Network security policy optimization system and method based on artificial intelligence

By using an AI-based cybersecurity strategy optimization system and leveraging multi-source data processing and attack chain identification technologies, the system addresses the challenges of defending against covert and fragmented attacks in existing technologies, achieving more efficient cybersecurity defense.

CN122053148APending Publication Date: 2026-05-15GUANGDONG POWER GRID CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUANGDONG POWER GRID CO LTD
Filing Date
2026-02-04
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively defend against attackers' long-term, covert, multi-stage, or fragmented low-frequency attacks, resulting in reduced network security defense effectiveness.

Method used

By using artificial intelligence-based methods, we acquire multi-source network data, perform unified processing, establish event data models and dynamic behavior relationship diagrams, identify potential attack chains, and implement multi-level security policies at critical paths and cut points. We also optimize and filter based on attack risk, false alarm risk, and policy redundancy to generate the optimal policy combination.

Benefits of technology

It enhances the defense capabilities against stealthy and fragmented attacks, reduces the impact of attacks and the risk of false alarms, and improves the efficiency and accuracy of security strategy implementation.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention discloses a network security policy optimization system and method based on artificial intelligence, and relates to the technical field of network security, and the method comprises the steps: obtaining network multi-source data, and building an event data model and a dynamic behavior relation graph; obtaining an attack evidence accumulation score of the suspicious security behavior for the network subject; obtaining a potential behavior attack chain, and identifying a key path and a key cut point of the development of the potential behavior attack chain; establishing a multi-level security policy set, and forming different policy candidate sets for the attack chain; and determining an optimal strategy combination and executing the optimal strategy combination. According to the method, the multi-source network data is adopted as initial data, data unification and structural processing are carried out, event behaviors are converted into structured evidences, and evidence accumulation is carried out, so that the attack evidence accumulation score is obtained, the problem that fragmented attacks and latent low abnormal behaviors are difficult to discover and defend by a network strategy is solved, and the security of the network strategy is improved. And the network security defense effect is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, specifically to a network security strategy optimization system and method based on artificial intelligence. Background Technology

[0002] The current enterprise network environment is characterized by a trend towards both mobility and distributed collaboration. Network boundaries are constantly weakening, and the number of business systems and terminal assets is growing rapidly, resulting in highly diverse and semantically heterogeneous sources of security data. To improve network security, protection is generally achieved by setting security policies to counter specific attacks. However, attackers are increasingly inclined to employ a combination of long-term, covert penetration and multi-stage or fragmented, low-frequency operations to carry out attacks. This makes attacks often exhibit low-risk, weakly anomaly characteristics, making it difficult to trigger traditional rule-based or single-point threshold-based alerting mechanisms, thus reducing the effectiveness of network security defenses. Summary of the Invention

[0003] The purpose of this invention is to provide a network security strategy optimization system and method based on artificial intelligence to solve the problems mentioned in the background art.

[0004] To achieve the above objectives, the present invention provides the following technical solution: a network security strategy optimization method based on artificial intelligence, comprising the following steps: Step S1: Obtain multi-source network data and perform unified processing on the multi-source network data to obtain unified data. Based on the unified data, establish an event data model and a dynamic behavior relationship diagram. Step S2: Based on the event data model and dynamic behavior relationship diagram, obtain suspicious security behaviors, perform security evidence transformation and accumulation processing on the suspicious security behaviors, and obtain the cumulative score of attack evidence against network subjects by the suspicious security behaviors; Step S3: Obtain a set of security behaviors, perform correlation analysis on the security behaviors in the set of security behaviors based on the cumulative score of attack evidence, obtain potential attack chains, and identify the critical paths and critical cut points in the development of potential attack chains. Step S4: Based on the critical path and critical cut points, establish a multi-level security policy set to form a different policy candidate set for the attack chain; Step S5: Based on the strategy candidate set, perform multi-objective optimization screening by combining the attack risk reduction effect, false alarm risk, business impact and strategy redundancy, determine the optimal strategy combination and execute the optimal strategy combination, and at the same time perform feedback analysis on the execution results to update the evidence accumulation standard structured evidence unit and candidate strategy generation process.

[0005] Preferably, step S1 includes the following steps: Collect multi-source network data, including network communication data, host behavior data, identity authentication data, and asset configuration data, and aggregate the multi-source network data to obtain a multi-source dataset with data source identifiers and traceability pointers; The time base of the network multi-source data in the multi-source dataset is unified and converted for time synchronization. The converted data is corrected and aligned based on the time protocol to obtain time-unified data. The time-unified data is then parsed and fields are extracted. The extracted fields are mapped to event and behavior data with unified semantic structure to form a security event set. The data identifiers in the security incident set undergo multi-identifier ambiguity elimination and merging processing to obtain unique entity identifiers and related identifier sets, forming a complete entity identifier set; Based on the security event set and the set of all entity identifiers, each security event is recorded as a structured system containing events, entities and relationships. An event data model is established, and a dynamic behavior relationship diagram is constructed based on the multiple types of relationships between the subject and object attachments. The event data model and the dynamic behavior relationship diagram together form a network behavior state dataset used to represent the overall behavior state of the network.

[0006] Preferably, step S2 includes the following steps: Events are filtered from the event data model according to preset event categories. Based on the set of all entity identifiers, the filtered events are bound to the corresponding entities to obtain a candidate set sequence divided by entity. Then, asset configuration data and dynamic behavior relationship diagram are used as additional conditions to obtain a behavior candidate set composed of an entity-based behavior candidate sequence. Establish a multi-baseline judgment benchmark, perform behavior judgment on the behavior candidate sequence in the behavior candidate set based on the judgment benchmark to obtain low-frequency events, and output a low-frequency event set. Based on the security event set and the low-frequency event set, calculate the behavior event anomaly score in the event set, determine the behavior event status according to the anomaly score, and obtain suspicious security behaviors. Based on multiple overlapping factors, repetitive behavioral events in suspicious security behaviors are aggregated. The aggregated behavioral events are then processed for field standardization and source pointer retention to obtain standard structured evidence units. A time decay weighted algorithm is used to accumulate and calculate the standard structured evidence units corresponding to the same entity. During the calculation process, when the evidence units are consecutive or the behavioral events are related in the dynamic behavioral relationship graph, the calculation result is increased to obtain the cumulative score of the attack evidence.

[0007] Preferably, step S2 further includes: Uncertainty parameters for standard structured evidence units are obtained based on data integrity, consistency of evidence sources, and differences among similar data. The uncertainty of the cumulative score of attack evidence is evaluated based on the uncertainty parameters to obtain the uncertainty evaluation result of the cumulative score of attack evidence. The cumulative score of attack evidence is then calibrated based on the uncertainty evaluation result to obtain the calibrated cumulative score.

[0008] Preferably, step S3 includes the following steps: Based on the event data model, dynamic behavior relationship diagram, all entity identifier set, standard structured evidence unit, attack evidence cumulative score and calibration cumulative score as screening conditions, the screened events and corresponding entities are merged with the standard structured evidence unit to form a set of security behavior objects. The correlation score between safety behavior objects is calculated based on the dynamic behavior relationship graph. When the correlation score exceeds the preset score threshold, a behavior relationship graph is constructed with safety behavior objects as nodes and behavior relationships as connecting edges. Based on the cumulative score of attack evidence and the uncertainty assessment results, a risk-weighted algorithm or a probabilistic inference algorithm is used to infer potential behavioral attack chains in the behavioral association graph, forming a set of potential behavioral attack chains. The potential behavioral attack chains include node sequences, connection edge sequences, chain stage labels, and chain risk scores. Targeting high-value asset allocation data from multi-source datasets, the starting behavior of potential behavioral attack chains is taken as the source subject. Attack chains connecting the source subject and the target are searched in the potential behavioral attack chain set as attack paths. Risk-weighted search algorithm or path contribution algorithm is used to calculate the paths, resulting in a set of critical paths and a ranking of attack path contributions. Based on the potential attack chain set and the critical path set, the cut point positions used to block the source subject from the target are obtained through the minimum cut, maximum flow or minimum fixed point cut algorithm, resulting in the set of critical cut points and the risk reduction contribution of each cut point to the target.

[0009] Preferably, step S3 further includes: When inferring potential behavioral attack chains, the inference is based on discontinuous behavioral objects in the behavioral association graph.

[0010] Preferably, step S4 includes the following steps: For potential attack chains, critical paths, and critical cut points, based on the cumulative attack evidence score and uncertainty analysis results, the interception targets, risk characteristics, and attack stage information of the critical cut points are obtained, and the input structure for strategy construction is generated. Based on the policy, an input structure is constructed, a policy template set is established according to the control type, and the policy templates in the policy template set are instantiated in a parameterized manner to obtain a policy instance set; Based on the policy instance set, the policy templates are hierarchically divided according to their impact on the target, and the hierarchical policy templates are then structured to obtain a multi-level security policy set generated according to key cut points.

[0011] Preferably, step S4 includes the following steps: Establish a correspondence between a multi-level security policy set and a potential behavioral attack chain set. Select the corresponding level of security policy based on the uncertainty analysis results and the cumulative score of attack evidence, and obtain a candidate subset of policies for different stages and risk levels of potential behavioral attack chains.

[0012] Preferably, step S5 includes the following steps: Based on a multi-level security policy set and policy candidate subset, the hierarchy, action type, target and scope of the candidate policies and the estimated impact fields are extracted. Based on the uncertainty analysis results and the risk reduction contribution of key cut points, a multi-objective optimization input data structure is obtained. A multi-objective function is established based on multi-objective optimization of input data structure, attack risk reduction effect, false alarm risk, business impact and policy redundancy, and constraints are set to obtain a multi-objective optimization model; The candidate policies in the policy candidate subset are defined as hierarchical multi-valued decision variables, and the optimal combination of candidate policies is solved by a multi-objective optimization model. The optimal candidate strategy combination is structurally encapsulated to obtain a combined encapsulation package. The combined encapsulation package is then sent to the strategy execution point and the strategy is executed in the execution order. At the same time, the strategy execution record and execution status data are obtained and used for updating the evidence accumulation standard structured evidence unit and the candidate strategy generation process.

[0013] An artificial intelligence-based cybersecurity strategy optimization system, the system comprising: Multi-source data acquisition and processing unit: used to acquire multi-source network data and perform unified processing on the multi-source network data; Event Model and Behavior Diagram Building Unit: Used to build event data models and dynamic behavior diagrams; Behavioral Event Recognition Unit: Used to identify the state of event behavior and calculate the cumulative score of attack evidence for event behavior. Multi-stage potential attack chain inference unit: used to infer potential behavioral attack chains based on event behavior; Path and cut point identification unit: used to identify critical paths and critical cut points in potential behavioral attack chains; Policy generation and solution unit: used to solve the security policy corresponding to the potential behavioral attack chain.

[0014] Compared with the prior art, the beneficial effects of the present invention are: 1. This invention uses multi-source network data as initial data, performs data unification and structuring processing, transforms event behavior into structured evidence, and accumulates the evidence to obtain an attack evidence accumulation score. This solves the problem that network strategies are difficult to detect and defend against fragmented attacks and latent low-abnormal behavior, thus improving the effectiveness of network security defense.

[0015] 2. This invention infers potential hidden attack chains and obtains the critical paths and cut points of the attack chains, enabling protection strategies to intercept potential hidden attack chains at critical cut points, thereby reducing the impact of attack behavior on network security and security losses, while improving the accuracy of interception and reducing ineffective interception.

[0016] 3. This invention establishes a multi-level security policy set for event behavior based on associated paths and associated cut points, and selects corresponding security policies according to the level based on the cumulative score of attack evidence and the degree of network security impact. This avoids the mismatch phenomenon of implementing strong intervention policies for low-risk behaviors, reduces the risk of false alarms, avoids the overlap of corresponding policies, and improves the efficiency of security policy implementation. Detailed Implementation

[0017] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.

[0018] One embodiment of the present invention provides an artificial intelligence-based network security strategy optimization method, comprising the following steps: Step S1: Obtain multi-source network data and perform unified processing on the multi-source network data to obtain unified data. Based on the unified data, establish an event data model and a dynamic behavior relationship diagram. Step S2: Based on the event data model and dynamic behavior relationship diagram, obtain suspicious security behaviors, perform security evidence transformation and accumulation processing on the suspicious security behaviors, and obtain the cumulative score of attack evidence against network subjects by the suspicious security behaviors; Step S3: Obtain a set of security behaviors, perform correlation analysis on the security behaviors in the set of security behaviors based on the cumulative score of attack evidence, obtain potential attack chains, and identify the critical paths and critical cut points in the development of potential attack chains. Step S4: Based on the critical path and critical cut points, establish a multi-level security policy set to form a different policy candidate set for the attack chain; Step S5: Based on the strategy candidate set, perform multi-objective optimization screening by combining the attack risk reduction effect, false alarm risk, business impact and strategy redundancy, determine the optimal strategy combination and execute the optimal strategy combination, and at the same time perform feedback analysis on the execution results to update the evidence accumulation standard structured evidence unit and candidate strategy generation process.

[0019] One embodiment of the present invention is a network security strategy optimization system and method based on artificial intelligence, including step S1: acquiring multi-source network data and performing unified processing on the multi-source network data to obtain unified data, and establishing an event data model and a dynamic behavior relationship diagram based on the unified data; Step S1 further includes the following steps: collecting multi-source network data including network communication data, host behavior data, identity authentication data and asset configuration data, and aggregating the multi-source network data to obtain a multi-source dataset with data source identifiers and traceability pointers; The collection of network communication data includes obtaining raw packet data, network flow record data, and session logs and alarm logs corresponding to firewalls and gateway security devices through methods such as network optical splitting devices and bypass probes; host behavior data is obtained through interface collection to obtain behavior logs about the host's internal execution and resource access; identity authentication data is collected through identity and access management systems, authentication gateways, and multi-factor authentication systems to collect authentication and authorization data such as login, authorization, permission changes, and abnormal sessions; asset configuration data includes configuration data such as asset value, exposure surface, and collection list. The collected data is connected to a unified data aggregation component through at least one of the following methods: log forwarding protocol, streaming pipeline, and file-based collection. The multi-source dataset with data source identifiers and traceability pointers enables data traceability across devices or regions, facilitating the preservation of data sources for standardized structured evidence units; The time base of the network multi-source data in the multi-source dataset is unified and converted for time synchronization. The converted data is corrected and aligned based on the time protocol to obtain time-unified data. The time-unified data is then parsed and fields are extracted. The extracted fields are mapped to event and behavior data with unified semantic structure to form a security event set. The data identifiers in the security incident set undergo multi-identifier ambiguity elimination and merging processing to obtain unique entity identifiers and related identifier sets, forming a complete entity identifier set; The timestamps of multi-source network data are uniformly converted to the same time base, while the time source information of the collection end is recorded. The clocks of data-related devices are aligned based on the network time protocol. When an accurate device time standard is lacking, clock drift is estimated and corrected based on time series or causal constraints of adjacent events to avoid cross-source data and corresponding time being unable to be correlated. For log data types, feature parsing or template rules are used to parse the data format and extract fields to obtain the minimum field set of the corresponding data. The extracted fields are mapped into event and behavior data with a unified semantic structure, including event type, subject, object, action, result, and environmental context fields, resulting in a unified structured security event set. The user identifier, host identifier, process identifier, session identifier, account identifier, IP address, device identifier, and cloud instance identifier in the security event set are disambiguated and merged, and a global entity unique identifier mapping table and its same confidence level are generated to form a set of all entity identifiers. This helps to reduce the inconsistency between the mapping of subject entities and multiple identifiers, and reduces the phenomenon of lack of structured field mapping after the splitting of a subject entity, providing unified and complete data for subsequent evidence accumulation. Based on the security event set and the set of all entity identifiers, each security event is recorded as a structured system containing events, entities and relationships. An event data model is established, and a dynamic behavior relationship diagram is constructed based on the multi-type relationships of subject and object attachments. The event data model and the dynamic behavior relationship diagram together form a network behavior state dataset used to represent the overall behavior state of the network. Based on the security event set and the entire entity identifier set, and using fields as constraints, combined with business tags, importance levels, network partitions, and control policy information provided by asset configuration data as context, each security event is set as a structured record containing a timestamp, event type, subject entity, object entity, action, result, environmental context, and tracing pointer. Event indexes are created according to time, subject, or behavior to generate an indexed event data model. Then, a dynamic behavioral relationship graph is constructed based on the login relationship, access relationship, process derivation relationship, network connection relationship, and permission change relationship between the subject and object. The subject and object are the nodes of the relationship graph, including nodes such as users, hosts, processes, and assets. The dynamic relationship graph provides the association relationships between events and can provide association relationship support for non-continuous events.

[0020] One embodiment of the present invention is a network security strategy optimization system and method based on artificial intelligence, including step S2: obtaining suspicious security behaviors based on event data models and dynamic behavior relationship graphs, performing security evidence transformation and accumulation processing on the suspicious security behaviors, and obtaining the cumulative score of attack evidence against network subjects by the suspicious security behaviors; Step S2 includes the following steps: Events are filtered from the event data model according to preset event categories. Based on the set of all entity identifiers, the filtered events are bound to the corresponding entities to obtain a candidate set sequence divided by entity. Then, asset configuration data and dynamic behavior relationship diagram are used as additional conditions to obtain a behavior candidate set composed of an entity-based behavior candidate sequence. The preset event categories include login, authentication, permission change, configuration change, network connection and access, lateral access attempt, asset detection, etc. Events are bound to attack entities to form structured data of subject entities, event behaviors, and the relationship between events and objects. The structured data serves as the component of the candidate sequence divided by entity. Under the action of additional conditions, a set of behavior candidates is formed, making the events in the behavior candidate set closer to the actual event behaviors. Establish a multi-baseline judgment benchmark, perform behavior judgment on the behavior candidate sequence in the behavior candidate set based on the judgment benchmark to obtain low-frequency events, and output a low-frequency event set. Based on the security event set and the low-frequency event set, calculate the behavior event anomaly score in the event set, determine the behavior event status according to the anomaly score, and obtain suspicious security behaviors. Among them, the multi-baseline judgment criteria include, for each entity and each behavior event type, establishing time baseline judgment criteria according to frequency distribution, time distribution and persistence distribution within a preset historical window, and establishing baseline judgment criteria for similar entity groups according to at least one of departments, hosts, business systems and network partitions, performing probability estimation on the event behaviors corresponding to the behavior candidate sequences in the behavior candidate set, when the probability of the behavior event is set to a first threshold, it is recorded as a low-frequency event, the low-frequency event set is obtained and the deviation parameter between the behavior event and the limit judgment criteria is obtained, for the behavior event, the behavior event anomaly score is obtained through an unsupervised learning algorithm, when the anomaly score is in a preset low-to-medium range, the behavior event is recorded as a weak anomaly event, and the behavior corresponding to the weak anomaly event is a suspicious security behavior; Based on multiple overlapping factors, repetitive behavioral events in suspicious security behaviors are aggregated; Among them, multiple overlapping factors include the same subject repeating the same action type and targeting the same object or asset domain within a short time window. Aggregating repeated behavioral events reduces event redundancy and helps reduce the redundancy of corresponding strategies for event behaviors. It also helps improve the efficiency of strategy selection and execution for behavioral events that reduce network security and enables quick and correct handling of behavioral events that reduce network security. The aggregated behavioral events are subjected to field standardization and source pointer retention processing to obtain standard structured evidence units. The standard structured evidence units include at least subject identifier, object identifier, event type, timestamp or time window, context features, and initial anomaly score and confidence level. The time decay weighted algorithm is used to accumulate the standard structured evidence units corresponding to the same entity. During the calculation process, when the evidence units are consecutive or the behavioral events are related in the dynamic behavioral relationship graph, the calculation result is increased to obtain the cumulative score of the attack evidence. Among them, continuous evidence units include the same subject appearing similar evidence units in adjacent time windows, or evidence that is discontinuous in time or space but related in the dynamic behavior relationship diagram. By performing evidence accumulation calculation, it is beneficial to combine fragmented standard structured evidence for behavioral events into complete risk evidence, which improves the network security strategy optimization system's ability to identify long-term hidden attacks and staged hidden attacks, and effectively improves network security defense capabilities. Step S2 also includes: Uncertainty parameters for standard structured evidence units are obtained based on data integrity, consistency of evidence sources, and differences among similar data. The uncertainty of the cumulative score of attack evidence is evaluated by risk reduction and other methods based on the uncertainty parameters. The uncertainty evaluation result of the cumulative score of attack evidence is obtained, and the cumulative score of attack evidence is calibrated based on the uncertainty evaluation result to obtain the calibrated cumulative score. Using the uncertainty evaluation result to calibrate the cumulative score of attack evidence helps to improve the calculation accuracy of the cumulative score of attack evidence.

[0021] One embodiment of the present invention provides: a network security strategy optimization system and method based on artificial intelligence, wherein step S3 includes the following steps: Based on the event data model, dynamic behavior relationship diagram, all entity identifier set, standard structured evidence unit, attack evidence cumulative score and calibration cumulative score as screening conditions, the screened events and corresponding entities are merged with the standard structured evidence unit to form a set of security behavior objects. Among them, the event data model, dynamic behavior relationship diagram, all entity identifier set, and standard structured evidence unit provide the security source of behavioral events, while the cumulative score of attack evidence and the cumulative score of calibration are the security source of evidence. A preset threshold for the cumulative score of evidence is set as a filtering condition. Events related to entity subjects are obtained from the event data model and dynamic behavior relationship diagram, and are integrated with the standard structured evidence unit to obtain a set of secure behavioral objects containing subject identifier, object identifier, timestamp or time window, behavior type, behavior characteristics, and evidence weight and confidence fields. By combining events, entity subjects, and evidence, it is convenient to infer potential behavioral attack chains in the future. The correlation score between safety behavior objects is calculated based on the dynamic behavior relationship graph. When the correlation score exceeds the preset score threshold, a behavior relationship graph is constructed with safety behavior objects as nodes and behavior relationships as connecting edges. The correlation score is calculated based on the entity correlation and path continuity of the behavior object over time using a dynamic behavior relationship graph. It is weighted by combining time constraint order and consistency constraint. When the correlation score exceeds a preset correlation score threshold, a correlation graph is constructed regarding the security behavior object and the relationships between behaviors. Based on the cumulative score of attack evidence and the uncertainty assessment results, a risk-weighted algorithm or a probabilistic inference algorithm is used to infer potential behavioral attack chains in the behavioral association graph, forming a set of potential behavioral attack chains. The potential behavioral attack chains include node sequences, connection edge sequences, chain stage labels, and chain risk scores. Simultaneously considering the cumulative score of attack evidence and the uncertainty assessment results to infer the potential behavior supply chain reduces the incorrect supply chain inference caused by pure topological chaining and improves the accuracy of potential behavior supply chain inference. Targeting high-value asset allocation data from multi-source datasets, the starting behavior of potential behavioral attack chains is taken as the source subject. Attack chains connecting the source subject and the target are searched in the potential behavioral attack chain set as attack paths. Risk-weighted search algorithm or path contribution algorithm is used to calculate the paths, resulting in a set of critical paths and a ranking of attack path contributions. Based on the potential attack chain set and the critical path set, the cut point positions used to block the source subject from the target are obtained through the minimum cut, maximum flow or minimum fixed point cut algorithm, resulting in the set of critical cut points and the risk reduction contribution of each cut point to the target. Step S3 also includes: When inferring potential behavioral attack chains, the potential behavioral attack chains are inferred based on discontinuous behavioral objects in the behavioral association graph. For discontinuous behavioral objects, when the behavioral objects meet at least one of the following conditions, the behavioral objects can be associated and the supply chain can be inferred: the links of the same subject entity are traceable, there is a reachable path based on the dynamic security relationship graph and the path length does not exceed the threshold, or the similarity of behavioral features exceeds the threshold. By incorporating discontinuous behavioral objects into a dynamic association graph, it is beneficial to avoid the impact of missed fragmented attacks and long-term breakpoint attacks on network security, thereby improving the effectiveness of network security defense.

[0022] One embodiment of the present invention provides: a network security strategy optimization system and method based on artificial intelligence, wherein step S4 includes the following steps: For potential attack chains, critical path sets, and critical cutpoint sets, based on the cumulative attack evidence score and uncertainty analysis results, the interception targets, risk representations, and attack stage information of the critical cutpoints are obtained, and a strategy construction input structure is generated. The strategy construction data structure includes cutpoint identifiers, control objects, stage labels, chain-level risk scores, cutpoint contribution, and uncertainty assessment results. Based on the policy-based input structure, a policy template set is established according to the control type. The policy templates in the policy template set are instantiated according to parameters such as the control object, network partition, asset or service, protocol port and effective duration to obtain a policy instance set. The policy instance set includes the policy action type, target object, scope, triggering condition and exception rule fields. Based on the policy instance set, the policy templates are hierarchically divided according to the degree of impact on the target. This includes dividing the policy templates into non-intervention, light intervention, medium intervention, and heavy intervention levels according to the level of business disturbance from low to high or the level of control strength from weak to strong. The hierarchical policy templates are then structured to obtain a multi-level security policy set generated according to the key cut points.

[0023] Step S4 includes the following steps: Establish a correspondence between a multi-level security policy set and a potential behavioral attack chain set. Select the corresponding level of security policy based on the uncertainty analysis results and the cumulative score of attack evidence. Obtain a policy candidate subset for different stages and risk levels of potential behavioral attack chains. The policy candidate subset also includes the mapping results of attack chain stage, risk level and policy level. The acquisition of the strategy candidate subset includes prioritizing non-intervention or light intervention levels when uncertainty is high, allowing the selection of medium or heavy intervention levels when the risk level is high and the confidence level meets the threshold, and the strategy level can be upgraded as the risk increases, thereby improving the adaptability of behavioral events and risk response strategies and better responding to network risks.

[0024] One embodiment of the present invention provides: a network security strategy optimization system and method based on artificial intelligence, wherein step S5 includes the following steps: Based on a multi-level security policy set and policy candidate subset, the hierarchy, action type, target and scope of the candidate policies and the estimated impact fields are extracted. Based on the uncertainty analysis results and the risk reduction contribution of key cut points, a multi-objective optimization input data structure is obtained. A multi-objective function is established based on the multi-objective optimization of input data structure, attack risk reduction effect, false alarm risk, business impact and strategy redundancy. Constraints are set to obtain a multi-objective optimization model. The multi-objective function includes security benefit objective, false alarm risk objective, business impact objective and strategy redundancy conflict objective. Constraints include business impact limit, number of re-intervention strategies for the same object limit, and must cover a preset number of high-risk critical cut points or critical paths. Candidate policies in the policy candidate subset are defined as hierarchical multi-valued decision variables. The optimal combination of candidate policies is solved by a multi-objective optimization model. The policies in the optimal combination of candidate policies defend against or block potential behavioral attack chains or event behaviors, while reducing the probability of false alarms in network system operation. The optimal candidate strategy combination is structurally encapsulated to obtain a combined encapsulation package, which includes strategy actions, hierarchy, key cut point locations, target objects, scope, sequence information, and target results. The combined encapsulation package is then sent to the strategy execution point and the strategy is executed in the execution order. At the same time, strategy execution records and execution status data are acquired and used to update the evidence accumulation standard structured evidence unit and the candidate strategy generation process.

[0025] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the invention. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, it is intended that all variations falling within the meaning and scope of equivalents of the claims be included within the present invention.

Claims

1. A method for optimizing network security strategies based on artificial intelligence, characterized in that, Includes the following steps: Step S1: Obtain multi-source network data and perform unified processing on the multi-source network data to obtain unified data. Based on the unified data, establish an event data model and a dynamic behavior relationship diagram. Step S2: Based on the event data model and dynamic behavior relationship diagram, obtain suspicious security behaviors, perform security evidence transformation and accumulation processing on the suspicious security behaviors, and obtain the cumulative score of attack evidence against network subjects by the suspicious security behaviors; Step S3: Obtain a set of security behaviors, perform correlation analysis on the security behaviors in the set of security behaviors based on the cumulative score of attack evidence, obtain potential attack chains, and identify the critical paths and critical cut points in the development of potential attack chains. Step S4: Based on the critical path and critical cut points, establish a multi-level security policy set to form a different policy candidate set for the attack chain; Step S5: Based on the strategy candidate set, perform multi-objective optimization screening by combining the attack risk reduction effect, false alarm risk, business impact and strategy redundancy, determine the optimal strategy combination and execute the optimal strategy combination, and at the same time perform feedback analysis on the execution results to update the evidence accumulation standard structured evidence unit and candidate strategy generation process.

2. The method for optimizing network security strategies based on artificial intelligence according to claim 1, characterized in that: Step S1 includes the following steps: Collect multi-source network data, including network communication data, host behavior data, identity authentication data, and asset configuration data, and aggregate the multi-source network data to obtain a multi-source dataset with data source identifiers and traceability pointers; The time base of the network multi-source data in the multi-source dataset is unified and converted for time synchronization. The converted data is corrected and aligned based on the time protocol to obtain time-unified data. The time-unified data is then parsed and fields are extracted. The extracted fields are mapped to event and behavior data with unified semantic structure to form a security event set. The data identifiers in the security incident set undergo multi-identifier ambiguity elimination and merging processing to obtain unique entity identifiers and related identifier sets, forming a complete entity identifier set; Based on the security event set and the set of all entity identifiers, each security event is recorded as a structured system containing events, entities and relationships. An event data model is established, and a dynamic behavior relationship diagram is constructed based on the multiple types of relationships between the subject and object attachments. The event data model and the dynamic behavior relationship diagram together form a network behavior state dataset used to represent the overall behavior state of the network.

3. The method for optimizing network security strategies based on artificial intelligence according to claim 2, characterized in that: Step S2 includes the following steps: Events are filtered from the event data model according to preset event categories. Based on the set of all entity identifiers, the filtered events are bound to the corresponding entities to obtain a candidate set sequence divided by entity. Then, asset configuration data and dynamic behavior relationship diagram are used as additional conditions to obtain a behavior candidate set composed of an entity-based behavior candidate sequence. Establish a multi-baseline judgment benchmark, perform behavior judgment on the behavior candidate sequence in the behavior candidate set based on the judgment benchmark to obtain low-frequency events, and output a low-frequency event set. Based on the security event set and the low-frequency event set, calculate the behavior event anomaly score in the event set, determine the behavior event status according to the anomaly score, and obtain suspicious security behaviors. Based on multiple overlapping factors, repetitive behavioral events in suspicious security behaviors are aggregated. The aggregated behavioral events are then processed for field standardization and source pointer retention to obtain standard structured evidence units. A time decay weighted algorithm is used to accumulate and calculate the standard structured evidence units corresponding to the same entity. During the calculation process, when the evidence units are consecutive or the behavioral events are related in the dynamic behavioral relationship graph, the calculation result is increased to obtain the cumulative score of the attack evidence.

4. The method for optimizing network security strategies based on artificial intelligence according to claim 3, characterized in that: Step S2 also includes: Uncertainty parameters for standard structured evidence units are obtained based on data integrity, consistency of evidence sources, and differences among similar data. The uncertainty of the cumulative score of attack evidence is evaluated based on the uncertainty parameters to obtain the uncertainty evaluation result of the cumulative score of attack evidence. The cumulative score of attack evidence is then calibrated based on the uncertainty evaluation result to obtain the calibrated cumulative score.

5. The method for optimizing network security strategies based on artificial intelligence according to claim 4, characterized in that: Step S3 includes the following steps: Based on the event data model, dynamic behavior relationship diagram, all entity identifier set, standard structured evidence unit, attack evidence cumulative score and calibration cumulative score as screening conditions, the screened events and corresponding entities are merged with the standard structured evidence unit to form a set of security behavior objects. The correlation score between safety behavior objects is calculated based on the dynamic behavior relationship graph. When the correlation score exceeds the preset score threshold, a behavior relationship graph is constructed with safety behavior objects as nodes and behavior relationships as connecting edges. Based on the cumulative score of attack evidence and the uncertainty assessment results, a risk-weighted algorithm or a probabilistic inference algorithm is used to infer potential behavioral attack chains in the behavioral association graph, forming a set of potential behavioral attack chains. The potential behavioral attack chains include node sequences, connection edge sequences, chain stage labels, and chain risk scores. Targeting high-value asset allocation data from multi-source datasets, the starting behavior of potential behavioral attack chains is taken as the source subject. Attack chains connecting the source subject and the target are searched in the potential behavioral attack chain set as attack paths. Risk-weighted search algorithm or path contribution algorithm is used to calculate the paths, resulting in a set of critical paths and a ranking of attack path contributions. Based on the potential attack chain set and the critical path set, the cut point positions used to block the source subject from the target are obtained through the minimum cut, maximum flow or minimum fixed point cut algorithm, resulting in the set of critical cut points and the risk reduction contribution of each cut point to the target.

6. The method for optimizing network security strategies based on artificial intelligence according to claim 5, characterized in that: Step S3 also includes: When inferring potential behavioral attack chains, the inference is based on discontinuous behavioral objects in the behavioral association graph.

7. The method for optimizing network security strategies based on artificial intelligence according to claim 6, characterized in that: Step S4 includes the following steps: For potential attack chains, critical paths, and critical cut points, based on the cumulative attack evidence score and uncertainty analysis results, the interception targets, risk characteristics, and attack stage information of the critical cut points are obtained, and the input structure for strategy construction is generated. Based on the policy, an input structure is constructed, a policy template set is established according to the control type, and the policy templates in the policy template set are instantiated in a parameterized manner to obtain a policy instance set; Based on the policy instance set, the policy templates are hierarchically divided according to their impact on the target, and the hierarchical policy templates are then structured to obtain a multi-level security policy set generated according to key cut points.

8. The method for optimizing network security strategies based on artificial intelligence according to claim 7, characterized in that: Step S4 includes the following steps: Establish a correspondence between a multi-level security policy set and a potential behavioral attack chain set. Select the corresponding level of security policy based on the uncertainty analysis results and the cumulative score of attack evidence, and obtain a candidate subset of policies for different stages and risk levels of potential behavioral attack chains.

9. The method for optimizing network security strategies based on artificial intelligence according to claim 8, characterized in that: Step S5 includes the following steps: Based on a multi-level security policy set and policy candidate subset, the hierarchy, action type, target and scope of the candidate policies and the estimated impact fields are extracted. Based on the uncertainty analysis results and the risk reduction contribution of key cut points, a multi-objective optimization input data structure is obtained. A multi-objective function is established based on multi-objective optimization of input data structure, attack risk reduction effect, false alarm risk, business impact and policy redundancy, and constraints are set to obtain a multi-objective optimization model; The candidate policies in the policy candidate subset are defined as hierarchical multi-valued decision variables, and the optimal combination of candidate policies is solved by a multi-objective optimization model. The optimal candidate strategy combination is structurally encapsulated to obtain a combined encapsulation package. The combined encapsulation package is then sent to the strategy execution point and the strategy is executed in the execution order. At the same time, the strategy execution record and execution status data are obtained and used for updating the evidence accumulation standard structured evidence unit and the candidate strategy generation process.

10. An artificial intelligence-based network security policy optimization system, used to execute the method of an artificial intelligence-based network security policy optimization system according to claim 9, characterized in that, The system includes: Multi-source data acquisition and processing unit: used to acquire multi-source network data and perform unified processing on the multi-source network data; Event Model and Behavior Diagram Building Unit: Used to build event data models and dynamic behavior diagrams; Behavioral Event Recognition Unit: Used to identify the state of event behavior and calculate the cumulative score of attack evidence for event behavior. Multi-stage potential attack chain inference unit: used to infer potential behavioral attack chains based on event behavior; Path and cut point identification unit: used to identify critical paths and critical cut points in potential behavioral attack chains; Policy generation and solution unit: used to solve the security policy corresponding to the potential behavioral attack chain.