Network security protection method and device, equipment and storage medium

By simulating a network attack and defense cognitive model and dynamically adjusting defense strategies, the shortcomings of existing network security defense systems in terms of dynamic applicability are addressed, achieving more intelligent and efficient network security protection.

CN122053252APending Publication Date: 2026-05-15PENG CHENG LAB
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
PENG CHENG LAB
Filing Date
2026-04-08
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing network security defense systems are insufficient in terms of dynamic applicability, failing to effectively combine the attacker's motivation for selecting targets with the defender's decision-making process. This results in a disconnect between security strategies and real attack and defense logic, limiting proactive defense capabilities.

Method used

By inputting current network attack and defense information into a preset attack and defense cognitive model, the cognitive decision-making process of attackers and defenders in network security games is simulated, generating current attack paths and defense strategies, and making dynamic adjustments based on these.

Benefits of technology

It enables intelligent and efficient dynamic adjustment of defense strategies, improving the applicability of network security protection and proactive defense capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122053252A_ABST
    Figure CN122053252A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network security, and discloses a network security protection method and device, equipment and a storage medium. Current network attack and defense information is input into a preset attack and defense cognitive model, then a cognitive decision process of an attacker and a defender in a network security game is simulated through a preset attack model and a preset defense model, and a current defense strategy is adjusted based on a current attack path. And performing network security protection based on the obtained target defense strategy. According to the method, the current network attack and defense information is input into the preset attack model for the network attack side and the preset defense model for the network defense side, the cognitive decision process of an attacker and a defender in a network security game is simulated, and quantitative prediction and strategy generation of intentions of the two parties are realized by introducing the preset attack and defense cognitive model; and then the current defense strategy is adjusted based on the current attack path, so that the defense strategy can be dynamically adjusted, and more intelligent and efficient network security protection is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a network security protection method, apparatus, device and storage medium. Background Technology

[0002] Currently, methods for detecting and defending against cyber threats only focus on objective technical indicators such as network traffic and logs, completely ignoring the attacker's motivation for choosing targets and the trade-offs made by defenders. This leads to a disconnect between security strategies and real attack and defense logic, resulting in insufficient dynamic applicability of existing defense systems and severely restricting the proactive defense capabilities of cybersecurity. Summary of the Invention

[0003] The main purpose of this application is to provide a network security protection method, device, equipment and storage medium, which aims to solve the technical problem of how to dynamically adjust the defense strategy to achieve more intelligent and efficient network security protection.

[0004] To achieve the above objectives, this application provides a network security protection method, which includes the following steps: The current network attack and defense information is input into the preset attack and defense cognitive model, which includes a preset attack model for the network attack side and a preset defense model for the network defense side. The preset attack model and the preset defense model are used to simulate the cognitive decision-making process of attackers and defenders in network security games, so as to obtain the current attack path and the current defense strategy. The current defense strategy is adjusted based on the current attack path, and network security protection is carried out based on the obtained target defense strategy.

[0005] Optionally, before inputting the current network attack and defense information into the preset attack and defense cognitive model, the method further includes: Determine the attack value level and attack difficulty level of the network attack side based on historical network attack and defense information; The attack intention is determined based on the attack value level and the attack difficulty level, and the initial attack path is determined based on the attack intention. The initial attack model is trained based on the historical network attack and defense information and the initial attack path to obtain a preset attack model for the network attack side.

[0006] Optionally, determining the attack value level and attack difficulty level against the network attack side based on historical network attack and defense information includes: Value evaluation indicators are determined based on the data sensitivity, business impact, and intelligence acquisition value corresponding to the network attack side. The membership degree of the value evaluation index to each evaluation level is determined based on the historical network attack and defense information. The attack value level for the network attack side is determined based on the weights corresponding to the value evaluation indicators, the membership degree, and the evaluation values ​​corresponding to each evaluation level. A baseline value for the difficulty of attacking the network attacking side is determined based on the attack complexity and attack privileges of the network attacking side. The attack difficulty baseline is adjusted based on the training factor, sensitive document information, and historical threat intelligence in the historical network attack and defense information to obtain the adjusted attack difficulty level.

[0007] Optionally, determining the attack intention based on the attack value level and the attack difficulty level, and determining the initial attack path based on the attack intention, includes: The attack intensity is calculated based on the attack value level, the value sensitivity coefficient, and the attack difficulty level. The attack intensity is compared with a preset attack threshold, and the attack intention is determined based on the attack comparison result; The intent of the attack behavior is determined based on the attack intent and the constituent factors corresponding to the attack difficulty level. The initial network topology corresponding to the network attack side is adjusted according to the attack intent, and the initial attack path is determined according to the adjusted target network topology.

[0008] Optionally, before inputting the current network attack and defense information into the preset attack and defense cognitive model, the method further includes: Determine the defense value level and defense difficulty level for the network defense side based on historical network attack and defense information; The defense intention is determined based on the defense value level and the defense difficulty level, and the initial defense strategy is determined based on the defense intention. The initial defense model is trained based on the historical network attack and defense information and the initial defense strategy to obtain a preset defense model for the network defense side.

[0009] Optionally, determining the defense value level and defense difficulty level for the network defense side based on historical network attack and defense information includes: Construct a directed weighted graph based on network defense topology and service flow data from historical network attack and defense information; The total indirect loss of each node is calculated based on the direct value of each node in the directed weighted graph and a variant algorithm, and the defense value level for the network defense side is determined based on the total indirect loss. The baseline value for defense difficulty for the network defense side is determined based on the technical compatibility risks, resource investment time, and service interruption risks in the historical network attack and defense information. The defense difficulty baseline value is adjusted based on the difficulty reduction coefficient to obtain the adjusted defense difficulty level.

[0010] Optionally, determining the defense intention based on the defense value level and the defense difficulty level, and determining the initial defense strategy based on the defense intention, includes: The defense strength is calculated based on the defense value level, the defense difficulty level, and the attack strength. The defense strength is compared with a preset defense threshold, and the defense intention is determined based on the defense comparison result; Determine the pre-defense strategy based on the stated defense intentions; Security checks are performed on the common critical nodes of the initial attack path targeting the network attack side, and the pre-emptive defense strategy is adjusted based on the detection results to obtain the adjusted initial defense strategy.

[0011] Furthermore, to achieve the above objectives, this application also provides a network security protection device, which includes: The model building module is used to input current network attack and defense information into a preset attack and defense cognitive model, which includes a preset attack model for the network attack side and a preset defense model for the network defense side. The strategy generation module is used to simulate the cognitive decision-making process of attackers and defenders in network security games through the preset attack model and the preset defense model, so as to obtain the current attack path and the current defense strategy. The network security protection module is used to adjust the current defense strategy based on the current attack path and to perform network security protection based on the obtained target defense strategy.

[0012] In addition, to achieve the above objectives, this application also proposes a network security protection device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the network security protection method described above.

[0013] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the network security protection method described above.

[0014] This application inputs current network attack and defense information into a preset attack and defense cognitive model. This model includes a preset attack model for the attacking side and a preset defense model for the defending side. Then, it simulates the cognitive decision-making process of attackers and defenders in a network security game using these models, obtaining the current attack path and current defense strategy. Based on the current attack path, the current defense strategy is adjusted, and network security protection is implemented based on the obtained target defense strategy. This application inputs current network attack and defense information into the preset attack model for the attacking side and the preset defense model for the defending side, and simulates the cognitive decision-making process of attackers and defenders in a network security game. By introducing the preset attack and defense cognitive model, it achieves quantitative prediction of the intentions of both parties and strategy generation. Then, based on the current attack path, it adjusts the current defense strategy, thereby enabling dynamic adjustment of the defense strategy and achieving more intelligent and efficient network security protection. Attached Figure Description

[0015] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0016] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1 This is a flowchart illustrating the first embodiment of the network security protection method of this application; Figure 2 This is a flowchart illustrating the second embodiment of the network security protection method of this application; Figure 3 This is a flowchart illustrating the third embodiment of the network security protection method of this application; Figure 4 This is a schematic diagram of the overall framework of an embodiment of the network security protection method of this application; Figure 5 This is a structural block diagram of the first embodiment of the network security protection device of this application; Figure 6 This is a schematic diagram of the network security protection device for the hardware operating environment involved in the embodiments of this application.

[0018] The realization of the purpose, functional features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0019] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.

[0020] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.

[0021] The main solution of this application embodiment is as follows: inputting current network attack and defense information into a preset attack and defense cognitive model, the preset attack and defense cognitive model including a preset attack model for the network attack side and a preset defense model for the network defense side; simulating the cognitive decision-making process of attackers and defenders in network security game through the preset attack model and the preset defense model to obtain the current attack path and the current defense strategy; adjusting the current defense strategy based on the current attack path, and performing network security protection based on the obtained target defense strategy.

[0022] Currently, methods for detecting and defending against cyber threats only focus on objective technical indicators such as network traffic and logs, completely ignoring the attacker's motivation for choosing targets and the trade-offs made by defenders. This leads to a disconnect between security strategies and real attack and defense logic, resulting in insufficient dynamic applicability of existing defense systems and severely restricting the proactive defense capabilities of cybersecurity.

[0023] This application inputs current network attack and defense information into a preset attack and defense cognitive model. This model includes a preset attack model for the attacking side and a preset defense model for the defending side. Then, it simulates the cognitive decision-making process of attackers and defenders in a network security game using these models, obtaining the current attack path and current defense strategy. Based on the current attack path, the current defense strategy is adjusted, and network security protection is implemented based on the obtained target defense strategy. This application inputs current network attack and defense information into the preset attack model for the attacking side and the preset defense model for the defending side, and simulates the cognitive decision-making process of attackers and defenders in a network security game. By introducing the preset attack and defense cognitive model, it achieves quantitative prediction of the intentions of both parties and strategy generation. Then, based on the current attack path, it adjusts the current defense strategy, thereby enabling dynamic adjustment of the defense strategy and achieving more intelligent and efficient network security protection.

[0024] It should be noted that the executing entity of this application can be a computing service device with data processing, network communication, and program execution functions, such as a computer. The following description uses a network security protection device as an example to illustrate this embodiment and the subsequent embodiments.

[0025] Based on this, the embodiments of this application provide a network security protection method, referring to... Figure 1 , Figure 1This is a flowchart illustrating the first embodiment of the network security protection method of this application.

[0026] In this embodiment, the network security protection method includes the following steps: Step S10: Input the current network attack and defense information into the preset attack and defense cognitive model, which includes a preset attack model for the network attack side and a preset defense model for the network defense side.

[0027] Understandably, current network attack and defense information refers to information related to network attacks and defenses at the current moment, such as network topology adjacency relationships, open port lists, known vulnerability numbers and their basic scores, training factors (i.e., the timestamp of the most recent company-wide security training), and document exposure factors (i.e., detecting whether there are publicly available documents containing system architecture diagrams, interface documents, or default password tables).

[0028] It should be understood that the preset attack and defense cognitive model in this embodiment may include a preset attack model for the network attack side and a preset defense model for the network defense side, and the preset attack and defense cognitive model is formed by combining the two models.

[0029] Step S20: Simulate the cognitive decision-making process of attackers and defenders in network security game using the preset attack model and the preset defense model to obtain the current attack path and the current defense strategy.

[0030] Understandably, a preset attack model can represent the attacker's perspective on the profit model, and a preset defense model can represent the defender's perspective on the cascading model. By using the preset attack model and the preset defense model, the cognitive decision-making process of the attacker and the defender in the cybersecurity game can be simulated, and the current attack path output by the preset attack model can be obtained, such as the path of phishing email → lateral movement → PLC instruction injection, and the current defense strategy output by the preset defense model can be obtained, such as the strategy of enabling multi-factor authentication + real-time SQL injection detection for the database.

[0031] Step S30: Adjust the current defense strategy based on the current attack path, and perform network security protection based on the obtained target defense strategy.

[0032] In a practical implementation, the current defense strategy can be adjusted based on the current attack path to achieve collaborative cooperation between the attacking and defending sides. In one feasible embodiment, all current attack paths can be analyzed. If an attack path is proven to be ineffective in practice, i.e., the attack fails, the defense strategy corresponding to the relevant attack path will be deleted, thereby adjusting the current defense strategy. At this time, the defender can carry out network security protection through the adjusted target defense strategy.

[0033] This embodiment inputs current network attack and defense information into a preset attack and defense cognitive model. This model includes a preset attack model for the attacking side and a preset defense model for the defending side. Then, it simulates the cognitive decision-making process of attackers and defenders in a network security game, obtaining the current attack path and current defense strategy. Based on the current attack path, the current defense strategy is adjusted, and network security protection is implemented based on the obtained target defense strategy. This embodiment inputs current network attack and defense information into the preset attack model for the attacking side and the preset defense model for the defending side, and simulates the cognitive decision-making process of attackers and defenders in a network security game. By introducing the preset attack and defense cognitive model, it achieves quantitative prediction of the intentions of both parties and strategy generation. Then, it adjusts the current defense strategy based on the current attack path, thereby enabling dynamic adjustment of the defense strategy and achieving more intelligent and efficient network security protection.

[0034] refer to Figure 2 , Figure 2 This is a flowchart illustrating the second embodiment of the network security protection method of this application.

[0035] Based on the first embodiment described above, in this embodiment, before step S10, the method further includes: Step S01: Determine the attack value level and attack difficulty level of the network attack side based on historical network attack and defense information.

[0036] Understandably, historical network attack and defense information refers to information related to the network attack side and the network defense side within a historical time period. This information can be used as input samples for model training.

[0037] It should be understood that the unified collection of observable external variables of the target environment not only covers traditional technical indicators, but also focuses on collecting non-technical indicators that reflect human cognitive state. During implementation, the system first accesses multi-source data in real time through application programming interfaces, log auditing systems, configuration management databases, and manual input interfaces. Subsequently, feature extraction and classification are performed to obtain historical network attack and defense information. The historical network attack and defense information collected from the target system includes: 1. Extracting technical features such as network topology adjacency relationships, open port lists, known vulnerability numbers and their basic scores, protocol types, and authentication mechanism strength; extracting network topology adjacency matrices, open port lists, known vulnerability CVE numbers and CVSS basic scores, protocol types (e.g., whether encrypted), and authentication mechanism strength; 2. Focusing on extracting three major cognitive features: First, the training factor D1. The system reads the timestamp t1 of the most recent company-wide security training and calculates the time decay coefficient α = e λ(t2 t1)If the exposure exceeds a set threshold (e.g., 2 weeks), it is marked as having weak awareness. Secondly, the system reads the document exposure factor D2, automatically crawling public and intranet knowledge bases to check for publicly available documents containing system architecture diagrams, interface documents, or default password tables. If found, the document is scored based on its level of detail; if found, it is marked as high exposure, and the document detail score S∈ [0,1] is extracted. Finally, the historical performance factor D3 is used to query historical attack and defense drill records, calculating the attack success rate Psuccess and the average defense response time Tresp for this type of asset. Ultimately, the system normalizes the above heterogeneous data into a standard vector, serving as the unified input basis for subsequent evaluation modules.

[0038] In practical implementation, the aforementioned historical network attack and defense information serves both the attacker (red side) and the defender (blue side) in cognitive modeling: for attackers, missing manuals or outdated protocols mean a lower attack threshold; for defenders, the cascading dependencies of core business systems reflect their protection priorities. Then, based on the historical network attack and defense information, the attack value level and attack difficulty level for the attacking side are determined.

[0039] Furthermore, in order to calculate the attack value level and attack difficulty level, in this embodiment, step S01 includes: determining a value evaluation index based on the data sensitivity, business influence, and intelligence acquisition value corresponding to the network attack side; determining the membership degree of the value evaluation index to each evaluation level based on the historical network attack and defense information; determining the attack value level for the network attack side based on the weight corresponding to the value evaluation index, the membership degree, and the evaluation value corresponding to each evaluation level; determining the attack difficulty benchmark value for the network attack side based on the attack complexity and attack privileges for the network attack side; and adjusting the attack difficulty benchmark value based on the training factor, sensitive document information, and historical threat intelligence in the historical network attack and defense information to obtain the adjusted attack difficulty level.

[0040] Understandably, in calculating the attack value level against the network attack side, this embodiment first establishes an evaluation index system that includes data sensitivity, business impact, and intelligence acquisition value. This system includes several value evaluation indicators, and the weights W of each value evaluation indicator are dynamically adjusted based on historical threat intelligence. Next, a fuzzy relation matrix R is constructed, containing elements r ij Let represent the membership degree of the i-th value evaluation index to the j-th comment level. The membership degree is obtained by mapping the feature values ​​in the historical network attack and defense information, and a comment set U = {low, medium, high} evaluation level and its corresponding evaluation value mapping {0.2, 0.5, 0.8} are established.

[0041] It should be understood that the comprehensive evaluation value V = W * R * U TFor example, historical threat intelligence indicated that a hacker group was buying up patient data for specific diseases at high prices for the electronic medical records and registration system of a large hospital, and that ransomware attacks targeting the healthcare industry had surged recently. Based on historical threat intelligence, data sensitivity becomes the most important factor, followed by business impact, while intelligence acquisition value is relatively low (because patient data is easier to monetize through the dark web). A weighting of W = [0.5, 0.3, 0.2] can be set, and membership degree can be mapped using the characteristic values ​​of historical network attack and defense information (such as whether the database is encrypted, whether the system is on a critical link in medical insurance, whether there are historical attack records, etc.). Assuming the evaluation results are: Data Sensitivity: High sensitivity (containing a large number of real names, identity information, and diagnostic records) → Membership degree [0.0, 0.2, 0.8] (0% low, 20% medium, 80% high); Business Impact: One hour of downtime will affect emergency and hospitalization services, but not 24 / 7 → Membership degree [0.1, 0.6, 0.3] (10% low, 60% medium, 30% high); Intelligence Acquisition Value: Patient data has stable demand on the dark web, but is not a state secret → Membership degree [0.2, 0.5, 0.3] (20% low, 50% medium, 30%). (High), thus constructing a fuzzy relation matrix R. Next, calculate the weighted comprehensive membership vector B = W * R, where B1 (membership degree to "low") = 0.5 × 0.0 + 0.3 × 0.1 + 0.2 × 0.2 = 0 + 0.03 + 0.04 = 0.07, B2 (membership degree to "medium") = 0.5 × 0.2 + 0.3 × 0.6 + 0.2 × 0.5 = 0.10 + 0.18 + 0.10 = 0.38, B3 (membership degree to "high") = 0.5 × 0.8 + 0.3 × 0.3 + 0.2 × 0.3 = 0.40 + 0.09 + 0.06 = 0.55, B = [0.07, 0.38, 0.55]. Then calculate the comprehensive evaluation value V = W * R * U. T =0.07×0.2 + 0.38×0.5 + 0.55×0.8 = 0.644. 0.644 falls between 0.5 (medium) and 0.8 (high), closer to 0.8, indicating a medium-to-high attack value level for the network attack side. Furthermore, this embodiment introduces a cognitive correction mechanism. If publicly available sensitive documents are detected, it is assumed that the attacker will subjectively amplify the target's value level. Therefore, a gain coefficient is introduced to adjust the base value score upwards, reflecting the psychological allure of information leakage. For example, if the "document exposure factor D" is detected to be too high, a gain coefficient β>1 is introduced, correcting the final evaluation value V1' = V*(1 +β×S), where S is the normalized document sensitivity score. Thus, the attack value level for the network attack side is determined based on the final evaluation value V1'.

[0042] In practical implementation, the attack difficulty level L for the network attack side is... a During the assessment process, the attack difficulty benchmark value S1 can be calculated based on the two core dimensions of attack complexity and required privileges in the internationally accepted vulnerability scoring standard. This benchmark value represents the inherent technical barrier to attacking using known vulnerabilities. Based on this, three key environmental perception correction factors are introduced to dynamically adjust the attack difficulty benchmark S1 by adjusting ΔS. First, there's the personnel defense maturity correction. The system calculates the time difference between the most recent security training or drill and the present, using a time decay model to quantify the retention of personnel security awareness. If training has been conducted recently, the difficulty score increases significantly; otherwise, it gradually returns to a basic level over time. Second, there's the information exposure surface correction. The system calculates an exposure index based on the number and detail of scanned sensitive documents. The more severe the document leak, the greater the assistance to the attacker's reconnaissance, and the corresponding attack difficulty score decreases linearly. Finally, there's the attack path maturity correction. The system uses the frequency of successful attacks on this type of asset in historical threat intelligence. High-frequency successful attack paths indicate a mature toolchain, thus appropriately reducing the perceived difficulty. Ultimately, the attack difficulty benchmark S1 is linearly superimposed with the above three correction factors ΔS, and the result is strictly constrained within the range of zero to one using a non-linear mapping function, expressed as L. a = Sigmoid(S1 +∑ΔS), thus outputting an attack difficulty level that encompasses both technical barriers and environmental awareness thresholds.

[0043] Step S02: Determine the attack intention based on the attack value level and the attack difficulty level, and determine the initial attack path based on the attack intention.

[0044] Further, in this embodiment, step S02 includes: calculating the attack strength based on the attack value level, the value sensitivity coefficient, and the attack difficulty level; comparing the attack strength with a preset attack threshold and determining the attack intention based on the attack comparison result; determining the attack behavior intent based on the attack intention and the constituent factors corresponding to the attack difficulty level; adjusting the initial network topology corresponding to the network attack side based on the attack behavior intent, and determining the initial attack path based on the adjusted target network topology.

[0045] Understandably, this embodiment utilizes an improved expected utility theory to transform attack value level and attack difficulty level into specific attack intensity. When deriving the attack intensity I1, it assumes the attacker is a rational economic agent whose attack intention depends on the ratio of expected benefit to expected cost. A utility function is constructed: a value sensitivity coefficient is set, causing the attacker's preference for high-value targets to increase exponentially. Simultaneously, combined with a difficulty sensitivity coefficient, the final attack intention intensity value is calculated and determined as extremely high, medium, or low attack intention based on a preset threshold. The calculation formula is: I1 = (V1') m / ((Ld) n + p), where m is the value sensitivity coefficient, usually greater than 1, indicating that the attacker's preference for high-value targets increases exponentially, n is the difficulty sensitivity coefficient, and p is a minimum value to prevent the denominator from being zero. Based on the comparison between I1 and the preset attack threshold, the attack intention can be determined according to the comparison result.

[0046] It should be understood that, for the attacker, the output is a high-probability attack sequence (e.g., "using publicly available manual information to launch a phishing attack → using weak passwords to move laterally"). Specifically, this is based on the attack strength I1 and the attack difficulty level L. a The main constituent factors (such as whether the low difficulty is due to "document leakage" or "unpatched vulnerability") are used to search for matching initial access tactics in the pre-built ATT&CK tactic library. If the document exposure factor D2 contributes significantly, the attack intent is generated as "collecting publicly available document information" → "constructing targeted phishing emails," and the output is a JSON-formatted action sequence object.

[0047] In the specific implementation, when generating multi-step attack paths, the initial network topology corresponding to the attacking side is used as the core graph. High-probability attack behaviors in the generated attack intent are used as edge weights. If a behavior has extremely high intent, the edge weight is close to the maximum value; if the intent is low, it is pruned directly to obtain the adjusted target network topology. Subsequently, an improved maximum reliable path algorithm is used. Starting from mutually compromised nodes in the target network topology and ending at high-value core assets, the most likely attack chain is searched under the constraints of path length and single-step success rate. Finally, multiple high-probability initial attack paths (Top-K) are output, and key stepping stone nodes and estimated time are marked.

[0048] Step S03: Train the initial attack model based on the historical network attack and defense information and the initial attack path to obtain a preset attack model for the network attack side.

[0049] Understandably, the initial attack model can be an initial model for the network attack side, such as the STRIDE or PASTA model. It takes historical network attack and defense information as input and the initial attack path as output to build training samples. Based on these training samples, the initial attack model is trained to obtain a preset attack model for the network attack side.

[0050] This embodiment determines the attack value level and attack difficulty level of the network attack side based on historical network attack and defense information. Then, it determines the attack intention based on the attack value level and attack difficulty level, and determines the initial attack path based on the attack intention. Finally, it trains the initial attack model based on the historical network attack and defense information and the initial attack path to obtain a preset attack model for the network attack side. This embodiment, by deriving the attack value level and attack difficulty level of the network attack side, determining the attack intention based on the attack value level and attack difficulty level, and determining the initial attack path based on the attack intention, can accurately and effectively train the initial attack model to obtain a preset attack model for the network attack side.

[0051] refer to Figure 3 , Figure 3 This is a flowchart illustrating the third embodiment of the network security protection method of this application.

[0052] Based on the above embodiments, in this embodiment, before step S01, the method further includes: Step S04: Determine the defense value level and defense difficulty level for the network defense side based on historical network attack and defense information.

[0053] Further, in this embodiment, step S04 includes: constructing a directed weighted graph based on network defense topology and service flow data in historical network attack and defense information; calculating the total indirect loss of each node according to the direct value of each node in the directed weighted graph and variant algorithms, and determining the defense value level for the network defense side according to the total indirect loss; determining the defense difficulty benchmark value for the network defense side according to the technical compatibility risk, resource investment time, and service interruption risk in the historical network attack and defense information; and adjusting the defense difficulty benchmark value based on the difficulty reduction coefficient to obtain the adjusted defense difficulty level.

[0054] Understandably, when calculating the defense value level for the network defense side, an asset dependency graph is constructed based on business flow data. An improved PageRank algorithm or fault tree analysis method is used to simulate the total indirect losses to upstream critical business nodes when a node fails. This yields a cascading rating that includes not only the asset's intrinsic value but also its criticality in business continuity. First, a business dependency graph is constructed: based on the input network topology and business flow data, a directed weighted graph G = (N, E) is constructed, where nodes represent assets and edges represent dependencies. Then, a cascading impact propagation algorithm is used: defining the direct value of each node, a variant of the PageRank algorithm is used to calculate the total indirect losses to upstream critical business nodes when a node fails. Finally, the normalized output is mapped to the [0,1] interval to obtain the defense value level V2.

[0055] It should be understood that at the defense difficulty level L d In the assessment, the abstract difficulty of defense is broken down into three quantifiable hard cost indicators, all normalized to the [0,1] range for calculation. First is the technical compatibility risk C1, which automatically searches patch vendor announcements and asset configuration libraries. If a patch is detected to have known conflicts with existing business software or requires a core service restart, this item is scored high (e.g., 0.9), representing extremely high implementation risk; if only a hot update is needed and there are no dependency conflicts, it is scored low (e.g., 0.2). Second is resource investment man-hours C2, where the system estimates the man-hours required for repair based on standard operating procedures (SOPs). If the estimated time exceeds a set threshold (e.g., 40 man-hours), this item is directly scored full 1.0, indicating excessively high man-hours; if only a small amount of man-hours is required, it is calculated proportionally. Finally, there is the business interruption risk C3, which the system considers in conjunction with the Business Continuity Plan (BCP). If the defense operation must be performed during peak business hours or will cause temporary service unavailability, this item is scored 1.0; conversely, if seamless switching is possible during maintenance windows, it is scored low. The system multiplies these three indicators by preset weights and sums them to obtain a baseline value for defense difficulty. Based on this, an automation efficiency discount mechanism is introduced: if a fully automated remediation playbook is detected in the current scenario, the baseline defense difficulty value is multiplied by a very small discount factor (e.g., 0.2), meaning that machine replacement of manual labor significantly reduces the difficulty; if only semi-automated assistance is available, a medium factor (e.g., 0.6) is applied; if there is no automation support, the factor is 1.0, keeping the original cost unchanged. The final defense difficulty level is determined by formula L. d = (∑wi×C i The result is calculated by multiplying γ by w, where w is the result of multiplying γ by w. i As a preset weight, γ represents the difficulty reduction coefficient brought about by automation technology.

[0056] In its implementation, to ensure the feasibility of the solution, the system strictly follows the process of data instantiation, parameter mapping, model calculation, and result output. The system first retrieves multi-source data in real time, including vulnerability details, training timestamps, document scanning reports, historical attack logs, patch compatibility tags, and automated script status of the target asset. Next, this heterogeneous data is rigorously converted into standardized numerical parameters according to defined mapping rules. Then, it is substituted into the aforementioned linear weighting and nonlinear mapping logic to calculate the specific numerical values ​​for the difficulty levels of attacks and defenses. Finally, the calculation results are encapsulated into a structured object containing difficulty scores, level determinations, and major contribution factors, which can be directly called by downstream modules. Through this rigorous calculation process, this solution successfully transforms the abstract concept of "difficulty" into a data-driven, logically rigorous, and reproducible engineering calculation process.

[0057] Step S05: Determine the defense intention based on the defense value level and the defense difficulty level, and determine the initial defense strategy based on the defense intention.

[0058] Further, in this embodiment, step S05 includes: calculating the defense strength based on the defense value level, the defense difficulty level, and the attack strength; comparing the defense strength with a preset defense threshold and determining the defense intention based on the defense comparison result; determining a pre-emptive defense strategy based on the defense intention; performing security detection on common key nodes of the initial attack path against the network attack side, and adjusting the pre-emptive defense strategy based on the detection result to obtain an adjusted initial defense strategy.

[0059] Understandably, when deriving defense intent, a defense utility function is constructed to maximize business continuity and minimize investment costs. The calculation formula comprehensively considers the cascading value of assets, the cost-effectiveness of defense implementation, and external threat linkage. The threat linkage is an innovative design; when an increase in external attack intent against a particular asset is detected, the defense priority weight of that asset is automatically increased, thereby achieving dynamic linkage between attack and defense intents. Finally, the system calculates defense intent for all assets, generating a list of defense priorities in descending order. To maximize business continuity and minimize investment costs, a defense utility function is constructed: Defense Strength I² = (V²) × (1 - L) d The calculation is: t*I1)×(1+t*I1), where t*I1 is a threat linkage term, meaning that when an external attack strength I1 is detected to increase, the defense priority weight of that target is automatically increased. The defense strength is then compared with a preset defense threshold, and the defense intention is determined based on the comparison result.

[0060] It should be understood that, for the defender, when generating the list of defensive action intentions, the best practices are matched from the defense knowledge base based on the assets ranked highest according to their defense strength (I2) and their vulnerability types. For high-value and easily hardened assets, instructions to immediately deploy virtual patches or enable enhanced auditing are generated; for high-value but difficult-to-harden assets, instructions to deploy honeypot traps or restrict access to a whitelist are generated. The final output is a structured response ticket containing the target asset, action type, priority, and estimated cost. Examples are as follows: For high-value + low-defense-difficulty assets → generate pre-emptive defense strategies: "Immediately deploy virtual patches," "Enable enhanced log auditing"; For high-value + high-defense-difficulty assets → generate pre-emptive defense strategies: "Restrict access to a whitelist," "Develop an emergency response plan." Finally, a structured response ticket format is generated.

[0061] In the specific implementation, when generating a phased defense strategy, multiple initial attack paths are analyzed to identify common critical nodes across all paths. Based on this, specific strategies are formulated for three phases: pre-attack prevention, in-attack detection, and post-attack response. Pre-attack prevention phase: For vulnerabilities or configuration flaws corresponding to bottleneck edges, hardening instructions are issued, i.e., the aforementioned pre-attack defense strategy. In-attack detection phase: High-precision probes are deployed at critical jump node nodes, and detection rules are set for specific TTPs. Post-attack response phase: Isolation scripts and recovery procedures are pre-set; once any link in the path triggers an alarm, automatic blocking is executed. The results obtained in the post-attack response phase can be used as the adjusted initial defense strategy.

[0062] Step S06: Train the initial defense model based on the historical network attack and defense information and the initial defense strategy to obtain a preset defense model for the network defense side.

[0063] Understandably, the initial defense model can be an initial model for the network defense side, such as IPDRR, P2DR, etc. It takes historical network attack and defense information as input and the initial defense strategy as output to build training samples, and then trains the initial attack model based on the training samples to obtain a preset defense model for the network defense side.

[0064] In the specific implementation, refer to Figure 4 , Figure 4 This is a schematic diagram of the overall framework of an embodiment of the network security protection method of this application, as shown below. Figure 4As shown, the upper part is the attacker's intention model for launching a (multi-step) attack, i.e., the preset attack model, and the lower part is the defender's intention model for proactive defense, i.e., the preset defense model. For the attacker, the external variables can be considered as the aforementioned historical network attack and defense information, including system training time, system user manuals, and the system's own design features. Based on the external variables, the target system value level and the attack implementation difficulty level are calculated, i.e., the attack value level and the attack difficulty level. The target system value level can reflect the degree to which the attacker (organization) believes that attacking a certain asset or system will increase their expected benefits. The attack implementation difficulty level can reflect the difficulty that the attacker (organization) believes is to launch a single-step (multi-step) attack. Then, the attack intention is determined based on the target system value level and the attack implementation difficulty level, and the behavioral intent is determined based on the attack intention, thereby formulating the attack plan, including multi-step attack path planning. Similarly, for the defender, the cascading rating of the attacked system and the difficulty level of defense implementation are calculated based on external variables, namely the defense value level and the defense difficulty level. The cascading rating of the attacked system can reflect the importance or value of a certain asset or system in the cascading operation as perceived by the defender (team), and the difficulty level of defense implementation can reflect the difficulty of the defender (team) in preventing single-step (multi-step) attacks from attacking them. Then, the defense intention is determined based on the cascading rating of the attacked system and the difficulty level of defense implementation, and the behavioral intention is determined based on the defense intention, thereby formulating a defense plan, including multi-step attack path planning and planning for multi-step attack paths.

[0065] In this embodiment, the entire system can also be considered to include an input module, a value assessment module, a difficulty assessment module, an intention inference module, a behavior intention generation module, and a path planning module. The input module, as the system's perception layer, uniformly collects observable external variables of the target environment, covering not only traditional technical indicators but also, more importantly, non-technical indicators reflecting human cognitive states. During implementation, the system first accesses multi-source data in real time through application programming interfaces (APIs), log auditing systems, configuration management databases, and manual input interfaces. Feature extraction and classification are then performed. The value assessment module constructs a "profit model" from the attacker's perspective and a "cascade model" from the defender's perspective, addressing why attackers choose specific targets and where defenders should prioritize protection. This module aims to build a comprehensive evaluation mechanism that integrates objective technical indicators and subjective environmental factors, accurately quantifying the actual difficulty of attack implementation and defense deployment through standardized data mapping and weighted calculation logic. The difficulty assessment module abandons the traditional model of relying solely on static vulnerability scoring, adopting a three-level processing flow of "baseline score calculation, dynamic factor correction, and nonlinear normalization" to transform abstract operational thresholds into calculable numerical levels, providing precise quantitative basis for subsequent attack and defense intent deduction. The intent deduction module utilizes an improved expected utility theory to transform value and difficulty into specific behavioral intent strengths. The behavioral intent generation module translates abstract intent strengths into specific, executable structured instructions (i.e., behavioral intents) based on attack and defense intents. The path planning module, based on the generated behavioral intents, uses graph algorithms to deduce complete multi-step paths and formulate defense strategies. Specifically, the attack side generates a complete attack chain (including jump node nodes and TTP mappings), for example: "phishing email → privilege escalation → lateral movement → data leakage." The defense side formulates a phased response plan (such as isolation, source tracing, and recovery), and supports dynamic adjustments. This achieves the following technical effects: 1. Addressing the problem that traditional threat detection and response systems rely solely on behavior logs or rule matching and lack modeling of attacker / defender decision-making motivations, a dual-perspective quantitative framework of "attack and defense cognition" is constructed for the first time. Through observable external system features, the attacker's "target value score" and "implementation difficulty score," as well as the defender's "asset cascade value" and "protection cost score," are automatically derived, achieving objective and computable modeling of the cognitive state of the attack and defense subjects, and providing a motivational explanation mechanism for intent prediction; 2. Innovatively using "attack and defense cognition" variables as driving factors, an end-to-end intent prediction engine is constructed, outputting structured attack behavior tendency intensity and defense response priority.Unlike existing systems that only output alarms or risk scores, this invention can generate high-probability multi-step attack paths and corresponding defensive action sequences, and supports dynamic updates to cognitive scores (such as adjusting difficulty weights based on historical attack and defense success and failure feedback), realizing a shift from "passive response" to "active defense." Furthermore, it proposes a joint decision-making mechanism that integrates cognitive priors and behavioral context, weighting and fusing subjective perceived variables (value, difficulty) with objective environmental states (network topology, asset attributes, vulnerability intelligence) to generate interpretable and schedulable intent outputs. This enables security operations personnel not only to know "where might be attacked," but also to understand "why might be attacked" and "what should be prioritized for defense," significantly improving the rationality of defense resource allocation and response efficiency.

[0066] Additionally, examples can be provided for both the attacker and defender. From the attacker's perspective, the background is as follows: A nation-state APT group plans to launch a multi-stage attack on a power company's SCADA (Supervisory and Data Acquisition) system, aiming to cause a regional power outage. The system recently underwent an upgrade, deploying a new user interface and releasing a detailed operation manual.

[0067] Application process in this embodiment: (1) Input module obtains external variables: System training time: 0 (no employee training organized); User manual content: Publicly released, including system architecture diagram and API interface description; System design features: Uses outdated industrial control protocols (such as xxx TCP), without two-way authentication.

[0068] (2) Value assessment module analysis: Because the system controls critical infrastructure and the manual reveals the internal structure, the target system's value level is assessed as "high" (e.g., a quantified value of 0.92).

[0069] (3) Difficulty assessment module analysis: Outdated protocols and lack of training resulted in weak security awareness among operators, and the difficulty level of attack implementation was assessed as "low" (i.e. easy to attack, with a quantitative value of 0.85).

[0070] (4) Calculation of the intention derivation module: High value + low difficulty → Attack intention intensity = 0.92 × 0.85 ≈ 0.78 (high) (the rating can be set internally by the organization or unit).

[0071] (5) Output of the behavior intent generation module: Attackers are highly likely to launch an attack, prioritizing the path of "phishing email → lateral movement → PLC instruction injection".

[0072] (6) Path planning module generation: Output three high-probability attack paths and mark the key jump host. From a defensive perspective, the background is as follows: A bank's data center faces a potential threat from a ransomware group. The security team needs to decide, within a limited budget, whether to prioritize hardening the database servers or the file-sharing servers.

[0073] Application process in this embodiment: (1) Input module obtains external variables: Database server: It carries core transaction data and has a cascading impact on the entire industry's business; File server: Stores non-sensitive documents, but is configured with a weak password policy.

[0074] (2) Valuation module: Calculate the cascading rating of the attacked system: Database = 0.95, File Server = 0.4.

[0075] (3) Difficulty assessment module: The database has been deployed with WAF and audit logs, and the defense implementation difficulty level is 0.3 (difficult to harden). The file server has no access control, and the difficulty level of defense implementation is 0.8 (easy to harden).

[0076] (4) The intention derivation module calculates the defense priority: Defense willingness = Cascade rating × (1 Defense difficulty); Database: 0.95 × (1 0.3) = 0.665; File server: 0.4×(1 0.8) = 0.08.

[0077] (5) Output of the behavior intent generation module: Although file servers are "easier" to harden, the system recommends prioritizing resources for database protection due to their low business value.

[0078] (6) Path planning module generation: Recommended strategy: Enable multi-factor authentication and real-time SQL injection detection for the database; only update the basic password policy for the file server.

[0079] With limited resources, avoid "spreading your efforts evenly" and allocate 80% of your defense budget to high-value and medium-difficulty targets to successfully defend against subsequent real ransomware attacks (attacks who fail to exploit the file server and then give up).

[0080] This embodiment determines the defense value level and defense difficulty level of the network defense side based on historical network attack and defense information. Then, it determines the defense intention based on the defense value level and defense difficulty level, and determines the initial defense strategy based on the defense intention. Finally, it trains the initial defense model based on the historical network attack and defense information and the initial defense strategy to obtain a preset defense model for the network defense side. This embodiment, by deriving the defense value level and defense difficulty level of the network defense side, determining the defense intention based on the defense value level and defense difficulty level, and determining the initial defense strategy based on the defense intention, can accurately and effectively train the initial defense model to obtain a preset defense model for the network defense side.

[0081] Reference Figure 5 , Figure 5 This is a structural block diagram of the first embodiment of the network security protection device of this application.

[0082] like Figure 5 As shown, the network security protection device proposed in this application includes: The model building module 10 is used to input the current network attack and defense information into the preset attack and defense cognitive model, which includes a preset attack model for the network attack side and a preset defense model for the network defense side. The strategy generation module 20 is used to simulate the cognitive decision-making process of attackers and defenders in network security games through the preset attack model and the preset defense model, so as to obtain the current attack path and the current defense strategy. The network security protection module 30 is used to adjust the current defense strategy based on the current attack path and to perform network security protection based on the obtained target defense strategy.

[0083] This embodiment inputs current network attack and defense information into a preset attack and defense cognitive model. This model includes a preset attack model for the attacking side and a preset defense model for the defending side. Then, it simulates the cognitive decision-making process of attackers and defenders in a network security game, obtaining the current attack path and current defense strategy. Based on the current attack path, the current defense strategy is adjusted, and network security protection is implemented based on the obtained target defense strategy. This embodiment inputs current network attack and defense information into the preset attack model for the attacking side and the preset defense model for the defending side, and simulates the cognitive decision-making process of attackers and defenders in a network security game. By introducing the preset attack and defense cognitive model, it achieves quantitative prediction of the intentions of both parties and strategy generation. Then, it adjusts the current defense strategy based on the current attack path, thereby enabling dynamic adjustment of the defense strategy and achieving more intelligent and efficient network security protection.

[0084] It should be noted that the workflow described above is merely illustrative and does not limit the scope of protection of this application. In practical applications, those skilled in the art can select some or all of it to achieve the purpose of this embodiment according to actual needs, and no restrictions are imposed here.

[0085] In addition, for technical details not described in detail in this embodiment, please refer to the network security protection methods provided in any embodiment of this application, which will not be repeated here.

[0086] Based on the first embodiment of the network security protection device described in this application, a second embodiment of the network security protection device of this application is proposed.

[0087] In this embodiment, the model building module 10 is further configured to determine the attack value level and attack difficulty level of the network attack side based on historical network attack and defense information; determine the attack intention based on the attack value level and the attack difficulty level, and determine the initial attack path based on the attack intention; and train the initial attack model based on the historical network attack and defense information and the initial attack path to obtain a preset attack model for the network attack side.

[0088] Furthermore, the model building module 10 is also used to determine value evaluation indicators based on the data sensitivity, business influence, and intelligence acquisition value corresponding to the network attack side; determine the membership degree of the value evaluation indicators to each evaluation level based on the historical network attack and defense information; determine the attack value level of the network attack side based on the weight corresponding to the value evaluation indicators, the membership degree, and the evaluation value corresponding to each evaluation level; determine the attack difficulty benchmark value of the network attack side based on the attack complexity and attack privileges of the network attack side; and adjust the attack difficulty benchmark value based on the training factor, sensitive document information, and historical threat intelligence in the historical network attack and defense information to obtain the adjusted attack difficulty level.

[0089] Furthermore, the model building module 10 is also used to calculate the attack strength based on the attack value level, the value sensitivity coefficient, and the attack difficulty level; compare the attack strength with a preset attack threshold, and determine the attack intention based on the attack comparison result; determine the attack behavior intent based on the attack intention and the constituent factors corresponding to the attack difficulty level; adjust the initial network topology corresponding to the network attack side based on the attack behavior intent, and determine the initial attack path based on the adjusted target network topology.

[0090] Furthermore, the model building module 10 is also used to determine the defense value level and defense difficulty level for the network defense side based on historical network attack and defense information; determine the defense intention based on the defense value level and the defense difficulty level, and determine the initial defense strategy based on the defense intention; train the initial defense model based on the historical network attack and defense information and the initial defense strategy to obtain a preset defense model for the network defense side.

[0091] Furthermore, the model building module 10 is also used to construct a directed weighted graph based on network defense topology and service flow data in historical network attack and defense information; calculate the total indirect loss of each node according to the direct value of each node in the directed weighted graph and variant algorithms, and determine the defense value level for the network defense side according to the total indirect loss; determine the defense difficulty benchmark value for the network defense side according to the technical compatibility risk, resource investment time and service interruption risk in the historical network attack and defense information; and adjust the defense difficulty benchmark value based on the difficulty reduction coefficient to obtain the adjusted defense difficulty level.

[0092] Furthermore, the model building module 10 is also used to calculate the defense strength based on the defense value level, the defense difficulty level, and the attack strength; compare the defense strength with a preset defense threshold, and determine the defense intention based on the defense comparison result; determine the pre-defense strategy based on the defense intention; perform security detection on the common key nodes of the initial attack path against the network attack side, and adjust the pre-defense strategy based on the detection result to obtain the adjusted initial defense strategy.

[0093] Other embodiments or specific implementations of the network security protection device of this application can be found in the above-described method embodiments, and will not be repeated here.

[0094] This application provides a network security protection device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the network security protection method in the above embodiment 1.

[0095] The following is for reference. Figure 6This document illustrates a structural diagram of a network security protection device suitable for implementing embodiments of this application. The network security protection device in these embodiments may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), and in-vehicle terminals (e.g., in-vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers. Figure 6 The network security protection device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0096] like Figure 6 As shown, the network security protection device may include a processing device 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM) 1004. The RAM 1004 also stores various programs and data required for the operation of the network security protection device. The processing device 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touch screen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 1003 including, for example, magnetic tape, hard disk, etc.; and communication devices 1009. Communication device 1009 allows network security protection devices to communicate wirelessly or wiredly with other devices to exchange data. While network security protection devices with various systems are shown in the figures, it should be understood that implementation or possession of all the systems shown is not required. More or fewer systems may be implemented alternatively.

[0097] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.

[0098] The network security protection device provided in this application, employing the network security protection method described in the above embodiments, can solve the technical problem of how to dynamically adjust defense strategies to achieve more intelligent and efficient network security protection. Compared with the prior art, the beneficial effects of the network security protection device provided in this application are the same as those of the network security protection method provided in the above embodiments, and other technical features of this network security protection device are the same as those disclosed in the previous embodiment method, and will not be repeated here.

[0099] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.

[0100] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0101] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, which are used to execute the network security protection method in the above embodiments.

[0102] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.

[0103] The aforementioned computer-readable storage medium may be included in a network security protection device; or it may exist independently and not be assembled into a network security protection device.

[0104] The aforementioned computer-readable storage medium carries one or more programs. When these programs are executed by a network security protection device, the network security protection device causes the following actions: inputs current network attack and defense information into a preset attack and defense cognitive model, which includes a preset attack model for the network attack side and a preset defense model for the network defense side; simulates the cognitive decision-making process of the attacker and defender in a network security game using the preset attack model and the preset defense model to obtain the current attack path and the current defense strategy; adjusts the current defense strategy based on the current attack path; and performs network security protection based on the obtained target defense strategy.

[0105] Computer program code for performing the operations of this application can be written in one or more programming languages ​​or a combination thereof. These programming languages ​​include object-oriented programming languages—such as Python, Java, Smalltalk, and C++—and conventional procedural programming languages—such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0106] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0107] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.

[0108] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., computer programs) for executing the above-described network security protection method. This solves the technical problem of how to dynamically adjust defense strategies to achieve more intelligent and efficient network security protection. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the network security protection method provided in the above embodiments, and will not be repeated here.

[0109] The above description is only a part of the embodiments of this application and does not limit the scope of protection of this application. All equivalent structural transformations made under the technical concept of this application and using the content of this application specification and drawings, or direct / indirect applications in other related technical fields, are included in the scope of protection of this application.

Claims

1. A network security protection method, characterized in that, The method includes the following steps: The current network attack and defense information is input into the preset attack and defense cognitive model, which includes a preset attack model for the network attack side and a preset defense model for the network defense side. The preset attack model and the preset defense model are used to simulate the cognitive decision-making process of attackers and defenders in network security games, so as to obtain the current attack path and the current defense strategy. The current defense strategy is adjusted based on the current attack path, and network security protection is carried out based on the obtained target defense strategy.

2. The network security protection method as described in claim 1, characterized in that, Before inputting the current network attack and defense information into the preset attack and defense cognitive model, the method further includes: Determine the attack value level and attack difficulty level of the network attack side based on historical network attack and defense information; The attack intention is determined based on the attack value level and the attack difficulty level, and the initial attack path is determined based on the attack intention. The initial attack model is trained based on the historical network attack and defense information and the initial attack path to obtain a preset attack model for the network attack side.

3. The network security protection method as described in claim 2, characterized in that, The process of determining the attack value level and attack difficulty level against the network attack side based on historical network attack and defense information includes: Value evaluation indicators are determined based on the data sensitivity, business impact, and intelligence acquisition value corresponding to the network attack side. The membership degree of the value evaluation index to each evaluation level is determined based on the historical network attack and defense information. The attack value level for the network attack side is determined based on the weights corresponding to the value evaluation indicators, the membership degree, and the evaluation values ​​corresponding to each evaluation level. A baseline value for the difficulty of attacking the network attacking side is determined based on the attack complexity and attack privileges of the network attacking side. The attack difficulty baseline is adjusted based on the training factor, sensitive document information, and historical threat intelligence in the historical network attack and defense information to obtain the adjusted attack difficulty level.

4. The network security protection method as described in claim 2, characterized in that, The step of determining the attack intention based on the attack value level and the attack difficulty level, and determining the initial attack path based on the attack intention, includes: The attack intensity is calculated based on the attack value level, the value sensitivity coefficient, and the attack difficulty level. The attack intensity is compared with a preset attack threshold, and the attack intention is determined based on the attack comparison result; The intent of the attack behavior is determined based on the attack intent and the constituent factors corresponding to the attack difficulty level. The initial network topology corresponding to the network attack side is adjusted according to the attack intent, and the initial attack path is determined according to the adjusted target network topology.

5. The network security protection method as described in any one of claims 1 to 4, characterized in that, Before inputting the current network attack and defense information into the preset attack and defense cognitive model, the method further includes: Determine the defense value level and defense difficulty level for the network defense side based on historical network attack and defense information; The defense intention is determined based on the defense value level and the defense difficulty level, and the initial defense strategy is determined based on the defense intention. The initial defense model is trained based on the historical network attack and defense information and the initial defense strategy to obtain a preset defense model for the network defense side.

6. The network security protection method as described in claim 5, characterized in that, The process of determining the defense value level and defense difficulty level for the network defense side based on historical network attack and defense information includes: Construct a directed weighted graph based on network defense topology and service flow data from historical network attack and defense information; The total indirect loss of each node is calculated based on the direct value of each node in the directed weighted graph and a variant algorithm, and the defense value level for the network defense side is determined based on the total indirect loss. The baseline value for defense difficulty for the network defense side is determined based on the technical compatibility risks, resource investment time, and service interruption risks in the historical network attack and defense information. The defense difficulty baseline value is adjusted based on the difficulty reduction coefficient to obtain the adjusted defense difficulty level.

7. The network security protection method as described in claim 5, characterized in that, The process of determining defense intention based on the defense value level and the defense difficulty level, and determining an initial defense strategy based on the defense intention, includes: The defense strength is calculated based on the defense value level, the defense difficulty level, and the attack strength. The defense strength is compared with a preset defense threshold, and the defense intention is determined based on the defense comparison result; Determine the pre-defense strategy based on the stated defense intentions; Security checks are performed on the common critical nodes of the initial attack path targeting the network attack side, and the pre-emptive defense strategy is adjusted based on the detection results to obtain the adjusted initial defense strategy.

8. A network security protection device, characterized in that, The network security protection device includes: The model building module is used to input current network attack and defense information into a preset attack and defense cognitive model, which includes a preset attack model for the network attack side and a preset defense model for the network defense side. The strategy generation module is used to simulate the cognitive decision-making process of attackers and defenders in network security games through the preset attack model and the preset defense model, so as to obtain the current attack path and the current defense strategy. The network security protection module is used to adjust the current defense strategy based on the current attack path and to perform network security protection based on the obtained target defense strategy.

9. A network security protection device, characterized in that, The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the network security protection method as described in any one of claims 1 to 7.

10. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the network security protection method as described in any one of claims 1 to 7.