A network security protection strategy generation method based on multi-source data fusion
Patent Information
- Application Number
- CN202610087457.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-22
- Publication Date
- 2026-09-11
- Estimated Expiration
- 2046-01-22
AI Technical Summary
[0003]多源安全数据格式异构、时间戳漂移与缺失频繁,现有对齐与补齐多停留在简单拼接,难以形成可追溯的一致证据序列;不同来源证据可靠性差异大且可伪造性不同,现有方法缺少可信度量化与门控机制,导致误报累积时策略触发不稳定;攻击链具有长时序依赖与跨域传播特性,传统短窗统计或浅层模型难以保持长上下文关联,影响攻击意图与风险态势判定;策略生成多依赖静态规则或人工经验,难以同时满足业务链路、变更窗口与合规审计约束,并缺少可回滚与执行反馈驱动的阈值自更新机制
[0053]This invention unifies the time alignment and missing data completion of multi-source security data from the network side, terminal side, identity side, asset and business topology side, and external threat intelligence side. It further standardizes heterogeneous observations into evidence unit sequences and generates evidence credibility vectors, enabling the construction of long, traceable evidence unit sequences aggregated by entity and sliding time window. This reduces the impact of cross-source time-series drift and data fragmentation on judgment from the source. In the inference stage, an improved Mamba-2 model is introduced, incorporating evidence unit embedding, credibility gating, business topology conditional injection, Mamba-2 backbone sequence modeling, and multi-task output. Simultaneously, it outputs attack intent distribution, risk posture embedding, and a set of key evidence citations, enabling long-time-series cross-... Domain attack clues can be stably integrated under credibility constraints, providing auditable evidence binding for subsequent policy generation. In the decision-making stage, a set of policy candidates is generated based on intent, situation, and evidence references. The policy package is then optimized under constraints of business links, change windows, and compliance audits. Combined with trigger thresholds and rollback conditions, controllable execution and reversible handling are achieved. Finally, the evidence credibility mapping parameters and trigger thresholds are updated through execution feedback, forming a closed-loop self-calibration mechanism. This improves the consistency of policy triggering and the reliability of business security collaboration, reduces the risk of false alarms, and enhances the response efficiency and continuous adaptation capability to complex and persistent attacks. It has significant engineering application importance and promotion value.
Smart Images

Figure CN121887510B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cyberspace security and automated security operations technology, and in particular to a method for generating network security protection strategies based on multi-source data fusion. Background Technology
[0002] With the expansion of enterprise networks and the normalization of cloud-edge collaboration and remote work, technologies for multi-source security data fusion analysis and automated protection strategy generation, targeting the network side, terminal side, identity side, asset and business topology side, and external threat intelligence side, have received widespread attention. Existing technologies mostly employ centralized log collection followed by rule association, alarm aggregation, or fixed script orchestration for processing, but in practical applications, the following problems are commonly encountered:
[0003] Multi-source security data suffers from heterogeneous formats, frequent timestamp drift and loss, and existing alignment and completion methods often rely on simple splicing, making it difficult to form a traceable and consistent evidence sequence. Evidence from different sources varies greatly in reliability and forgeryability, and existing methods lack credible quantification and gating mechanisms, leading to unstable policy triggering when false alarms accumulate. Attack chains have long temporal dependencies and cross-domain propagation characteristics, and traditional short-window statistics or shallow models cannot maintain long-term contextual relationships, affecting the determination of attack intent and risk posture. Policy generation relies heavily on static rules or human experience, making it difficult to simultaneously meet business links, change windows, and compliance audit constraints, and lacking a rollback and execution feedback-driven threshold self-update mechanism.
[0004] Therefore, how to provide a method for generating network security protection strategies based on multi-source data fusion is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0005] One objective of this invention is to propose a network security protection strategy generation method based on multi-source data fusion. This invention utilizes time alignment and missing data completion of multi-source security data, standardization of evidence units and gating of evidence credibility, conditional injection of business topology, and improved Mamba-2 sequence modeling and multi-task output to complete a closed-loop process from attack intent distribution and risk situation embedding reasoning to strategy candidate generation, constraint optimization to form a strategy package, and support for execution monitoring rollback and feedback self-update. It has the advantages of high strategy generation accuracy, strong evidence interpretability and auditability, minimal impact on business links, and strong continuous adaptive capability.
[0006] A method for generating network security protection strategies based on multi-source data fusion according to an embodiment of the present invention includes the following steps:
[0007] Step 1: Collect security data from the network side, terminal side, identity side, asset and business topology side, and external threat intelligence side, write timestamps, and perform time alignment and missing data filling to obtain a multi-source security data sequence;
[0008] Step 2: Standardize the multi-source security data sequence to generate an evidence unit sequence, and generate an evidence credibility vector for each evidence unit. Aggregate the evidence unit sequences according to entities and sliding time windows to construct a long sequence of evidence units.
[0009] Step 3: Input the long sequence of evidence units, the evidence credibility vector, and the business topology condition vector into the improved Mamba-2 model. The improved Mamba-2 model includes an evidence unit embedding module, a credibility gating module, a business topology conditional injection module, a Mamba-2 backbone sequence modeling module, and a multi-task output module, which outputs the attack intent distribution, risk posture embedding, and key evidence reference set.
[0010] Step 4: Generate a set of strategy candidates based on the distribution of attack intent, embedding of risk posture, and set of key evidence citations;
[0011] Step 5: Under the conditions of satisfying business link constraints, change window constraints, and compliance audit constraints, optimize the policy candidate set and output the policy package;
[0012] Step Six: Execute protective actions according to the policy package and monitor security and business indicators. When the rollback conditions are met, execute the rollback operation.
[0013] Step 7: Collect execution feedback and update the mapping parameters and trigger threshold of the evidence credibility vector.
[0014] Optionally, step one specifically includes:
[0015] Collect network-side session metadata and protocol events, terminal-side process and file events, identity-side login and session events, asset and business topology-side asset list and connectivity change events, and external threat intelligence events;
[0016] For each data collection record, write a record identifier, data source type identifier, entity identifier and original timestamp, and convert the original timestamp into a standard timestamp under the same clock reference.
[0017] Set up a unified time grid and map records from each data source to the unified time grid using standard timestamps to form aligned records. Perform missing field values in the unified time grid to fill in missing values.
[0018] The aligned records after completion time alignment and missing data filling are arranged in chronological order and associated by entity identifier to form a multi-source secure data sequence.
[0019] Optionally, step two specifically includes:
[0020] The multi-source security data sequence is divided into entity data streams according to entity identifiers, and a sliding time window is applied to each entity data stream to obtain windowed data segments.
[0021] Perform field normalization on each windowed data fragment;
[0022] An evidence unit sequence is generated based on a unified field set. Each evidence unit in the evidence unit sequence includes an entity identifier, behavior type, time window identifier, source type identifier, and feature vector.
[0023] For each evidence unit, an evidence credibility vector is generated, which includes a collection integrity component, a time alignment consistency component, an anomaly jump rate component, and a forgery penalty component.
[0024] The evidence unit sequence is aggregated according to entity and sliding time window to construct a long sequence of evidence units. The aggregation includes connecting evidence units in the same entity and the same time window according to standard timestamp, and truncating or retaining evidence unit sequences that exceed the preset maximum length within the time window according to preset priority.
[0025] Optionally, the improved Mamba-2 model includes an evidence unit embedding module, a credibility gating module, a service topology conditional injection module, a Mamba-2 backbone sequence modeling module, and a multi-task output module.
[0026] The credibility gating module includes a gating weight generation layer and an input gating layer. The gating weight generation layer maps the evidence credibility vector to a gating weight vector. The input gating layer multiplies the gating weight vector with the corresponding evidence embedding vector in the evidence embedding sequence element by element to obtain the gating evidence embedding sequence.
[0027] The business topology conditional injection module includes a condition vector generation layer and a dual-channel modulation layer. The condition vector generation layer concatenates the fields representing asset importance, business link dependency level, network partition identifier, and change window identifier in the business topology condition vector in sequence to form a condition vector. The dual-channel modulation layer obtains a condition bias vector and a condition scaling score vector by applying two sets of linear mappings to the condition vector. A Sigmoid activation is applied to the condition scaling score vector to obtain a condition scaling weight vector. The gated evidence embedding sequence is added to the condition bias vector by dimension and then multiplied element-wise by the condition scaling weight vector to obtain the conditional gated evidence embedding sequence.
[0028] The Mamba-2 backbone sequence modeling module is implemented based on the Structured State-Space Dual Computation Framework (SSD), which includes an input projection layer, a local convolutional layer, a nonlinear activation layer, a selective scan layer, and an output projection layer. The input projection layer performs a linear mapping on the conditionally gated evidence embedding sequence to obtain the backbone input sequence. The local convolutional layer performs one-dimensional depthwise separable convolution on the backbone input sequence to obtain the local feature sequence. The nonlinear activation layer applies SiLU activation to the local feature sequence to obtain the activated feature sequence. The selective scan layer performs state-space recursion on the activated feature sequence step by step to generate a state vector sequence and outputs the backbone output sequence. The output projection layer performs a linear mapping on the backbone output sequence to obtain the shared representation sequence.
[0029] The multi-task output module includes an attack intent output head, a risk situation output head, and an evidence citation output head. The attack intent output head performs time-weighted aggregation on the shared representation sequence to obtain an intent representation vector, and then applies Softmax normalization after linear mapping to obtain the attack intent distribution. The risk situation output head performs time-weighted mean pooling on the shared representation sequence to obtain a situation representation vector, and then applies linear mapping to obtain the risk situation embedding. The evidence citation output head applies linear mapping to the shared representation sequence to obtain a query vector sequence and a key vector sequence, calculates the dot product of the query vector sequence and the key vector sequence to obtain a citation score sequence, and selects the record identifiers of the top K evidence units according to the citation score from high to low to form a key evidence citation set.
[0030] Optionally, step four specifically includes:
[0031] Candidate categories for the policy primitive set are determined based on the distribution of attack intent. The policy primitive is an independently executable protection action unit. The policy primitive is divided into network-side policy primitives, terminal-side policy primitives, identity-side policy primitives and asset-side policy primitives according to the execution domain. Each policy primitive corresponds to a set of action parameter fields.
[0032] Based on the risk profile, a set of scopes is determined, which includes host scopes defined by entity identifiers, partition scopes defined by network partition identifiers, and service scopes defined by service link dependency levels. The policy primitives and the set of scopes are then combined using Cartesian combinations to generate initial candidate policies.
[0033] For each initial candidate strategy, a duration parameter is determined. The duration parameter is obtained by indexing a preset duration table according to the highest probability intent category in the attack intent distribution, and the duration parameter is written into the candidate strategy field.
[0034] Based on the key evidence citation set, an evidence binding field is generated for each initial candidate strategy. The evidence binding field includes the citation evidence unit record identifier set and the corresponding citation score.
[0035] Generate a rollback condition field for each initial candidate strategy, the rollback condition field including security rollback conditions and business rollback conditions;
[0036] The initial candidate strategies, which include policy primitives, scope, duration parameters, evidence binding fields, and rollback condition fields, are deduplicated and sorted by standard timestamps to form a policy candidate set.
[0037] Optionally, step five specifically includes:
[0038] Generate a value for each candidate strategy in the strategy candidate set, wherein the value consists of risk value, business value, compliance value and operation and maintenance value.
[0039] Construct a constraint set, which includes business link constraints, change window constraints, and compliance audit constraints;
[0040] Under the condition of satisfying the constraint set, the strategy candidate set is combined and selected. The combination and selection is to select candidate strategies from the strategy candidate set to form a subset of the candidate set, so that the total objective value after weighted summation of the cost values of each candidate strategy in the subset of the candidate set according to the preset weight is minimized, and the subset of the candidate set is used to generate a strategy package.
[0041] The strategy package is written into the action list field, trigger threshold field, rollback condition field, and key evidence reference field. The action list field is a sequence of candidate strategies in the candidate set subset sorted from high to low value. The trigger threshold field is obtained by weighting and summing the maximum probability value of the attack intent distribution and the combined value of the evidence credibility vector according to a preset ratio. The rollback condition field is the union of the rollback condition fields of the candidate strategies in the candidate set subset. The key evidence reference field is the union of the record identifier sets in the evidence binding field of the candidate strategies in the candidate set subset.
[0042] Optionally, step six specifically includes:
[0043] Parse the policy package to obtain the action list field, trigger threshold field, and rollback condition field, and generate a sequence of actions to be executed according to the order of the action list fields.
[0044] The execution determination is based on the trigger threshold field. The execution determination includes calculating the maximum probability value of the attack intent distribution and comparing it with the intent threshold, and calculating the comprehensive value of the evidence credibility vector and comparing it with the credibility threshold. When both the maximum probability value and the comprehensive value are not less than the corresponding threshold, the sequence of actions to be executed is executed.
[0045] The sequence of actions to be executed is distributed to the network-side execution channel, terminal-side execution channel, identity-side execution channel, and asset-side execution channel according to the execution domain and then executed.
[0046] A monitoring window is established and security indicators and business indicators are collected according to a preset sampling period to form a rollback judgment sequence. The security indicators include the maximum probability value sequence of attack intent distribution, and the business indicators include latency indicators and error rate indicators of key business links.
[0047] Rollback determination is performed on the rollback determination sequence based on the rollback condition field. When the rollback condition field is met, a rollback action sequence is generated and distributed to the corresponding execution channel for execution. The rollback action sequence cancels the executed actions according to the rule identifier, host identifier, session identifier and change identifier, and records the rollback timestamp and rollback reason identifier.
[0048] Optionally, step seven specifically includes:
[0049] Collect execution feedback and form feedback samples according to entity identifier and monitoring window identifier. The execution feedback includes security feedback and business feedback. The security feedback includes the maximum probability value change of the attack intent distribution and the hit rate of the key evidence reference set. The business feedback includes the key business link delay change, error rate change and rollback operation occurrence identifier.
[0050] Based on the feedback samples, update the mapping parameters of the evidence credibility vector and adjust the weight parameters of the source type identifier in the preset source reliability table;
[0051] Based on the feedback sample update trigger threshold, the mean of the comprehensive value of the evidence credibility vector and the maximum probability value of the attack intent distribution in the sample sets where the rollback action is marked as true and the rollback action is marked as false are respectively calculated, and the intent threshold and credibility threshold are updated according to the mean.
[0052] The beneficial effects of this invention are:
[0053] This invention unifies the time alignment and missing data completion of multi-source security data from the network side, terminal side, identity side, asset and business topology side, and external threat intelligence side. It further standardizes heterogeneous observations into evidence unit sequences and generates evidence credibility vectors, enabling the construction of long, traceable evidence unit sequences aggregated by entity and sliding time window. This reduces the impact of cross-source time-series drift and data fragmentation on judgment from the source. In the inference stage, an improved Mamba-2 model is introduced, incorporating evidence unit embedding, credibility gating, business topology conditional injection, Mamba-2 backbone sequence modeling, and multi-task output. Simultaneously, it outputs attack intent distribution, risk posture embedding, and a set of key evidence citations, enabling long-time-series cross-... Domain attack clues can be stably integrated under credibility constraints, providing auditable evidence binding for subsequent policy generation. In the decision-making stage, a set of policy candidates is generated based on intent, situation, and evidence references. The policy package is then optimized under constraints of business links, change windows, and compliance audits. Combined with trigger thresholds and rollback conditions, controllable execution and reversible handling are achieved. Finally, the evidence credibility mapping parameters and trigger thresholds are updated through execution feedback, forming a closed-loop self-calibration mechanism. This improves the consistency of policy triggering and the reliability of business security collaboration, reduces the risk of false alarms, and enhances the response efficiency and continuous adaptation capability to complex and persistent attacks. It has significant engineering application importance and promotion value. Attached Figure Description
[0054] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:
[0055] Figure 1 This is a flowchart of a network security protection strategy generation method based on multi-source data fusion proposed in this invention;
[0056] Figure 2 This is a schematic diagram of a network security protection strategy generation method based on multi-source data fusion proposed in this invention;
[0057] Figure 3 This is a framework diagram of the improved Mamba-2 model in the network security protection strategy generation method based on multi-source data fusion proposed in this invention. Detailed Implementation
[0058] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.
[0059] refer to Figure 1-3 A method for generating network security protection strategies based on multi-source data fusion includes the following steps:
[0060] Step 1: Collect security data from the network side, terminal side, identity side, asset and business topology side, and external threat intelligence side, write timestamps, and perform time alignment and missing data filling to obtain a multi-source security data sequence;
[0061] Step 2: Standardize the multi-source security data sequence to generate an evidence unit sequence, and generate an evidence credibility vector for each evidence unit. Aggregate the evidence unit sequences according to entities and sliding time windows to construct a long sequence of evidence units.
[0062] Step 3: Input the long sequence of evidence units, the evidence credibility vector, and the business topology condition vector into the improved Mamba-2 model. The improved Mamba-2 model includes an evidence unit embedding module, a credibility gating module, a business topology conditional injection module, a Mamba-2 backbone sequence modeling module, and a multi-task output module, which outputs the attack intent distribution, risk posture embedding, and key evidence reference set.
[0063] Step 4: Generate a set of strategy candidates based on the distribution of attack intent, embedding of risk posture, and set of key evidence citations;
[0064] Step 5: Under the conditions of satisfying business link constraints, change window constraints, and compliance audit constraints, optimize the policy candidate set and output the policy package;
[0065] Step Six: Execute protective actions according to the policy package and monitor security and business indicators. When the rollback conditions are met, execute the rollback operation.
[0066] Step 7: Collect execution feedback and update the mapping parameters and trigger threshold of the evidence credibility vector.
[0067] In this embodiment, step one specifically includes:
[0068] Collect network-side session metadata and protocol events, terminal-side process and file events, identity-side login and session events, asset and business topology-side asset list and connectivity change events, and external threat intelligence events;
[0069] For each data collection record, a record identifier, a data source type identifier, an entity identifier, and an original timestamp are written, and the original timestamps are uniformly converted into standard timestamps under the same clock reference. The clock reference is established through Network Time Protocol (NTP) or Precision Time Protocol (PTP).
[0070] Set up a unified time grid and map records from each data source to the unified time grid using standard timestamps to form aligned records. During alignment, linear interpolation is used for continuous numerical fields and nearest neighbor mapping is used for discrete event fields. Missing field values in the unified time grid are filled with missing values. Missing filling is performed according to the field type using one of three methods: keeping the previous valid value, filling with zero value, or filling with a predefined unknown enumeration code.
[0071] The aligned records after completion time alignment and missing data filling are arranged in chronological order and associated by entity identifier to form a multi-source secure data sequence.
[0072] In this embodiment, step two specifically includes:
[0073] The multi-source security data sequence is divided into entity data streams according to entity identifiers, and a sliding time window is applied to each entity data stream to obtain windowed data segments.
[0074] For each windowed data fragment, field standardization is performed. Field standardization includes mapping field names from different data sources to a unified set of fields, unifying units and value ranges to preset units and preset ranges, converting discrete category fields to enumeration codes, converting text fields to preset dictionary index sequences, and marking missing fields with predefined missing identifiers.
[0075] Evidence unit sequence is generated based on a unified field set. Each evidence unit in the evidence unit sequence includes an entity identifier, behavior type, time window identifier, source type identifier, and feature vector. The behavior type is a category label determined by the event type field and rule mapping table in the unified field set. The feature vector is obtained by embedding and concatenating the continuous numerical field statistics, discrete field count vector, and text index sequence associated with the behavior type within the windowed data fragment.
[0076] An evidence credibility vector is generated for each evidence unit. The evidence credibility vector includes a collection integrity component, a time alignment consistency component, an anomaly jump rate component, and a forgery penalty component. The collection integrity component is calculated by the ratio of the number of valid records in the window to the expected number of records. The time alignment consistency component is calculated by the time deviation statistics after the records of each data source are mapped to a unified time grid. The anomaly jump rate component is calculated by the ratio of the number of mutation points of continuous numerical fields in the window to the window length. The forgery penalty component is determined by the corresponding penalty value of the source type identifier in the preset source reliability table.
[0077] The evidence unit sequence is aggregated according to entity and sliding time window to construct a long sequence of evidence units. The aggregation includes connecting evidence units in the same entity and the same time window according to standard timestamps, and truncating or retaining evidence unit sequences that exceed the preset maximum length within the time window according to preset priority. The preset priority is determined by the comprehensive value of the evidence credibility vector from high to low.
[0078] In this embodiment, the improved Mamba-2 model includes an evidence unit embedding module, a credibility gating module, a service topology conditional injection module, a Mamba-2 backbone sequence modeling module, and a multi-task output module.
[0079] The credibility gating module includes a gating weight generation layer and an input gating layer. The gating weight generation layer performs a linear mapping on the evidence credibility vector to obtain a gating score vector, and obtains a gating weight vector with values between zero and one through Sigmoid activation. The input gating layer performs element-wise multiplication of the gating weight vector with the corresponding evidence embedding vector in the evidence embedding sequence to obtain a gating evidence embedding sequence.
[0080] The business topology conditional injection module includes a condition vector generation layer and a dual-channel modulation layer. The condition vector generation layer concatenates the fields representing asset importance, business link dependency level, network partition identifier, and change window identifier in the business topology condition vector in sequence to form a condition vector. The dual-channel modulation layer obtains a condition bias vector and a condition scaling score vector by applying two sets of linear mappings to the condition vector. A Sigmoid activation is applied to the condition scaling score vector to obtain a condition scaling weight vector. The gated evidence embedding sequence is added to the condition bias vector by dimension and then multiplied element-wise by the condition scaling weight vector to obtain the conditional gated evidence embedding sequence.
[0081] The Mamba-2 backbone sequence modeling module is implemented based on the Structured State-Space Dual Computation Framework (SSD), which includes an input projection layer, a local convolutional layer, a nonlinear activation layer, a selective scan layer, and an output projection layer. The input projection layer performs a linear mapping on the conditionally gated evidence embedding sequence to obtain the backbone input sequence. The local convolutional layer performs one-dimensional depthwise separable convolution on the backbone input sequence to obtain the local feature sequence. The nonlinear activation layer applies SiLU activation to the local feature sequence to obtain the activated feature sequence. The selective scan layer performs state-space recursion on the activated feature sequence step by step to generate a state vector sequence and outputs the backbone output sequence. The output projection layer performs a linear mapping on the backbone output sequence to obtain the shared representation sequence.
[0082] The multi-task output module includes an attack intent output header, a risk situation output header, and an evidence citation output header. The attack intent output header performs time-weighted aggregation on the shared representation sequence to obtain an intent representation vector, and then applies Softmax normalization after linear mapping to obtain the attack intent distribution. The risk situation output header performs time-weighted mean pooling on the shared representation sequence to obtain a situation representation vector, and then applies linear mapping to obtain the risk situation embedding. The evidence citation output header applies linear mapping to the shared representation sequence to obtain a query vector sequence and a key vector sequence, calculates the dot product of the query vector sequence and the key vector sequence to obtain a citation score sequence, and selects the record identifiers of the top K evidence units according to the citation score from high to low to form a key evidence citation set, wherein the key evidence citation set is consistent with the key evidence citation field in the strategy package.
[0083] This implementation introduces an improved Mamba-2 model into the long sequence modeling stage of evidence units to achieve long-context fusion inference of multi-source evidence. The Mamba-2 model, based on a structured state-space dual framework for backbone sequence modeling, maintains stable temporal memory and high inference efficiency under long sequence conditions, making it suitable for scenarios where security logs are cross-source, sparse, and long-duration. Compared to existing models primarily based on short-window statistics, rule association, or full-attention Transformers, this implementation does not rely on global pairwise attention computation, reducing the computational overhead of long sequences and the false associations caused by temporal drift. Simultaneously, evidence unit embedding and credibility gating are introduced at the model front end, suppressing noise from low credibility, forgery, or missing information before it enters the backbone element by element. Furthermore, business topology conditional injection encodes constraints such as asset importance, link dependency levels, partitions, and change windows into the representation, enabling differentiated risk expressions for the same attack intent across different business domains. Finally, multi-task output synchronously generates attack intent distribution, risk posture embedding, and key evidence reference sets, ensuring that strategy generation is auditable and traceable. Therefore, this implementation improves the consistency of intent determination and the stability of risk representation under conditions of conflicting and incomplete multi-source evidence, reduces the probability of false alarms-driven false positives, and improves the matching degree of strategy generation with business constraints.
[0084] In this embodiment, step four specifically includes:
[0085] Candidate categories for the policy primitive set are determined based on the distribution of attack intent. The policy primitive is an independently executable protection action unit. The policy primitive is divided into network-side policy primitives, terminal-side policy primitives, identity-side policy primitives and asset-side policy primitives according to the execution domain. Each policy primitive corresponds to a set of action parameter fields.
[0086] Based on the risk profile, a set of scopes is determined, which includes host scopes defined by entity identifiers, partition scopes defined by network partition identifiers, and service scopes defined by service link dependency levels. The policy primitives and the set of scopes are then combined using Cartesian combinations to generate initial candidate policies.
[0087] For each initial candidate strategy, a duration parameter is determined. The duration parameter is obtained by indexing a preset duration table according to the highest probability intent category in the attack intent distribution, and the duration parameter is written into the candidate strategy field.
[0088] Based on the key evidence reference set, an evidence binding field is generated for each initial candidate strategy. The evidence binding field includes the referenced evidence unit record identifier set and the corresponding reference score, and the reference score is taken from the score value corresponding to the record identifier in the reference score sequence.
[0089] A rollback condition field is generated for each initial candidate strategy. The rollback condition field includes a security rollback condition and a business rollback condition. The security rollback condition is determined by the switching of the highest probability intent category or the highest probability value being lower than a preset intent threshold within a continuous preset monitoring window. The business rollback condition is determined by the monitoring index of the key business link corresponding to the business topology condition vector exceeding a preset business threshold within a continuous preset monitoring window.
[0090] The initial candidate strategies, which include policy primitives, scope, duration parameters, evidence binding fields, and rollback condition fields, are deduplicated and sorted by standard timestamps to form a policy candidate set.
[0091] In this embodiment, step five specifically includes:
[0092] A cost value is generated for each candidate strategy in the strategy candidate set. The cost value consists of risk cost value, business cost value, compliance cost value, and operation and maintenance cost value. The risk cost value is obtained by embedding the risk situation within the scope of the candidate strategy into a risk score and multiplying it by the probability value of the intent category corresponding to the candidate strategy in the attack intent distribution. The business cost value is obtained by matching the scope of the candidate strategy with the business link dependency level in the business topology condition vector to obtain the business weight and multiplying it by the duration parameter of the candidate strategy. The compliance cost value is determined by matching the execution domain of the candidate strategy with the compliance level field in the business topology condition vector to obtain the compliance weight. The operation and maintenance cost value is obtained by summing the cost values retrieved from the preset operation and maintenance cost table for the action parameter field of the candidate strategy.
[0093] Construct a constraint set, which includes business link constraints, change window constraints, and compliance audit constraints. The business link constraint prohibits the selection of isolation and blocking policy primitives when the scope of the candidate policy covers the key business links identified by the business topology condition vector. The change window constraint prohibits the selection of asset-side policy primitives when the change window identifier of the business topology condition vector indicates a non-permitted period. The compliance audit constraint forces the writing of the evidence binding field and action parameter field of the candidate policy into the audit record field when the execution domain of the candidate policy is the network side or the identity side.
[0094] Under the condition of satisfying the constraint set, the strategy candidate set is combined and selected. The combination and selection is to select candidate strategies from the strategy candidate set to form a subset of the candidate set, so that the total objective value after weighted summation of the cost values of each candidate strategy in the subset of the candidate set according to the preset weight is minimized, and the subset of the candidate set is used to generate a strategy package.
[0095] The strategy package is written into the action list field, trigger threshold field, rollback condition field, and key evidence reference field. The action list field is a sequence of candidate strategies in the candidate set subset sorted from high to low value. The trigger threshold field is obtained by weighting and summing the maximum probability value of the attack intent distribution and the combined value of the evidence credibility vector according to a preset ratio. The rollback condition field is the union of the rollback condition fields of the candidate strategies in the candidate set subset. The key evidence reference field is the union of the record identifier sets in the evidence binding field of the candidate strategies in the candidate set subset.
[0096] In this embodiment, step six specifically includes:
[0097] The strategy package is parsed to obtain the action list field, trigger threshold field, and rollback condition field. The action sequence to be executed is generated according to the order of the action list fields. Each action in the action sequence to be executed includes the execution domain, scope, action parameter field, and duration parameter.
[0098] The execution determination is based on the trigger threshold field. The execution determination includes calculating the maximum probability value of the attack intent distribution and comparing it with the intent threshold, and calculating the comprehensive value of the evidence credibility vector and comparing it with the credibility threshold. When both the maximum probability value and the comprehensive value are not less than the corresponding threshold, the sequence of actions to be executed is executed.
[0099] The sequence of actions to be executed is distributed to the network-side execution channel, terminal-side execution channel, identity-side execution channel, and asset-side execution channel according to the execution domain and executed. The network-side execution channel issues access control rules or feature blocking rules and writes rule identifiers; the terminal-side execution channel issues process blocking instructions or host isolation instructions and writes host identifiers; the identity-side execution channel issues session invalidation instructions or mandatory authentication instructions and writes session identifiers; and the asset-side execution channel issues configuration change instructions or port closing instructions and writes change identifiers.
[0100] A monitoring window is established and security indicators and business indicators are collected according to a preset sampling period to form a rollback judgment sequence. The security indicators include the maximum probability value sequence of attack intent distribution, and the business indicators include latency indicators and error rate indicators of key business links.
[0101] Rollback determination is performed on the rollback determination sequence based on the rollback condition field. When the rollback condition field is met, a rollback action sequence is generated and distributed to the corresponding execution channel for execution. The rollback action sequence cancels the executed actions according to the rule identifier, host identifier, session identifier and change identifier, and records the rollback timestamp and rollback reason identifier.
[0102] In this embodiment, step seven specifically includes:
[0103] Collect execution feedback and form feedback samples according to entity identifier and monitoring window identifier. The execution feedback includes security feedback and business feedback. The security feedback includes the maximum probability value change of the attack intent distribution and the hit rate of the key evidence reference set. The business feedback includes the key business link delay change, error rate change and rollback operation occurrence identifier.
[0104] Based on the feedback sample, the mapping parameters of the evidence credibility vector are updated, and the weight parameters of the source type identifier in the preset source reliability table are adjusted. When the rollback operation occurrence identifier is true and the change in the delay of the critical business link exceeds the business threshold, the weight parameter of the source type identifier corresponding to the critical evidence reference set is reduced. When the rollback operation occurrence identifier is false and the change in the maximum probability value of the attack intent distribution is lower than the security threshold, the weight parameter of the source type identifier corresponding to the critical evidence reference set is increased.
[0105] Based on the feedback sample update trigger threshold, the mean of the comprehensive value of the evidence credibility vector and the maximum probability value of the attack intent distribution in the sample sets where the rollback action is marked as true and the rollback action is marked as false are respectively calculated, and the intent threshold and credibility threshold are updated according to the mean.
[0106] Example 1:
[0107] To verify the feasibility of this invention in practice, it was applied to the hybrid cloud office network of a manufacturing enterprise. The enterprise has approximately 2,500 terminals, 160 servers, 3 core business partitions, and 2 Internet exits, with an average of about 1.8 billion original security incident records per day. SIEM and SOAR have been deployed for coordinated handling on the current network.
[0108] The data collection side uniformly accesses network-side session metadata and protocol events, terminal-side process and file events, identity-side login and session events, asset and business topology-side asset list and connectivity change events, and external threat intelligence events. All collected records are written with record identifiers, data source type identifiers, entity identifiers, and original timestamps, and converted to standard timestamps after NTP time synchronization. The unified time grid is set to a 1-second granularity. Continuous numerical fields are mapped to the time grid using linear interpolation, while discrete event fields are mapped using nearest neighbor. In missing data completion, network-side traffic count fields are filled with zero values, identity-side status fields use predefined unknown enumeration encoding, and terminal-side continuous status fields retain the previous valid value. During operation, entity data streams are divided by entity identifiers. The sliding time window is set to a window length of 300 seconds and a step size of 30 seconds, forming windowed data fragments and standardizing the fields. Field names are mapped to a unified field set, and units and ranges are unified to preset ranges. Discrete category fields are enumerated and encoded, while text fields are converted to a preset dictionary index sequence and marked with missing identifiers. Subsequently, an evidence unit sequence is generated. Each evidence unit includes an entity identifier, behavior type, time window identifier, source type identifier, and feature vector. The feature vector is obtained by concatenating continuous statistics within the window, discrete count vectors, and text index embeddings. An evidence credibility vector is then generated. The collection integrity component is calculated as the ratio of the number of valid records within the window to the expected number of records. The time alignment consistency component is calculated as the time deviation statistics after mapping to the time raster. The anomalous jump rate component is calculated as the ratio of the number of consecutive field mutation points to the window length. The forgery penalty component is determined by the penalty value of the source type identifier in the preset source reliability table. After aggregation by entity and sliding time window, a long sequence of evidence units is constructed. The maximum number of evidence units per window is set to 2048. If the maximum is exceeded, evidence units are retained from high to low based on the comprehensive evidence credibility value.
[0109] The inference side employs an improved Mamba-2 model with an evidence unit embedding dimension of 256. Discrete field embeddings and continuous feature projections are layer-normalized to obtain the evidence embedding sequence. In the credibility gating, the evidence credibility vector is linearly mapped to a gating score, and a 0-to-1 gating weight is obtained through Sigmoid. This weight is then multiplied element-wise with the evidence embedding to obtain the gated evidence embedding sequence. The business topology condition vector is composed of asset importance grading values, business link dependency levels, network partition identifiers, and change window identifiers, concatenated sequentially. After dual-channel modulation, conditional biases and conditional scaling weights are obtained. The biases are first added and then multiplied element-wise to obtain the conditional gated evidence embedding sequence. The backbone sequence modeling adopts the Mamba-2 structure of the SSD framework. After input projection, it is subjected to one-dimensional depthwise separable convolution and SiLU activation, and then selectively scanned to obtain the shared representation sequence. The multi-task output simultaneously provides the attack intent distribution, risk posture embedding, and key evidence citation set. The top 10 key evidence is selected and written into the subsequent policy package. The strategy side determines candidate policy primitives based on the distribution of attack intent and combines them with the scope to form a policy candidate set. The duration is given by a preset duration table, with external control policies defaulting to 20 minutes, identity enhancement policies defaulting to 40 minutes, and terminal isolation policies defaulting to 15 minutes. Rollback conditions adopt a dual-threshold structure: the initial value of the intent threshold is set to 0.78, and the initial value of the trust threshold is set to 0.72. The business side triggers rollback when the critical link P95 latency increases by more than 25 milliseconds or the error rate increases by more than 0.3%. Constraint optimization selects the subset of candidate primitives with the lowest total proxy value to output the policy package, under the conditions of prohibiting isolation and blocking of critical business links, prohibiting asset-side changes during non-permitted periods, and mandating audit records on the network and identity sides. An action list is then formed by ranking proxy values from highest to lowest. After execution, a monitoring window is established with a sampling period of 10 seconds, continuously observing for 90 minutes. The sequence of the highest probability values of attack intent, along with critical link latency and error rate, are written into the rollback judgment sequence. If the rollback conditions are met, the action is revoked according to the rule identifier, host identifier, session identifier, and change identifier, and the reason is recorded. The feedback side aggregates security feedback and business feedback into a feedback sample, which is used to update the source reliability table weights and the two types of trigger thresholds.
[0110] To verify the effectiveness, 120 security incidents confirmed through review within 30 days were selected as positive samples, while noise alarms generated during peak business hours were selected as negative samples. Two existing solutions were compared: Solution A is a traditional solution of "rule association + fixed SOAR script," and Solution B is a learning solution of "Transformer encoder + unified feature concatenation." All three solutions access the same data source and use the same execution channel; the differences lie only in the evidence fusion inference and policy generation logic. The comprehensive comparison data is shown in Table 1 below.
[0111] Table 1. Comprehensive Comparison Data of Actual Measurements
[0112] Method of the present invention 0.91 0.88 0.895 38 3.8 14 2.1% 6 98% 1.6 Existing Solution A 0.72 0.63 0.672 96 11.5 42 7.8% 18 85% 4.3 Existing Solution B 0.84 0.75 0.792 55 6.2 24 4.9% 10 90% 2.8
[0113] As shown in Table 1, the method of this invention improves F1 to 0.895 under the same data source conditions, which is approximately 0.223 higher than the existing solution A and approximately 0.103 higher than the existing solution B. The average daily false alarms are reduced to 38, which is 58 fewer than the existing solution A, and the false alarm reduction is approximately 60%, which is 17 fewer than the existing solution B. In terms of discovery latency, the average discovery latency MTTD of this invention is 3.8 minutes, which is 7.7 minutes shorter than the existing solution A and 2.4 minutes shorter than the existing solution B, enabling earlier entry into the handling window. The average handling closed-loop MTTC is reduced to 14 minutes, mainly due to the constraint optimization selection of the strategy candidate set and the ordering of the action list, making the handling actions more focused and less repetitive. In terms of business impact, the critical link P95 latency increment is controlled at 6 milliseconds, which is significantly lower than the two comparative solutions, and the rollback trigger rate is only 2.1%, indicating that the strategy package is more stable under business link constraints and change window constraints. With an audit record completeness rate of 98%, and after being bound to the key evidence citation set, the evidence unit record identifier that triggered the strategy can be directly traced back during the review, reducing the cost of manual evidence collection and alignment. As a result, the average daily man-hours for security operations have been reduced to 1.6 hours.
[0114] Further ablation analysis was conducted on the two key improvements, "trustworthiness gating" and "business topology conditional injection." Keeping the backbone Mamba-2 and policy optimizer unchanged, only the corresponding modules were removed, and the same dataset was re-run. The results are shown in Table 2 below.
[0115] Table 2 Comparison of Ablation Data for Key Modules
[0116] Full configuration (gating + conditionalization + multi-task output) 0.895 38 2.1% 6 Remove the trust level gate module 0.851 49 3.4% 7 Remove the business topology conditional injection module 0.862 46 3.0% 9 Simultaneously remove gating and conditionalization. 0.823 61 4.6% 10
[0117] Table 2 shows that the absence of the credibility gating module increases both false alarms and rollbacks, indicating a decrease in the ability to suppress insufficient data collection integrity, time alignment deviations, and forged sources. The absence of the business topology conditional injection module significantly increases the incremental business latency and the rollback rate, indicating that without asset importance and link dependency level modulation, the strategy is more likely to have unnecessary impacts on critical links. The degradation of indicators is most obvious when both are removed simultaneously, verifying the synergistic effect of "credibility constraint evidence fusion" and "business constraint pre-injection".
[0118] This embodiment demonstrates that, based on time alignment and missing data completion of multi-source security data, the present invention constructs a traceable long sequence using evidence unit sequences and evidence credibility vectors, and simultaneously outputs intent, situation, and evidence references through an improved Mamba-2, combined with constraint optimization to form an executable, rollback, and auditable policy package. It can achieve stable improvements in false alarm suppression, detection and handling latency, business impact control, and operation and maintenance costs, and is particularly suitable for enterprise-level network security protection scenarios with multiple data sources, long attack chains, and strong business constraints.
[0119] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.
Claims
1. A method for generating network security protection strategies based on multi-source data fusion, characterized in that, Includes the following steps: Step 1: Collect security data from the network side, terminal side, identity side, asset and business topology side, and external threat intelligence side, write timestamps, and perform time alignment and missing data filling to obtain a multi-source security data sequence; Step 2: Standardize the multi-source security data sequence to generate an evidence unit sequence, and generate an evidence credibility vector for each evidence unit. Aggregate the evidence unit sequences according to entities and sliding time windows to construct a long sequence of evidence units. Step 3: Input the long sequence of evidence units, the evidence credibility vector, and the business topology condition vector into the improved Mamba-2 model. The improved Mamba-2 model includes an evidence unit embedding module, a credibility gating module, a business topology conditional injection module, a Mamba-2 backbone sequence modeling module, and a multi-task output module, which outputs the attack intent distribution, risk posture embedding, and key evidence reference set. Step 4: Generate a set of strategy candidates based on the distribution of attack intent, embedding of risk posture, and set of key evidence citations; Step 5: Under the conditions of satisfying business link constraints, change window constraints, and compliance audit constraints, optimize the policy candidate set and output the policy package; Step Six: Execute protective actions according to the policy package and monitor security and business indicators. When the rollback conditions are met, execute the rollback operation. Step 7: Collect execution feedback and update the mapping parameters and trigger threshold of the evidence credibility vector; The evidence unit embedding module performs discrete field embedding on discrete fields in the long sequence of evidence units, performs continuous feature projection on feature vectors, and performs layer normalization on the discrete field embedding results and continuous feature projection results to obtain the evidence embedding sequence. The credibility gating module includes a gating weight generation layer and an input gating layer. The gating weight generation layer maps the evidence credibility vector to a gating weight vector. The input gating layer multiplies the gating weight vector with the corresponding evidence embedding vector in the evidence embedding sequence element by element to obtain the gating evidence embedding sequence. The business topology conditional injection module includes a condition vector generation layer and a dual-channel modulation layer. The condition vector generation layer concatenates the fields representing asset importance, business link dependency level, network partition identifier, and change window identifier in the business topology condition vector in sequence to form a condition vector. The dual-channel modulation layer obtains a condition bias vector and a condition scaling score vector by applying two sets of linear mappings to the condition vector. A Sigmoid activation is applied to the condition scaling score vector to obtain a condition scaling weight vector. The gated evidence embedding sequence is added to the condition bias vector by dimension and then multiplied element-wise by the condition scaling weight vector to obtain the conditional gated evidence embedding sequence. The Mamba-2 backbone sequence modeling module is implemented based on the Structured State-Space Dual Computation Framework (SSD), which includes an input projection layer, a local convolutional layer, a nonlinear activation layer, a selective scan layer, and an output projection layer. The input projection layer performs a linear mapping on the conditionally gated evidence embedding sequence to obtain the backbone input sequence. The local convolutional layer performs one-dimensional depthwise separable convolution on the backbone input sequence to obtain the local feature sequence. The nonlinear activation layer applies SiLU activation to the local feature sequence to obtain the activated feature sequence. The selective scan layer performs state-space recursion on the activated feature sequence step by step to generate a state vector sequence and outputs the backbone output sequence. The output projection layer performs a linear mapping on the backbone output sequence to obtain the shared representation sequence. The multi-task output module includes an attack intent output head, a risk situation output head, and an evidence citation output head. The attack intent output head performs time-weighted aggregation on the shared representation sequence to obtain an intent representation vector, and then applies Softmax normalization after linear mapping to obtain the attack intent distribution. The risk situation output head performs time-weighted mean pooling on the shared representation sequence to obtain a situation representation vector, and then applies linear mapping to obtain the risk situation embedding. The evidence citation output head applies linear mapping to the shared representation sequence to obtain a query vector sequence and a key vector sequence, calculates the dot product of the query vector sequence and the key vector sequence to obtain a citation score sequence, and selects the record identifiers of the top K evidence units according to the citation score from high to low to form a key evidence citation set. The trigger threshold field is obtained by weighting and summing the maximum probability value of the attack intent distribution with the comprehensive value of the evidence credibility vector according to a preset ratio. The evidence credibility vector includes a collection integrity component, a time alignment consistency component, an anomaly jump rate component, and a forgery penalty component. The collection integrity component is calculated by the ratio of the number of valid records in the window to the expected number of records. The time alignment consistency component is calculated by the time deviation statistics after the records of each data source are mapped to a unified time grid. The anomaly jump rate component is calculated by the ratio of the mutation point count of the continuous numerical field in the window to the window length. The forgery penalty component is determined by the corresponding penalty value of the source type identifier in the preset source reliability table.
2. The method for generating network security protection strategies based on multi-source data fusion according to claim 1, characterized in that, Step one specifically includes: Collect network-side session metadata and protocol events, terminal-side process and file events, identity-side login and session events, asset and business topology-side asset list and connectivity change events, and external threat intelligence events; For each data collection record, write a record identifier, data source type identifier, entity identifier and original timestamp, and convert the original timestamp into a standard timestamp under the same clock reference. Set up a unified time grid and map records from each data source to the unified time grid using standard timestamps to form aligned records. Perform missing field values in the unified time grid to fill in missing values. The aligned records after completion time alignment and missing data filling are arranged in chronological order and associated by entity identifier to form a multi-source secure data sequence.
3. The method for generating network security protection strategies based on multi-source data fusion according to claim 1, characterized in that, Step two specifically includes: The multi-source security data sequence is divided into entity data streams according to entity identifiers, and a sliding time window is applied to each entity data stream to obtain windowed data segments. Perform field normalization on each windowed data fragment; An evidence unit sequence is generated based on a unified field set. Each evidence unit in the evidence unit sequence includes an entity identifier, behavior type, time window identifier, source type identifier, and feature vector. Generate an evidence credibility vector for each evidence unit; The evidence unit sequence is aggregated according to entity and sliding time window to construct a long sequence of evidence units. The aggregation includes connecting evidence units in the same entity and the same time window according to standard timestamp, and truncating or retaining evidence unit sequences that exceed the preset maximum length within the time window according to preset priority.
4. The method for generating network security protection strategies based on multi-source data fusion according to claim 1, characterized in that, Step four specifically includes: Candidate categories for the policy primitive set are determined based on the distribution of attack intent. The policy primitive is an independently executable protection action unit. The policy primitive is divided into network-side policy primitives, terminal-side policy primitives, identity-side policy primitives and asset-side policy primitives according to the execution domain. Each policy primitive corresponds to a set of action parameter fields. Based on the risk profile, a set of scopes is determined, which includes host scopes defined by entity identifiers, partition scopes defined by network partition identifiers, and service scopes defined by service link dependency levels. The policy primitives and the set of scopes are then combined using Cartesian combinations to generate initial candidate policies. For each initial candidate strategy, a duration parameter is determined. The duration parameter is obtained by indexing a preset duration table according to the highest probability intent category in the attack intent distribution, and the duration parameter is written into the candidate strategy field. Based on the key evidence citation set, an evidence binding field is generated for each initial candidate strategy. The evidence binding field includes the citation evidence unit record identifier set and the corresponding citation score. Generate a rollback condition field for each initial candidate strategy. The rollback condition field includes a security rollback condition and a business rollback condition. The initial candidate strategies, which include policy primitives, scope, duration parameters, evidence binding fields, and rollback condition fields, are deduplicated and sorted by standard timestamps to form a policy candidate set.
5. The method for generating network security protection strategies based on multi-source data fusion according to claim 1, characterized in that, Step five specifically includes: Generate a value for each candidate strategy in the strategy candidate set, wherein the value consists of risk value, business value, compliance value and operation and maintenance value. Construct a constraint set, which includes business link constraints, change window constraints, and compliance audit constraints; Under the condition of satisfying the constraint set, the strategy candidate set is combined and selected. The combination and selection is to select candidate strategies from the strategy candidate set to form a subset of the candidate set, so that the total objective value after weighted summation of the cost values of each candidate strategy in the subset of the candidate set according to the preset weight is minimized, and the subset of the candidate set is used to generate a strategy package. The strategy package is written into the action list field, trigger threshold field, rollback condition field, and key evidence reference field. The action list field is a sequence of candidate strategies in the candidate set subset sorted from high to low value. The rollback condition field is the union of the rollback condition fields of the candidate strategies in the candidate set subset. The key evidence reference field is the union of the record identifier sets in the evidence binding field of the candidate strategies in the candidate set subset.
6. The method for generating network security protection strategies based on multi-source data fusion according to claim 5, characterized in that, Step six specifically includes: Parse the policy package to obtain the action list field, trigger threshold field, and rollback condition field, and generate a sequence of actions to be executed according to the order of the action list fields. The execution determination is based on the trigger threshold field. The execution determination includes calculating the maximum probability value of the attack intent distribution and comparing it with the intent threshold, and calculating the comprehensive value of the evidence credibility vector and comparing it with the credibility threshold. When both the maximum probability value and the comprehensive value are not less than the corresponding threshold, the sequence of actions to be executed is executed. The sequence of actions to be executed is distributed to the network-side execution channel, terminal-side execution channel, identity-side execution channel, and asset-side execution channel according to the execution domain and then executed. A monitoring window is established and security indicators and business indicators are collected according to a preset sampling period to form a rollback judgment sequence. The security indicators include the maximum probability value sequence of attack intent distribution, and the business indicators include latency indicators and error rate indicators of key business links. Rollback determination is performed on the rollback determination sequence based on the rollback condition field. When the rollback condition field is met, a rollback action sequence is generated and distributed to the corresponding execution channel for execution. The rollback action sequence cancels the executed actions according to the rule identifier, host identifier, session identifier and change identifier, and records the rollback timestamp and rollback reason identifier.
7. The method for generating network security protection strategies based on multi-source data fusion according to claim 1, characterized in that, Step seven specifically includes: Collect execution feedback and form feedback samples according to entity identifier and monitoring window identifier. The execution feedback includes security feedback and business feedback. The security feedback includes the maximum probability value change of the attack intent distribution and the hit rate of the key evidence reference set. The business feedback includes the key business link delay change, error rate change and rollback operation occurrence identifier. Based on the feedback samples, update the mapping parameters of the evidence credibility vector and adjust the weight parameters of the source type identifier in the preset source reliability table; Based on the feedback sample update trigger threshold, the mean of the comprehensive value of the evidence credibility vector and the maximum probability value of the attack intent distribution in the sample sets where the rollback action is marked as true and the rollback action is marked as false are respectively calculated, and the intent threshold and credibility threshold are updated according to the mean.
Citation Information
Patent Citations
Network attack active defense strategy optimization method based on deep reinforcement learning
CN120934876A
User state intervention method and system based on multi-modal perception and interpretable decision
CN120951111A