A closed-loop optimization method and system for a dynamic threat assessment model

By constructing a dynamic threat assessment model and combining multi-source data fusion and swarm intelligence algorithm optimization, the problems of one-sided assessment results and fixed parameters in traditional threat assessment models have been solved, enabling accurate assessment and efficient protection of network threats, and improving the initiative and adaptability of security operations.

CN121691063BActive Publication Date: 2026-05-15STATE GRID ELECTRONIC COMMERCE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
STATE GRID ELECTRONIC COMMERCE TECH CO LTD
Filing Date
2026-02-09
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Traditional threat assessment models rely on static rule bases and single data sources, making it difficult to integrate information from multiple sources. This results in biased assessment results that fail to accurately reflect the dynamic evolution of attacks. Furthermore, fixed parameters lead to high false alarm rates and poor adaptability, failing to meet the continuous and efficient security protection needs of enterprise-level networks.

Method used

By collecting alarm events and external information data, a dynamic threat assessment model is constructed. Combining multi-source data fusion, dual feature extraction, and swarm intelligence algorithm closed-loop optimization, the weights are dynamically adjusted to form a closed-loop optimization mechanism, enabling adaptive assessment of the network environment and new attack methods.

Benefits of technology

It has achieved comprehensive, accurate, stable and reliable threat assessment, improved threat detection efficiency and attack chain tracing capabilities, promoted security operations from passive response to proactive management, and enhanced the intelligence and sustainability of security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121691063B_ABST
    Figure CN121691063B_ABST
Patent Text Reader

Abstract

The application belongs to the field of data processing, and provides a closed-loop optimization method and system of a dynamic threat assessment model, which comprises the following steps: collecting alarm events and external information data, and storing the external information data in a threat information database; analyzing the key information of the alarm events to obtain first features, and extracting graph model information of the alarm events to obtain second features; determining a plurality of threat assessment factors based on the first features and the second features in combination with the threat information database, and constructing a dynamic threat assessment model comprising a plurality of dynamic weights based on the plurality of threat assessment factors; constructing a fitness function of a swarm intelligence algorithm, and optimizing the plurality of dynamic weights in the dynamic threat assessment model through iterative training based on the fitness function to obtain a closed-loop optimized dynamic threat assessment model. The scheme makes the threat assessment more comprehensive, accurate, stable and reliable, improves the threat detection efficiency and attack chain tracing capability, and improves the intelligentialization and sustainability of security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, and in particular to a closed-loop optimization method and system for a dynamic threat assessment model. Background Technology

[0002] Against the backdrop of accelerated digital transformation, cybersecurity threats are becoming increasingly complex and diverse. Attack methods are exhibiting characteristics of concealment, multi-stage processes, and dynamic evolution, placing stringent demands on the real-time, accurate, and adaptive capabilities of threat assessments. Traditional threat assessment methods often rely on static rule bases or single data sources for analysis, judging the severity of threats based on fixed dimensions. They struggle to integrate multi-source information such as alerts and external data, resulting in biased assessment results that fail to accurately reflect the dynamic evolution of attacks and the actual risk situation, thus hindering precise decision-making in security operations.

[0003] In existing technologies, most threat assessment models rely on manual configuration of core parameters based on the experience of security experts. Once set, these parameters are fixed and lack dynamic adjustment mechanisms. As new attack methods continue to emerge and network environments and business scenarios constantly change, these fixed parameters cannot adapt to new threat forms. This not only leads to a high false positive rate but also makes it difficult to effectively identify complex multi-stage coordinated attacks. Furthermore, the weak attribution capability leaves security protection in a passive response state, unable to achieve early threat prediction and proactive control, and failing to meet the needs of enterprise networks for continuous, efficient, and secure protection.

[0004] This demonstrates that traditional cybersecurity threat assessment methods suffer from technical problems such as insufficient accuracy and efficiency, as well as inadequate stability and reliability. Summary of the Invention

[0005] This invention provides a closed-loop optimization method and system for a dynamic threat assessment model, which addresses the shortcomings of traditional network security threat assessment schemes, such as insufficient accuracy and efficiency, as well as inadequate stability and reliability.

[0006] On the one hand, this invention provides a closed-loop optimization method for a dynamic threat assessment model, comprising:

[0007] Collect alarm events and external information data, and store the external information data in a threat information database;

[0008] The alarm event is analyzed for key information to obtain a first feature, and the alarm event is extracted for graph model information to obtain a second feature;

[0009] Based on the first feature and the second feature, and in conjunction with the threat information database, multiple threat assessment factors are determined, and a dynamic threat assessment model containing multiple dynamic weights is constructed based on the multiple threat assessment factors.

[0010] A fitness function for a swarm intelligence algorithm is constructed, and based on the fitness function, multiple dynamic weights in the dynamic threat assessment model are optimized through iterative training to obtain a closed-loop optimized dynamic threat assessment model.

[0011] According to the closed-loop optimization method of the dynamic threat assessment model provided by the present invention, the alarm event is analyzed for key information to obtain a first feature, including:

[0012] Analyze the event type, event initiator, event target, and timestamp information of the alarm event;

[0013] The event type, event initiator, event target, and timestamp information are used as the first feature.

[0014] According to the closed-loop optimization method of the dynamic threat assessment model provided by the present invention, graph model information is extracted from the alarm event to obtain a second feature, including:

[0015] Multiple entities are extracted from the alarm event, and the multiple entities are used as multiple graph nodes. The event type of the alarm event is determined, and the event type is used as the edge between the graph nodes. Based on the multiple graph nodes and the edge between the graph nodes, a graph model of the alarm event is established.

[0016] Based on the alarm information corresponding to the historical events obtained in advance, a graph model of the historical events is established, and the graph model of the historical events is stored in the threat information database;

[0017] The graph model of the alarm event and the graph model of the historical event are used as the second feature.

[0018] According to the closed-loop optimization method of the dynamic threat assessment model provided by the present invention, based on the first feature and the second feature, and in conjunction with the threat information database, multiple threat assessment factors are determined, including:

[0019] Based on the first feature and in conjunction with the threat information database, a severity factor is determined;

[0020] Based on the second feature, the behavioral abnormality factor is determined;

[0021] Based on the asset importance of the event target in the first feature, determine the asset criticality coefficient;

[0022] The severity factor, the abnormal behavior factor, and the asset criticality coefficient are used as multiple threat assessment factors.

[0023] According to the closed-loop optimization method of the dynamic threat assessment model provided by the present invention, the severity factor is determined based on the first feature and in conjunction with the threat information database, including:

[0024] Based on the event type in the first feature, determine the severity baseline value;

[0025] Based on the first feature, a query is performed in the threat information database, and the threat information correlation coefficient is determined based on the query results;

[0026] Obtain the number of alarm events of the same type within the current time window, and obtain the average number of alarm events of the same type within the corresponding historical time period. Calculate the internal threat coefficient based on the number of alarm events and the average number.

[0027] The severity factor is calculated by multiplying the severity baseline value, the threat information correlation coefficient, and the internal threat coefficient.

[0028] According to the closed-loop optimization method of the dynamic threat assessment model provided by the present invention, the behavioral anomaly factor is determined based on the second feature, including:

[0029] The similarity scores are obtained by sequentially calculating the similarity between the graph model of the alarm event in the second feature and the graph model of the historical event.

[0030] Alarm events with similarity scores greater than a set score threshold are classified as anomalous events, and the actual number of anomalous events is determined.

[0031] Obtain the total number of abnormal events within the historical period, and calculate the ratio by dividing the actual number by the total number of events.

[0032] The behavioral abnormality factor is calculated by summing the actual quantity with 1 and multiplying the logarithm of the sum with the ratio of the quantity.

[0033] According to the closed-loop optimization method of the dynamic threat assessment model provided by the present invention, the plurality of dynamic weights include: a first dynamic weight, a second dynamic weight, and a third dynamic weight;

[0034] Based on the aforementioned multiple threat assessment factors, a dynamic threat assessment model containing multiple dynamic weights is constructed, including:

[0035] Multiply the severity factor by the first dynamic weight to obtain the first parameter term;

[0036] Multiply the abnormal behavior factor by the second dynamic weight to obtain the second parameter term;

[0037] Multiply the square root of the asset criticality coefficient by the third dynamic weight to obtain the third parameter term;

[0038] The sum of the first and second parameters is multiplied by the third parameter to obtain the dynamic threat assessment model.

[0039] According to the closed-loop optimization method of the dynamic threat assessment model provided by the present invention, the fitness function of the swarm intelligence algorithm is constructed, including:

[0040] Based on the dynamic threat assessment model, determine the dynamic threat assessment value of the alarm event;

[0041] The alarm events in which the dynamic threat assessment value is higher than the set assessment threshold are identified as a first number of real threats and a second number of false alarms. The alarm events in which the dynamic threat assessment value is lower than the set assessment threshold are identified as a third number of real threats.

[0042] The detection rate is calculated by dividing the first quantity by the sum of the first quantity and the third quantity, and the false alarm rate is calculated by dividing the second quantity by the sum of the first quantity and the second quantity.

[0043] Based on the timestamp information of alarm events where the dynamic threat assessment value is higher than the set assessment threshold, at least one attack chain is established, the sub-confidence of each attack chain is calculated, and the sub-confidence of all attack chains is averaged to obtain the attack chain confidence.

[0044] The detection rate, the false alarm rate, and the attack chain confidence are multiplied by their respective preset balance coefficients to obtain the detection rate weight term, the false alarm rate weight term, and the confidence weight term. The difference between the detection rate weight term and the false alarm rate weight term is added to the confidence weight term to obtain the fitness function of the swarm intelligence algorithm.

[0045] According to the closed-loop optimization method of the dynamic threat assessment model provided by the present invention, based on the fitness function, multiple dynamic weights in the dynamic threat assessment model are optimized through iterative training to obtain a closed-loop optimized dynamic threat assessment model, including:

[0046] The dynamic weights in the dynamic threat assessment model are used as the nests of the cuckoo in the cuckoo search algorithm, and the optimal combination of dynamic weights that maximizes the function value of the fitness function is found through iterative training in the set parameter space.

[0047] Based on the optimal dynamic weight combination, the closed-loop optimized dynamic threat assessment model is determined.

[0048] On the other hand, the present invention also provides a closed-loop optimization system for a dynamic threat assessment model, comprising:

[0049] The data acquisition module is used to collect alarm events and external information data, and store the external information data in the threat information database;

[0050] The extraction module is used to parse key information of the alarm event to obtain a first feature, and to extract graph model information of the alarm event to obtain a second feature;

[0051] The construction module is used to determine multiple threat assessment factors based on the first feature and the second feature, combined with the threat information database, and to construct a dynamic threat assessment model containing multiple dynamic weights based on the multiple threat assessment factors.

[0052] An optimization module is used to construct the fitness function of the swarm intelligence algorithm, and based on the fitness function, to iteratively train and optimize multiple dynamic weights in the dynamic threat assessment model to obtain a closed-loop optimized dynamic threat assessment model.

[0053] The closed-loop optimization method and system for the dynamic threat assessment model provided by this invention, through a full-process design of multi-source data fusion, dual feature extraction, multi-factor modeling, and swarm intelligence algorithm closed-loop optimization, not only solves the problems of single evaluation dimensions and one-sided results in traditional models, but also makes threat assessment more comprehensive, accurate, stable, and reliable by integrating multi-source information such as alarm events and external threat information. Furthermore, the dynamic weight optimization mechanism avoids the defects of high false alarm rate and poor adaptability caused by parameter fixation, significantly improving threat detection efficiency and attack chain tracing capabilities. Simultaneously, the closed-loop optimization mechanism formed by periodic iterative training enables the model to adapt to changes in the network environment and new attack methods, promoting a shift in security operations from passive alarm handling to proactive risk management, and greatly improving the intelligence and sustainability of security protection. Attached Figure Description

[0054] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0055] Figure 1 This is a flowchart illustrating the closed-loop optimization method for the dynamic threat assessment model provided in this embodiment of the invention.

[0056] Figure 2 This is a schematic diagram illustrating the implementation principle of the closed-loop optimization method for the dynamic threat assessment model in this embodiment of the invention.

[0057] Figure 3 This is a schematic diagram of the closed-loop optimization system of the dynamic threat assessment model provided in this embodiment of the invention;

[0058] Figure 4 This is a schematic diagram of the structure of the electronic device provided in an embodiment of the present invention. Detailed Implementation

[0059] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0060] The following is combined with Figures 1 to 4 This invention describes the detailed scheme of the closed-loop optimization method and system for the dynamic threat assessment model provided in the embodiments of the present invention.

[0061] like Figure 1 As shown, the closed-loop optimization method for the dynamic threat assessment model provided in this embodiment of the invention mainly includes the following steps:

[0062] Step 110: Collect alarm events and external information data, and store the external information data in the threat information database.

[0063] In practical applications, on the one hand, alarm events can be collected from firewalls, intrusion detection, endpoint detection, identity authentication servers, etc., and then the collected alarm events can be cleaned and standardized to solve problems such as different data formats and missing information. Standardization processing can ensure that data formats from different sources are consistent.

[0064] On the other hand, external information data can be collected from vulnerability databases, threat information platforms, etc. In this embodiment, external information data includes, but is not limited to: IP (Internet Protocol), domain name, file HASH (Hash Value), attacker's attack mode, URL (Uniform Resource Locator), vulnerability number, etc. The external information data is preprocessed by repeating and redundancy, and finally, the preprocessed external information data is stored in the threat information database.

[0065] Step 120: Analyze the key information of the alarm event to obtain the first feature, and extract the graph model information of the alarm event to obtain the second feature.

[0066] In this step, by extracting the first and second features of the alarm event, we can use them as core data for the subsequent construction of the dynamic threat assessment model, ensuring the comprehensiveness of the assessment dimensions.

[0067] Step 130: Based on the first feature and the second feature, and in conjunction with the threat information database, determine multiple threat assessment factors, and construct a dynamic threat assessment model containing multiple dynamic weights based on the multiple threat assessment factors.

[0068] In this embodiment, a dynamic threat assessment model with multiple dynamic weights, constructed based on the first feature and the second feature and combined with multiple threat assessment factors, can better assess the threat level of alarm events of different event types.

[0069] Step 140: Construct the fitness function of the swarm intelligence algorithm, and based on the fitness function, optimize multiple dynamic weights in the dynamic threat assessment model through iterative training to obtain the closed-loop optimized dynamic threat assessment model.

[0070] Understandably, in the closed-loop optimization process, by dynamically adjusting weights through swarm intelligence algorithms, the dynamic threat assessment model can continuously evolve based on actual detection results, false alarms, and the accuracy of attack chain tracing. This forms a cycle of data-supported model, model output results, and result feedback to optimize the model, ultimately achieving precise threat protection.

[0071] In one embodiment, key information is parsed from the alarm event to obtain a first feature, specifically including:

[0072] First, analyze the event type, event initiator, event target, and timestamp information of the alarm event.

[0073] Then, the event type, event initiator, event target, and timestamp information are used as the first feature.

[0074] In this embodiment, by analyzing and parsing the alarm event, a first feature of the alarm event can be extracted. The first feature can be represented as follows: ,in, The first characteristic of alarm event i. For event type, As the initiator of the incident, For the event target, This is timestamp information.

[0075] Specifically, event types can be generated based on built-in rules when collecting alarm events, including but not limited to reconnaissance scanning, initial intrusion, malicious code execution, privilege escalation, lateral movement, command and control, data leakage, and other threats. Among these, reconnaissance scanning refers to a single source IP attempting to connect to a large number of different target IPs or ports within a very short period; initial intrusion refers to a large number of failed login events with the same username or source IP in the authentication service logs; malicious code execution refers to the discovery of randomly generated, lengthy domain names or suspicious process chains; privilege escalation refers to abnormal changes in the permission levels of users or processes recorded in the logs; lateral movement refers to a large number of login attempts from the same internal IP targeting different hosts; command and control refers to internal hosts periodically communicating with known malicious domains or IPs or using uncommon protocols or ports in their communication traffic; data leakage refers to outgoing traffic containing sensitive data patterns; and other threats refer to events not listed above, with unknown threats categorized as other threat types.

[0076] In this embodiment, the event initiator specifically includes IP, domain name, user ID, etc., the event target specifically includes the event-affected IP, hostname, service name, MAC address, etc., and the timestamp information refers to the precise time when the alarm event occurred.

[0077] In one embodiment, graph model information is extracted from the alarm event to obtain a second feature, specifically including:

[0078] On the one hand, multiple entities are extracted from the alarm events, and these entities are used as multiple graph nodes. The event types of the alarm events are determined, and the event types are used as edges between graph nodes. Based on the multiple graph nodes and the edges between them, a graph model of the alarm events is established.

[0079] In this embodiment, a graph model of the current alarm event can be extracted. ,in This represents multiple entities extracted from the alarm event, i.e., graph nodes in the graph model, including but not limited to source IP, destination IP, user ID, etc. Indicates the event type of the alarm event. As edges between nodes in a graph model.

[0080] On the other hand, based on the alarm information corresponding to the historical events obtained in advance, a graph model of the historical events is established and stored in the threat information database.

[0081] Specifically, a graphical model can be used to extract alarm data corresponding to all historical alarm events (i.e., historical events). ,in, Indicates the first A graphical model of a historical event. ,and It is the total number of historical events. Indicates the first Graph nodes in a graph model of historical events Indicates the first The edges in the graph model of a historical event can be used to extract the graph model from the historical events and store it in the threat information database.

[0082] Finally, the graph models of alarm events and historical events are used as the second feature.

[0083] In one embodiment, combined with Figure 2 As shown, based on the first and second features, and in conjunction with the threat information database, multiple threat assessment factors are determined, specifically including:

[0084] On the one hand, severity factors are determined based on the primary characteristics and in conjunction with the threat information database.

[0085] In a specific implementation, the severity factor is determined based on the first feature and in conjunction with a threat information database, specifically including:

[0086] The first step is to determine the severity baseline based on the event type in the first feature.

[0087] In practical applications, severity baseline values ​​can be set for each type of event based on the event type. For example, the severity baseline value for reconnaissance scanning is 3, the severity baseline value for initial intrusion is 7, the severity baseline value for malicious code execution is 9, the severity baseline value for privilege escalation is 8, the severity baseline value for lateral movement is 10, the severity baseline value for command and control is 7, the severity baseline value for data leakage is 9.5, and the severity baseline value for other threats is 2.

[0088] The second step is to search the threat information database based on the first feature and determine the threat information correlation coefficient based on the search results.

[0089] In this embodiment, the first feature extracted from alarm event i can be queried in the threat information database. If no relevant information is found, a threat information correlation coefficient is set. If the query retrieves metric data of the event initiator, such as IP address or domain name, then a threat information correlation coefficient is set. .

[0090] The third step is to obtain the number of alarm events of the same type within the current time window, and the average number of alarm events of the same type within the corresponding historical time period. Based on the number of alarm events and the average number, the internal threat coefficient is calculated.

[0091] In this embodiment, the formula for calculating the internal threat coefficient of alarm event i is as follows:

[0092] (1)

[0093] In the above formula, Internal threat coefficient, In the time window The number of alarm events of the same type within the system. This represents the average number of events of the same type within the same historical time period.

[0094] The fourth step is to multiply the severity baseline, the threat information correlation coefficient, and the internal threat coefficient to calculate the severity factor.

[0095] On the other hand, behavioral abnormality factors are identified based on the second feature.

[0096] In a specific implementation, behavioral anomaly factors are determined based on the second feature, specifically including:

[0097] The first step is to calculate the similarity between the graph model of the alarm event in the second feature and the graph model of the historical event in turn, and obtain the similarity score.

[0098] In this embodiment, based on the extracted second feature, the graph model of the current alarm event and the graph model of the historical event are sequentially similar to calculate the similarity score, which ranges from 0 to 1.

[0099] The second step is to classify alarm events with similarity scores greater than a set score threshold as anomalous events and determine the actual number of anomalous events.

[0100] In practical applications, the score threshold can be set to 0.7. In this embodiment, events with a similarity score greater than 0.7 are judged as abnormal events, and the actual number of abnormal events is counted.

[0101] In this embodiment, the actual number of abnormal events can be expressed as:

[0102] (2)

[0103] In the above formula, This represents the actual number of anomalous events with a similarity score greater than 0.7. A graphical model of historical events. Indicates the first A graphical model of a historical event. ,and It is the total number of historical events. A graph model for the current alarm event. For indicator functions, when hour, The exponential function takes the value 1 when hour, The value of the exponential function is 0.

[0104] The third step is to obtain the total number of abnormal events within the historical period, and then calculate the ratio by dividing the actual number by the total number.

[0105] The fourth step is to sum the actual quantity with 1, and then multiply the logarithm of the sum with the quantity ratio to calculate the behavioral abnormality factor.

[0106] In this embodiment, the formula for calculating the behavioral abnormality factor is:

[0107] (3)

[0108] In the above formula, It is a behavioral abnormality factor. It is the total number of anomalous events within a historical period. It represents the actual number of anomalous events with a similarity score greater than 0.7.

[0109] On the other hand, the asset criticality coefficient is determined based on the asset importance of the event target in the first feature.

[0110] In this embodiment, the assets in the asset criticality coefficient include, but are not limited to, hardware equipment and software assets, which correspond to the event target in the first feature. The importance of the assets. The first characteristic (event objective) is measured by considering the asset's confidentiality, integrity, data sensitivity, business functionality, and business dependencies. The system determines the importance of assets by pre-setting an asset list and an asset keyness coefficient, and expresses the asset keyness coefficient as... .

[0111] Finally, severity factor, behavioral abnormality factor, and asset criticality coefficient are used as multiple threat assessment factors.

[0112] In one embodiment, the plurality of dynamic weights includes: a first dynamic weight. Second dynamic weight and the third dynamic weight .

[0113] A dynamic threat assessment model with multiple dynamic weights is constructed based on multiple threat assessment factors, specifically including:

[0114] On the one hand, the severity factor is multiplied by the first dynamic weight to obtain the first parameter term.

[0115] On the other hand, the abnormal behavior factor is multiplied by the second dynamic weight to obtain the second parameter term.

[0116] On the other hand, the square root of the asset criticality coefficient is multiplied by the third dynamic weight to obtain the third parameter.

[0117] Finally, the sum of the first and second parameters is multiplied by the third parameter to obtain the dynamic threat assessment model.

[0118] To better assess the threat level of alarm events of different event types, this embodiment uses alarm event i as an example to construct a dynamic threat assessment model. This dynamic threat assessment model is composed of the fusion of multiple threat assessment factors, and can be specifically expressed as follows:

[0119] (4)

[0120] In the above formula, The function value of the dynamic threat assessment model. , , For multiple dynamic weights, As a severity factor, As a behavioral abnormality factor, This is the asset criticality coefficient.

[0121] Understandably, the function value of the dynamic threat assessment model As different event types and multiple threat assessment factors become increasingly interconnected and dynamic, it is necessary to continuously optimize the dynamic weight values. , , It dynamically adjusts based on multiple factors to output a threat assessment value that accurately reflects the alarm event.

[0122] In one embodiment, constructing the fitness function of the swarm intelligence algorithm specifically includes:

[0123] The first step is to determine the dynamic threat assessment value of the alarm event based on the dynamic threat assessment model.

[0124] The second step is to determine the first number of alarm events marked as real threats and the second number of false alarms among alarm events where the dynamic threat assessment value is higher than the set assessment threshold, and to determine the third number of alarm events marked as real threats among alarm events where the dynamic threat assessment value is lower than the set assessment threshold.

[0125] During the assessment cycle, security personnel sequentially label the alarm events generated in the system's history, with the label information being either real threats or confirmed false alarms.

[0126] The third step is to divide the first quantity by the sum of the first and third quantities to calculate the detection rate, and to divide the second quantity by the sum of the first and second quantities to calculate the false alarm rate.

[0127] In this embodiment, the formula for calculating the detection rate is:

[0128] (5)

[0129] The formula for calculating the false alarm rate is:

[0130] (6)

[0131] In the above formula, TP is the first number of alarm events whose dynamic threat assessment value is higher than the set assessment threshold and which are labeled as "real threats" by security personnel; FP is the second number of alarm events whose dynamic threat assessment value is higher than the set assessment threshold and which are labeled as "false alarms" by security personnel; and FN is the third number of alarm events whose dynamic threat assessment value is lower than the set assessment threshold and which are labeled as "real threats" by security personnel.

[0132] The fourth step involves establishing at least one attack chain based on the timestamp information of alarm events where the dynamic threat assessment value exceeds the set assessment threshold. The sub-confidence of each attack chain is calculated, and the sub-confidence of all attack chains is averaged to obtain the attack chain confidence.

[0133] During the assessment period, by analyzing the timestamp information in the first feature of high dynamic threat assessments of completed tagged alert events, the alert events are sorted by time, and the event types are linked together to generate an attack chain of alert events. This allows us to calculate the attack chain confidence of all alert events with high dynamic threat assessment values ​​within the assessment period.

[0134] The input to the attack chain confidence score is a set of attack chains consisting of tagged alert events with high dynamic threat assessment values. Taking the attack chain containing alert event i as an example, the sub-confidence score of a single attack chain can be expressed as:

[0135] (7)

[0136] Furthermore, the attack chain confidence can be expressed as:

[0137] (8)

[0138] In the above formula, The sub-confidence of the attack chain to which alarm event i belongs. Let be the dynamic threat assessment value of alarm event i, and M be the number of events in an attack chain linked together by alarm event i. Let be the time decay function. ,in The current time is the time difference between the time of the event i and the time of its occurrence. k is the decay constant, which is set to k=0.5. Here, N represents the attack chain confidence level, and N is the number of attack chains. Indicates the first One attack chain.

[0139] The fifth step involves multiplying the detection rate, false alarm rate, and attack chain confidence by their respective preset balance coefficients to obtain the detection rate weight term, false alarm rate weight term, and confidence weight term. The difference between the detection rate weight term and the false alarm rate weight term is then added to the confidence weight term to obtain the fitness function of the swarm intelligence algorithm.

[0140] In this embodiment, the fitness function of the swarm intelligence algorithm can be expressed as:

[0141] (9)

[0142] In the above formula, The fitness function value of the swarm intelligence algorithm. This represents the current iteration number of the swarm intelligence algorithm. , , These are all balance coefficients for swarm intelligence algorithms, used to define optimization preferences, and are set as follows: , , ; For detection rate, For false alarm rate, For attack chain confidence, when When the maximum value is achieved, the optimal dynamic weight for the corresponding alarm event type is obtained by achieving high detection rate, low false alarm rate and high source tracing accuracy.

[0143] Based on different alarm event types, and through multiple iterations, the dynamic weights of the dynamic threat assessment model are continuously adjusted. , , When the fitness function value At its maximum, the corresponding dynamic weight , , Optimal configuration.

[0144] In some embodiments, a monthly unit is used as each evaluation cycle to continuously train and optimize the dynamic weight configuration, allowing the system to automatically learn from actual feedback, optimize the dynamic threat assessment model in a closed loop, and achieve overall threat perception.

[0145] In one embodiment, based on the fitness function, multiple dynamic weights in the dynamic threat assessment model are iteratively trained and optimized to obtain a closed-loop optimized dynamic threat assessment model, specifically including:

[0146] First, multiple dynamic weights in the dynamic threat assessment model are used as the nests of the cuckoo in the cuckoo search algorithm, and the optimal combination of dynamic weights that maximizes the fitness function is found through iterative training in a set parameter space.

[0147] Then, based on the optimal dynamic weight combination, the closed-loop optimized dynamic threat assessment model is determined.

[0148] The swarm intelligence algorithm used in this embodiment is the Cuckoo Search (CS) algorithm. The principle of the Cuckoo Search algorithm is to map the location of the nests where cuckoos parasitize to the solution of the algorithm's population space, and to judge the fitness function value of the solution based on the quality of the nest location. By simulating the parasitic breeding behavior of cuckoos, combined with the Levy flight search mechanism, global optimization is performed.

[0149] This embodiment incorporates the dynamic weights in the dynamic threat assessment model. , , As a cuckoo's nest, one nest location represents a set of parameter configurations to be optimized. , , The goal of the cuckoo search algorithm is to find a function value in the parameter space that satisfies the fitness function. Maximize the optimal configuration [ , , ].

[0150] Based on the cuckoo search algorithm, optimize the dynamic weights in the dynamic threat assessment model. , , The training process is as follows:

[0151] The first step, the initialization phase, involves setting key parameters for the cuckoo search algorithm, including the total number of nests. The function value of the fitness function Maximum number of iterations Parameters are initialized, and dynamic weight configuration is determined based on the dynamic threat assessment model. The initial location and optimization parameters of each bird's nest.

[0152] The second step is to calculate the fitness function value of the currently initialized bird's nest. The nest with the largest fitness function value is selected as the global optimum and marked as such. Record the location of the bird's nest. .

[0153] The third step involves updating the nest locations using Levy flight. Specifically, this can be done by continuously updating the nest locations based on a step size factor and a random search path. The fitness function value for this group of nests is then recalculated, and the value with the highest fitness function is selected and compared with... Compare and assign the better value to .

[0154] Specifically, the The bird's nest in the first The position of the round iteration can be represented as:

[0155] (10)

[0156] In the above formula, For the first A bird's nest. , The total number of bird nests For the first The bird's nest in the first The position of the round iteration, For the first The bird's nest in the first The position of the round iteration, Step size factor For random search paths, This is point-to-point multiplication.

[0157] The random search path can be represented as:

[0158] (11)

[0159] In the above formula, and All are random numbers that follow a normal distribution, where, , ,set up , For the first The bird's nest in the first The optimal location of the Bird's Nest in the round of iteration.

[0160] The fourth step, after updating the location of the bird's nest in the third step, is to use random numbers... With dynamic discovery probability In contrast, generating a preference random walk, when random numbers At that time, among them Discarding some solutions, generating the same number of new solutions, and comparing the updated bird's nest fitness values, assigning the better values ​​to the new solutions. And retain the current optimal location of the Bird's Nest. When random numbers At this time, the optimal bird's nest position saved in step 3 is retained and no update is required.

[0161] Specifically, the probability of dynamic discovery can be expressed as:

[0162] (12)

[0163] In the above formula, To dynamically discover probabilities, , For the maximum and minimum discovery probabilities, and These are the current iteration number and the maximum iteration number, respectively.

[0164] The fifth step involves iterative updates until the maximum number of iterations is reached. At that time, the optimal fitness function value will be obtained, and its corresponding bird's nest location will be determined. As the optimal dynamic weight in the dynamic threat assessment model , , .

[0165] In practical applications, in order to cope with changes in the network environment and attack methods, it is necessary to collect new alarm events on a monthly cycle and repeat the training process of the dynamic weights of the dynamic threat assessment model using swarm intelligence algorithms. This enables the model to adaptively learn and evolve in a closed loop, automatically discovering the most effective defense strategy and thus making the assessment of alarm events more accurate.

[0166] In summary, the closed-loop optimization method for the dynamic threat assessment model provided in this embodiment of the invention constructs a dynamic threat assessment model and optimizes dynamic weights using swarm intelligence algorithms to achieve accurate threat perception and assessment capabilities. This process constitutes a complete closed-loop flow of assessment, optimization, execution, and reassessment. This method combines multiple factors, including severity factors, abnormal behavior factors, and asset criticality coefficients, to construct the dynamic threat assessment model. It incorporates swarm intelligence algorithms, specifically the Cuckoo Search algorithm, and constructs a fitness function that integrates detection rate, false alarm rate, and attack chain confidence. It dynamically optimizes each dynamic weight and optimizes the assessment through alarm events of different event types, achieving highly accurate security protection.

[0167] Based on the same general inventive concept, this invention also protects a closed-loop optimization system for a dynamic threat assessment model. The closed-loop optimization system for the dynamic threat assessment model provided by this invention will be described below. The closed-loop optimization system for the dynamic threat assessment model described below can be referred to in correspondence with the closed-loop optimization method for the dynamic threat assessment model described above.

[0168] like Figure 3As shown, the closed-loop optimization system for the dynamic threat assessment model provided in this embodiment of the invention specifically includes:

[0169] The acquisition module 210 is used to collect alarm events and external information data, and store the external information data in the threat information database.

[0170] The extraction module 220 is used to analyze key information of alarm events to obtain the first feature, and to extract graph model information of alarm events to obtain the second feature.

[0171] The construction module 230 is used to determine multiple threat assessment factors based on the first feature and the second feature, combined with the threat information database, and to construct a dynamic threat assessment model containing multiple dynamic weights based on the multiple threat assessment factors.

[0172] The optimization module 240 is used to construct the fitness function of the swarm intelligence algorithm, and based on the fitness function, it iteratively trains and optimizes multiple dynamic weights in the dynamic threat assessment model to obtain the closed-loop optimized dynamic threat assessment model.

[0173] Regarding the system in the above embodiments, the specific ways in which each module performs operations have been described in detail in the embodiments of the relevant methods, and will not be elaborated further here.

[0174] Figure 4 This is a schematic diagram of the structure of the electronic device provided in an embodiment of the present invention.

[0175] like Figure 4 As shown, the electronic device may include a processor 310, a communications interface 320, a memory 330, and a communication bus 340, wherein the processor 310, communications interface 320, and memory 330 communicate with each other via the communication bus 340. The processor 310 can call logical instructions in the memory 330 to execute the closed-loop optimization method of the dynamic threat assessment model provided in the above embodiments.

[0176] Furthermore, the logical instructions in the aforementioned memory 330 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0177] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer is able to execute the closed-loop optimization method of the dynamic threat assessment model provided in the above embodiments.

[0178] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the closed-loop optimization method of the dynamic threat assessment model provided in the above embodiments.

[0179] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0180] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0181] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A closed-loop optimization method for a dynamic threat assessment model, characterized in that, include: Collect alarm events and external information data, and store the external information data in a threat information database; The alarm event is analyzed for key information to obtain a first feature, and the alarm event is extracted for graph model information to obtain a second feature; Based on the first feature and the second feature, and in conjunction with the threat information database, multiple threat assessment factors are determined, including: determining a severity factor based on the first feature and in conjunction with the threat information database; determining a behavioral anomaly factor based on the second feature; determining an asset criticality coefficient based on the asset importance of the event target in the first feature; using the severity factor, behavioral anomaly factor, and asset criticality coefficient as multiple threat assessment factors; constructing a dynamic threat assessment model containing multiple dynamic weights based on the multiple threat assessment factors; wherein the multiple dynamic weights include: a first dynamic weight, a second dynamic weight, and a third dynamic weight; constructing a dynamic threat assessment model containing multiple dynamic weights based on the multiple threat assessment factors includes: multiplying the severity factor by the first dynamic weight to obtain a first parameter term; multiplying the behavioral anomaly factor by the second dynamic weight to obtain a second parameter term; multiplying the square root of the asset criticality coefficient by the third dynamic weight to obtain a third parameter term; multiplying the sum of the first parameter term and the second parameter term by the third parameter term to obtain the dynamic threat assessment model; A fitness function for a swarm intelligence algorithm is constructed, and based on the fitness function, multiple dynamic weights in the dynamic threat assessment model are optimized through iterative training to obtain a closed-loop optimized dynamic threat assessment model.

2. The closed-loop optimization method for the dynamic threat assessment model according to claim 1, characterized in that, The alarm event is analyzed for key information to obtain a first feature, including: Analyze the event type, event initiator, event target, and timestamp information of the alarm event; The event type, event initiator, event target, and timestamp information are used as the first feature.

3. The closed-loop optimization method for the dynamic threat assessment model according to claim 1, characterized in that, The graph model information of the alarm event is extracted to obtain the second feature, including: Multiple entities are extracted from the alarm event, and the multiple entities are used as multiple graph nodes. The event type of the alarm event is determined, and the event type is used as the edge between the graph nodes. Based on the multiple graph nodes and the edge between the graph nodes, a graph model of the alarm event is established. Based on the alarm information corresponding to the historical events obtained in advance, a graph model of the historical events is established, and the graph model of the historical events is stored in the threat information database; The graph model of the alarm event and the graph model of the historical event are used as the second feature.

4. The closed-loop optimization method for the dynamic threat assessment model according to claim 1, characterized in that, Based on the first feature and in conjunction with the threat information database, a severity factor is determined, including: Based on the event type in the first feature, determine the severity baseline value; Based on the first feature, a query is performed in the threat information database, and the threat information correlation coefficient is determined based on the query results; Obtain the number of alarm events of the same type within the current time window, and obtain the average number of alarm events of the same type within the corresponding historical time period. Calculate the internal threat coefficient based on the number of alarm events and the average number. The severity factor is calculated by multiplying the severity baseline value, the threat information correlation coefficient, and the internal threat coefficient.

5. The closed-loop optimization method for the dynamic threat assessment model according to claim 1, characterized in that, Based on the second feature, behavioral abnormality factors are determined, including: The similarity scores are obtained by sequentially calculating the similarity between the graph model of the alarm event in the second feature and the graph model of the historical event. Alarm events with similarity scores greater than a set score threshold are classified as anomalous events, and the actual number of anomalous events is determined. Obtain the total number of abnormal events within a historical period, and calculate the ratio by dividing the actual number by the total number of events. The behavioral abnormality factor is calculated by summing the actual quantity with 1 and multiplying the logarithm of the sum with the ratio of the quantity.

6. The closed-loop optimization method for the dynamic threat assessment model according to claim 1, characterized in that, Constructing the fitness function for swarm intelligence algorithms includes: Based on the dynamic threat assessment model, determine the dynamic threat assessment value of the alarm event; The alarm events in which the dynamic threat assessment value is higher than the set assessment threshold are identified as a first number of real threats and a second number of false alarms. The alarm events in which the dynamic threat assessment value is lower than the set assessment threshold are identified as a third number of real threats. The detection rate is calculated by dividing the first quantity by the sum of the first quantity and the third quantity, and the false alarm rate is calculated by dividing the second quantity by the sum of the first quantity and the second quantity. Based on the timestamp information of alarm events where the dynamic threat assessment value is higher than the set assessment threshold, at least one attack chain is established, the sub-confidence of each attack chain is calculated, and the sub-confidence of all attack chains is averaged to obtain the attack chain confidence. The detection rate, the false alarm rate, and the attack chain confidence are multiplied by their respective preset balance coefficients to obtain the detection rate weight term, the false alarm rate weight term, and the confidence weight term. The difference between the detection rate weight term and the false alarm rate weight term is added to the confidence weight term to obtain the fitness function of the swarm intelligence algorithm.

7. The closed-loop optimization method for the dynamic threat assessment model according to any one of claims 1 to 6, characterized in that, Based on the fitness function, multiple dynamic weights in the dynamic threat assessment model are optimized through iterative training to obtain a closed-loop optimized dynamic threat assessment model, including: The dynamic weights in the dynamic threat assessment model are used as the nests of the cuckoo in the cuckoo search algorithm, and the optimal combination of dynamic weights that maximizes the function value of the fitness function is found through iterative training in the set parameter space. Based on the optimal dynamic weight combination, the closed-loop optimized dynamic threat assessment model is determined.

8. A closed-loop optimization system for a dynamic threat assessment model, characterized in that, include: The data acquisition module is used to collect alarm events and external information data, and store the external information data in the threat information database; The extraction module is used to parse key information of the alarm event to obtain a first feature, and to extract graph model information of the alarm event to obtain a second feature; A construction module is used to determine multiple threat assessment factors based on the first feature and the second feature, combined with the threat information database, including: determining a severity factor based on the first feature and the threat information database; determining a behavioral anomaly factor based on the second feature; determining an asset criticality coefficient based on the asset importance of the event target in the first feature; using the severity factor, behavioral anomaly factor, and asset criticality coefficient as multiple threat assessment factors; and constructing a dynamic threat assessment model containing multiple dynamic weights based on the multiple threat assessment factors; wherein the multiple dynamic weights include: a first dynamic weight, a second dynamic weight, and a third dynamic weight; constructing a dynamic threat assessment model containing multiple dynamic weights based on the multiple threat assessment factors includes: multiplying the severity factor by the first dynamic weight to obtain a first parameter term; multiplying the behavioral anomaly factor by the second dynamic weight to obtain a second parameter term; multiplying the square root of the asset criticality coefficient by the third dynamic weight to obtain a third parameter term; and multiplying the sum of the first parameter term and the second parameter term by the third parameter term to obtain the dynamic threat assessment model; An optimization module is used to construct the fitness function of the swarm intelligence algorithm, and based on the fitness function, to iteratively train and optimize multiple dynamic weights in the dynamic threat assessment model to obtain a closed-loop optimized dynamic threat assessment model.