An artificial intelligence-based security penetration reinforcement method and system
By using artificial intelligence-based methods, attack boundary trigger zones are constructed, path offsets and privilege transitions are analyzed, and a sequence of conflict-free behavior execution fragments is formed. This solves the problem that traditional security penetration and hardening methods are unable to cope with complex attacks, and realizes dynamic hardening and effective defense of network security systems.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- JIANGSU ZHENGCAI DATA TECH CO LTD
- Filing Date
- 2026-03-05
- Publication Date
- 2026-06-02
AI Technical Summary
Traditional security penetration and hardening methods rely on experience-based judgment, making it difficult to dynamically respond to complex and ever-changing attack methods. Furthermore, the fixed process makes it impossible to effectively identify and respond to cyberattacks.
By using artificial intelligence-based methods, we track changes in resource usage, construct attack boundary trigger zones, analyze path offsets and permission transitions, form a sequence of conflict-free behavior execution fragments, encapsulate them into executable action structures, and achieve dynamic hardening.
It enhances the dynamic response capability of network security systems, enabling them to effectively identify and respond to complex and ever-changing attack behaviors, thereby strengthening the security and stability of the system.
Smart Images

Figure CN122137624A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a security penetration and hardening method and system based on artificial intelligence. Background Technology
[0002] The field of cybersecurity technology involves protecting the confidentiality, integrity, and availability of computer networks and data transmission. Core aspects include intrusion detection, authentication, data encryption, vulnerability scanning, and network behavior monitoring, aiming to prevent malicious attacks, information leaks, and service interruptions, and ensure the safe and stable operation of information systems.
[0003] Traditional security penetration testing and hardening methods and systems refer to the technical means of conducting penetration tests by simulating attack behaviors and then hardening the system accordingly. This typically includes: security personnel manually setting up the test process, using vulnerability scanning tools to probe the system, identifying risk points through preset rules, manually analyzing the test results, and then taking measures such as updating access controls, modifying system configurations, or patching vulnerabilities to complete the hardening. This relies on experience-based judgment, the process is fixed, and it is difficult to dynamically respond to complex and ever-changing attack methods.
[0004] By tracking changes in resource calls and identifying the starting points of jumps in the access trajectory, anomaly trigger zones with correlations are constructed, providing an analyzable basis for the boundaries of the behavior chain. Path index expansion and node deviation filtering characterize differences in path directions, supporting the identification of abnormal paths. By comparing permission level evolution, unidirectional continuous change segments are preserved, forming a permission evolution framework. Deduplication of resource access intervals maintains the independence of behavior segments. Encapsulation of trajectories and control actions forms an executable behavior structure, strengthening the collaborative constraints between access and permissions. Summary of the Invention
[0005] To address the technical problems existing in the prior art, embodiments of the present invention provide a security penetration testing and hardening method and system based on artificial intelligence. The technical solution is as follows: A security penetration testing and hardening method based on artificial intelligence includes the following steps: S1: Extract the resource call change position in the network behavior sequence, expand the access trajectory before and after the position, track the interval change of resource name in the timeline, locate the starting segment of the access trajectory jump, and associate the starting segment with the behavior chain to form a list of attack boundary trigger zones; S2: Call the behavior chain content in the attack boundary trigger zone list, map the resource names in the access trajectory to the path index set, expand the position of each resource in the path, compare the changes in the path direction, select the node content of the path offset, and form a path offset anomaly point sequence. S3: Call the resource nodes in the path offset anomaly point sequence, and according to the permission level change process associated with the resource nodes, compare the corresponding relationship before and after the level change segment by segment, eliminate the process of jump or wrap-around, retain the continuous change content of unidirectional evolution, and form a permission jump structure fragment set. S4: Call all segments in the permission transition structure segment set, and based on the resource access range involved in each segment and the path coverage interval, eliminate the cases where resources appear repeatedly in different intervals, retain the behavior segments whose path coverage does not overlap, and form a sequence of conflict-free behavior execution segments. S5: Invoke the behavior content in the non-conflicting behavior execution segment sequence, unfold the resource access trajectory and permission change trajectory according to the time progression of the behavior occurrence, associate each trajectory with the control action expression method, encapsulate the continuous trajectory into an executable action structure, and form an artificial intelligence penetration reinforcement structure.
[0006] As a further aspect of the present invention, the attack boundary trigger zone list includes resource call mutation location identifiers, time interval change characteristics, jump start segment labels, and behavior chain association indexes; the path offset anomaly point sequence includes resource path index positions, path direction deviation nodes, path structure change labels, and offset matching markers; the permission jump structure fragment set includes permission level evolution chains, resource node association sets, unidirectional jump segments, and continuous permission change fragments; the conflict-free behavior execution fragment sequence includes resource access unique identifiers, behavior path coverage ranges, non-overlapping fragment labels, and interval independent behavior sets; and the artificial intelligence penetration hardening structure includes time-series access trajectories, permission evolution trajectory sets, control action expression units, and executable action structures.
[0007] As a further aspect of the present invention, the step of obtaining the attack boundary trigger zone list is as follows: S101: Extract the order of resource calls in the network behavior sequence, compare whether the resource names of adjacent calls have been replaced, locate the position where the resource call name has changed, and merge it into the position sequence as the operation entry point to obtain the resource call change index sequence. S102: Call each position in the resource call change index sequence, extract the access trajectory segments within the equidistant range before and after it, track the position where each resource name reappears on the timeline in the segment, and sort out the differences in the order of appearance between each resource name to obtain the resource trajectory change segment sequence. S103: Based on the differences in the order of resource appearance in the resource trajectory change segment sequence, and in comparison with the resource arrangement in the behavior chain, the access segments with continuous jump relationships are screened out, and their corresponding starting positions are used as positioning anchors to obtain the attack boundary trigger area positioning sequence.
[0008] As a further aspect of the present invention, the step of obtaining the path offset anomaly point sequence is as follows: S201: Call the behavior chain content corresponding to each position in the attack boundary trigger zone location sequence, extract the resource name in the access trajectory, and map each resource in the access trajectory to the path number list according to the corresponding order position of the resource name in the behavior chain, and obtain the path resource mapping result sequence. S202: Based on the path location number corresponding to each resource name in the path resource mapping result sequence, restore the original path order of the behavior chain according to the number order, and expand the path according to the resource arrangement order in the access trajectory, extract the number string after the path order transformation, and obtain the path order sequence. S203: Call each number string in the path sequence and compare it with the standard path number sequence item by item to filter out the number nodes with sequence deviations. Combine the original resource position of the node in the access trajectory to extract the resource name and its position number to obtain the path deviation anomaly point sequence.
[0009] As a further aspect of the present invention, the step of obtaining the permission transition structure fragment set is as follows: S301: Call each group of number strings in the path sequence and compare them one-to-one with the number sequence in the corresponding standard path to identify the difference in the order of the two groups of numbers and locate them according to the number position to obtain the set of order deviation numbers. S302: Based on the original position index of each number in the access trajectory corresponding to each number in the sequence deviation number set, extract the corresponding resource name from the original trajectory, pair the name with the number, and merge them into the same number sequence as an independent mapping item to obtain the resource deviation mapping content; S303: Based on the numbering order of each resource name in the resource deviation mapping content, reorder them according to their position in the behavior chain path, and then filter each resource based on the difference in numbering position, retain the node content that is misaligned, and obtain the path offset anomaly point sequence.
[0010] As a further aspect of the present invention, the step of obtaining the conflict-free behavior execution fragment sequence is as follows: S401: Call all behavior fragments in the permission transition structure fragment set, extract the resource name and its corresponding access range involved in each fragment, and number them according to the order of resource appearance. Then merge the interval positions between the numbers to obtain the resource access interval sorting result. S402: Based on the merged position of each resource number in the resource access interval sorting result, detect whether the same resource name appears in multiple interval ranges, and according to the correspondence between resource name and number, compare the path number position to remove resource entries that overlap in path coverage, and obtain the path overlap exclusion set. S403: For the resource names retained in the path overlap exclusion set, call the original behavior fragment content, filter out the fragments containing the corresponding unremoved resource names, and merge them into the same sequence according to their order numbering to obtain a conflict-free behavior execution fragment sequence.
[0011] As a further aspect of the present invention, the step of obtaining the artificial intelligence-based penetration reinforcement structure is as follows: S501: Call each action content in the conflict-free action execution segment sequence, arrange the resource access action and permission change action according to the action time order, extract the resource and permission advancement path in each action segment, and organize the trajectory content on the same time line into parallel trajectory segments to obtain the resource permission advancement trajectory set; S502: Based on the resource name and permission level in each segment of the resource permission advancement trajectory set, extract the corresponding behavior control action description content, and match and locate the control action according to the resource position and permission change order in the trajectory to obtain the control action correspondence table. S503: Call the control action descriptions with consecutive numbers in the control action correspondence table, merge the resource trajectory segments and permission trajectory segments to which they belong in chronological order, combine the merged trajectories into a unified structure block, and incorporate them into the same structure set to obtain the artificial intelligence penetration hardening structure.
[0012] A security penetration testing and hardening system based on artificial intelligence, the system comprising: The resource boundary identification module obtains the resource call field and access time from the network access log, compares the resource name and path field, extracts the location of the resource name in the path and the access duration before and after it, extends the access trajectory content, locates the resource segment where the access direction changes, and matches the starting call resource with the known behavior chain in the trajectory to obtain the list of attack boundary trigger zones. The path offset analysis module calls the resource trajectory content in the attack boundary trigger zone list, retrieves the path information contained in the behavior chain, associates the resource name with each node in the path, sequentially checks the changes between the path distribution positions, sorts out the resource positions where the path flow direction turns, extracts the resources in the abnormal trajectory segment and puts them into the sequence to obtain the path offset anomaly point sequence. The permission transition extraction module calls the resource number listed in the path offset anomaly point sequence, retrieves the permission log entry corresponding to each resource, extracts the permission change content according to time, unfolds the continuous change content of the resource permission status from the beginning to the end, filters out the permission stage with jump or wrap-around expression, and only retains the part of the permission expression direction that is unidirectional, to obtain the permission transition structure fragment set. The conflict behavior filtering module calls the resource behavior content in the permission jump structure fragment set, organizes the start and end positions of the resource access path, extracts the path coverage interval, compares the intersection relationship between intervals one by one, removes the path access content with overlapping positions, and only retains the behavior content that does not overlap or repeat between resource trajectories, thus obtaining a conflict-free behavior execution fragment sequence. The penetration structure encapsulation module calls the resource trajectory content and permission change content in the conflict-free behavior execution segment sequence, linearly expands the resource access and permission expression according to time, compares the permission behavior content and control action mode in each trajectory, and combines the continuous trajectory content in resource behavior and permission expression into a unified structure to obtain the artificial intelligence penetration hardening structure.
[0013] The beneficial effects of the technical solutions provided by the embodiments of the present invention include at least the following: In this invention, by tracking changes in resource calls and identifying the starting points of jumps in the access trajectory, anomaly trigger zones with correlations are constructed, providing an analyzable basis for the boundaries of the behavior chain. Path index expansion and node deviation filtering characterize differences in path directions, supporting the identification of abnormal paths. By comparing permission level evolution, unidirectional continuous change segments are preserved, forming a permission evolution framework. Deduplication of resource access intervals maintains the independence of behavior segments. Encapsulation of trajectories and control actions forms an executable behavior structure, strengthening the collaborative constraints between access and permissions. Attached Figure Description
[0014] Figure 1 This is a flowchart of the method of the present invention; Figure 2 This is a flowchart illustrating the process of obtaining the attack boundary trigger zone list for this invention. Figure 3 This is a flowchart illustrating the process of obtaining the path offset anomaly point sequence in this invention. Figure 4 This is a flowchart illustrating the process of obtaining the permission transition structure fragment set of the present invention. Figure 5 This is a flowchart illustrating the process of obtaining the execution fragment sequence of the conflict-free behavior according to the present invention. Figure 6 This is a flowchart illustrating the process of obtaining the artificial intelligence-based penetration reinforcement structure of this invention. Detailed Implementation
[0015] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.
[0016] refer to Figures 1 to 6 A security penetration testing and hardening method based on artificial intelligence includes the following steps: S1: Extract the locations where resource call changes occur in the network behavior sequence, continuously expand the access trajectory before and after the location, track the interval changes of resource names in the timeline, locate the starting segment where the access trajectory jumps, and associate the starting segment with the behavior chain to form a list of attack boundary trigger zones. S2: Call the corresponding behavior chain content in the attack boundary trigger zone list, map the resource names in the access trajectory to the path index set, expand the position of each resource in the path, compare the changes in the path after expansion, select the node content with path deviation, and form a path deviation anomaly point sequence. S3: Call the resource nodes listed in the path offset anomaly point sequence, and according to the permission level change process associated with each resource node, compare the corresponding relationship before and after the level change segment by segment, eliminate the change process that shows jump or wrap-around, retain the continuous change content that maintains the unidirectional evolution characteristics, and form a permission jump structure fragment set. S4: Call all fragments in the permission jump structure fragment set, and based on the resource access range involved in each fragment and the path coverage interval, eliminate the cases where the same resource appears repeatedly in different access intervals, retain the behavior fragments with non-overlapping path coverage, and form a sequence of conflict-free behavior execution fragments. S5: Invoke the behavior content in the sequence of conflict-free behavior execution segments, unfold the resource access trajectory and permission change trajectory according to the time progression of the behavior, associate the control action expression method with each trajectory, and encapsulate the continuous trajectory into an executable action structure to form an artificial intelligence penetration and hardening structure.
[0017] The attack boundary trigger zone list includes resource call mutation location identifiers, time interval change characteristics, jump start segment labels, and behavior chain association indexes. The path offset anomaly point sequence includes resource path index location, path direction deviation nodes, path structure change labels, and offset matching markers. The permission jump structure fragment set includes permission level evolution chain, resource node association set, unidirectional jump segment, and continuous permission change fragments. The conflict-free behavior execution fragment sequence includes resource access unique identifiers, behavior path coverage range, non-overlapping fragment labels, and interval independent behavior sets. The AI penetration hardening structure includes time series access trajectory, permission evolution trajectory set, control action expression unit, and executable action structure.
[0018] Please see Figure 2 The steps to obtain the list of attack boundary trigger zones are as follows: S101: Extract the order of resource calls in the network behavior sequence, compare whether the resource names of adjacent calls have been replaced, locate the position where the resource call name has changed, and merge it into the position sequence as the operation entry point to obtain the resource call change index sequence. In the advanced network security monitoring system constructed in this embodiment, a full-traffic deep log collection probe deployed behind the Web Application Firewall is activated. This probe uses a sliding window mechanism with high concurrency processing capabilities to capture HTTP and HTTPS request traffic in the network in real time, and defines 1000 continuously captured log records as a standard behavior monitoring window to ensure the continuity and real-time nature of data analysis. The processor reads the raw log data within the current monitoring window, uses a high-precision regular expression extraction algorithm to identify and separate the Uniform Resource Identifier (URI) of each record, thereby constructing an actual resource call sequence reflecting the user's real behavior trajectory within the current time window. At the same time, the system retrieves the standard resource call benchmark sequence for this specific business scenario from the pre-set security baseline database and performs a character-level comparison item by item. During the comparison process, for To accurately distinguish between resource renaming caused by normal software version iterations and resource replacement behavior deliberately constructed by attackers, the system introduces a character edit distance algorithm to quantitatively evaluate the string difference between the actual resource name and the baseline resource name. This algorithm measures similarity by calculating the minimum number of single-character edit operations required to convert one string into another. Based on statistical analysis of a large amount of historical change data and SQL injection samples, the difference threshold for judging whether there is a substantial replacement is set to 5. This means that when the character difference value calculated by the processor exceeds this preset threshold, it is determined that an unexpected resource replacement behavior has occurred at that location. The system then stores the indexes of all confirmed changes in a temporary cache and sorts them in ascending order to obtain a resource call change index sequence that can accurately locate the coordinates of all abnormal calls in the behavior chain. S102: Call the resource call change index sequence, extract the access trajectory segments within the equidistant range before and after each position, track the position of each resource name in the segment when it reappears on the timeline, and sort out the differences in the order of appearance between each resource name to obtain the resource trajectory change segment sequence. Based on the resource call change index sequence, the first index position in the sequence is selected as the central anchor point for analysis. Considering that network attacks are usually accompanied by early probing and later overwriting operations, and that these operations are closely related in time and space, the system sets the radius of the interception window to 15 based on statistical analysis of the span of related behaviors in historical attack chain samples. Then, using this anchor point as the center, it intercepts access trajectory segments within equidistant ranges before and after the actual resource call sequence. The processor performs cross-timeline tracing of each resource name contained in this trajectory segment in the global log database, retrieving its recurrence at subsequent time points. To ensure that the analysis is limited to the valid user session period and excludes historical data, further analysis is conducted. To mitigate interference from irrelevant data, the system sets the time span threshold for judgment at the standard session timeout of 1800 seconds. Any resource reappearing within this time threshold is included in the recurrence matrix analysis. Furthermore, the system compares the original order of resource appearance in the current trajectory segment with the average time order of its recurrence on subsequent timelines. By constructing a temporal correlation matrix, it accurately identifies order reversal phenomena that violate normal business logic, such as accessing sensitive data before accessing the login interface. Once such anomalies are detected, the system records the involved resource pairs and their temporal characteristics in detail. It then structures and organizes all resources marked with order differences along with their corresponding timestamps and location information to generate a sequence of resource trajectory change segments. S103: Based on the differences in the order of resource appearance in the resource trajectory change segment sequence, and by comparing the resource arrangement in the behavior chain, filter out the access segments with continuous jump relationships, use their corresponding starting positions as positioning anchors, and obtain the attack boundary trigger zone positioning sequence.
[0019] Based on the sequence of resource trajectory changes, a pre-built business logic topology graph is invoked to deeply analyze the legality of connections between resource nodes in the sequence. This topology graph stores all legal page jumps and resource call relationships in the system in the form of an adjacency matrix. By querying the matrix, the system can determine whether there is a direct legal jump path between adjacent resources in the trajectory. For resource pairs without a direct connection relationship, the system identifies them as non-continuous skip-level jumps. To quantify the degree of abnormality of this jump behavior, the system introduces the concept of a jump span coefficient based on the URL directory hierarchy depth. This coefficient reflects the user's jump from a depth of URL directory hierarchy. Based on the difference between the behavior characteristics of normal users browsing level by level and malicious attackers probing across directories, the system sets the threshold for judging abnormal anchor points to 2. This means that when the level span value of the detected jump behavior reaches or exceeds 2, the system judges that the behavior has a very high risk of path traversal or forced browsing, such as the behavior of trying to access deep database configuration files directly from the root directory. The system then accurately locks the starting position of the abnormal jump in the segment as the attack entry point, and gathers all the locked coordinates to obtain the attack boundary trigger zone location sequence, providing a solid physical location for subsequent path reconstruction.
[0020] Please see Figure 3 The steps for obtaining the path offset anomaly point sequence are as follows: S201: Call the behavior chain content corresponding to each position in the attack boundary trigger zone location sequence, extract the resource name in the access trajectory, and map each resource in the access trajectory to the path number list according to the corresponding order position of the resource name in the behavior chain, and obtain the path resource mapping result sequence. By utilizing the complete behavioral chain data pointed to by each anchor point in the attack boundary trigger zone location sequence, the processor extracts all resource names contained in the access trajectory and performs standardized digital mapping operations. This process relies on a pre-built high-performance resource path mapping database, which uses a hash table structure to store the one-to-one correspondence between resource URL strings and unique integer path numbers. For regular business resources that are explicitly recorded in the database, the system directly assigns standard path numbers such as 1001, 1002, or 2005. These numbers were predefined according to business logic modules during system design. However, for resources that appear in the logs but are not explicitly recorded... For unknown resources registered in the database, the system adopts a dynamic allocation mechanism, automatically assigning them temporary serial numbers starting from 9000 and marking them as unknown node attributes to prevent data flow interruption caused by undefined resources. The processor traverses the entire behavior chain, converting the originally unstructured text format resource sequence into a structured list of integer path serial numbers one by one. This step not only realizes the dimensionality reduction transformation of data from semantic space to numerical space, but also lays the foundation for subsequent efficient numerical calculations, transforming complex string comparisons into efficient integer operations, and generating a path resource mapping result sequence containing all path information.
[0021] S202: Based on the path location number corresponding to each resource name in the path resource mapping result sequence, restore the original path sequence of the behavior chain according to the number order, and expand the path according to the resource arrangement order in the access trajectory, extract the number string after the path sequence transformation, and obtain the path sequence sequence. Based on the path numbering sequence in the path resource mapping result sequence, the processor aims to reconstruct its theoretical path in the standard business process diagram. The system calls a directed graph model containing all legal business flow rules to perform compliance checks on the connection relationships between adjacent path numbers in the sequence. When it is detected that there is no direct legal edge connection between two adjacent numbers, the processor immediately activates the shortest path completion algorithm (such as Dijkstra's algorithm or BFS algorithm) to calculate the set of theoretical intermediate nodes required to reach the next node from the previous node in the standard graph model. These calculated missing nodes represent the business links that the attacker attempts to bypass during the actual access process, such as bypassing CAPTCHA verification or identity authentication pages. The processor then compares and expands the actual access path with the theoretically complete path based on the calculation results, generating a complete path description sequence that includes both actual access nodes and theoretical nodes marked as missing. This sequence intuitively shows the damage and skipping of the standard business process by the attack behavior. Through this "real and virtual" path reconstruction, the system can clearly depict the attacker's escape route, thereby obtaining the path sequence.
[0022] S203: Call each number string in the path sequence and compare it with the standard path number sequence item by item to filter out the number nodes with sequence deviations. Combine the original resource position of the node in the access trajectory to extract the resource name and its position number to obtain the path offset anomaly point sequence.
[0023] The system performs in-depth numerical sequence deviation analysis on the call path sequence. The core of this analysis lies in comparing the position of each node in the actual sequence with its pre-defined execution order in the standard business flow design. The difference between the two is used to assess the degree of deviation from the standard process, thereby quantifying the abnormality of the behavior. To scientifically distinguish between normal sequence fine-tuning caused by network latency, asynchronous page loading, or unintentional user refresh, and severe path deviations caused by malicious unauthorized access, the system sets a strict anomaly judgment threshold of 1 based on statistical data from comparative experiments on a large number of normal user behavior and attack behavior samples. This threshold means that normal fluctuations should not exceed the range of one operation step. During the full sequence scan, once a node's deviation value exceeds this threshold and its deviation characteristics fall within a predefined malicious behavior range, the system immediately confirms that the node has a severe path deviation anomaly and quickly extracts and records the node's number and its resource location information in the original trajectory. This statistical threshold-based judgment method effectively reduces the false alarm rate and summarizes the path deviation anomaly point sequence.
[0024] Please see Figure 4 The steps for obtaining the permission transition structure fragment set are as follows: S301: Call each group of number strings in the path sequence, compare them one-to-one with the number sequence in the corresponding standard path, identify the difference in the order of the two groups of numbers, locate them according to the number position, and obtain the set of numbers that deviate from the order. The system invokes a sequence of path offset anomalies, focusing on the number strings marked as deviation anomalies. It then initiates a deep difference analysis program based on bidirectional pointer scanning technology. This program locates the logical starting point and actual landing point numbers of the actual jump behavior within the standard sequence. Simultaneously, it searches a pre-set standard path template library for a set of intermediate numbers that should theoretically exist between these two numbers but are actually missing, thus constructing a complete difference set. Based on this, the system executes strict inversion pair detection logic to identify differences in the order of events, specifically checking whether the actual node order fundamentally violates the logical pre-dependencies in the standard template. For example, if the node order should be... If an order confirmation node, which appears only after payment verification, is accessed directly before verification, or if the jumps between nodes far exceed the normal range allowed by the business logic, such non-linear jumps usually mean that vulnerabilities at the business logic level are being exploited by attackers. When the system monitors and confirms such sequential mutations or illegal jumps that violate logical priorities, it will precisely match and record all such discrepancies and their absolute position indexes in the current execution sequence. This process not only identifies "missing links" in the path but also deeply identifies "misalignment anomalies" in the timing, thereby constructing a set of sequence deviation numbers containing all details of timing logic errors.
[0025] S302: Based on the original position index of each number in the access trajectory corresponding to each number in the sequence deviation number set, extract the corresponding resource name from the original trajectory, pair the name with the number, and merge them into the same number sequence as an independent mapping item to obtain the resource deviation mapping content; Based on the sequence deviation number set, the system initiates a high-precision tracing mechanism to trace back the original access trajectory data. Using the precise location index recorded in the set as a navigation anchor, the processor quickly and accurately locates the specific resource name that caused the anomaly in the massive raw log data stream. Using this resource name as a unique index key, a high-concurrency query request is initiated to the pre-set permission attribute database to extract the inherent permission tag corresponding to the resource in the system security design specifications. These tags cover multiple role levels, from visitors, ordinary users, and senior administrators to API-specific interfaces. The processor strongly associates and binds the extracted resource name, its corresponding standardized path number, and the permission tag obtained from the database. This process essentially concretizes the originally single-dimensional path deviation problem into a multi-dimensional data entity with rich attribute characteristics, thereby clarifying the functional attributes and security level of each abnormal node. This allows the system to not only know "where" the anomaly occurred, but also to deeply understand "what kind" of resource was involved. All the constructed mapping items are merged into the same sequence structure to ensure that each abnormal point carries complete contextual information, thus obtaining the resource deviation mapping content.
[0026] S303: Based on the numbering order of each resource name in the resource deviation mapping content, reorder them according to their position in the behavior chain path, and then filter each resource based on the difference in numbering position, retain the node content that is misaligned, and obtain the path offset anomaly point sequence.
[0027] For resource deviation mappings, the processor executes the core permission jump detection algorithm. This algorithm quantifies and numerically classifies permissions for different user roles based on a Role-Based Access Control (RBAC) model. For example, it maps visitors, regular users, and administrators to monotonically increasing integer weights and calculates the permission gradient value between the previous node and the current deviation node during the path jump process. Based on the principle of least privilege and zero-trust architecture design specifications in information security, the system sets an illegal jump threshold of 0. The physical meaning of this threshold is that in normal peer-to-peer or degraded access flows, the permission gradient value should always remain less than 0. If the system detects that the permission gradient value of a certain jump is greater than 0, and the jump process does not contain any legitimate privilege escalation authentication interface calls (such as login verification, secondary authorization, or Sudo commands), then the behavior is determined to be an illegal unauthorized access. The processor, in conjunction with the number difference position determined in S301, filters out all misaligned nodes that meet the illegal unauthorized access conditions, and completely retains their detailed resource names and permission level information. This effectively eliminates benign anomalies caused by simple misoperation, focuses on malicious attack behaviors with clear privilege escalation intentions, and generates a set of permission jump structure fragments containing clear evidence of unauthorized access.
[0028] Please see Figure 5 The steps for obtaining the sequence of execution fragments without conflict are as follows: S401: Call all behavior fragments in the permission jump structure fragment set, extract the resource name and its corresponding access range involved in each fragment, and organize them by number according to the order of resource appearance. Then, merge the interval positions between the numbers to obtain the resource access interval organization result. The system reads all behavior segments from the permission transition structure fragment set, extracts the resource name involved in each segment and its specific access duration range on the time axis. Considering that in a high-concurrency network attack and defense environment, the same attack behavior may be captured by multiple parallel detection windows at the same time, or multiple short-term accesses to the same resource may cause data overlap and redundancy in the time dimension, the system adopts an efficient interval scanline algorithm to merge these time intervals. This algorithm sorts all time intervals in ascending order according to their start time, traverses the sequence, and intelligently merges multiple segments with time overlap into a continuous long interval covering the entire time period, while maintaining the integrity of independent and non-overlapping time periods. This ensures the uniqueness and continuity of each attack behavior segment on the time axis. This processing method effectively eliminates the fragmentation problem caused by the time slicing characteristics of the detection mechanism, enabling subsequent analysis to be based on the complete attack session cycle, avoiding missed or false alarms caused by data fragmentation, and obtaining resource access interval sorting results that have been strictly sorted by time sequence.
[0029] S402: Based on the merged position of each resource number in the resource access interval sorting results, detect whether the same resource name appears in multiple interval ranges, and according to the correspondence between resource name and number, compare the path number position to remove resource entries that overlap in path coverage, and obtain the path overlap exclusion set. Based on the resource access interval analysis results, the system further performs deep correlation analysis to detect whether the same resource name appears repeatedly in multiple non-contiguous time intervals. It also checks whether the behavioral paths corresponding to these intervals originate from the same parent node's trigger action by comparing the path number positions. This identifies whether there are duplicate probes targeting the same vulnerability or redundant alarms generated by automated scanning tools. To accurately eliminate such duplicate alarms and optimize system performance, the system uses the Jaccard similarity coefficient algorithm to calculate the overlap between the path coverage node sets corresponding to different intervals, setting an overlap threshold of 0.8. If the calculation results show that the path overlap between two intervals exceeds this threshold, the system statistically determines that these two records belong to redundant alarms targeting the same attack behavior. At this point, the system follows the data cleaning principle of "retaining the latest and eliminating the old," retaining the interval records with the latest timestamps to reflect the current attack status, and adding the old resource entry IDs to the elimination list. This ensures the timeliness of alarms while minimizing the consumption of redundant data on subsequent computing resources, resulting in a path overlap exclusion set.
[0030] S403: For resource names retained in the path overlap exclusion set, call the original behavior fragment content, filter out the fragments containing the corresponding unremoved resource names, and merge them into the same sequence according to their order numbering to obtain a sequence of conflict-free behavior execution fragments.
[0031] Based on the filtering and cleaning operations performed on the original behavior fragments according to the path overlap exclusion set, the system traverses all original fragments and uses an efficient hash lookup mechanism to automatically identify and remove redundant items whose IDs are included in the exclusion set, retaining only valid fragments with independent characteristics that are not marked as duplicates. All the retained valid fragments are re-indexed, numbered, and sorted according to their start time order, and these deeply cleaned, deduplicated, and time-series-correct independent attack behavior records are merged into the same standardized sequence structure. This step completely removes noise data generated by the concurrent detection mechanism and system data redundancy, providing high-purity, low-noise, and structurally regular sample data for subsequent artificial intelligence analysis, ensuring the accuracy of AI model training and inference, and obtaining conflict-free behavior execution fragment sequences.
[0032] Please see Figure 6 The steps for obtaining artificial intelligence-based reinforced structures are as follows: S501: Call each action in the sequence of conflict-free action execution segments, arrange the resource access action and permission change action according to the action time order, extract the resource and permission advancement path in each action segment, and organize the trajectory content on the same time line into parallel trajectory segments to obtain the resource permission advancement trajectory set; The system retrieves conflict-free behavior execution sequences to construct a multidimensional feature tensor for deep AI analysis. It extracts the resource advancement path sequence and permission advancement path sequence from each behavior sequence, and uses a unified timeline as a reference frame to strictly align and merge resource access actions occurring at the same moment with the corresponding permission changes. In this way, the system integrates the logically separate resource and permission flows into parallel trajectory segments. Each segment completely and three-dimensionally records "what resources the user accessed" and "what permissions the user held" at a specific point in time, thus completing the transformation of data from a single dimension to multidimensional features. This multidimensional trajectory set not only contains static resource attribute information but also dynamic permission evolution processes, enabling a more comprehensive and detailed characterization of attacker behavior patterns and tactical paths, resulting in a resource and permission advancement trajectory set rich in spatiotemporal features.
[0033] S502: Based on the resource name and permission level in each segment of the resource permission advancement trajectory set, extract the corresponding behavior control action description content, and match and locate the control action according to the resource position and permission change order in the trajectory to obtain the control action correspondence table; For each segment of the resource permission advancement trajectory set, the system performs pattern matching queries in a pre-defined control action semantic library based on a specific combination of resource location and permission level to parse the attacker's control intent hidden in the trajectory. The semantic library predefines a large number of specific attack semantics corresponding to resource and permission combinations, such as a low-privilege user attempting to write a high-privilege configuration file, or an external IP directly calling the internal database management interface. When the system detects an unexpected change in permission level accompanying access to sensitive resources in the trajectory, it automatically matches and inserts explicit control action tags such as "privilege escalation attempt," "illegal read," "remote code execution," or "database injection." This process transforms the raw and obscure underlying log data stream into a sequence of control actions with clear security semantics, intuitively revealing the attacker's tactical intent and attack stage, turning the originally scattered data into an attack narrative that can be understood by machines, and generating a detailed control action correspondence table.
[0034] S503: Call the descriptions of control actions with consecutive numbers in the control action correspondence table, merge the resource trajectory segments and permission trajectory segments to which they belong in chronological order, combine the merged trajectories into a unified structure block, and incorporate them into the same structure set to obtain the artificial intelligence penetration hardening structure.
[0035] The system uses a standardized, structured encapsulation of control action mapping tables. Strictly following the chronological order of events, it groups consecutive control action descriptions, corresponding resource trajectory segments, and permission trajectory segments into a unified structural block. Within this block, input, state, and label layer vectors are rigorously defined. The input layer carries the encoded information of resources to represent the attack target; the state layer records changes in permission values to reflect attack capabilities; and the label layer annotates the corresponding control action semantics to reveal attack intent. This three-layer structure perfectly matches the input data requirements of advanced AI models such as Long Short-Term Memory (LSTM) networks or Transformers. It not only objectively records the facts of attack behavior but also enhances the model's understanding of deep attack intent through semantic labels. This provides standardized data support for subsequent model training, inference, and automated defense strategy generation, resulting in an AI penetration hardening structure suitable for intelligent defense systems.
[0036] A security penetration testing and hardening system based on artificial intelligence, the system includes: The resource boundary identification module obtains the resource call field and access time from the network access log, compares the resource name and path field, extracts the location of the resource name in the path and the access duration before and after it, extends the access trajectory content, locates the resource segment where the access direction changes, and matches the starting call resource with the known behavior chain in the trajectory to obtain the list of attack boundary trigger zones. The path offset analysis module calls the resource trajectory content in the attack boundary trigger zone list, retrieves the path information contained in the behavior chain, associates the resource name with each node in the path, sequentially examines the changes between the path distribution positions, sorts out the resource positions where the path flow turns, extracts the resources in the abnormal trajectory segment and puts them into the sequence to obtain the path offset anomaly point sequence. The permission transition extraction module calls the resource number listed in the path offset anomaly point sequence, retrieves the permission log entry corresponding to each resource, extracts the permission change content according to time, unfolds the continuous change content of the resource permission status from the beginning to the end, filters out the permission stage with jump or wrap-around expression, and only retains the part of the permission expression direction that is unidirectional, to obtain the permission transition structure fragment set. The conflict behavior filtering module calls the permission jump structure fragment to collect resource behavior content, organizes the start and end positions of the resource access path, extracts the path coverage interval, compares the intersection relationship between intervals, removes the path access content with overlapping positions, and only retains the behavior content that does not overlap or duplicate between resource trajectories, thus obtaining a conflict-free behavior execution fragment sequence. The penetration structure encapsulation module calls the resource trajectory content and permission change content in the sequence of conflict-free behavior execution segments, linearly expands the resource access and permission expression according to time, compares the permission behavior content and control action mode in each trajectory, and combines the continuous trajectory content in resource behavior and permission expression into a unified structure to obtain the artificial intelligence penetration hardening structure.
[0037] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A security penetration testing and hardening method based on artificial intelligence, characterized in that, Includes the following steps: S1: Extract the resource call change position in the network behavior sequence, expand the access trajectory before and after the position, track the interval change of resource name in the timeline, locate the starting segment of the access trajectory jump, and associate the starting segment with the behavior chain to form a list of attack boundary trigger zones; S2: Call the behavior chain content in the attack boundary trigger zone list, map the resource names in the access trajectory to the path index set, expand the position of each resource in the path, compare the changes in the path direction, select the node content of the path offset, and form a path offset anomaly point sequence. S3: Call the resource nodes in the path offset anomaly point sequence, and according to the permission level change process associated with the resource nodes, compare the corresponding relationship before and after the level change segment by segment, eliminate the process of jump or wrap-around, retain the continuous change content of unidirectional evolution, and form a permission jump structure fragment set. S4: Call all segments in the permission transition structure segment set, and based on the resource access range involved in each segment and the path coverage interval, eliminate the cases where resources appear repeatedly in different intervals, retain the behavior segments whose path coverage does not overlap, and form a sequence of conflict-free behavior execution segments.
2. The security penetration testing and hardening method based on artificial intelligence according to claim 1, characterized in that: The attack boundary trigger zone list includes resource call mutation location identifiers, time interval change characteristics, jump start segment labels, and behavior chain association indexes. The path offset anomaly point sequence includes resource path index positions, path direction deviation nodes, path structure change labels, and offset matching markers. The permission jump structure fragment set includes permission level evolution chains, resource node association sets, unidirectional jump segments, and continuous permission change fragments. The conflict-free behavior execution fragment sequence includes resource access unique identifiers, behavior path coverage, non-overlapping fragment labels, and interval independent behavior sets.
3. The security penetration testing and hardening method based on artificial intelligence according to claim 1, characterized in that: The steps for obtaining the list of attack boundary trigger zones are as follows: S101: Extract the order of resource calls in the network behavior sequence, compare whether the resource names of adjacent calls have been replaced, locate the position where the resource call name has changed, and merge it into the position sequence as the operation entry point to obtain the resource call change index sequence. S102: Call each position in the resource call change index sequence, extract the access trajectory segments within the equidistant range before and after it, track the position where each resource name reappears on the timeline in the segment, and sort out the differences in the order of appearance between each resource name to obtain the resource trajectory change segment sequence. S103: Based on the differences in the order of resource appearance in the resource trajectory change segment sequence, and in comparison with the resource arrangement in the behavior chain, the access segments with continuous jump relationships are screened out, and their corresponding starting positions are used as positioning anchors to obtain the attack boundary trigger area positioning sequence.
4. The security penetration testing and hardening method based on artificial intelligence according to claim 1, characterized in that: The steps for obtaining the path offset anomaly point sequence are as follows: S201: Call the behavior chain content corresponding to each position in the attack boundary trigger zone location sequence, extract the resource name in the access trajectory, and map each resource in the access trajectory to the path number list according to the corresponding order position of the resource name in the behavior chain, and obtain the path resource mapping result sequence. S202: Based on the path location number corresponding to each resource name in the path resource mapping result sequence, restore the original path order of the behavior chain according to the number order, and expand the path according to the resource arrangement order in the access trajectory, extract the number string after the path order transformation, and obtain the path order sequence. S203: Call each number string in the path sequence and compare it with the standard path number sequence item by item to filter out the number nodes with sequence deviations. Combine the original resource position of the node in the access trajectory to extract the resource name and its position number to obtain the path deviation anomaly point sequence.
5. The security penetration testing and hardening method based on artificial intelligence according to claim 1, characterized in that: The steps for obtaining the permission transition structure fragment set are as follows: S301: Call each group of number strings in the path sequence and compare them one-to-one with the number sequence in the corresponding standard path to identify the difference in the order of the two groups of numbers and locate them according to the number position to obtain the set of order deviation numbers. S302: Based on the original position index of each number in the access trajectory corresponding to each number in the sequence deviation number set, extract the corresponding resource name from the original trajectory, pair the name with the number, and merge them into the same number sequence as an independent mapping item to obtain the resource deviation mapping content; S303: Based on the numbering order of each resource name in the resource deviation mapping content, reorder them according to their position in the behavior chain path, and then filter each resource based on the difference in numbering position, retain the node content that is misaligned, and obtain the path offset anomaly point sequence.
6. The security penetration testing and hardening method based on artificial intelligence according to claim 1, characterized in that: The steps for obtaining the conflict-free behavior execution fragment sequence are as follows: S401: Call all behavior fragments in the permission transition structure fragment set, extract the resource name and its corresponding access range involved in each fragment, and number them according to the order of resource appearance. Then merge the interval positions between the numbers to obtain the resource access interval sorting result. S402: Based on the merged position of each resource number in the resource access interval sorting result, detect whether the same resource name appears in multiple interval ranges, and according to the correspondence between resource name and number, compare the path number position to remove resource entries that overlap in path coverage, and obtain the path overlap exclusion set. S403: For the resource names retained in the path overlap exclusion set, call the original behavior fragment content, filter out the fragments containing the corresponding unremoved resource names, and merge them into the same sequence according to their order numbering to obtain a conflict-free behavior execution fragment sequence.
7. The security penetration testing and hardening method based on artificial intelligence according to claim 1, characterized in that, The method further includes step S5: S5: Invoke the behavior content in the non-conflicting behavior execution fragment sequence, unfold the resource access trajectory and permission change trajectory according to the time progression of the behavior occurrence, associate each trajectory with the control action expression method, encapsulate the continuous trajectory into an executable action structure, and form an artificial intelligence penetration reinforcement structure. The AI penetration hardening structure includes a time-series access trajectory, a set of permission evolution trajectories, a control action expression unit, and an executable action structure.
8. The security penetration testing and hardening method based on artificial intelligence according to claim 7, characterized in that: The steps for obtaining the AI-based penetration and reinforcement structure are as follows: S501: Call each action content in the conflict-free action execution segment sequence, arrange the resource access action and permission change action according to the action time order, extract the resource and permission advancement path in each action segment, and organize the trajectory content on the same time line into parallel trajectory segments to obtain the resource permission advancement trajectory set; S502: Based on the resource name and permission level in each segment of the resource permission advancement trajectory set, extract the corresponding behavior control action description content, and match and locate the control action according to the resource position and permission change order in the trajectory to obtain the control action correspondence table. S503: Call the control action descriptions with consecutive numbers in the control action correspondence table, merge the resource trajectory segments and permission trajectory segments to which they belong in chronological order, combine the merged trajectories into a unified structure block, and incorporate them into the same structure set to obtain the artificial intelligence penetration hardening structure.
9. A security penetration testing and hardening system based on artificial intelligence, characterized in that, The system is used in the AI-based security penetration and hardening method according to any one of claims 1-8, the system comprising: The resource boundary identification module obtains the resource call field and access time from the network access log, compares the resource name and path field, extracts the location of the resource name in the path and the access duration before and after it, extends the access trajectory content, locates the resource segment where the access direction changes, and matches the starting call resource with the known behavior chain in the trajectory to obtain the list of attack boundary trigger zones. The path offset analysis module calls the resource trajectory content in the attack boundary trigger zone list, retrieves the path information contained in the behavior chain, associates the resource name with each node in the path, sequentially checks the changes between the path distribution positions, sorts out the resource positions where the path flow direction turns, extracts the resources in the abnormal trajectory segment and puts them into the sequence to obtain the path offset anomaly point sequence. The permission transition extraction module calls the resource number listed in the path offset anomaly point sequence, retrieves the permission log entry corresponding to each resource, extracts the permission change content according to time, unfolds the continuous change content of the resource permission status from the beginning to the end, filters out the permission stage with jump or wrap-around expression, and only retains the part of the permission expression direction that is unidirectional, to obtain the permission transition structure fragment set. The conflict behavior filtering module calls the resource behavior content in the permission jump structure fragment set, organizes the start and end positions of the resource access path, extracts the path coverage interval, compares the intersection relationship between intervals one by one, removes the path access content with overlapping positions, and only retains the behavior content that does not overlap or repeat between resource trajectories, thus obtaining a conflict-free behavior execution fragment sequence. The penetration structure encapsulation module calls the resource trajectory content and permission change content in the conflict-free behavior execution segment sequence, linearly expands the resource access and permission expression according to time, compares the permission behavior content and control action mode in each trajectory, and combines the continuous trajectory content in resource behavior and permission expression into a unified structure to obtain the artificial intelligence penetration hardening structure.