Network security defense strategy accurate evaluation and protection effect quantitative analysis method and system

By acquiring real-time attack data and policy execution records, and using analogy models for disturbance and correlation analysis, a profile of the effectiveness of defense strategies is generated, and a stability index is calculated. This solves the problem of inaccurate evaluation of defense strategies in existing technologies and enables accurate evaluation and optimization in dynamic network environments.

CN122027352APending Publication Date: 2026-05-12STATE GRID HENAN ELECTRIC POWER ELECTRIC POWER SCI RES INST +3
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
STATE GRID HENAN ELECTRIC POWER ELECTRIC POWER SCI RES INST
Filing Date
2026-04-09
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Existing technologies struggle to accurately quantify the real-time matching degree between defense strategies and dynamic attack intentions in dynamic network environments, leading to unstable evaluation results and failing to provide a reliable basis for strategy optimization.

Method used

By acquiring real-time attack data and strategy execution records, perturbation analysis is performed using a pre-trained analog model. The response trajectory of the defense strategy is correlated with abnormal features to generate an effect profile. The stability index is then calculated, and the strategy parameters are adjusted in reverse.

Benefits of technology

It enables precise evaluation of the effectiveness of defense strategies in dynamic adversarial environments, improves the accuracy and scenario relevance of evaluation results, and enhances the adaptability and stability of the protection system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122027352A_ABST
    Figure CN122027352A_ABST
Patent Text Reader

Abstract

The invention provides a network security defense strategy accurate evaluation and protection effect quantitative analysis method and system, and relates to the technical field of network security analysis. The method comprises the following steps: firstly, acquiring real-time attack data and strategy execution records in a target network environment; secondly, performing disturbance analysis on the real-time attack data through a pre-trained analogy model to obtain abnormal features representing attack intentions; then, on the basis of the strategy execution record, constructing a response track and carrying out association analysis on the response track and the abnormal features to generate an effect profile of the defense strategy; key state data are collected, and the stability index of the protection effect is calculated according to the effect profile; and finally, according to the stability index, reversely adjusting strategy parameters for generating a response track. According to the technical scheme provided by the invention, a data-driven closed loop from attack intention feature extraction to defense strategy parameter adaptive adjustment is realized, and the accuracy and dynamic adaptability of network security defense are also improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security analysis technology, and in particular to a method and system for accurate evaluation of network security defense strategies and quantitative analysis of protection effectiveness. Background Technology

[0002] As cyberattacks become increasingly dynamic and covert, accurately assessing and quantifying the effectiveness of cybersecurity defense strategies has become an urgent technical requirement for ensuring the stable operation of critical information systems.

[0003] One current technical solution to this technical need is an evaluation method based on machine learning models. This method trains the model to learn the mapping relationship between historical attack and defense data, and then predicts and scores the protection effect of the current defense strategy.

[0004] However, this method still has its shortcomings. Its evaluation process is highly dependent on the completeness and static characteristics of the training data, making it difficult to accurately quantify the real-time matching degree and synergy between defense strategies and dynamically evolving attack intentions in a constantly changing network environment. This results in large fluctuations in the evaluation results when dealing with new or complex attacks, and it cannot provide a stable and reliable basis for the precise optimization of strategies. Summary of the Invention

[0005] This application provides a method and system for accurate evaluation of network security defense strategies and quantitative analysis of protection effects, in order to solve the problems of insufficient accuracy in defense effect evaluation and poor stability of evaluation results in dynamic adversarial environments in the prior art.

[0006] Firstly, this application provides a method for accurately evaluating network security defense strategies and quantitatively analyzing their effectiveness, including: Acquire real-time attack data and policy execution records in the target network environment, wherein the real-time attack data includes abnormal operation sequences; The real-time attack data is perturbed using a pre-trained analogy model to obtain abnormal features that characterize the attack intent. Based on the strategy execution records, a response trajectory of the defense strategy is constructed, and the response trajectory is correlated with the anomaly features. Based on the correlation analysis results, an effectiveness profile of the defense strategy is generated. Collect key state data in the target network environment and calculate the stability index of the protection effect based on the effect profile; Based on the stability index, the strategy parameters for generating the response trajectory are adjusted in reverse.

[0007] Optionally, the real-time attack data is perturbed using a pre-trained analogy model to obtain anomalous features characterizing the attack intent, including: Obtain the abnormal operation sequence from the real-time attack data and reconstruct the abnormal operation sequence into a continuous chain of behaviors; The analog model is used to inject virtual perturbation signals into the continuous chain of behaviors, and the propagation state of the virtual perturbation signals in the chain of behaviors is tracked. Based on the propagation state, analyze the interaction pattern between the virtual perturbation signal and the inherent signal of the behavior chain; Based on the interaction pattern, patterns that remain stable under different virtual perturbation signals are extracted from the behavior chain as anomalous features characterizing attack intent.

[0008] Optionally, based on the policy execution records, a response trajectory of the defense policy is constructed, and the response trajectory is correlated with the anomaly features. Based on the correlation analysis results, an effectiveness profile of the defense policy is generated, including: From the strategy execution record, defense action nodes are extracted according to the time sequence in which the defense actions are recorded in the strategy execution record, and consecutive defense action nodes are connected to form the response trajectory of the defense strategy. The target of each defense action node in the response trajectory of the defense strategy is mapped to the corresponding time stamp behavior unit in the behavior chain. The association status of the defense action node acting on the behavior unit is determined based on whether each behavior unit contains the abnormal feature. Summarize the associated states of all defense action nodes to form a record of the coverage of the defense strategy for the aforementioned abnormal characteristics; Based on the coverage records, an effect profile is generated that reflects the dynamic relationship between defense strategies and attack intentions over the entire time span of the behavior chain.

[0009] Optionally, based on the coverage records, an effect profile is generated that reflects the dynamic relationship between defense strategies and attack intentions over the complete time span of the behavior chain, including: The coverage record is parsed to identify the associated successful segments that successfully correspond to the defense action node and the behavior unit containing the abnormal feature, and to identify the associated missing segments that contain the abnormal feature but have no corresponding defense action node. The success strength of the associated successful fragment is calculated based on the number of defense action nodes corresponding to success within the successfully associated fragment and the number of abnormal features contained in the behavioral unit. The missing strength of the associated missing fragment is calculated based on the number of abnormal features contained in the behavioral unit within the associated missing fragment. Based on the temporal order of the behavioral chain, the success intensity of the successfully associated segments and the loss intensity of the associated missing segments are combined along the temporal order to form a sequence of profile units arranged by time. Based on a time-ordered sequence of profile units, an effect profile is generated that covers the entire time span of the behavior chain and reflects the dynamic relationship between defense strategies and attack intentions.

[0010] Optionally, key state data in the target network environment are collected, and a stability index of the protection effect is calculated based on the effect profile, including: Indicators reflecting the system's operating load and security status are collected from the target network environment as key status data; The key state data is matched and bound to the corresponding time point profile unit on the effect profile according to the generated timestamp; For each profile element that has been matched and bound, the element stability value of the profile element in the current system state is calculated by combining the key state data bound to the matched and bound profile element. The element stability values ​​of all profile elements are synthesized in chronological order of the behavior chain to generate a synthesis sequence; The consistency metric of the synthesized sequence is calculated to obtain a stability index of the protective effect.

[0011] Optionally, for each matched profile element, the element stability value of the profile element in the current system state is calculated by combining the key state data bound to the matched profile element, including: By analyzing the key status data bound to the profile unit, the specific values ​​of the system operating load and the quantitative scores reflecting the safety status are obtained; Determine whether the profile unit is formed by the success intensity of successfully associated fragments or by the missing intensity of associated missing fragments; If the profile unit is formed by the success intensity of the associated successful segments, then the success intensity is positively superimposed with the quantitative score reflecting the security situation, and then reduced by combining the specific value of the system operating load to obtain the unit stability value of the profile unit. If the profile unit is formed by the missing intensity of the associated missing segments, then the missing intensity is correlated and amplified with the specific value of the system operating load, and then offset with the quantitative score reflecting the safety status to obtain the unit stability value of the profile unit.

[0012] Optionally, the strategy parameters for generating the response trajectory are adjusted in reverse according to the stability index, including: The stability index is compared with a preset stability threshold. If the stability index is lower than the stability threshold, then the target profile unit whose unit stability value is lower than the overall average level is located from the effect profile. Based on the correspondence between the effect profile and the behavior chain, determine the target association success segment or target association missing segment associated with the target profile unit; Tracing back to the response trajectory of the defense strategy, identify the target defense action nodes in time that correspond to the successfully associated segments or missing associated segments of the target; Based on the difference between the unit stability value of the target profile unit and the overall average level, the correction amount for adjusting the strategy parameters of the target defense action node is calculated. The policy parameters of the target defense action node are updated using the correction amount.

[0013] Secondly, this application provides a system for precise evaluation of network security defense strategies and quantitative analysis of protection effectiveness, including: The acquisition module is used to acquire real-time attack data and policy execution records in the target network environment, wherein the real-time attack data includes abnormal operation sequences; The analysis module is used to perform perturbation analysis on the real-time attack data using a pre-trained analogy model to obtain abnormal features that characterize the attack intent. The construction module is used to construct the response trajectory of the defense strategy based on the strategy execution record, perform correlation analysis between the response trajectory and the abnormal features, and generate the effect profile of the defense strategy based on the correlation analysis results. The acquisition module is used to collect key status data in the target network environment and calculate the stability index of the protection effect based on the effect profile. The adjustment module is used to adjust the strategy parameters for generating the response trajectory in reverse according to the stability index.

[0014] Thirdly, this application provides a computing device, including a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are invoked and executed by the processing component to realize a method for accurate evaluation of network security defense strategies and quantitative analysis of protection effects as described in the first aspect above.

[0015] Fourthly, this application provides a computer storage medium storing a computer program, which, when executed by a computer, implements a method for accurately evaluating network security defense strategies and quantitatively analyzing protection effectiveness as described in the first aspect.

[0016] This application extracts anomalous features representing dynamic attack intentions from real-time attack data through perturbation analysis, and constructs a response trajectory of the defense strategy to conduct fine-grained correlation analysis. The resulting effect profile can accurately depict the real-time matching and interaction between defense actions and attack intentions during continuous confrontation. This overcomes the limitations of existing technologies that rely on static historical data mapping, enabling the evaluation of the effectiveness of defense strategies to closely follow the real-time evolution of the attack, thereby improving the accuracy and scenario relevance of the evaluation results.

[0017] Furthermore, by integrating key network state data, a stability index characterizing the overall robustness of protection is calculated based on the effect profile. Using this index, weak links in the defense are precisely located, and parameters are adjusted in reverse to specific defense action nodes. This technical approach establishes a closed-loop feedback mechanism of assessment-location-optimization, enabling the defense strategy to iterate and optimize itself based on dynamic and quantitative assessment results. This effectively enhances the adaptability and overall stability of the protection system in complex adversarial environments, providing an effective solution to the problem of large fluctuations in assessment results and difficulty in guiding precise optimization.

[0018] These or other aspects of this application will become more apparent from the description of the following embodiments. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 This paper presents a flowchart illustrating a method for accurately evaluating and quantitatively analyzing the protection effectiveness of a network security defense strategy, as provided in this application. Figure 2 This paper presents a schematic diagram of the structure of a network security defense strategy accurate evaluation and protection effect quantitative analysis system provided in this application; Figure 3 A schematic diagram of the structure of a computing device provided in this application is shown. Detailed Implementation

[0021] To enable those skilled in the art to better understand the present application, the technical solution of the present application will be clearly and completely described below with reference to the accompanying drawings.

[0022] In some of the processes described in the specification, claims, and accompanying drawings of this application, multiple operations appearing in a specific order are included. However, it should be clearly understood that these operations may not be executed in the order they appear herein, or may be executed in parallel. The operation numbers, such as 101, 102, etc., are merely used to distinguish different operations and do not themselves represent any execution order. Furthermore, these processes may include more or fewer operations, and these operations may be executed sequentially or in parallel. It should be noted that the descriptions such as "first," "second," etc., in this document are used to distinguish different messages, devices, modules, etc., and do not represent a chronological order, nor do they limit "first" and "second" to different types.

[0023] The technical solutions of this application will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0024] Figure 1 This application provides a flowchart of a method for accurately evaluating network security defense strategies and quantitatively analyzing protection effectiveness, such as... Figure 1 As shown, the method includes: Step 101: Obtain real-time attack data and policy execution records in the target network environment, wherein the real-time attack data includes abnormal operation sequences.

[0025] In this step, real-time attack data refers to information on potentially malicious network activities that are continuously collected by network monitoring equipment and reflect ongoing or recently occurring activities. This data is used to capture and record the original manifestations of attack behavior and is obtained in real time through traffic probes, intrusion detection systems, or endpoint security agents deployed on key nodes of the target network.

[0026] Policy execution logs refer to the logs generated by various security defense devices or software deployed in the network after they intervene in network traffic or host behavior according to preset rules during operation. They are used to trace and confirm the specific actions taken by the defense system for a specific event at a specific time. They are synchronized and aggregated from devices such as firewalls, intrusion prevention systems, and web application firewalls through a centralized log platform or security management interface.

[0027] An abnormal operation sequence refers to a series of network operation units that are sequentially and logically related and deviate from normal behavior patterns, identified and linked from continuous real-time attack data. It is used to initially outline the main contours and key steps of a complete attack activity.

[0028] In this step, probes with deep packet inspection technology and host agents with system call monitoring capabilities are first deployed at the boundary and key areas of the target network to continuously scan the data packets and host system activities. These probes and agents encapsulate suspicious connections, protocol violations, or abnormal file access into standardized security events with timestamps and details, and send them to the security platform in real time, thus forming a continuous real-time attack data stream. Secondly, the security platform uses standard log collection protocols such as Syslog, SNMP, or RESTful API to send queries to security devices such as firewalls and intrusion prevention systems in the network. These devices respond to the queries and retrieve all policy action records executed within a specific time period from their local log databases, including the action time, the triggered rule, the source and destination addresses, and the execution result. The platform collects and standardizes these records to form a unified, time-series policy execution record. Next, the platform launches a built-in sequence analysis engine to process real-time attack data. It uses an association algorithm based on time windows and causal inference rules to scan the event stream. According to preset time thresholds and logical relationships, for example, a port scan event is associated with an exploit attempt event targeting the same port, and they are considered to belong to the same attack activity. Through this rule, the algorithm links discrete but logically coherent security events together to form a complete abnormal operation sequence. Finally, the platform uses a unified time server as a benchmark to align and merge the collected real-time attack data, policy execution records, and extracted abnormal operation sequences with timestamps, ensuring that attack behaviors and defense responses can accurately correspond on the timeline, thus preparing a time-consistent and structured data foundation for subsequent correlation analysis.

[0029] For example, the internal office network of a large enterprise A is the target network environment that needs to be protected. The firewall deployed at the network egress and the host intrusion detection system on the critical server serve as the main data sources. First, during a certain working period, the firewall detects high-frequency abnormal connections from external IP address B to internal server C, while the host intrusion detection system detects abnormal logins and suspicious process behavior on server C. Second, this information is reported to the security platform in real time, forming real-time attack data. At the same time, the firewall automatically blocks some abnormal connections according to preset policies, and the host detection system also monitors suspicious processes. Both generate log records containing time, action, and target. These records are aggregated by the platform into policy execution records. Finally, the analysis engine within the platform processes the real-time attack data. It identifies the high-frequency connections, abnormal logins, and suspicious process creations that occur within a short period of time targeting the same server C as a coherent whole based on time sequence and logical correlation, thereby defining an abnormal operation sequence aimed at committing an intrusion.

[0030] Step 102: Perform perturbation analysis on the real-time attack data using a pre-trained analogy model to obtain abnormal features that characterize the attack intent.

[0031] Optionally, step 102 may specifically include: Step 1021: Obtain the abnormal operation sequence in the real-time attack data and reconstruct the abnormal operation sequence into a continuous chain of behaviors.

[0032] Step 1022: Inject virtual perturbation signals into the continuous behavioral chain using the analog model, and track the propagation state of the virtual perturbation signals in the behavioral chain.

[0033] Step 1023: Based on the propagation state, analyze the interaction pattern between the virtual disturbance signal and the inherent signal of the behavior chain.

[0034] Step 1024: Based on the interaction pattern, extract the pattern that remains stable under different virtual perturbation signals from the behavior chain as an anomalous feature characterizing the attack intent.

[0035] In this step, the pre-trained analogy model refers to a computer model that compares the dynamic characteristics of a network security event sequence to the dynamics of a specific physical system, and is used to simulate and analyze the reaction patterns of an attack behavior chain when it is interfered with.

[0036] A continuous chain of actions refers to tightly connecting each operational unit in a discrete sequence of abnormal operations according to the order of their occurrence, forming a coherent description of attack behavior that is seamlessly connected in time and logic. This provides a complete and orderly analytical object for subsequent perturbation analysis.

[0037] Virtual perturbation signals refer to virtual data stimuli generated by analogy models that simulate external intervention or environmental changes. They are used to actively test the stability and internal consistency of behavioral chains and are dynamically calculated and generated by analogy models based on their internal mechanisms and the current state of the behavioral chain.

[0038] The propagation state refers to the entire process of how a virtual disturbance signal is injected into a link of a behavioral chain, and how its effects are transmitted and evolved sequentially along the behavioral chain. It is used to observe how the disturbance changes or reveals the inherent dynamics of the behavioral chain.

[0039] Interaction patterns refer to a specific pattern or form formed by the mutual influence, superposition, or cancellation of virtual perturbation signals and the inherent activity signals of the behavior chain during propagation. They are used to reveal the deep and stable behavioral characteristics of attack behavior when faced with interference. They are obtained by comparative analysis of the changes in behavior chain signals before and after the injection of perturbation.

[0040] Anomalies refer to the core behavioral patterns extracted from the attack behavior chain that can stably characterize the underlying attack purpose or strategy, and are used as a key basis for quantitatively evaluating the effectiveness of defense.

[0041] In this step, we first start with the acquired abnormal operation sequence and use a sequence filling and smoothing algorithm to strictly arrange them on a timeline according to the timestamp of each operation unit accurate to milliseconds. For the tiny time gap between two consecutive events, the sequence filling and smoothing algorithm inserts a virtual node representing the transition state, thereby reconstructing a sequence composed of discrete points into a continuous chain of behaviors that is continuous in time and without breaks. Next, the pre-trained analog model begins to work. It first encapsulates a mechanism for simulating signal propagation and feedback. It selects one or more key time points on a continuous chain of actions, such as the moment when an exploit attempt has just begun, and actively generates a virtual perturbation signal. This virtual perturbation signal can simulate a temporary increase in network latency or an unexpected authentication failure. The analog model then injects this signal into the corresponding nodes of the chain of actions like water. Then, the analog model starts a state tracker to closely monitor what happens after the virtual perturbation signal is injected. It records how the virtual perturbation signal flows forward along the time direction of the chain of actions, observes whether it will be amplified by subsequent attack steps, such as downloading malicious load, whether it will be weakened or changed in direction by certain steps such as switching communication tunnels, and how much influence it will leave at the end of the chain of actions. This complete evolution process is recorded in detail as the propagation state. The analog model then enters the analysis phase, employing a pattern separation technique to compare the recorded propagation state data with the inherent activity signal data of the continuous behavioral chain without injected perturbations. It distinguishes which changes are temporary ripples caused by perturbation signals and which reveal inherent, stable response characteristics of the behavioral chain. For example, the analog model might discover that regardless of whether a simulated delay or a simulated failure is injected, the attack will persistently attempt to re-establish an encrypted connection with a specific IP address; this persistence is a stable interaction pattern. Finally, based on the above analysis, feature extraction is performed, designing multiple sets of virtual perturbation signals of different properties and intensities, and repeating the injection, tracking, and parsing process. Ultimately, the model filters out those consistent interaction patterns that consistently appear in the vast majority, or even all, of the perturbation tests. These stable patterns that withstand stress testing are identified by the model as the most representative anomaly features of the core intent of this attack and are output to subsequent steps.

[0042] For example, following the specific implementation of the previous step, the central security analysis platform first defines an abnormal operation sequence for server C, including high-frequency SMB connections, abnormal authentication, and suspicious process creation. Then, this abnormal operation sequence is reconstructed into a continuous chain of actions, ensuring that the three key actions are tightly linked in time. Next, the pre-trained analog model begins to work, injecting a virtual perturbation signal into the abnormal authentication stage of the action chain. This virtual perturbation signal simulates an abnormal extension of the login credential verification time. The impact of this delay signal is then tracked, revealing that although the login process is simulated to be delayed, the subsequent suspicious process creation action is still rapidly triggered, and the suspicious process immediately attempts to access the network shared directory. This propagation state indicates that the attack is insensitive to login delays; its core objective is to quickly execute the theft action. Finally, further perturbations simulating temporary unavailability of the shared directory are injected, revealing that the attack process continuously retryes access. Simultaneously, by analyzing these interaction patterns, a stable behavior pattern of ignoring authentication interference and continuously and directionally accessing network shared resources is extracted as the core abnormal feature of this attack, indicating that its intent is to steal files.

[0043] This step delves into the understanding of the attack, from what happened to why it happened and what the key elements are. This provides crucial, high-quality input features for accurately assessing whether the defense strategy effectively curbs the attack intent itself, rather than merely blocking a specific action.

[0044] Step 103: Based on the strategy execution record, construct the response trajectory of the defense strategy, perform correlation analysis between the response trajectory and the abnormal features, and generate the effect profile of the defense strategy based on the correlation analysis results.

[0045] Optionally, step 103 may specifically include: Step 1031: Extract defense action nodes from the strategy execution record according to the time sequence in which the defense actions are recorded in the strategy execution record, and connect consecutive defense action nodes to form the response trajectory of the defense strategy.

[0046] Step 1032: Match the target of each defense action node in the response trajectory of the defense strategy with the corresponding time stamp behavior unit in the behavior chain, and determine the association status of the defense action node acting on the behavior unit based on whether each behavior unit contains the abnormal feature.

[0047] Step 1033: Summarize the associated states of all defense action nodes to form a record of the coverage of the defense strategy for the abnormal features.

[0048] Step 1034: Based on the coverage record, generate an effect profile that reflects the dynamic relationship between defense strategies and attack intentions over the entire time span of the behavior chain.

[0049] Optionally, step 1034 may specifically include the following steps: The coverage record is analyzed to identify successful association segments where the defense action node successfully corresponds to a behavior unit containing the anomalous feature, and to identify missing association segments containing the anomalous feature but without a corresponding defense action node. The success strength of the successful association segments is calculated based on the number of successfully associated defense action nodes and the number of anomalous features contained in the behavior unit. The loss strength of the missing association segments is calculated based on the number of anomalous features contained in the behavior unit. The success strength of the successful association segments and the loss strength of the missing association segments are combined along the time sequence of the behavior chain to form a time-arranged sequence of profile units. Based on this time-arranged sequence of profile units, an effect profile is generated that covers the entire time span of the behavior chain, reflecting the dynamic relationship between the defense strategy and the attack intent.

[0050] In this step, a defense action node refers to an independent entry extracted from the policy execution record that records a specific defense operation, such as blocking, alarming, or isolation, performed on a specific target at a specific time. It serves as the basic unit for constructing the defense response process. It is obtained by parsing the policy execution record and extracting each independent defense log entry in chronological order.

[0051] A response trajectory refers to a path formed by connecting multiple defense action nodes that occur consecutively in time according to their chronological order. This path reflects the complete response process of the defense system over a period of time and is used to visually demonstrate the sequence of defense activities evolving over time.

[0052] A behavioral unit refers to the basic unit that constitutes a continuous chain of behaviors. Each behavioral unit corresponds to an operation in an abnormal operation sequence or a transitional state filled by the model, and carries the attack feature information at that moment. It is used to accurately align with the defensive actions in terms of time and content. It is obtained by discretizing the continuous chain of behaviors on the timeline.

[0053] The association status refers to the determination result of the relationship between a defense action node and the behavioral unit it acts upon at a specific point in time. It mainly determines whether the defense action is applied to a behavioral unit containing abnormal characteristics, and is used to quantify the effectiveness of a single defense action.

[0054] Coverage record refers to a complete list of the coverage of abnormal features of the defense strategy throughout the entire attack timeline, formed by summarizing the associated states of all defense action nodes. It is used to review the matching and missing information of the defense globally and is obtained by summarizing the associated states at all time points.

[0055] A successful association segment refers to a continuous time period in the coverage record during which each behavioral unit containing abnormal characteristics has at least one corresponding defensive action node. It is used to identify the time interval where the defense is effective and is obtained by identifying the time period in the coverage record where the association status is continuously successful.

[0056] Missing associated segments refer to a continuous time period in the coverage record where there are behavioral units with abnormal characteristics, but no corresponding defense action nodes. This is used to identify time intervals where defense is missing or ineffective, and is obtained by identifying time periods in the coverage record where the associated status is continuously missing.

[0057] Success intensity refers to the comprehensive quantitative value of the defense density and attack feature intensity of a related successful segment. It is used to measure the strength and quality of defense during the successful defense period. It is obtained by calculating the ratio between the number of defense action nodes corresponding to success in the segment and the number of abnormal features contained in the behavioral unit.

[0058] Missing strength refers to the quantitative value of the intensity of attack features not covered by defense in an associated missing segment. It is used to measure the severity of the attack threat during the period of defense absence and is obtained by counting the number of abnormal features contained in the behavioral unit within the segment.

[0059] A profile unit sequence refers to a numerical sequence formed by arranging the calculated success strength values ​​of associated successful segments and the loss strength values ​​of associated missing segments in chronological order according to the behavioral chain. This sequence reflects the strength of the defense effect at different time periods and serves as the data foundation for constructing the effect profile.

[0060] The effectiveness profile of a defense strategy is a dynamic graph with time as the horizontal axis and the strength of the defense effect as the vertical axis. It intuitively shows the changes in the strength of the matching relationship between the defense strategy and the attack intent throughout the entire attack. It is used to comprehensively and visually present the overall effect and fluctuation of the defense. It is generated based on the sequence of profile units through data visualization or continuous function fitting techniques.

[0061] The complete time span refers to the entire period of time from the beginning to the end of the attack behavior chain, and is used to define the time range covered by the effect profile.

[0062] In this step, the acquired policy execution records are first read. Timestamp parsing and event extraction techniques are used to extract from each record what action (allow, deny, alarm) was performed on which target (IP address, port, process) at what time, and for which target. Each such entry is defined as a defense action node. Then, based on the timestamps of these nodes, a linear linking algorithm is used to connect them sequentially from morning to night, forming a path depicting the defense activity unfolding over time—the response trajectory of the defense policy. Next, time alignment and feature matching operations are performed, placing this response trajectory and the resulting continuous behavioral chain on the same high-precision timeline. A continuous chain of actions has been divided into multiple continuous action units. The process begins by traversing each defensive action node on the response trajectory, finding the action unit with the closest timestamp on the timeline, and then checking whether this action unit contains the extracted abnormal features. If it does, and the target of the defensive action matches the attack target described by the action unit, then the association status of the defensive action node is determined to be a successful correspondence. If the action unit contains abnormal features but the defensive action does not apply to it, or the target of the defensive action does not contain abnormal features, then it is determined to be missing. This comparison process assigns a clear association status to each defensive action node. Next, the associated states of all defense action nodes are organized into a list in chronological order, clearly indicating whether the defense successfully covered the ongoing attack action with a specific intent at each moment within the complete attack time span. This complete list is a record of the coverage of the defense strategy against the aforementioned abnormal features. Then, a segment recognition algorithm is run to scan the entire record and find all consecutive time periods in which all defense action nodes successfully correspond to behavioral units containing abnormal features. These time periods are marked as successfully associated segments. At the same time, the segment recognition algorithm also finds all consecutive time periods in which there are behavioral units containing abnormal features but no corresponding defense action nodes. These are marked as missing associated segments. Then, for each successfully associated segment, the ratio between the number of successfully associated defense action nodes in the segment and the total number of abnormal features contained in the behavioral units in the segment is calculated. After standardization, this ratio is defined as the success intensity of the segment. The higher the value, the more intensive and effective the defense is during that period. For each missing associated segment, the total number of abnormal features contained in the behavioral units in the failed associated segment is directly counted. After standardization, this is defined as the missing intensity of the failed associated segment. The higher the value, the more prominent the attack threat and the defense gap during that period. Finally, following the chronological order of the behavioral chain from beginning to end, the success strength of each successfully associated segment and the loss strength of each missing associated segment are analyzed, like piecing together a puzzle. Figure 1These units are arranged strictly according to their respective time periods to form a sequence of profile units distributed along the time axis. Finally, using data visualization technology, this sequence of profile units is plotted as a curve or filled graph that fluctuates over time, thus revealing the effectiveness of the final defense strategy and fully and dynamically revealing the entire process of the confrontation between defense and attack intentions.

[0063] For example, following the specific implementation of the previous step, the platform first extracted the core abnormal characteristics of the attack and obtained the policy execution records; secondly, it extracted two key defense actions from the records: at time T1, the firewall blocked the abnormal connection, and at time T2, the host IDS started monitoring the suspicious process; then, these two actions were connected in chronological order to form a defense response trajectory; subsequently, this defense response trajectory was aligned with the attack behavior chain, including the three behavioral units of scanning at time T0, authentication attempt at time T1, and resource access at time T2, and compared on the timeline; analysis revealed that the blocking action at time T1 successfully intervened in the authentication behavior that was occurring at that time and contained specific abnormal characteristics; while the monitoring action at time T2... Although the attack had been initiated, it failed to effectively block resource access behavior containing another core anomaly. Based on this, a defense coverage record covering the entire attack timeline was generated, identifying the T1 period as a successfully defended segment and the T0 and T2 periods as missing segments. Through calculation, the defense success intensity was relatively high in the T1 period, the threat missing intensity was moderate in the T0 period, and the threat missing intensity was relatively high in the T2 period. Finally, these intensity values ​​arranged in chronological order were combined to create an effect profile, clearly showing that the defense effect fluctuated during the attack: initially missing, improved in the middle, but significantly decreased in the final stage of the attack, intuitively revealing the weakness of the current defense strategy in blocking the final attack intent.

[0064] The final effect profile generated in this step not only reveals when the defense is effective or ineffective, but also depicts the degree of its effectiveness or ineffectiveness and its dynamic changes as the attack progresses. This elevates the defense effect from a simple binary judgment of success / failure to a continuous, detailed, and dynamic graph that reflects the rhythm of attack and defense confrontation, providing a core basis for a comprehensive and in-depth evaluation of the quality of defense strategies.

[0065] Step 104: Collect key status data in the target network environment and calculate the stability index of the protection effect based on the effect profile.

[0066] Optionally, step 104 may specifically include: Step 1041: Collect indicators reflecting the system's operating load and security status from the target network environment as key status data.

[0067] Step 1042: Match and bind the key state data with the corresponding time point profile unit on the effect profile according to the generated timestamp.

[0068] Step 1043: For each profile element that has been matched and bound, calculate the element stability value of the profile element in the current system state by combining the key state data bound to the profile element that has been matched and bound.

[0069] Optionally, step 1043 may specifically include the following steps: parsing the key state data bound to the profile unit to obtain the specific value of the system operating load and the quantitative score reflecting the security situation; determining whether the profile unit is formed by the success intensity of associated successful segments or by the missing intensity of associated missing segments; if the profile unit is formed by the success intensity of associated successful segments, then the success intensity is positively superimposed with the quantitative score reflecting the security situation, and then reduced by combining it with the specific value of the system operating load to obtain the unit stability value of the profile unit; if the profile unit is formed by the missing intensity of associated missing segments, then the missing intensity is amplified by associating it with the specific value of the system operating load, and then canceled by combining it with the quantitative score reflecting the security situation to obtain the unit stability value of the profile unit.

[0070] Step 1044: Synthesize the element stability values ​​of all profile elements according to the time sequence of the behavior chain to generate a synthesis sequence.

[0071] Step 1045: Calculate the consistency metric of the synthesized sequence to obtain the stability index of the protective effect.

[0072] In this step, critical status data refers to a set of quantitative indicators collected from the target network environment that can reflect its overall operational health and security risks in real time. These indicators are used to provide system operating context and environmental background for evaluating the effectiveness of the defense. They are obtained by periodically pulling indicators such as CPU utilization and memory usage from the performance monitoring interface and logs.

[0073] System load is one dimension of critical status data, referring to the busyness and usage pressure of computing, storage, and network resources in the target network environment. It is used to measure the system's carrying capacity when defense actions are executed. High load may affect the defense effect. It is usually characterized by obtaining specific values ​​of indicators such as the average CPU utilization, memory utilization, or network interface throughput of the server cluster.

[0074] The quantitative score of security posture is another dimension in critical status data. It refers to a numerical score of the overall security risk level of the current network environment through a specific assessment model. It is used to measure the threat environment level when defensive actions are performed. It is calculated by aggregating and analyzing the severity level, frequency and vulnerability scanning results of various security alarms generated in a short period of time, and inputting them into a preset scoring model.

[0075] The unit stability value refers to a composite index value that reflects the quality or reliability of the defense effect at a specific moment by combining the strength of the defense effect at that moment with the system operating state at that time. It is used to correct isolated defense effect assessments in a dynamic system environment. It is obtained by applying a set of weighted calculation rules that combine state data to the profile units that are matched and bound to key state data.

[0076] Synthetic sequence refers to a new time series data formed by arranging the stable values ​​of all profile units in strict chronological order on the attack behavior chain. It is used to depict the complete trajectory of the quality of defense effectiveness fluctuating over time during the entire attack process.

[0077] The stability index is a comprehensive scalar value used to quantify the overall stability and consistency of the defense effect when facing a specific attack, and is used to evaluate the robustness of the defense strategy as a whole.

[0078] In this step, the system first periodically collects indicators such as server CPU utilization and memory usage as system load by calling the system performance monitoring API. At the same time, alarm logs are obtained through the interface of the security information and event management system, and the preset threat assessment model is input to calculate the quantitative score of the security situation in real time, which together constitutes the key status data. Secondly, a timestamp matching algorithm is used to accurately align and bind the collected key status data with the corresponding profile units on the effect profile according to the time point of its occurrence, so that each profile unit is associated with the system state at the time of its occurrence. Next, for each bound profile unit, conditional calculation logic is executed to obtain the unit stability value. First, it is determined whether the unit originates from a successfully associated segment or a missing segment. If it originates from a successfully associated segment, the success intensity of the unit is added to the quantitative score of the bound security status through weighted addition. Then, a reduction calculation is performed by combining the specific value of the bound system operating load with the load-based reduction function. If it originates from a missing segment, the missing intensity is first amplified by multiplication with the specific value of the system operating load, and then the reduction calculation is performed by subtraction with the quantitative score of the security status. Then, using a sequence splicing method, all calculated unit stability values ​​are arranged strictly according to their chronological order in the attack behavior chain to generate a continuous synthetic sequence. Finally, a consistency measurement algorithm in time series analysis is applied to the synthetic sequence, such as calculating its standard deviation and trend stability index. By comprehensively evaluating the degree of fluctuation of the sequence, a scalar that characterizes the overall stability of protection is finally calculated, namely the stability index of protection effect.

[0079] For example, following the specific implementation of the previous step, firstly, at times T0, T1, and T2 where the attack occurred, the platform collected server load data via the monitoring API, which showed loads of 40%, 40%, and 75% respectively. The security posture scores obtained through the threat assessment model were 30, 30, and 70 respectively. Secondly, these data were bound to the units at the corresponding time points in the effect profile. For successful units at time T1, their success intensity was added to the security score of 30, and then subtracted by the normal load of 40% to calculate a higher unit stability value. Next, for high-risk missing units at time T2, their high missing intensity was multiplied by the high load of 75% to amplify it, and then subtracted from the high security score of 70 to calculate an extremely high unit stability value. Then, for low-risk missing units at time T0, a lower value was calculated. Finally, these three values ​​were arranged in chronological order to obtain a highly fluctuating composite sequence. After calculation using a consistency measurement algorithm, a low stability index was obtained, indicating that the overall protection was unstable in responding to this attack.

[0080] This step enhances the practical relevance and reliability of the assessment results by deeply integrating the defense effectiveness assessment with the real-time system environment status. It uses a weighted calculation logic that combines state data to transform the defense effectiveness intensity under different system loads and threat backgrounds into unit stability values ​​that better reflect the actual effectiveness quality. Finally, these values ​​are aggregated into a stability index that characterizes the overall protection stability, enabling the assessment conclusions to more accurately reflect the comprehensive performance and robustness of the defense system in real and complex environments.

[0081] Step 105: Adjust the strategy parameters for generating the response trajectory in reverse according to the stability index.

[0082] Optionally, step 105 may specifically include: Step 1051: Compare the stability index with a preset stability threshold.

[0083] Step 1052: If the stability index is lower than the stability threshold, then locate the target profile unit whose unit stability value is lower than the overall average level from the effect profile.

[0084] Step 1053: Based on the correspondence between the effect profile and the behavior chain, determine the target association success segment or target association missing segment associated with the target profile unit.

[0085] Step 1054: Backtrack to the response trajectory of the defense strategy and find the target defense action nodes that correspond in time to the successfully associated segments or missing associated segments of the target.

[0086] Step 1055: Based on the difference between the unit stability value of the target profile unit and the overall average level, calculate the correction amount for adjusting the strategy parameters of the target defense action node.

[0087] Step 1056: Use the correction amount to update the strategy parameters of the target defense action node.

[0088] In this step, the policy parameters of the response trajectory refer to the specific rule settings that can be configured on the security device for each defense action node in the constructed defense policy response trajectory. These settings are used to directly define and modify the execution conditions and behaviors of the defense actions. They are obtained by parsing the source policy rules of the defense action nodes that constitute the response trajectory, such as the source IP and destination port of the firewall rules.

[0089] The preset stability threshold refers to a pre-set numerical standard used to judge whether the stability index of the protection effect is qualified, and is used as a judgment condition to trigger the strategy parameter adjustment process.

[0090] Target profile elements refer to specific profile elements in the effect profile whose calculated stability values ​​are lower than the average of all profile elements. They are used to accurately locate specific moments when the defense effect is weak or unstable.

[0091] Target defense action nodes refer to those defense action nodes in the response trajectory of the defense strategy that correspond to the attack segments associated with the target profile unit in time. They are used to locate the specific defense operations that need to be adjusted. They are found by tracing back the response trajectory and finding them according to the time correspondence.

[0092] The correction amount refers to a numerical change in the strategy parameters corresponding to the target defense action node, used to quantitatively adjust the strategy parameters. It guides the direction and magnitude of the adjustment of the strategy parameters. It is obtained by calculating the difference between the stable value of the target profile unit and the overall average level, and mapping it through a preset transformation function.

[0093] In this step, a numerical comparison operation is first performed, directly comparing the calculated stability index of the protection effect with a preset stability threshold stored in the configuration library, which is achieved through simple numerical comparison. Secondly, if the comparison result shows that the stability index is lower than the stability threshold, the root cause localization process is initiated. A filtering and sorting algorithm is called to traverse the generated effect profiles with attached unit stability values. This algorithm calculates the arithmetic mean of the unit stability values ​​of all profile units, and then filters out specific units whose unit stability values ​​are lower than this average, marking these units as target profile units. Next, a relational mapping is performed. Based on the correspondence between the effect profile and the behavior chain, the specific time interval associated with each target profile unit on the original attack behavior chain is found. Then, using the established correspondence between attack behavior and defense action, the target associated successful segment or target associated missing segment corresponding to that time interval is determined. Then, time backtracking is performed to access the response trajectory of the constructed defense strategy. On this trajectory, based on timestamp matching, all defense action nodes falling within the time intervals corresponding to the successfully associated or missing associated segments of the target are identified, and these nodes are defined as target defense action nodes. Next, the adjustment amount is calculated. For each target profile unit, the specific difference between its unit stability value and the overall average level is calculated. Subsequently, a preset parameter adjustment mapping function is applied to convert this difference into a specific strategy correction amount for the corresponding target defense action node. For example, the larger the difference, the larger the absolute value of the correction amount. For successfully associated segments, the correction amount may be used to enhance detection sensitivity; for missing associated segments, the correction amount is used to add rules or lower the trigger threshold. Finally, parameter updates are performed. By calling the policy management interface of the network security device, the calculated correction is applied to the original policy parameters corresponding to each target defense action node. This is usually an incremental update operation, such as adding an address to the source IP list of a firewall blocking rule, or lowering the confidence threshold of an intrusion detection rule by a specific value, thereby completing the closed-loop optimization of the defense policy.

[0094] For example, following the specific implementation of the previous step, firstly, the calculated stability index is lower than a preset stability threshold; secondly, in the effect profile, it is located that the profile unit at time T2 is the main target profile unit because its unit stability value is extremely low; then, based on the correspondence between the profile and the behavior chain, it is determined that this unit is associated with the missing segment of the target at time T2; then, the response trajectory is traced back to find the only target defense action node at time T2, that is, the host IDS monitors the suspicious process; the huge negative difference between the unit stability value corresponding to the target defense action node and the average level is calculated and mapped to a correction amount: a new sub-rule is generated for the abnormal file access detection rule of the IDS, its response action is changed from monitoring to blocking and alarming, and the associated process feature hash value is added to the monitoring list; finally, this update is deployed to the IDS of server C through the management interface, thereby strengthening the ability to curb similar continuous access to shared resources attacks.

[0095] This step realizes a closed-loop decision-making process from quantitative assessment to precise optimization. By associating the abstract stability index with the specific weak links in the effect profile, it traces back to the original defensive actions that caused the problem and intelligently calculates the specific parameter adjustment based on the effect gap. This makes the optimization of security strategies no longer a blind attempt based on experience, but a data-driven, targeted, and precise operation.

[0096] Figure 2 This application provides a schematic diagram of the structure of a network security defense strategy accurate evaluation and protection effect quantitative analysis system, such as... Figure 2 As shown, the system includes: The acquisition module 21 is used to acquire real-time attack data and policy execution records in the target network environment, wherein the real-time attack data includes abnormal operation sequences; Analysis module 22 is used to perform perturbation analysis on the real-time attack data through a pre-trained analogy model in order to obtain abnormal features that characterize the attack intent. The construction module 23 is used to construct the response trajectory of the defense strategy based on the strategy execution record, perform correlation analysis between the response trajectory and the abnormal features, and generate the effect profile of the defense strategy based on the correlation analysis results. The acquisition module 24 is used to acquire key status data in the target network environment and calculate the stability index of the protection effect based on the effect profile. The adjustment module 25 is used to adjust the strategy parameters for generating the response trajectory in reverse according to the stability index.

[0097] Figure 2 The aforementioned network security defense strategy precision evaluation and protection effect quantitative analysis system can perform... Figure 1The implementation principle and technical effects of the method for accurate evaluation and quantitative analysis of network security defense strategies described in the illustrated embodiment will not be elaborated further. The specific methods by which each module and unit of the network security defense strategy accurate evaluation and quantitative analysis system performs its operations have been described in detail in the embodiments related to this method, and will not be elaborated upon here.

[0098] In one possible design, Figure 2 The network security defense strategy accurate evaluation and protection effect quantitative analysis system of the embodiment shown can be implemented as a computing device, such as... Figure 3 As shown, the computing device may include a storage component 31 and a processing component 32; The storage component 31 stores one or more computer instructions, wherein the one or more computer instructions are invoked and executed by the processing component 32.

[0099] The processing component 32 is used for the above Figure 1 The embodiment describes a method for accurately evaluating network security defense strategies and quantitatively analyzing their protection effectiveness.

[0100] The processing component 32 may include one or more processors to execute computer instructions to complete all or part of the steps in the above-described method. Alternatively, the processing component may be implemented as one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the above-described method.

[0101] Storage component 31 is configured to store various types of data to support operations at the terminal. The storage component can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0102] Of course, computing devices may also include other components, such as input / output interfaces, display components, communication components, etc.

[0103] Input / output interfaces provide interfaces between processing components and peripheral interface modules, which can be output devices, input devices, etc.

[0104] The communication components are configured to facilitate wired or wireless communication between computing devices and other devices.

[0105] The computing device can be a physical device or an elastic computing host provided by a cloud computing platform. In this case, the computing device can refer to a cloud server, and the aforementioned processing components, storage components, etc., can be basic server resources rented or purchased from the cloud computing platform.

[0106] This application also provides a computer storage medium storing a computer program, which, when executed by a computer, can perform the above-described functions. Figure 1 The embodiment shown is a method for accurate evaluation and quantitative analysis of network security defense strategies and protection effects.

[0107] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0108] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0109] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0110] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A method for accurately evaluating network security defense strategies and quantitatively analyzing their protection effectiveness, characterized in that, include: Acquire real-time attack data and policy execution records in the target network environment, wherein the real-time attack data includes abnormal operation sequences; The real-time attack data is perturbed using a pre-trained analogy model to obtain abnormal features that characterize the attack intent. Based on the strategy execution records, a response trajectory of the defense strategy is constructed, and the response trajectory is correlated with the anomaly features. Based on the correlation analysis results, an effectiveness profile of the defense strategy is generated. Collect key state data in the target network environment and calculate the stability index of the protection effect based on the effect profile; Based on the stability index, the strategy parameters for generating the response trajectory are adjusted in reverse.

2. The method according to claim 1, characterized in that, The real-time attack data is perturbed using a pre-trained analogy model to obtain anomalous features characterizing the attack intent, including: Obtain the abnormal operation sequence from the real-time attack data and reconstruct the abnormal operation sequence into a continuous chain of behaviors; The analog model is used to inject virtual perturbation signals into the continuous chain of behaviors, and the propagation state of the virtual perturbation signals in the chain of behaviors is tracked. Based on the propagation state, analyze the interaction pattern between the virtual perturbation signal and the inherent signal of the behavior chain; Based on the interaction pattern, patterns that remain stable under different virtual perturbation signals are extracted from the behavior chain as anomalous features characterizing attack intent.

3. The method according to claim 1, characterized in that, Based on the policy execution records, a response trajectory of the defense policy is constructed, and the response trajectory is correlated with the anomaly features. Based on the correlation analysis results, an effectiveness profile of the defense policy is generated, including: From the strategy execution record, defense action nodes are extracted according to the time sequence in which the defense actions are recorded in the strategy execution record, and consecutive defense action nodes are connected to form the response trajectory of the defense strategy. The target of each defense action node in the response trajectory of the defense strategy is mapped to the corresponding time stamp behavior unit in the behavior chain. The association status of the defense action node acting on the behavior unit is determined based on whether each behavior unit contains the abnormal feature. Summarize the associated states of all defense action nodes to form a record of the coverage of the defense strategy for the aforementioned abnormal characteristics; Based on the coverage records, an effect profile is generated that reflects the dynamic relationship between defense strategies and attack intentions over the entire time span of the behavior chain.

4. The method according to claim 3, characterized in that, Based on the coverage records, an effect profile is generated that reflects the dynamic relationship between defense strategies and attack intentions over the complete time span of the behavior chain, including: The coverage record is parsed to identify the associated successful segments that successfully correspond to the defense action node and the behavior unit containing the abnormal feature, and to identify the associated missing segments that contain the abnormal feature but have no corresponding defense action node. The success strength of the associated successful fragment is calculated based on the number of defense action nodes corresponding to success within the successfully associated fragment and the number of abnormal features contained in the behavioral unit. The missing strength of the associated missing fragment is calculated based on the number of abnormal features contained in the behavioral unit within the associated missing fragment. Based on the temporal order of the behavioral chain, the success intensity of the successfully associated segments and the loss intensity of the associated missing segments are combined along the temporal order to form a sequence of profile units arranged by time. Based on a time-ordered sequence of profile units, an effect profile is generated that covers the entire time span of the behavior chain and reflects the dynamic relationship between defense strategies and attack intentions.

5. The method according to claim 1, characterized in that, Collect key state data in the target network environment and calculate the stability index of the protection effect based on the effect profile, including: Indicators reflecting the system's operating load and security status are collected from the target network environment as key status data; The key state data is matched and bound to the corresponding time point profile unit on the effect profile according to the generated timestamp; For each profile element that has been matched and bound, the element stability value of the profile element in the current system state is calculated by combining the key state data bound to the matched and bound profile element. The element stability values ​​of all profile elements are synthesized in chronological order of the behavior chain to generate a synthesis sequence; The consistency metric of the synthesized sequence is calculated to obtain a stability index of the protective effect.

6. The method according to claim 5, characterized in that, For each profile element that has completed matching and binding, the element stability value of the profile element in the current system state is calculated by combining the key state data bound to the matched profile element, including: By analyzing the key status data bound to the profile unit, the specific values ​​of the system operating load and the quantitative scores reflecting the safety status are obtained; Determine whether the profile unit is formed by the success intensity of successfully associated fragments or by the missing intensity of associated missing fragments; If the profile unit is formed by the success intensity of the associated successful segments, then the success intensity is positively superimposed with the quantitative score reflecting the security situation, and then reduced by combining the specific value of the system operating load to obtain the unit stability value of the profile unit. If the profile unit is formed by the missing intensity of the associated missing segments, then the missing intensity is correlated and amplified with the specific value of the system operating load, and then offset with the quantitative score reflecting the safety status to obtain the unit stability value of the profile unit.

7. The method according to claim 1, characterized in that, Based on the stability index, the strategy parameters for generating the response trajectory are adjusted in reverse, including: The stability index is compared with a preset stability threshold. If the stability index is lower than the stability threshold, then the target profile unit whose unit stability value is lower than the overall average level is located from the effect profile. Based on the correspondence between the effect profile and the behavior chain, the target association success segment or target association missing segment associated with the target profile unit is determined. Tracing back to the response trajectory of the defense strategy, identify the target defense action nodes in time that correspond to the successfully associated segments or missing associated segments of the target; Based on the difference between the unit stability value of the target profile unit and the overall average level, the correction amount for adjusting the strategy parameters of the target defense action node is calculated. The policy parameters of the target defense action node are updated using the correction amount.

8. A system for precise evaluation and quantitative analysis of network security defense strategies, characterized in that, include: The acquisition module is used to acquire real-time attack data and policy execution records in the target network environment, wherein the real-time attack data includes abnormal operation sequences; The analysis module is used to perform perturbation analysis on the real-time attack data using a pre-trained analogy model to obtain abnormal features that characterize the attack intent. The construction module is used to construct the response trajectory of the defense strategy based on the strategy execution record, perform correlation analysis between the response trajectory and the abnormal features, and generate the effect profile of the defense strategy based on the correlation analysis results. The acquisition module is used to collect key status data in the target network environment and calculate the stability index of the protection effect based on the effect profile. The adjustment module is used to adjust the strategy parameters for generating the response trajectory in reverse according to the stability index.

9. A computing device, characterized in that, It includes a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are invoked and executed by the processing component to implement the method for accurate evaluation and quantitative analysis of network security defense strategies as described in any one of claims 1 to 7.

10. A computer storage medium, characterized in that, The system contains a computer program that, when executed by a computer, implements a method for precise evaluation and quantitative analysis of network security defense strategies as described in any one of claims 1 to 7.