Method and device for dynamic security defense of wireless network based on risk evolution reasoning

CN122054149BActive Publication Date: 2026-08-11XIDIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-02-04
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

这类方法在已知攻击模式下能够提供较好防护,但在复杂动态环境中存在明显局限:集群中多智能体的协作与信息交互增加了安全事件的多维度性,攻击往往呈现多阶段、分布式和隐蔽化特征,传统集中控制与静态策略难以及时感知风险演化并生成响应防御决策

Benefits of technology

[0008]本发明提供的一种基于风险演化推理的无线网络动态安全防御方法及装置,通过基于风险演化推理的安全威胁识别与预测,能够实时分析和预测攻击演化趋势,提前识别多阶段、分布式及隐蔽型攻击,增强了目标集群系统的主动防御能力;并且,通过及时预测攻击趋势并触发相应的风险防御策略,从而为基于无线网络通信的目标集群系统提供更具前瞻性和全局性的安全防护。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122054149B_ABST
    Figure CN122054149B_ABST
Patent Text Reader

Abstract

This invention discloses a dynamic security defense method and apparatus for wireless networks based on risk evolution reasoning. It acquires log data and network communication data from each node in a target cluster system based on wireless network communication; constructs time-series graph structures based on the log data and network communication data of each node to obtain a log risk evolution graph and a communication risk evolution graph; merges the log risk evolution graph and the communication risk evolution graph to obtain a risk evolution fusion graph; predicts the risk of each node based on the risk evolution fusion graph to obtain the predicted risk value of each node; and determines the target risk defense strategy for each node at different times based on pre-set dynamic risk defense rules and the predicted risk values ​​of each node. This invention, based on risk evolution reasoning for threat identification and prediction, can analyze and predict attack evolution trends in real time and trigger corresponding risk defense strategies in a timely manner, thereby providing the system with more forward-looking and comprehensive security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of wireless communication network security technology, specifically relating to a method and apparatus for dynamic security defense of wireless networks based on risk evolution reasoning. Background Technology

[0002] A wireless network is a communication network that uses wireless channels such as radio and infrared as transmission media to enable data exchange and service collaboration among multiple terminal nodes without the need for fixed wired connections. A wireless network system consists of a large number of heterogeneous communication nodes, terminal devices, or intelligent agents. These nodes interact with each other and make collaborative decisions to execute tasks together via wireless links. Because wireless communication relies on open spectrum, link establishment is affected by node mobility and environmental changes, and signals are easily captured and interfered with in space. Therefore, wireless networks inherently possess characteristics such as high openness, rapid dynamic changes in topology, and limited link stability, making them more vulnerable to security threats such as eavesdropping, interference, and deception. In scenarios such as unmanned combat and industrial control systems, wireless networks are the fundamental environment for supporting the collaborative operation of multiple devices. Intelligent cluster systems are a typical application scenario built upon wireless networks, where nodes form a collaborative system through wireless communication. In this scenario, the dynamic and uncertain nature of wireless communication further amplifies the security risks faced by the system, making attacks more likely to spread across nodes and exhibit characteristics of concealment, multi-stage, and distributed attacks.

[0003] Intelligent swarm systems consist of multiple intelligent agents that collaborate to execute tasks through information exchange and joint decision-making, achieving objectives such as resource coordination and security assurance in complex environments. In applications such as unmanned combat and industrial control systems, intelligent swarms typically exhibit characteristics such as distributed deployment, high autonomy and proximity interaction, and collaborative dependence. These characteristics make the security threats they face during task execution multi-stage, distributed, and covert. When intelligent swarms operate via wireless networks, the openness and dynamism of wireless links allow attacks to propagate rapidly between multiple nodes. Traditional single-point defenses are insufficient to effectively block threat propagation, and attacks may cross multiple intelligent agents or task stages, thus increasing the difficulty of protection.

[0004] Current security defenses in intelligent swarm systems primarily rely on centralized strategies, rule-driven approaches, or static decision-making mechanisms. These methods use predefined rules and centralized control to block risky behaviors and remediate tasks. While these methods provide good protection under known attack patterns, they have significant limitations in complex and dynamic environments. The collaboration and information exchange among multiple agents in a swarm increase the multidimensionality of security events, and attacks often exhibit multi-stage, distributed, and covert characteristics. Traditional centralized control and static strategies struggle to detect risk evolution and generate timely defensive decisions. The root cause of these problems lies in the lack of understanding and reasoning ability regarding the laws governing risk evolution in existing methods. Defense strategies cannot be rapidly adjusted according to the attack posture, thus hindering continuous and effective security defense. Summary of the Invention

[0005] To address the aforementioned problems in the existing technology, this invention provides a method and apparatus for dynamic security defense of wireless networks based on risk evolution reasoning.

[0006] The technical problem to be solved by this invention is achieved through the following technical solution: In a first aspect, the present invention provides a dynamic security defense method for wireless networks based on risk evolution reasoning, comprising: Acquire log data and network communication data of each node in the target cluster system based on wireless network communication; Based on the log data and network communication data of each node, a time-series graph structure is constructed to obtain the log risk evolution graph and the communication risk evolution graph. By fusing the log risk evolution diagram and the communication risk evolution diagram, a risk evolution fusion diagram is obtained; Risk prediction is performed on each node based on the risk evolution fusion diagram to obtain the predicted risk value of each node; Based on the pre-set dynamic risk defense rules and the predicted risk values ​​of each node, the target risk defense strategy for each node at different times is determined.

[0007] Secondly, the present invention provides a dynamic security defense device for wireless networks based on risk evolution reasoning, comprising: The data acquisition module is used to acquire log data and network communication data of each node in the target cluster system based on wireless network communication; The evolution graph construction module is used to construct time-series graph structures based on the log data and network communication data of each node, respectively, to obtain the log risk evolution graph and the communication risk evolution graph; The graph fusion module is used to fuse the log risk evolution graph and the communication risk evolution graph to obtain a risk evolution fusion graph; The risk prediction module is used to predict the risk of each node based on the risk evolution fusion diagram and obtain the predicted risk value of each node. The risk defense module is used to determine the target risk defense strategy for each node at different times based on the pre-set dynamic risk defense rules and the predicted risk value of each node.

[0008] This invention provides a dynamic security defense method and device for wireless networks based on risk evolution reasoning. By identifying and predicting security threats based on risk evolution reasoning, it can analyze and predict attack evolution trends in real time, identify multi-stage, distributed, and covert attacks in advance, and enhance the proactive defense capabilities of the target cluster system. Furthermore, by predicting attack trends in a timely manner and triggering corresponding risk defense strategies, it provides more forward-looking and global security protection for target cluster systems based on wireless network communication.

[0009] The present invention will now be described in further detail with reference to the accompanying drawings. Attached Figure Description

[0010] Figure 1 This is a flowchart illustrating a dynamic security defense method for wireless networks based on risk evolution reasoning, provided in an embodiment of the present invention. Figure 2 This is a schematic diagram illustrating an application scenario of the wireless network dynamic security defense method based on risk evolution reasoning, according to an embodiment of the present invention. Figure 3 This is a schematic diagram illustrating the construction process of the risk evolution fusion diagram in an embodiment of the present invention; Figure 4 This is a schematic diagram of the working mechanism of the preset knowledge graph embedding model TransR in an embodiment of the present invention; Figure 5 This is a structural block diagram of a wireless network dynamic security defense device based on risk evolution reasoning provided in an embodiment of the present invention. Detailed Implementation

[0011] The present invention will be further described in detail below with reference to specific embodiments, but the implementation of the present invention is not limited thereto.

[0012] Firstly, embodiments of the present invention provide a dynamic security defense method for wireless networks based on risk evolution reasoning. See also... Figure 1 The method includes the following steps: S10. Obtain log data and network communication data of each node in the target cluster system based on wireless network communication.

[0013] For example, refer to Figure 2The target cluster system based on wireless network communication consists of multiple nodes and multi-task collaboration. When a threat occurs, the nodes of the target cluster system can be divided into normal nodes, infected nodes, and attack source nodes. The risk spreads from the attack source node, forming infected nodes within its risk propagation range. The risk propagation direction is multi-stage and covert. A lightweight data acquisition agent is deployed on each node of the target cluster system at a fixed sampling frequency. Continuously monitor the node's operational status (i.e., log data) and communication behavior (i.e., network communication data) to obtain the log data and network communication data of each node. To ensure global time consistency, all nodes use a unified time base for synchronization sampling, defining the first... The time point for the second sampling was ,in This is the sampling sequence number.

[0014] During the log data collection process, the system collects operating system logs, security audit logs, and control program logs in real time, and each log event is defined as a five-tuple. ,in Indicates the time when the event occurred. For event types (such as login, process creation, file modification, etc.). This serves as the identifier for the event subject (corresponding to the user, process, or host that triggered the event). For the affected objects (such as files, devices, or target hosts). The event outcome status (such as success, failure, or exception). This represents the index number of a log event, used to identify the first log event recorded in chronological order within the same sampling time window. Log event.

[0015] During the collection of network communication data, the communication traffic is passively monitored, and the five-tuple of each communication connection is recorded. ,in Indicates the source address or source node. Indicates the target address or target node. Indicates the communication protocol used (such as TCP, UDP, etc.). Indicates the target port number. Indicates the number of bytes transmitted.

[0016] S20. Based on the log data and network communication data of each node, construct time-series graph structures to obtain the log risk evolution graph and the communication risk evolution graph.

[0017] Optionally, step S20 may specifically include: S201. Extract features from the log data and network communication data of each node to obtain log feature vectors and communication feature vectors.

[0018] For example, log data can be preprocessed by matching preset rule templates with key fields, including time sorting, duplicate event deduplication, noise filtering, and field standardization. Then, within the sampling time window... Within this time period, the set of log 5-tuples. Perform statistical mapping and define log feature extraction functions. Log events are aggregated into multidimensional statistical features to form a log feature vector. :

[0019] Each component This represents the statistical result of a log feature within a sampling time window (e.g., Indicates the frequency of login events. Indicates the proportion of abnormal events. (This indicates the number of operations on critical files, etc.). This vector is used to quantify the node's behavior patterns and security activity characteristics at that moment.

[0020] For network communication data, the sampling time window will be... The set of network communication data within is denoted as Then, feature extraction and mapping are performed on it to obtain the communication feature vector. :

[0021] in, For communication connection request rate, For average communication delay, This represents the percentage of abnormal connections. The flow direction ratio is used to characterize the node. The ratio of transmitted traffic to received traffic within the sampling time window, where Indicates the number of bytes sent. This ratio represents the number of bytes received and is used to characterize the node. In the active / passive relationship in communication, if This indicates a node. Active communication is the primary mode of communication, while passive response is the secondary mode of communication. Indicates the sampling time window Inside, with nodes The number of different nodes that engage in communication interactions is used to characterize the nodes. The breadth of communication and the scope of external connections; mapping function Network communication data is aggregated into network behavior statistical features, reflecting the nodes' behavior. Interaction activity and risk exposure level during the sampling period.

[0022] Log feature vectors and network feature vectors can be aligned based on node identifiers and timestamps to form a node-level comprehensive risk input vector. Used to uniformly describe nodes At any moment The system's operational behavior and interaction status. As the data collection process continues, the system forms a set of risk characteristics over time. :

[0023] in, This represents the total number of nodes in the target cluster system. Risk feature set. It can fully characterize the global security status of the target cluster system at different times, providing a unified, quantitative, and time-continuous input basis for subsequent risk evolution modeling and dynamic defense decision-making.

[0024] S202. Construct time-series graph structures based on the log feature vectors and communication feature vectors of each node to obtain the initial log risk evolution graph and the initial communication risk evolution graph.

[0025] For example, refer to Figure 3 In order to obtain a comprehensive risk feature set that characterizes the operating status and interaction features of each node. Subsequently, in order to further characterize the interdependence and risk propagation relationships of these nodes in the target cluster system, this embodiment maps the feature set into a temporally sequenced risk evolution graph structure to achieve explicit modeling of risk propagation paths and spatiotemporal evolution patterns.

[0026] Specifically, at the sampling time The following defines the time-series risk evolution diagram as follows:

[0027] in, This represents a set of risk nodes, corresponding to various devices, task units, or functional modules in the target cluster system. Each node... The risk state is determined by its feature vector. This indicates that it includes log feature vectors and network feature vectors; It represents a set of risk propagation relationships, used to describe communication dependencies, task coordination, or control links between nodes, and is determined based on temporal characteristics; For the set of edge weights, Used to quantify risk from nodes propagation to nodes The extent of the risk impact.

[0028] To ensure the temporal consistency of the graph structure, during the sliding time window Establish an edge set inside If two nodes have consecutive log interaction events or communication traffic within that time window, then in Establish a directed edge in the middle Border rights By normalization function The calculation yielded:

[0029] in, For the feature similarity function, cosine similarity can be used (e.g., cosine similarity). ),in The magnitude of the vector is denoted by , and its range is . When the value is close to 1, it indicates that the two nodes are highly similar in behavioral characteristics; when the value is close to 0, it indicates that the two nodes are basically unrelated; when the value is negative, it indicates that the two nodes behave in opposite directions. In this embodiment, cosine similarity is used to characterize the "degree of behavioral consistency" of different nodes in the log and network feature space. The larger the value, the more likely the two nodes are to be on the same risk propagation path. This is a time decay function used to reduce the weight of edges with long time intervals (in the "Time Series Risk Evolution Graph"), where edges... This indicates the influence relationship between nodes, and the propagation strength varies with time intervals. Increase and decrease. This is the time decay coefficient, used to adjust the time interval. The degree of impact on risk propagation weight; The larger the value, the faster the risk propagation weight decays with increasing time interval, thus reducing the impact of early actions on current risk assessment. This is used to apply weight penalties to edges with long time intervals, thus conforming to the temporal pattern of risk propagation. , Let be the weighting coefficient, satisfying ,in For spatial similarity weights, This is the time decay weight.

[0030] Risk transmission intensity It consists of two parts: spatial similarity and temporal decay. Taking into account the differences in importance of the two in different scenarios, a linear weighted fusion method is used to make the result normalized and the proportion of each part in the propagation calculation can be adjusted as needed.

[0031] Based on the above method of constructing the time-series risk evolution graph, a time-series graph structure is constructed based on the log feature vectors and communication feature vectors of each node, resulting in the initial log risk evolution graph. Evolution of initial communication risk diagram The log risk evolution diagram reflects the internal operation and access behavior of the system, while the communication risk evolution diagram describes the communication and data interaction between nodes.

[0032] S203. Based on the preset edge weight threshold, prune the edge relationships in the initial log risk evolution graph and the initial communication risk evolution graph respectively to obtain the log risk evolution graph and the communication risk evolution graph.

[0033] For example, after the initial log risk evolution graph and the initial communication risk evolution graph are constructed, a preset edge weight threshold is applied. If the edge weight is lower than the preset edge weight threshold ( Prune weakly related edges, retaining only those with high risk propagation intensity. By analyzing the edge relationships, log risk evolution graphs and communication risk evolution graphs are obtained to form a sparse and stable risk propagation topology, preventing noisy connections from interfering with the stability of the risk propagation structure. Simultaneously, to support online updates and dynamic maintenance, an incremental update mechanism is adopted. That is, when new log data or network communication data arrives, only the affected nodes and their adjacent edges are locally updated, avoiding the computational overhead of full graph reconstruction.

[0034] Ultimately, the evolution of time-series risks Forming a continuous sequence on the timeline:

[0035] in, The sampling time indicates that a risk evolution map is constructed at different time points. ( include and Each risk evolution diagram The diagrams describe the security relationship structure within the cluster at a given moment. Multiple diagrams are arranged in chronological order, forming the evolution trajectory of the risk state over time.

[0036] S30. Merge the log risk evolution diagram and the communication risk evolution diagram to obtain the risk evolution fusion diagram.

[0037] Optionally, step S30 may specifically include: S301. Match log nodes in the log risk evolution graph with network nodes in the communication risk evolution graph, and establish cross-modal edges between successfully matched log nodes and network nodes.

[0038] For example, cross-modal edges can be established based on key attribute matching. Although log data and network communication data originate from different sources, there are identifiable commonalities between nodes. For example, the host identifier, process ID, or user ID in log data can point to the same entity as the source address, port, and protocol type in network communication data. This can be verified through a matching function. The nodes in the log risk evolution graph and the communication risk evolution graph are compared, and the similarity of each node on key fields (such as IP, MAC, hostname) is calculated. If the similarity is higher than a threshold, the node is considered similar. Log nodes are considered With network nodes Representing the same object, and establishing cross-modal edges in the risk evolution fusion graph. .

[0039] S302. The log feature vector and communication feature vector corresponding to the same node in the log risk evolution diagram and the communication risk evolution diagram are fused to obtain the fused features of each node; and the fused features of each node are semantically mapped to obtain the fused semantic features of each node.

[0040] For example, a concatenation function is used to merge node attributes. Align and combine the feature vectors of the same node across different layers in terms of dimensions to obtain fused features. :

[0041] in, This is a feature concatenation function used to sequentially connect two feature vectors along their corresponding dimensions to form a complete multidimensional input description.

[0042] Subsequently, the fusion characteristics By applying a learnable nonlinear mapping function, the fused semantic features of each node are obtained. :

[0043] in, It is the fusion semantic feature of the node; mapping function Multilayer perceptrons (MLPs) or lightweight graph neural network (GNN) structures can be used to achieve nonlinear semantic extraction of fused features; parameters Deep semantic features are obtained through a sample-driven learning process to capture cross-modal risk. The fused semantic features output at this stage... As a high-dimensional risk representation of cross-modal fusion features, it is used to describe the semantic state of nodes.

[0044] Through the aforementioned entity alignment, structural fusion, and semantic mapping, operational and communication behaviors are unified at the structural level, and a comprehensive representation of multi-source risks is achieved at the semantic level. Ultimately, a fused semantic feature set can be obtained. :

[0045] The fused feature set Used for subsequent risk propagation and trend prediction.

[0046] S303. Construct a risk evolution fusion graph based on the cross-modal edges and fusion semantic features of each node.

[0047] For example, the risk evolution fusion diagram is represented as follows:

[0048] in, , , This is a set of cross-modal edges between the log layer and the network interaction layer, used to connect nodes representing the same entity or having related behaviors in different data modalities. It is crucial for achieving multi-source information fusion. Mapping function. The fusion logic is based on the node correspondence and overlap. That is, on the basis of semantic alignment of nodes, edges describing the same interaction relationship or behavioral event in the two domains are merged. If the same communication behavior exists in both log data and network communication data (such as "host A accesses host B"), then the two are merged into a unified edge to avoid duplication.

[0049] S40. Based on the risk evolution fusion diagram, perform risk prediction for each node to obtain the predicted risk value for each node.

[0050] Optionally, step S40 may specifically include: S401. At continuous time points of the target, determine the risk score sequence of each node based on the risk evolution fusion diagram and the pre-constructed risk propagation intensity function between nodes.

[0051] For example, in order to characterize the propagation relationship and scope of impact of risks in the system, this embodiment constructs a risk propagation model based on a risk evolution fusion graph structure.

[0052] If node For nodes There is an impact path Risk propagation strength function between nodes Represented as:

[0053] in, This is a normalization function used to restrict the propagated values ​​to a certain range. interval; This represents the inner product of semantic similarity between nodes. The result is... Representation Nodes Risk to nodes The greater the value of the influence, the easier it is for the risk to spread between the two.

[0054] Based on the intensity of risk propagation, calculate the risk score for each node. :

[0055] in, Represents a node The set of neighboring nodes, As edge weights, reflecting the nodes right The direct risk contribution. For the risk score of a node, if... Continuously exceeding the preset risk threshold If so, the node can be marked as a potential threat node.

[0056] Node risk score Reflects the node at time [time]. The overall risk level will serve as the input basis for subsequent time evolution predictions.

[0057] Furthermore, to characterize the changing trend of risk over time, the target is considered at continuous moments. Record node risk score sequence .

[0058] S402. Perform time-weighted prediction on the risk score sequence of each node to obtain the predicted risk value of each node.

[0059] For example, the rate of change of risk is calculated using a sliding time window. :

[0060] in, Represents a node Risk score at the current moment, Represents a node exist Risk score at any given moment.

[0061] like This indicates that the risk at the node is increasing, and its propagation trend can be assessed accordingly.

[0062] By performing time-weighted prediction on the risk score sequence, the node's position can be obtained. Predicted risk value at any time :

[0063] in, This is the historical average risk value. As a time-weighted coefficient, this mechanism achieves short-term predictions of future risk evolution by balancing real-time changes with historical trends, providing a time-a priori basis for subsequent risk path reasoning.

[0064] Optionally, the method in this embodiment further includes: S403. Based on the preset knowledge graph embedding model, risk propagation calculation is performed on the edge relationships between nodes in the risk evolution fusion graph to obtain the risk propagation score of the edge relationships between nodes.

[0065] S404. Calculate the total risk propagation score of each candidate propagation path based on the risk propagation score of the edge relationships between each node.

[0066] S405. Determine the risk source node based on the total risk propagation score of each candidate propagation path.

[0067] For example, in obtaining the fused semantic features of each node After identifying the corresponding edge relationships, reasoning methods based on knowledge graph embedding (such as TransR, TransE, RotatE, R-GCN, etc.) can be used to identify the propagation path of risk in the multi-relationship graph.

[0068] The working mechanism of the pre-defined knowledge graph embedding model TransR is as follows: Figure 4 As shown, by defining each risk relationship (i.e., the intensity of risk propagation between nodes) Define an independent relation space, and represent risk propagation as a translational transformation of the fused semantic features of nodes within this relation space:

[0069] in, Indicates risk relationship The migration vector, expressed as if node and If an effective risk propagation relationship exists between the nodes, then... The semantic embedding should be able to be used in the relation space through Embedding plus transfer vector get; For nodes The fused semantic features continue to serve as node representations input to the TransR model during the risk reasoning stage, and also serve as nodes... The semantic representation of risk target represents the receiving node of potential risk.

[0070] Calculate the relationship of each edge Risk transmission score :

[0071] in, Representing an edge In the relational space, the risk propagation score indicates a higher probability of risk propagating along that path. The "semantic deviation" between the two entities is calculated by measuring their Euclidean distance; a smaller distance indicates a stronger risk propagation relationship. Above the threshold If so, it is believed that the risk may propagate under this relationship.

[0072] By accumulating the scores of all pre-defined candidate paths, a total risk propagation score for each candidate propagation path is obtained. Then, the total risk propagation scores of each candidate propagation path are sorted to generate a risk propagation path set and identify the starting node, i.e., the risk source node, thus achieving threat source localization.

[0073] S50. Based on the pre-set dynamic risk defense rules and the predicted risk values ​​of each node, determine the target risk defense strategy for each node at different times.

[0074] Optionally, step S50 may specifically include: S501. Based on the preset risk defense strategy selection rules and the predicted risk values ​​of each node, construct a dynamic defense decision function.

[0075] Optionally, a preset risk defense strategy selection rule is defined as follows:

[0076] in, Indicates the first Nodes exist The risk defense strategy to be chosen at all times Indicates the first Nodes exist Predicted risk value at any given time. Indicates the current moment. Indicates the interval duration. These represent lightweight monitoring. Partial isolation Complete blocking Three risk defense strategies and Switch values ​​for different strategies.

[0077] For example, a set of risk defense strategies can be set up for different risk levels. These correspond to three protection strategies: lightweight monitoring, partial isolation, and complete blocking. For nodes... If the predicted risk value Different risk defense strategies are automatically selected depending on the range in which the risk is located.

[0078] This embodiment dynamically adjusts the response strength when risks change by adaptively selecting the risk defense strategy.

[0079] Next, a dynamic defense decision model is constructed to achieve an optimal balance between security, business continuity, and resource consumption. At each moment... To predict risk value As input, the security status of all nodes is evaluated, and a dynamic defense decision function is constructed.

[0080] Optionally, the dynamic defense decision function is expressed as:

[0081] in, This represents the dynamic defense decision function. Represents a node The risk cost, This is the loss coefficient; This indicates the resource overhead incurred by risk defense strategies. This indicates the impact and cost of risk defense strategies on business operations. This is the business penalty coefficient. Represents a node In implementing risk defense strategies Subsequent business availability metrics, using This indicates the extent to which risk defense strategies affect business operations, specifically the percentage of service interruptions or performance degradation. , , Let be the weighting coefficient, satisfying , This represents the total number of nodes in the target cluster system.

[0082] For example, The value is determined based on indicators such as CPU usage, bandwidth reduction, and memory usage. A larger value indicates a greater overhead for the risk defense strategy. Used to describe the impact of policies on service availability. It is used to reflect the business continuity of the system in a defensive state. The business load cost of quantifying defense strategies is used. The dynamic defense decision function is used to comprehensively evaluate the overall system effectiveness under different risk defense strategies.

[0083] S502. Solve for the minimum value of the dynamic defense decision function to obtain the target risk defense strategy of each node at different times.

[0084] For example, to achieve the optimal balance between security, business continuity, and resource consumption, the decision-making process can be transformed into a multi-objective optimization problem, expressed as:

[0085] By employing weighted normalization or the Pareto optimality principle, the strategy combination with the highest overall benefit is selected, and the weights are adjusted based on historical defense results and real-time monitoring information. , , Adaptive updates are performed to enable the dynamic evolution of decision-making strategies.

[0086] After executing the strategy decision, real-time monitoring information can be continuously collected, including the blocking effect, business impact, and new risk changes. Weight parameters and strategy thresholds can be automatically adjusted to achieve dynamic re-optimization. The weight update function is expressed as:

[0087] in, Indicates the current moment For the first One optimization item (security) Business continuity With resource consumption The weight of ) The learning rate is used to control the adjustment range when the target value at the current time is calculated. Then, the direction of its influence will be determined based on the partial derivatives of the function with respect to each weight. This means that if increasing this cost will improve the overall objective, then the weight of that cost will be decreased; conversely, if it will decrease, the weight will be increased. The weight update function represents the update based on the current objective function. Adjust the coefficients according to the sensitivity of the weights to continuously optimize the balance between different protection targets.

[0088] After completing multi-objective optimization, the candidate risk defense strategies for each node are comprehensively evaluated, and the target risk defense strategy that satisfies the optimal objective function is selected. Final target risk defense strategy. It can be represented as:

[0089] in, This indicates the dynamic defense decision function. The risk defense strategy that achieves the minimum value is the optimal risk defense strategy generated under multi-objective constraints. This represents a node. At the present moment The target risk defense strategy.

[0090] The present invention provides a dynamic security defense method for wireless networks based on risk evolution reasoning, which has the following advantages: (1) Threat prediction capability driven by risk evolution: Existing defense methods based on rule matching or machine learning mostly remain at the static detection level, making it difficult to characterize the propagation and evolution of risks over time. This invention constructs a time-series risk evolution graph and introduces a joint modeling mechanism of time decay function and spatial similarity to dynamically quantify the risk impact relationship between multiple nodes. It can predict the potential propagation direction and affected nodes before the risk spreads, realizing the transformation from passive detection to active prediction, and significantly improving the foresight and accuracy of threat identification.

[0091] (2) A dynamic defense decision-making mechanism based on multi-objective optimization: Existing technologies often focus on single-objective optimization in defense strategy generation, lacking the ability to balance multiple factors. This invention proposes a dynamic defense decision-making method based on multi-objective optimization, which incorporates risk control, task continuity, and resource consumption into a unified decision-making model. By dynamically adjusting the weights of risk cost, resource expenditure, and task performance, real-time collaborative optimization decision-making is achieved. This mechanism can select the optimal protection strategy based on the predicted risk level and system operating status, ensuring the effectiveness of defense while avoiding over-protection and resource waste.

[0092] In summary, this invention achieves intelligent enhancement of the entire process from risk understanding to defense decision-making, significantly improving the protection effectiveness and reliability of intelligent cluster systems in complex and dynamic environments.

[0093] Secondly, embodiments of the present invention also provide a dynamic security defense device for wireless networks based on risk evolution reasoning, referring to... Figure 5 The device may specifically include: The data acquisition module 501 is used to acquire log data and network communication data of each node in the target cluster system based on wireless network communication; The evolution graph construction module 502 is used to construct time-series graph structures based on the log data and network communication data of each node, respectively, to obtain the log risk evolution graph and the communication risk evolution graph; The graph fusion module 503 is used to fuse the log risk evolution graph and the communication risk evolution graph to obtain a risk evolution fusion graph; The risk prediction module 504 is used to predict the risk of each node based on the risk evolution fusion diagram and obtain the predicted risk value of each node. The risk defense module 505 is used to determine the risk defense strategy of each node at different times based on the pre-set dynamic risk defense rules and the predicted risk value of each node.

[0094] For details regarding the device, please refer to the steps of the "Dynamic Security Defense Method for Wireless Networks Based on Risk Evolution Reasoning" provided in the first aspect; it will not be repeated here.

[0095] The present invention provides a dynamic security defense device for wireless networks based on risk evolution reasoning, which has the following advantages: (1) Security threat identification and prediction based on risk evolution reasoning: By introducing a risk evolution reasoning mechanism, this invention can dynamically identify and analyze the evolution path of attacks, predict potential security threats, and assess the risk of threat evolution in real time. This method breaks through the limitations of existing technologies in understanding and predicting attack evolution, and can identify multi-stage, distributed, and covert attacks in advance, ensuring that the system has the proactive protection capability to continuously combat risk threats in complex environments.

[0096] (2) Dynamic security defense based on multi-objective optimization: Existing defense methods often struggle to achieve effective collaborative optimization when dealing with multi-objective constraints such as attack blocking, task execution continuity, and resource consumption. Through dynamic security defense decision-making, this invention adopts a multi-objective collaborative optimization method, which can balance and optimize multiple task objectives such as security protection, task efficiency, and resource consumption when the attack situation changes, ensuring the stable operation and security reliability of the system in complex environments.

[0097] This invention addresses the shortcomings of existing intelligent cluster security defense methods in complex threat environments by introducing risk evolution reasoning and dynamic security defense optimization mechanisms. Through security threat identification and prediction based on risk evolution reasoning, this invention can analyze and predict attack evolution trends in real time, proactively identifying multi-stage, distributed, and covert attacks, thus enhancing the system's proactive protection capabilities. Simultaneously, the dynamic security decision-making method based on multi-objective optimization can balance and optimize defense strategies under multiple constraints such as attack blocking, task execution, and resource consumption, providing continuous and reliable proactive protection to support the efficient operation of intelligent clusters in complex environments.

[0098] It should be noted that the terms "first," "second," etc., are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the invention.

[0099] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Furthermore, those skilled in the art can combine and integrate the different embodiments or examples described in this specification.

[0100] Although the invention has been described herein in conjunction with various embodiments, those skilled in the art will understand and implement other variations of the disclosed embodiments by reviewing the accompanying drawings and the disclosure in carrying out the claimed invention. In the description of the invention, the word "comprising" does not exclude other components or steps, "a" or "an" does not exclude a plurality, and "a plurality" means two or more, unless otherwise explicitly specified. Furthermore, while different embodiments may describe certain measures, this does not mean that these measures cannot be combined to produce good results.

[0101] The above description, in conjunction with specific preferred embodiments, provides a further detailed explanation of the present invention. It should not be construed that the specific implementation of the present invention is limited to these descriptions. For those skilled in the art, various simple deductions or substitutions can be made without departing from the concept of the present invention, and all such modifications and substitutions should be considered within the scope of protection of the present invention.

Claims

1. A wireless network dynamic security defense method based on risk evolution reasoning, characterized in that, include: Acquire log data and network communication data of each node in the target cluster system based on wireless network communication; Based on the log data and network communication data of each node, a time-series graph structure is constructed to obtain the log risk evolution graph and the communication risk evolution graph. The log risk evolution diagram and the communication risk evolution diagram are fused to obtain a risk evolution fusion diagram; Based on the risk evolution fusion diagram, risk prediction is performed on each node to obtain the predicted risk value of each node; Based on the pre-set dynamic risk defense rules and the predicted risk values ​​of each node, the target risk defense strategy for each node at different times is determined.

2. The method of claim 1, wherein, Based on the log data and network communication data of each node, a time-series graph structure is constructed to obtain a log risk evolution graph and a communication risk evolution graph, including: Feature extraction is performed on the log data and network communication data of each node to obtain log feature vectors and communication feature vectors; Based on the log feature vectors and communication feature vectors of each node, a time-series graph structure is constructed to obtain the initial log risk evolution graph and the initial communication risk evolution graph. Based on a preset edge weight threshold, the edge relationships in the initial log risk evolution graph and the initial communication risk evolution graph are pruned respectively to obtain the log risk evolution graph and the communication risk evolution graph.

3. The method of claim 2, wherein, The step of fusing the log risk evolution map and the communication risk evolution map to obtain a risk evolution fusion map includes: The log nodes in the log risk evolution graph and the network nodes in the communication risk evolution graph are matched, and cross-modal edges are established between the successfully matched log nodes and network nodes. The log feature vector and the communication feature vector corresponding to the same node in the log risk evolution diagram and the communication risk evolution diagram are fused to obtain the fused feature of each node; and the fused feature of each node is semantically mapped to obtain the fused semantic feature of each node. Based on the cross-modal edges and fusion semantic features of each node, a risk evolution fusion graph is constructed.

4. The method of claim 1, wherein, The step of predicting the risk of each node based on the risk evolution fusion graph to obtain the predicted risk value of each node includes: At consecutive target moments, the risk score sequence of each node is determined based on the risk evolution fusion graph and the pre-constructed risk propagation intensity function between nodes; The risk score sequence of each node is time-weighted for prediction to obtain the predicted risk value of each node.

5. The method of claim 4, wherein, The method further includes: Based on a preset knowledge graph embedding model, risk propagation calculation is performed on the edge relationships between nodes in the risk evolution fusion graph to obtain the risk propagation score of the edge relationships between nodes. Based on the risk propagation score of the edge relationships between nodes, calculate the total risk propagation score of each pre-set candidate propagation path; The risk source node is determined based on the total risk propagation score of each candidate propagation path.

6. The method of claim 1, wherein, The process of determining the target risk defense strategy for each node at different times based on pre-set dynamic risk defense rules and the predicted risk values ​​of each node includes: Based on the preset risk defense strategy selection rules and the predicted risk values ​​of each node, a dynamic defense decision function is constructed. The minimum value of the dynamic defense decision function is obtained to determine the target risk defense strategy of each node at different times.

7. The method of claim 6, wherein the method further comprises: The preset risk defense strategy selection rules are expressed as follows: wherein, represents the th node at the selected risk defense strategy at the moment, represents the th node at the predicted risk value at the moment, represents the current moment, represents the interval duration, respectively represent three risk defense strategies of light monitoring , partial isolation and complete blocking, and are different strategy switching values.​ 8. The method of claim 7, wherein the method further comprises: The dynamic defense decision function is expressed as follows: wherein, represents the dynamic defense decision function, represents the risk cost of a node , is a loss coefficient; represents the resource overhead brought by the risk defense strategy; represents the impact cost of the risk defense strategy on the operation of the business, is a business penalty coefficient, represents the business availability index of a node after executing the risk defense strategy , using represents the impact degree of the risk defense strategy on the business, i.e., the proportion of service interruption or performance decline; , , is a weight coefficient, satisfying , is the total number of nodes in the target cluster system.

9. A dynamic security defense device for wireless networks based on risk evolution reasoning, characterized in that, include: The data acquisition module is used to acquire log data and network communication data of each node in the target cluster system based on wireless network communication; An evolution graph construction module is used to construct time-series graph structures based on the log data and network communication data of each node, respectively, to obtain a log risk evolution graph and a communication risk evolution graph; The graph fusion module is used to fuse the log risk evolution graph and the communication risk evolution graph to obtain a risk evolution fusion graph; The risk prediction module is used to predict the risk of each node based on the risk evolution fusion diagram and obtain the predicted risk value of each node. The risk defense module is used to determine the target risk defense strategy for each node at different times based on the pre-set dynamic risk defense rules and the predicted risk value of each node.

Citation Information

Patent Citations

  • Network security situation awareness prediction system and method based on large model

    CN120498800A

  • Network mapping behavior anomaly detection method and system based on machine learning

    US20250358316A1