculation result can be normalized to obtain the posterior probability value of various anomaly risks under the current behavioral deviation conditions. Through the above calculation steps, the behavioral deviation sequence can be transformed into a probabilistic result reflecting the degree of anomaly risk, and the normalized probability result can be used as the posterior probability value of the anomaly risk. Finally, multiple risk threshold ranges are pre-defined, and an abnormal risk type is configured for each threshold range. For example, [0, 0.3) represents low risk, [0.3, 0.7) represents medium risk, and [0.7, 1.0] represents high risk. Subsequently, the posterior probability value of the abnormal risk is compared with the threshold range one by one. When the posterior probability value falls into a certain threshold range, the risk type corresponding to the abnormal risk is determined. Through the above comparison and mapping process, the posterior probability value can be converted into a clear abnormal risk type label, and the abnormal risk type label can be used as the classification result of the abnormal risk.

[0079] It should be noted that the Bayesian prior probability distribution is a priori knowledge of the likelihood of abnormal risks occurring based on normal behavior models and historical security event data, which can provide a basic probabilistic reference for subsequent probabilistic inference; the likelihood probability refers to the probability that the abnormal risk hypothesis is true, used to characterize the degree to which the current observed behavior supports the judgment of abnormal risks; the posterior probability value refers to the probability of abnormal risks occurring after comprehensively considering prior knowledge and the deviation of current behavior from observed information, used to quantify the degree of abnormal risks; the type label refers to the abnormal risk category identifier, which can be used as the discrete risk classification result for graded response and safety control.

[0080] The safety control feedback module 400 is used to trigger hierarchical collaboration and inference through the posterior probability value and the type label, and then generate safety control instructions based on the inference results, and determine the collaboration efficiency index based on the execution feedback data of the safety control instructions.

[0081] In this embodiment, the hierarchical collaboration and inference triggered by the posterior probability value and the type label, and the generation of security control instructions based on the inference results, can be specifically carried out in the following manner:

[0082] A hierarchical response rule base is constructed, which generates a set of intervention strategies based on the type label and the posterior probability value.

[0083] Perform simulations on all intervention strategies in the set of intervention strategies to obtain the changes in the carrier state after each intervention strategy is implemented;

[0084] The effectiveness of the carrier state changes after the implementation of each intervention strategy is evaluated, and the deduction results of the effectiveness evaluation are obtained.

[0085] Based on the simulation results, a target intervention strategy is selected from the set of intervention strategies, and a safety control instruction is generated according to the target intervention strategy.

[0086] In practical implementation, firstly, the type label and posterior probability value range of the abnormal risk can be used as conditions. Based on actual needs, the corresponding results of these conditions are set as hierarchical response rules. Each hierarchical response rule includes at least the risk type, probability threshold range, and a description of the corresponding intervention action, such as access restriction, operation freeze, permission downgrade, or enhanced auditing. During actual operation, the type label and posterior probability value of the abnormal risk can be input into the hierarchical response rule table for condition matching. All intervention actions that meet the matching conditions are then selected, and all selected intervention actions are combined to form an intervention strategy set. Secondly, each intervention strategy in the intervention strategy set can be sequentially loaded into the secure digital twin for simulation execution. During the simulation, corresponding restrictions or state adjustments can be applied to the virtual carrier model according to the control actions defined in the intervention strategy, such as simulating access restrictions, pausing data interfaces, and adjusting operation processes. After the simulation is completed, the corresponding state change data of the virtual carrier model is recorded. By simulating the execution of all intervention strategies, the carrier state change results corresponding to all intervention strategies can be obtained, thus obtaining the carrier state change after the execution of each intervention strategy. Then, basic indicators reflecting the safety effect are extracted from the state change results, including: the degree of abnormal behavior suppression, the degree of impact on system operation, and response timeliness. These basic indicators are then quantified, and weighted calculations are performed according to preset evaluation rules to obtain a comprehensive evaluation value for measuring the intervention effect. All comprehensive evaluation values ​​are then used as the deduction results for the effectiveness evaluation. Finally, the effectiveness evaluation deduction results corresponding to all intervention strategies are sorted or compared, and the intervention strategy that meets the preset conditions between safety effect and system impact is selected as the target intervention strategy. Subsequently, corresponding control command descriptions are generated based on the control actions defined in the target intervention strategy, and these control command descriptions are encapsulated into a standardized instruction format. Through this encapsulation process, the control command descriptions are transformed into safety control instructions that can be executed by the system, and these safety control instructions are the final output.

[0087] It should be noted that the hierarchical response rule base in this embodiment is a set of rules used to describe the mapping relationship between different levels of abnormal risk and corresponding security intervention actions, which is beneficial for realizing hierarchical processing of abnormal risks; the intervention strategy set is a collection of various security intervention schemes that can be selected based on the hierarchical response rule base; simulation refers to the process of pre-simulating the execution effect of different intervention strategies in a secure digital twin, used to predict the possible changes in the carrier state caused by the intervention strategy; the simulation result of the effectiveness evaluation refers to the result obtained after quantitatively evaluating the changes in the carrier state after the simulated execution of each intervention strategy, used to compare the effects of different intervention strategies; the security control command refers to the standardized control command generated according to the selected target intervention strategy, which can drive the classified carrier to execute the corresponding security control action.

[0088] In this embodiment, the collaborative efficiency index is determined based on the execution feedback data of the security control command, which can be done in the following way:

[0089] The response results and status change data of the classified carrier to the security control command are collected to obtain the execution feedback vector;

[0090] The execution feedback vector is decomposed and calculated to obtain the threat suppression rate, response time ratio, and resource utilization rate.

[0091] The threat suppression rate, response timeliness, and resource utilization rate are smoothly corrected based on the historical performance index to obtain the collaborative performance index.

[0092] In specific implementation, firstly, after the security control command is issued and executed, the state change data of the classified carrier before and after the execution of the security control command can be collected in real time through the state monitoring interface of the classified carrier. The state change data includes information such as whether the operation is blocked, whether the access permission has changed, whether the abnormal event continues to occur, and whether the system operation status has returned to normal. Then, the multi-dimensional data set composed of the state change data is converted into a vector through one-hot encoding, and then the vector is used as the execution feedback vector. Then, statistical analysis can be performed on the abnormal behavior-related data in the execution feedback vector. By comparing the changes in the number or duration of abnormal behavior before and after the execution of security control commands, the proportion of abnormal behavior suppressed can be calculated, and this proportion can be used as the threat suppression rate. Based on the recorded command issuance time and effective time, the actual response time of the security control command can be calculated, and the ratio of this response time to the preset standard response time can be calculated to obtain the response time efficiency ratio. By monitoring the computing resources or system resources consumed by the classified carrier during the execution of security control commands, such as processor utilization, changes in memory utilization, or network resource utilization, the resource consumption ratio can be calculated, and this ratio can be used as the resource utilization rate. Through the above calculation process, the threat suppression rate, response time efficiency ratio, and resource utilization rate can be calculated. Finally, the historical performance evaluation results calculated within the historical monitoring period can be retrieved as the historical performance index. Using the historical performance index as a reference benchmark, a sliding window is used to correct the threat suppression rate, response timeliness ratio, and resource utilization rate to reduce the impact of a single abnormal fluctuation on the overall evaluation results. Then, the smoothed and corrected indicators are comprehensively calculated according to the preset weights to obtain the collaborative performance index used to measure the collaborative effect of this security control. The preset weights of the threat suppression rate, response timeliness ratio, and resource utilization rate can be obtained by setting the initial value to 1 / 3 and then performing autoregressive analysis.

[0093] It should be noted that the execution feedback vector in this application is a multi-dimensional data set characterizing the execution effect of security control instructions, used to describe the state changes of classified carriers after executing security control instructions; the threat suppression rate represents the suppression effect of security control instructions on abnormal risks, and can describe the degree to which abnormal behavior is effectively controlled; the response time ratio measures the execution response speed of security control instructions, representing the time efficiency from instruction issuance to effectiveness; the resource utilization rate describes the consumption of system resources during the execution of security control instructions, and can assess the impact of security control measures on system operating load; the synergy effectiveness index is a quantitative indicator obtained after comprehensively evaluating the threat suppression rate, response time ratio, and resource utilization rate, and can represent the overall synergy level of security control strategies between effectiveness and cost.

[0094] The linkage optimization module 500 is used to perform linkage optimization on the normal behavior model, the prior parameters in the Bayesian posterior anomaly diagnosis, and the strategy rules in the hierarchical collaboration using the collaborative efficiency index, so as to realize adaptive management of the security monitoring of classified carriers throughout their entire life cycle.

[0095] In this embodiment, the collaborative effectiveness index is used to optimize the prior parameters in the normal behavior model, the Bayesian posterior anomaly diagnosis, and the strategy rules in the hierarchical collaboration, thereby achieving adaptive management of the full lifecycle security monitoring of classified carriers. Specifically, this can be achieved through the following methods:

[0096] A time-series analysis was performed on the constituent dimensions and changing trends of the collaborative effectiveness index to obtain the optimization factors;

[0097] Based on the correlation mapping relationship between the tuning factor, the normal behavior model, the prior parameters in Bayesian posterior anomaly diagnosis, and the strategy rules in hierarchical collaboration, a set of adjustment instructions for parameters and rules is generated synchronously.

[0098] The baseline threshold of the normal behavior model, the parameters of the Bayesian prior probability distribution, and the policy matching conditions in the hierarchical response rule base are updated by adjusting the instruction set to complete adaptive management within the monitoring period.

[0099] In practice, firstly, the calculated collaborative effectiveness index can be recorded over multiple consecutive monitoring periods, and the threat suppression rate, response timeliness ratio, and resource utilization rate corresponding to each monitoring period can be used as the constituent dimensions of the collaborative effectiveness index. Subsequently, the constituent dimensions can be arranged in chronological order to form time series data reflecting the effectiveness change process, and the magnitude and direction of change of each constituent dimension in different monitoring periods can be calculated based on this time series data. Through statistical analysis of the magnitude and direction of change, the degree of influence of each constituent dimension on the overall effectiveness change can be determined, and then numerical factors used to guide subsequent parameter adjustments can be extracted and used as optimization factors. Then, a mapping table between tuning factors and various adjustment objects can be pre-established in the system. The adjustment objects include: baseline thresholds in the normal behavior model, parameters in the Bayesian prior probability distribution, and policy matching conditions in the hierarchical response rule base. Subsequently, based on the magnitude and direction of change of the tuning factors, the corresponding parameter or rule adjustment method is found in the mapping table, and the adjustment method is converted into specific parameter modification instructions or rule update instructions. By summarizing all parameter modification instructions and rule update instructions to be adjusted, an adjustment instruction set for unified scheduling can be formed, and the result of the instruction set can be used as the parameter and rule adjustment instruction set. Finally, the instructions in the instruction set are parsed and applied to the corresponding adjustment objects according to their types. For example, the baseline threshold of the normal behavior model is updated by increasing or decreasing, the probability parameters of the Bayesian prior probability distribution are reassigned, and the policy matching conditions of the hierarchical response rule base are adjusted. After the instructions are executed, the updated model parameters and rule configurations can be loaded into the system operating environment so that they take effect in subsequent monitoring cycles. Through the above update process, the model and strategy can be dynamically corrected based on the feedback results of the collaborative effectiveness index, so as to achieve adaptive management of classified carriers during the monitoring cycle.

[0100] It should be noted that the tuning factor in this application refers to the numerical adjustment basis obtained by performing time-series analysis on the constituent dimensions of the collaborative effectiveness index, which can be used to quantitatively describe the changing trend of the safety control effect relative to the historical state; the correlation mapping relationship refers to the correspondence between the tuning factor and the parameters of the normal behavior model, the parameters of the Bayesian prior probability distribution, and the policy conditions of the hierarchical response rule base, which is used to guide the adjustment direction and adjustment magnitude of different types of adjustment objects; the adjustment instruction set refers to the set of parameter modification instructions and rule update instructions generated synchronously for multiple adjustment objects, which can realize the collaborative update of multiple models and multiple strategies; adaptive management refers to the management method of dynamically adjusting model parameters and policy rules without manual intervention based on the feedback results of the collaborative effectiveness index.

[0101] In summary, the technical solution adopted in this application can realize real-time simulation and risk post-evaluation of the operation behavior of classified carriers in a secure digital twin, so as to improve the response efficiency of identifying security risks of classified carriers.

[0102] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0103] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, including read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-Erasable Programmable Read-Only Memory (EEPROM), compactdisc read-only memory (CD-ROM) or other optical disc storage, disk storage, magnetic tape storage, or any other computer-readable medium capable of carrying or storing data.

[0104] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

Claims

1. A full lifecycle monitoring and security management system for classified carriers, characterized in that, The monitoring and security management system includes: The twin monitoring module is used to construct a secure digital twin based on multi-dimensional monitoring data of classified carriers, and to define a normal behavior model in the secure digital twin, wherein the normal behavior model refers to a quantitative evaluation model of the expected behavior norms of the classified carrier. The behavior simulation module is used to synchronize the real-time operation behavior sequence of the classified carrier to the secure digital twin for simulation execution, thereby generating a behavior deviation sequence, wherein the behavior deviation sequence refers to the set of state deviation values ​​arranged in the order of operation time. The posterior anomaly diagnosis module is used to perform Bayesian posterior anomaly diagnosis on the behavioral deviation sequence and the normal behavior model to obtain the posterior probability value and type label of the abnormal risk. The safety control feedback module is used to trigger hierarchical collaboration and inference through the posterior probability value and the type label, and then generate safety control instructions based on the inference results, and determine the collaboration efficiency index based on the execution feedback data of the safety control instructions; The linkage optimization module is used to use the collaborative efficiency index to perform linkage optimization on the normal behavior model, the prior parameters in the Bayesian posterior anomaly diagnosis, and the strategy rules in the hierarchical collaboration, so as to realize adaptive management of the full life cycle security monitoring of classified carriers. Specifically, defining the normal behavior model in the secure digital twin includes: Feature extraction and pattern learning are performed on the compliant operational behavior sequence of the security digital twin within a historical period to obtain a behavior baseline rule base. A normal behavior model is generated by the rule engine based on the aforementioned behavior baseline rule base. Specifically, synchronizing the real-time operational behavior sequence of the classified carrier to the secure digital twin for simulated execution, and thereby generating a behavior deviation sequence, includes: Based on the secure digital twin, the real-time operation behavior sequence is analyzed to obtain a virtual operation instruction set; The virtual operation instruction set is simulated and executed in the secure digital twin to obtain the simulation state result; The simulated state results are compared with the expected state of the normal behavior model to obtain the state deviation values ​​of different operational behaviors, and then a behavior deviation sequence is generated. Specifically, the Bayesian posterior anomaly diagnosis of the behavioral deviation sequence and the normal behavior model, to obtain the posterior probability value and type label of the abnormal risk, includes: The Bayesian prior probability distribution is determined based on the normal behavior model and historical security event data. Determine the likelihood probability of the behavioral deviation sequence in the Bayesian prior probability distribution; The posterior probability value of the abnormal risk is calculated using the Bayesian prior probability distribution and the likelihood probability. The posterior probability value is compared with a preset threshold range to obtain the type label of the abnormal risk.

2. The full lifecycle monitoring and security management system for classified carriers as described in claim 1, characterized in that, The multi-dimensional monitoring data of the classified carrier includes: unique identifier, operational behavior events, physical state parameters, environmental temperature and humidity, and network access records; the multi-dimensional monitoring data is collected through sensor networks and business system log interfaces.

3. The full lifecycle monitoring and security management system for classified carriers as described in claim 1, characterized in that, The construction of a secure digital twin based on multi-dimensional monitoring data from classified carriers specifically includes: The multi-dimensional monitoring data is spatiotemporally aligned and consistency verified to obtain standardized state time-series data; A secure digital twin is obtained by mapping the state time sequence data and the three-dimensional geometric model of the classified carrier.

4. The full lifecycle monitoring and security management system for classified carriers as described in claim 1, characterized in that, The real-time operation behavior sequence of a classified carrier refers to an ordered set of operation events of the classified carrier sorted by timestamp. The real-time operation behavior sequence includes: operation subject, operation type, operation object, and operation time. The real-time operation behavior sequence is obtained by parsing the operation behavior events and network access records in the multi-dimensional monitoring data and integrating the audit logs associated with the classified carrier.

5. The full lifecycle monitoring and security management system for classified carriers as described in claim 1, characterized in that, Triggering hierarchical collaboration and inference through the posterior probability value and the type label, and then generating security control instructions based on the inference results, specifically includes: A hierarchical response rule base is constructed, which generates a set of intervention strategies based on the type label and the posterior probability value. Perform simulations on all intervention strategies in the set of intervention strategies to obtain the changes in the carrier state after each intervention strategy is implemented; The effectiveness of the carrier state changes after the implementation of each intervention strategy is evaluated, and the deduction results of the effectiveness evaluation are obtained. Based on the simulation results, a target intervention strategy is selected from the set of intervention strategies, and a safety control instruction is generated according to the target intervention strategy.

6. The full lifecycle monitoring and security management system for classified carriers as described in claim 1, characterized in that, Determining the collaborative effectiveness index based on the execution feedback data of the aforementioned security control commands specifically includes: The response results and status change data of the classified carrier to the security control command are collected to obtain the execution feedback vector; The execution feedback vector is decomposed and calculated to obtain the threat suppression rate, response time ratio, and resource utilization rate. The threat suppression rate, response timeliness, and resource utilization rate are smoothly corrected based on the historical performance index to obtain the collaborative performance index.

7. The full lifecycle monitoring and security management system for classified carriers as described in claim 1, characterized in that, The collaborative effectiveness index is used to optimize the prior parameters in the normal behavior model, the Bayesian posterior anomaly diagnosis, and the strategy rules in the hierarchical collaboration, thereby achieving adaptive management of the full lifecycle security monitoring of classified carriers. Specifically, this includes: A time-series analysis was performed on the constituent dimensions and changing trends of the collaborative effectiveness index to obtain the optimization factors; Based on the correlation mapping relationship between the tuning factor, the normal behavior model, the prior parameters in Bayesian posterior anomaly diagnosis, and the strategy rules in hierarchical collaboration, a set of adjustment instructions for parameters and rules is generated synchronously. The baseline threshold of the normal behavior model, the parameters of the Bayesian prior probability distribution, and the policy matching conditions in the hierarchical response rule base are updated by adjusting the instruction set to complete adaptive management within the monitoring period.

Citation Information

Patent Citations

  • Greenhouse gas observation station intelligent operation and maintenance and fault diagnosis method based on digital twinning

    CN121052806A

  • Digital twin-driven bridge full life cycle damage prediction and evaluation method and system

    CN121435775A