A four-dimensional closed-loop-based safe operation platform system

By constructing a security operation platform system based on a four-dimensional closed loop, the problem of long iteration cycles in traditional security operation systems has been solved, achieving rapid iteration and precise response security effects, and adapting to the rapid evolution of security threats.

CN122137657APending Publication Date: 2026-06-02TANGSHAN DUNSHI INFORMATION TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
TANGSHAN DUNSHI INFORMATION TECH CO LTD
Filing Date
2026-03-18
Publication Date
2026-06-02

Smart Images

  • Figure CN122137657A_ABST
    Figure CN122137657A_ABST
Patent Text Reader

Abstract

This invention discloses a security operation platform system based on a four-dimensional closed loop. It connects the operation team, operation processes, and operation services to construct a four-dimensional closed loop. The system is built on a five-layer network architecture and includes the following modules: data acquisition module, data storage module, threat detection module, business security module, platform openness module, and platform security module. This system collects telemetry data from key nodes using native traffic acquisition tools and endpoint acquisition tools. Through a network-endpoint aggregation and analysis engine, it performs automated contextual analysis of the data, enabling deep attack chain tracing, freeing up the time of operation personnel. It also reserves scalable ecosystem openness capabilities. Through the collaborative capabilities of each module, it delivers a security experience characterized by deep detection, accurate response, and continuous improvement.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of operations management technology, and in particular to a safety operations platform system based on a four-dimensional closed loop. Background Technology

[0002] Over the past few decades, software architecture and application hosting models have undergone several major transformations, from centralized to decentralized, from virtual machine hosting to cloud hosting, and then to microservices and container technologies. Enterprises are also constantly updating their architectural patterns and best practices to suit their own needs. The security capabilities of traditional vendor hardware security equipment have a long iteration and effectiveness verification cycle, often requiring multiple rounds of iteration and verification over several weeks before the security capabilities can be truly effective. Moreover, effectiveness verification is difficult and often requires verification in the customer's environment to obtain effective security results.

[0003] In a security operations system, "people, processes, tools, and services" are four interdependent core elements that jointly support security objectives. They not only define "who does it, how it's done, what's used, and to what level," but also determine the maturity and practical effectiveness of the entire security operations. Among them: People: The "brain" and "execution force" of security operations; People are the core driving force of security operations, encompassing various roles from frontline analysts to threat hunters, security architects, incident response experts, and more. Process: The "operating system" of security operations; a process is a system design that standardizes security activities and ensures response efficiency and consistency, covering the entire lifecycle from alarm discovery to incident closure; Tools: The "weapon system" for safe operations; tools are the technical means that support personnel in executing processes, covering all aspects such as data collection, detection, analysis, response, and orchestration. Services: The "capability extension" of security operations; services refer to the continuous operational support provided externally or internally to make up for the organization's shortcomings in personnel, technology or processes and improve overall security effectiveness.

[0004] Therefore, in order to quickly track and adapt to the rapid evolution of security threats, forming a closed loop by integrating the four dimensions of "people, processes, tools, and services" is an inevitable trend for security operations systems. Summary of the Invention

[0005] To address the aforementioned technical problems, this invention provides a security operation platform system based on a four-dimensional closed loop.

[0006] This invention is achieved using the following technical solution: A security operations platform system based on a four-dimensional closed loop connects the operations team, operations processes, and operations services to form a four-dimensional closed loop. The system is built on a five-layer network architecture and includes the following modules: Data acquisition module: Collects network-side telemetry data, terminal-side telemetry data, and third-party data respectively, and transmits and reports the collected data in JSON or file format; Data storage module: A data lake is built based on message queue middleware, distributed real-time analytical columnar storage database and distributed storage architecture to store and manage massive amounts of data; Threat detection module: performs threat detection on terminal-side capabilities, network-side capabilities, and platform capabilities respectively, and performs correlation analysis. It combines data collected from the terminal-side and network-side with cloud factors to perform timeline correlation and causal inference, and generates related events on the platform side. Business security module: Centralizes all isolated endpoint network security events and threat alerts for unified management, enables retrieval of security events based on multiple filtering criteria, and provides a security visualization center with charts and graphs; Platform open module: Based on API interface, it forms three modes of data exchange with third-party components: data reporting, linkage handling and distribution, and event alarm external transmission, and uses the App center to manage the application life cycle; Platform security module: Based on local and cloud deployment methods, it sets up three layers of protection: data isolation, access isolation, and transmission isolation. The authentication interface and data transmission interface are set up independently. The data upload of components obtains a token through the authentication interface.

[0007] Specifically, the five-layer network architecture includes, in sequence: Enablement layer: Configures security GPT, cloud capability center and cloud operation center to provide the system with a variety of models, intelligence and services; Application layer: Configure security monitoring, detection response, risk management, asset center, SOAR, work order, APP center and configuration strategy center; Logic layer: Provides the system with asset and vulnerability identification capabilities, detection and investigation capabilities, response and handling capabilities, and ecosystem openness capabilities; Engine layer: Configured with a multi-level engine, including a level 1 threat alert engine, a level 2 alert aggregation engine, and a level 3 event recovery engine; Data layer: Implements system metadata management and storage management based on interfaces; Security Component Layer: Configures various security components, including perimeter security components, endpoint security components, network security components, host security components, application security components, and data security components.

[0008] Specifically, the data acquisition module comprises: API Access Submodule: Runs a distributed microservice architecture based on the access gateway and integrated API interfaces; Data transmission submodule: Configure data transmission protocols for data reporting and component linkage respectively; configure the telemetry data reporting of network-side and terminal-side components with HTTP / 2 and TLS encryption protocols; configure gRPC bidirectional stream protocol based on HTTP / 2 for component linkage, and set a unique component ID for authentication; The data enrichment submodule configures parsing operators, logical processing operators, and labeling operators to parse and standardize the various forms of data uploaded by users to the system. At the same time, it performs preliminary screening, transformation, and storage of basic raw data collected from the network side based on the data lake.

[0009] Specifically, the data storage module comprises: Message middleware submodule: Based on Pulsar middleware, a three-layer message queue is built, consisting of raw JSON data, enriched JSON data, and serialized data converted to AVRO format and finally stored in the database. The data persistence submodule uses a distributed, real-time analytical columnar storage database to store hot data and provides multi-level retrieval and approximate queries. The file object storage submodule stores cold data based on a distributed storage architecture and performs file object storage, backup, and disaster recovery.

[0010] Specifically, the threat detection capabilities of each side in the threat detection module include: Terminal-side capabilities: Collect comprehensive data from the terminal side, perform local layering and aggregate effective data before uploading it to the platform, combine it with the user's real environment to perform strong contextual correlation analysis, and use a funnel-shaped three-level detection mechanism for behavior detection to output detection results; the three-level detection mechanism includes the first level of single terminal event detection, the second level of multi-alarm correlation detection, and the third level of cross-terminal multi-source detection. Network-side capabilities: Based on traffic and log collection, configure multiple rules for preliminary analysis, data labeling, and feature detection; use threat detection models to quickly locate scenario threats; perform full backtracking and correlation based on the entire session traffic to locate abnormal risks; and configure feature-based optimization detection based on optimization algorithm models. Platform capabilities include alarm correlation analysis of network and endpoints, linking endpoint, network and cloud telemetry data through storylines to build a complete, high-quality, scenario-based data chain, and empowering the platform by delivering cloud-based threat intelligence and expert capabilities to user networks and endpoints.

[0011] Specifically, the threat detection module correlation analysis includes: For strong signals from components uploaded to the platform system, perform strong correlation analysis; When the signal uploaded to the platform system by the component is of varying strength, it is detected through multi-factor correlation. For multiple weak signals uploaded to the platform system by components, a unified integration is performed; It also provides atomic operations for responses, intelligently recommends responses, classifies responses by role, and supports custom responses.

[0012] Specifically, in the platform open module: The data reporting is based on the logs, alarms, and events reported by third-party components, and is used to analyze the display scenarios. The coordinated handling dispatch is used by the platform system to dispatch handling strategies to the terminal and network side components when the event handling is closed-loop; The event alarm external transmission is used for the platform system to connect with other operating platforms or data centers to transmit alarms or events to third-party platforms; The application management in the App Center includes the entire application process. It adds a redirect to a third-party application on the front end. Users select the corresponding application to subscribe to, and after clicking the redirect, they are directly taken to the page of the third-party application. At the same time, the event is synchronized to the third-party application.

[0013] Specifically, the platform security module's three layers of protection are as follows: Data isolation: The result data of different tenants is isolated through database namespaces. The platform system's raw logs are written to a distributed real-time analytical columnar storage database, and different tenants are isolated through different tables and partitions. Access isolation: Different tenants access their own data through different web applications and services. Security capabilities ensure that different tenants use different paths to isolate tenants when consuming data from the data lake. Transport isolation: During transmission, logs from different tenants carry tenant IDs and enter the message queue using different tenant paths.

[0014] Specifically, the system is also configured with a variety of components, including: network traffic collection tools, endpoint behavior collection tools, other telemetry point collection tools, other optional response components, and third-party components.

[0015] The beneficial effects of this invention are as follows: The security operation platform system based on a four-dimensional closed loop proposed in this invention collects key data through native traffic collection tools and endpoint collection tools, performs contextual correlation analysis on the data through a network-endpoint aggregation analysis engine, realizes in-depth tracing of attack chains, and, combined with managed detection and response service (MDR), frees up personnel's energy; at the same time, it has scalable interface openness, collaborates with products such as SOAR, simplifies complexity, and brings a security experience of in-depth detection, accurate response, and continuous growth. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the structures shown in these drawings without creative effort.

[0017] Figure 1 This is a schematic diagram of a four-dimensional closed-loop-based security operation platform system in an embodiment of the present invention; Figure 2 This is a schematic diagram of telemetry data acquisition in this embodiment; Figure 3 This is a schematic diagram of the data acquisition process in this embodiment; Figure 4 This is a schematic diagram of the data transmission component linkage in this embodiment; Figure 5 This is a schematic diagram of the message middleware in this embodiment; Figure 6 This is a schematic diagram of the three-level detection mechanism in this embodiment. Detailed Implementation

[0018] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.

[0019] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0020] The following is in conjunction with the appendix Figures 1-6 The following describes some embodiments of the present invention in detail. Unless otherwise specified, the following embodiments and features can be combined with each other.

[0021] This invention proposes a security operation platform system based on a four-dimensional closed loop. In a preferred embodiment, such as... Figure 1 As shown, the security operations platform system connects with the operations team, operations processes, and operations services to form a four-dimensional closed loop. The system is built on a five-layer network architecture and includes the following modules: Data acquisition module: Collects network-side telemetry data, terminal-side telemetry data, and third-party data respectively, and transmits and reports the collected data in JSON or file format; Data storage module: A data lake is built based on message queue middleware, distributed real-time analytical columnar storage database and distributed storage architecture to store and manage massive amounts of data; Threat detection module: performs threat detection on terminal-side capabilities, network-side capabilities, and platform capabilities respectively, and performs correlation analysis. It combines data collected from the terminal-side and network-side with cloud factors to perform timeline correlation and causal inference, and generates related events on the platform side. Business security module: Centralizes all isolated endpoint network security events and threat alerts for unified management, enables retrieval of security events based on multiple filtering criteria, and provides a security visualization center with charts and graphs; Platform open module: Based on API interface, it forms three modes of data exchange with third-party components: data reporting, linkage handling and distribution, and event alarm external transmission, and uses the App center to manage the application life cycle; Platform security module: Based on local and cloud deployment methods, it sets up three layers of protection: data isolation, access isolation, and transmission isolation. The authentication interface and data transmission interface are set up independently. The data upload of components obtains a token through the authentication interface.

[0022] In this embodiment, the five-layer network architecture is as follows: Figure 1 As shown, it includes, in sequence: Enablement layer: Configures security GPT, cloud capability center and cloud operation center to provide the system with a variety of models, intelligence and services; Application layer: Configure security monitoring, detection response, risk management, asset center, SOAR, work order, APP center and configuration strategy center; Logic layer: Provides the system with asset and vulnerability identification capabilities, detection and investigation capabilities, response and handling capabilities, and ecosystem openness capabilities; Engine layer: Configured with a multi-level engine, including a level 1 threat alert engine, a level 2 alert aggregation engine, and a level 3 event recovery engine; Data layer: Implements system metadata management and storage management based on interfaces; Security Component Layer: Configures various security components, including perimeter security components, endpoint security components, network security components, host security components, application security components, and data security components. In one specific embodiment, the security operations platform system collects telemetry data from key nodes using native traffic acquisition and endpoint acquisition tools. It then performs automated contextual analysis on the data using a network-endpoint aggregation and analysis engine to achieve deep attack chain tracing. Combined with the industry-first security domain vertical large-scale model—Security GPT—and managed detection and response services, it further frees up the time available to operations personnel. This solution also reserves scalable ecosystem open capabilities, simplifying complex processes through an APP center, openAPI interfaces, openXDR standard datasets, and collaborative capabilities such as SOAR, work orders, and IoT, delivering a security experience characterized by deep detection, accurate response, and continuous improvement. The detailed architecture of the security operations platform is as follows: Figure 1 As shown, it adopts a cloud-native architecture and canary deployment technology to achieve daily iterative deployment and verification of security capabilities, forming a constantly enhancing and iterating security capability flywheel that can quickly track and adapt to the rapid evolution of security threats. This is faster than the security capability iteration efficiency of traditional hardware security equipment vendors, enabling the entire security operations solution to quickly perceive, iterate, and respond to ever-changing security threats. The specific technology selections for each component are described below.

[0023] I. Data Collection (1) Data collection type The effectiveness of detection depends on high-quality data acquisition capabilities. Past detection equipment based on single-source data has struggled to effectively detect advanced and unknown threats. In this embodiment, the telemetry data collected by the security operations platform system is categorized into three types: network-side telemetry data, terminal-side telemetry data, and third-party data. The collected data is reported in JSON or file format, such as... Figure 2-3 As shown. The network-side telemetry data specifically includes the following information: Situational awareness: vulnerability detection, service detection, host detection, website attacks, backdoor communication, account brute-force attacks, attack exploitation, email attacks, DoS attacks, vulnerability exploitation, hacking tools, abnormal traffic; Firewall: Addressing website attacks, vulnerability exploits, business risks, DoS attacks, ransomware mining, botnets, and abnormal traffic. Probes: Protocol, NetFlow, and a small amount of payload; Situational Awareness / Firewall / Probe: Suspicious Logs; Vulnerability scanning: assets, vulnerable data.

[0024] The telemetry data from the terminal side specifically includes the following information: Antivirus / Antivirus: Traditional antivirus logs and IOA logs.

[0025] Windows: Process information, network connection, DNS lookup, registry modification, file behavior, service information, scheduled tasks, account information, WMI (Windows Management Instrumentation), application vulnerability exploitation probes, API information.

[0026] Linux: Files, processes, drivers, system calls, module events, vulnerabilities.

[0027] Third-party data specifically includes the following information: The system also includes AD domain and VPN logs, and has extensive third-party data access capabilities, enabling unified display of users' existing third-party device logs to protect users' original investments. Supports third-party vendors: NSFOCUS, Topsec, Qiming, NetGuard, Qi An Xin, AsiaInfo, DPtech, QingTeng, etc.

[0028] (2) Access API In this embodiment, the security operations platform system uses Istio as the unified access gateway. Istio, originally developed by IBM, Google, and Lyft, is a fully open-source service mesh that serves as a transparent layer connecting to existing distributed applications. It is also a platform with APIs that can integrate with any logging, telemetry, and policy system. Istio's diverse features enable the successful and efficient operation of distributed microservice architectures, providing a unified approach to protecting, connecting, and monitoring microservices. Istio offers the ability to gain behavioral insights and operational control over the entire service mesh, as well as a complete solution that meets the various needs of microservice applications. This includes basic requirements such as service discovery, load balancing, fault recovery, measurement, and monitoring, as well as more complex operational needs such as A / B testing, canary deployments, rate limiting, access control, and end-to-end authentication, exhibiting high performance and extremely high stability.

[0029] (3) Data transmission In this embodiment, the security operations platform system employs two self-developed data transmission protocols for data reporting and component linkage: Data Reporting: Telemetry data reported by network-side and terminal-side components is transmitted via a self-developed encryption protocol based on HTTP / 2 and TLS encryption, ensuring performance and security during large-volume data transmission. Data transmission supports both JSON and file upload formats. Component Interoperability: Employing a self-developed gRPC bidirectional streaming protocol, gRPC is a modern, open-source Remote Procedure Call (RPC) framework based on the HTTP / 2 protocol. It enables transparent communication between client and server applications, making it easier to build connected systems and facilitating the construction of highly visible and scalable systems. TLS encryption ensures security during transmission. The gRPC bidirectional streaming protocol allows asynchronous communication between the XDR platform and various interconnected components, such as... Figure 4 As shown, this provides a guarantee of response speed for security scenarios where "speed is paramount." Component linkage also requires authentication of unique component IDs, ensuring the security of communication between the platform and components.

[0030] (4) Data enrichment In this embodiment, due to the diverse formats of data uploaded by users to the security operations platform system, powerful parsing operators, logic processing operators, and tagging operators are provided to standardize the data parsing and ETL processes. The parsing operators currently support parsing various data formats, including CSV, KV, JSON, GROOK, regular expressions, and XML, covering most enterprise data analysis usage scenarios. Data filtering supports combinations of multiple fields and conditions to form complex filtering conditions, meeting the flexible needs of various analysis scenarios. The tagging operators can combine information such as geographic location, asset information, blacklists / whitelists, and threat intelligence to provide different options for different application scenarios, adding corresponding tags to the raw data and enriching it into structured data. Simultaneously, the data lake includes a security analysis platform that performs preliminary screening and transformation of the basic raw data collected from the network side before storage, saving storage costs and providing a foundation for subsequent analysis capabilities.

[0031] II. Data Storage In this embodiment, the security operations platform system utilizes an industry-leading data lake concept built upon Pulsar message queues, ClickHouse database, and EDS to easily handle petabyte-scale massive data. Pulsar boasts higher performance than the K firewall (ka), enabling efficient and easy data collection. ClickHouse, as a columnar database, perfectly suits the data center usage scenarios of the security operations platform system. By employing distributed storage (EDS), a global and unified data lake information platform is constructed, providing a robust data foundation for the security capabilities of the security operations platform system and offering multiple data models for more flexible application building and data querying.

[0032] (1) Message middleware In a distributed computing environment, message queues are the best practice for abstracting data input. In this embodiment, the security operations platform system largely uses Pulsar as its message queue. Pulsar employs a layered architecture, resolving the loose coupling between storage and computation, while providing excellent scalability and maintainability, and boasting higher performance than K-firewall ka. Pulsar also provides a unified message consumption model through the abstraction of the subscription layer. In particular, Pulsar's initial design emphasized multi-tenancy requirements, addressing the business needs of the security operations platform system.

[0033] In this embodiment, the security operations platform system adopts a three-layer message queue architecture design, such as... Figure 5 As shown, the first layer is the raw JSON data that is received. After enrichment, it becomes structured JSON data, which is then serialized and converted into AVRO format before being stored in the database.

[0034] When the distributed security operations platform system connects to third-party data, it still uses Kafka, which is commonly used in the industry, as the message queue, which has good scalability and openness.

[0035] (2) Data persistence The security operations platform system uses ClickHouse database to store hot data. ClickHouse is a columnar database management system (DBMS) for online analytical processing (OLAP), providing a millisecond-level log retrieval and analysis experience.

[0036] ClickHouse database advantages: Diverse Table Engines: ClickHouse abstracts the storage component, treating the storage engine as an independent interface. ClickHouse offers over 20 table engines across 6 main categories: merge tree, memory, file, interface, and others. Each table engine has its own unique characteristics, allowing users to choose the appropriate engine based on their specific business requirements. Columnar storage: Columnar storage is an essential feature for a high-performance database. ClickHouse uses columnar storage, which is highly efficient for analytical requests. Data compression: Since ClickHouse uses column storage, data in the same column belongs to the same type, which is beneficial to achieving a higher data compression ratio; ClickHouse supports general compression algorithms such as GZ and ZSTD, as well as dedicated encoding algorithms such as Delta, DoubleDelta, and Gorilla; Multi-level indexes: Columnar storage is used to trim unnecessary field reads, while indexes are used to trim unnecessary record reads. ClickHouse supports a rich set of index types, including first-level indexes and second-level indexes, thereby minimizing unnecessary record reads during queries and improving query performance. Vectorized execution engine: Based on columnar storage, ClickHouse implements a computation engine oriented towards vectorized processing. A large number of processing operations are executed in a vectorized manner, and ClickHouse can further accelerate execution efficiency by utilizing SIMD instructions. This is one of the important factors that makes ClickHouse superior to many similar OLAP products. Complete DBMS functionality: ClickHouse has complete management functions, is compatible with ANSISQL, and supports interfaces such as JDBC and ODBC. It also has functions such as access control, data backup and recovery. Approximate Query: Supports approximate query algorithms, data sampling, and other approximate query schemes to accelerate query performance.

[0037] Based on the specific business characteristics of the security operations platform system, ClickHouse can provide fast querying. It primarily stores frequently exchanged data with business operations, facilitating local computation.

[0038] (3) File object storage In this embodiment, the data lake employs Distributed Storage (EDS) for file object storage and backup / disaster recovery capabilities. EDS is a software-defined distributed storage system; each data center uses a single storage unit, offering broad application compatibility, hardware decoupling, and flexible capacity expansion. It features a tiered storage solution for hot, warm, and cold data, and provides lifecycle management strategies such as data archiving and destruction, helping the XDR platform easily handle the challenges of managing massive amounts of data. Its inherently multi-active architecture constructs a closed-loop fault handling framework encompassing pre-event, during-event, and post-event stages; simultaneously, it deeply integrates security features, incorporating a systematic data security solution to easily address advanced threats.

[0039] In the security operations platform system, it is mainly responsible for storing cold data such as file objects, and serving as a disaster recovery backup for the ClickHouse database, thereby improving the reliability of the entire data lake.

[0040] III. Threat Detection The security operations platform system's security detection capabilities primarily revolve around a "trident of capabilities"—threat detection, correlation analysis, and emergency response. Through deep coverage of these three capabilities, it delivers a complete security loop value across various security scenarios. In addition, it also possesses the capabilities to detect, integrate, and analyze risks.

[0041] (1) Threat detection capability The threat detection capabilities of a security operations platform system are reflected in three parts: endpoint-side capabilities, network-side capabilities, and platform capabilities. Terminal-side capabilities: Traditional endpoint threat detection relies primarily on rules to detect attacks, but this approach struggles to cover advanced threats such as fileless attacks, mimicry attacks, and APT attacks that span restarts and long time windows. Endpoint-based advanced threat detection capabilities utilize comprehensive data collection at the endpoint, including data on endpoints, users, files, processes, and behaviors. This data is layered locally, and only the most effective data is aggregated and uploaded to the platform. Strong contextual correlation analysis is performed based on the user's real-world environment to improve the accuracy of attack analysis. Behavioral detection is based on a multi-event complex association rule matching algorithm. By leveraging IOA (Independent Attributes) to generalize behavioral rules, it enhances the detection capabilities for both known and unknown advanced threat attacks, filling gaps in complex behavioral correlation detection, building a multi-layered behavioral defense system, and strengthening multi-layered, in-depth defense capabilities to help users effectively defend against both known and unknown advanced threat attacks.

[0042] In this embodiment, a three-level detection mechanism is adopted, which is funnel-shaped, such as... Figure 6 As shown, the system employs a three-tiered detection engine. The first tier is single-terminal event detection, which detects obvious attack behaviors on a single terminal (single-terminal single-behavior, single-terminal multiple-behavior, etc.) and outputs analysis. The second tier is multi-alarm correlation detection, which involves in-depth detection based on a large amount of correlated data to suppress false alarms. The third tier is cross-terminal multi-source detection, which recreates attack scenarios based on the correlation between data from multiple terminals and sources. Through this three-tiered detection engine, the security operations platform system outputs high-quality detection and analysis results.

[0043] Network-side capabilities: On the network side, based on traffic and log collection, preliminary analysis is performed using four rules: W Firewall, IPS, PVS Vulnerability Detection, and Threat Intelligence. This data is then labeled and feature-detected. Next, basic threat detection models from UEBA and AI are used for matching to quickly locate scenario-specific threats such as prevalent viruses, hacker tools, brute-force attacks, scanning, and DGA. For more complex and irregular combined threat attack methods, such as successful attack identification, custom tools, zero-day vulnerability exploits, proxy forwarding tools, and covert tunnels, detection is performed based on the entire session traffic. This includes a complete backtracking and correlation of traffic request echoes, abnormal feature correlations, abnormal behavior exploitation, and multi-stage attack exploitation behaviors to ultimately locate abnormal risks. Finally, based on optimized algorithm models, detection of typical encrypted traffic and zero-day vulnerability exploit features is optimized to achieve high detection rates and low false positives.

[0044] Platform capabilities: The platform's capabilities include network and endpoint alarm correlation analysis, aggregating telemetry data into storylines to drive a qualitative shift from focusing on alarms to emphasizing events. It correlates telemetry data from endpoints, networks, and the cloud to construct a complete, high-quality, scenario-based data chain, clearly presenting the entire event process. It also features cloud-based capabilities, distributing threat intelligence and expert capabilities from the cloud to user networks and endpoints. In the current security landscape where speed is paramount, cloud capabilities are updated instantly and rapidly deployed locally, reversing the previous disadvantage of defense lagging behind offense, allowing users to gain the upper hand in security confrontations. 24 / 7 cloud expert support also significantly reduces labor costs and barriers to entry for enterprise security operations, bringing time-saving, labor-saving, and worry-free user value.

[0045] The security operations platform system also includes functional detection capabilities, such as security event backscanning, which helps users review previous attacks after discovering a threat, allowing them to assess the attack's impact over a larger timeline—a crucial feature in responding to APT attacks. It also features custom rule capabilities, enabling users to write customized detection rules based on their specific business needs, resulting in more precise and flexible threat responses.

[0046] Association analysis capabilities: In this embodiment, the security operations platform system uses FlinkCEP (ComplexEventProcessing) technology as the core of its underlying data processing, combining various association rule templates to achieve complex CEP semantics. Data collected from the endpoint and network sides is correlated with cloud-based threat intelligence, assets, time, and other factors in a timeline and causal inference, ultimately generating associated events on the platform side. Below, we examine several association scenarios.

[0047] For strong signals uploaded to the security operations platform system by components (strong signals are behavioral information that only hackers would trigger, such as IOC, which are relatively rare), the security operations platform system performs strong correlation analysis (strong signal 1 + strong signal 2). The platform system provides visualization and high visibility, combined with accurate and detailed handling and response suggestions, to help security operations personnel improve efficiency and significantly reduce MTTD (Mean Time To Detect) / MTTR (Mean Time To Response).

[0048] When the signals uploaded by components to the security operations platform system vary in strength (weak signals are common in both hacker and routine maintenance scenarios, and are often gray-scale signals that are prone to false alarms), the security operations platform system improves detection accuracy through multi-factor correlation, effectively reducing the number of false alarms. For attacks that cannot be accurately detected by a single network or terminal side, such as successful Webshell uploads or successful RDP brute-force attacks, network and terminal data corroborate and complement each other, significantly improving detection accuracy.

[0049] For multiple weak signals uploaded to the security operations platform system by components, the security operations platform system will integrate them in a unified manner, improving the coverage of threat detection. Whether it is a low-risk automated script attack or a high-risk advanced persistent threat, it will have nowhere to hide under the security operations platform system.

[0050] Response and handling capabilities: The security operations platform system provides atomic response operations, such as killing processes, isolating files, disabling users, isolating terminals, restoring the registry, etc. Compared with the traditional crude shutdown and network disconnection methods, the handling methods are more precise and have less impact, avoiding significant impact on business.

[0051] In terms of response targets and filtering, the security operations platform system intelligently recommends response targets, classifying them into roles such as Attacker, C2, Scanner, and Downloader, and intelligently recommending different handling methods for different roles. It also includes built-in SOAR micro-scripts, enabling one-click handling of simple events, improving security operations efficiency and lowering the barrier to entry for operations personnel. The security operations platform system also supports custom responses; the endpoint provides custom IOA capabilities, allowing users to selectively configure capabilities and corresponding response options, customize script arrangements, and achieve SOAR-like response methods.

[0052] IV. Security Operations The security operations platform system's security business layer takes a holistic approach to security incidents, providing users with precise and concise visualizations, as well as convenient and efficient business interaction interfaces. Starting with the innovative concept of attack surface management, the security operations platform system breaks away from traditional vendor asset and vulnerability management frameworks. From an attacker's perspective, all attack points that can be exploited to launch attacks and pose security risks to the business are considered part of attack surface management, including assets, vulnerabilities, and more. This broader scope gives the security operations platform system greater initiative in attack and defense. It supports vulnerability assessments of assets, hotspot vulnerability recommendations, and self-inspection capabilities, helping users gain the upper hand in attack and defense confrontations.

[0053] The threat investigation center of the security operations platform system provides log, alarm, and event management functions, centralizing all isolated endpoint security events and threat alarms for unified management. It supports standardized tracking and management of different incidents and their handling processes through the tools and workflows provided by the security operations platform system. It allows for searching logs, alarms, and security events using various filtering criteria and enables custom modeling based on business security needs.

[0054] The security closed-loop function enables users to handle and respond to threats. The security operations platform system provides precise technical and tactical response suggestions corresponding to the ATT&CK matrix for alerts and security incidents. The platform supports one-click containment, linking firewalls and antivirus software via API interfaces to issue processing actions and complete the handling of alerts and incidents. Automated closed-loop handling can be achieved through intelligent countermeasures and SOAR, improving security operations efficiency. Work order processes enable collaboration and streamlined operations among different roles.

[0055] The device management configuration allows you to manage security components and data that interface with the security operations platform system, including third-party components. The device management page requires secondary authentication to ensure the security of the platform and its interconnected components.

[0056] The security visualization center offers a wealth of chart visualizations, including a security event overview, a monitoring dashboard, and a customizable visualization center, which can clearly show the security situation and the direction of incident handling.

[0057] V. Platform Openness If a platform lacks sufficient openness, integration may require significant modifications to existing functionality. This not only slows down project delivery and jeopardizes product stability but also incurs substantial manpower costs. Therefore, the security operations platform aims to leverage openness to enable rapid application development, meeting user needs without compromising the stability of existing system functions and fully utilizing the value of other security components.

[0058] In this embodiment, the security operations platform system provides external openness in two ways: OpenAPI and App Store.

[0059] OpenAPI, by implementing RESTful API interfaces at the underlying level, enables data exchange with third-party components in three modes: data reporting, coordinated response deployment, and event alarm dissemination. This allows third parties to develop based on the API. Data reporting is primarily used by third-party components to report their own logs, alarms, and events, which are then analyzed and displayed by the security operations platform system. Coordinated response deployment is used by the security operations platform system to deploy response policies to endpoint and network-side components during the closed-loop event handling process, performing operations such as file isolation and IP blocking. Event alarm dissemination is used by the security operations platform system to connect with other operations platforms or data centers, sending alarms or events to third-party platforms. The entire data exchange process uses standard OAuth authentication to ensure secure data transmission.

[0060] The App Store manages the entire application lifecycle, featuring pluggable, scalable, and modular decoupling. Management encompasses the entire process of application development, listing, delisting, subscription, installation, configuration, and uninstallation. A third-party application redirect is added to the front end; users select the corresponding application to subscribe to, and clicking the redirect leads directly to the third-party application's page. Simultaneously, events are synchronized to the third-party application for convenient subsequent operations. Third-party applications, such as FogBite and Moan Honeypot, can provide the security operations platform system with extended functionalities such as coordinated response and automation, vulnerability scanning and discovery, asset management, process management, threat hunting, and proactive trapping.

[0061] VI. Platform Security Testing In this embodiment, the security operations platform system serves as a scalable detection and response platform, supporting both localized and cloud-based deployments. However, its own security is paramount. For cloud-based XDR, ensuring secure data transmission, preventing leaks and theft by attackers, is of utmost importance. For the localized security operations platform system, enhancing its own security and eliminating high-risk vulnerabilities are fundamental to its survival in attack and defense scenarios. Furthermore, component authentication, data link security, and other aspects are also indispensable parts of platform security.

[0062] In terms of data security, the security operations platform system implements three layers of protection: data isolation, access isolation, and transmission isolation. Data isolation: The result data of different tenants is isolated through database namespaces. The original logs of the security operation platform system are written to ClickHouse, and different tenants are isolated through different tables (partitions). Access isolation: Different tenants access their own data through different web applications and services. Security capabilities consume data from different tenants in the data lake using different paths (tenant isolation). Transmission isolation: During transmission, logs from different tenants carry tenant IDs and enter the message queue using different tenant TOPICs (different paths).

[0063] In this embodiment, the authentication interface and the data transmission interface are independent of each other. Before a component reports data, it first needs to obtain a token through the authentication interface, which includes identity verification information, device key, etc. Before receiving data, the platform's data transmission interface will first verify the token to prevent forgery and reuse.

[0064] VII. Solution Components In this embodiment, the security operation platform system adopts a "platform + component + service" approach, supporting both cloud-based and distributed local deployment methods. Components include network traffic collection tools (next-generation firewall / threat detection probe / situational awareness), endpoint behavior collection tools (antivirus probe version / antivirus full version / antivirus), other telemetry point collection tools (container data collection tools, email data collection tools), other optional response components, and third-party components.

[0065] Latent Threat Probes: Built on an x86 hardware architecture, these probes are deployed in a bypass configuration at key nodes (switches) on the external network to collect and inspect all traffic, extracting valid data and reporting it to the security operations platform system. The probes possess IDS (Intrusion Detection System) capabilities, including rules for detecting web application attacks and exploit attacks. They can detect known threats from traffic and provide security logs to the platform. Simultaneously, a built-in abnormal behavior detection engine matches traffic in real time. When abnormal behavior is detected, traffic segments are marked in the collected traffic data and transmitted to the security operations platform system for in-depth correlation analysis to uncover potential threats.

[0066] Next-generation firewalls, based on x86 hardware architecture, are typically deployed at the egress points of the internet or data centers. As a component of a security operations platform system, they collect data on external attacks and policy violations, enabling coordinated blocking of attack sources and ACL policy control of abnormal access. This gives the security operations platform system a robust defense capability. Simultaneously, the security operations platform system's ability to detect unknown threats allows for coordinated defense against these threats and targeted policy control of vulnerable entry points, addressing the issue of egress security bypass attacks.

[0067] Endpoint Security: The endpoint security response platform provides effective protection for endpoint host security. Using this as a component, host security logs from servers / office PCs can be collected, enhancing the endpoint analysis, source tracing, and forensic capabilities of the security operations platform system. Combined with antivirus / anti-virus virus detection and removal capabilities, a closed-loop system for handling security issues can be achieved.

[0068] Vulnerability Scanning: This local vulnerability scanning product scans all assets on the internal network in a localized manner to discover vulnerabilities and risks. As a component of the security operations platform system, it provides proactive vulnerability scanning and discovery capabilities for all assets on the internal network.

[0069] In a security operations system, "people, processes, tools, and services" are four interdependent core elements that jointly support security objectives. They not only define "who does it, how to do it, what to use, and to what level," but also determine the maturity and practical effectiveness of the entire security operations.

[0070] In this embodiment, the specific applications of "personnel" include: A tiered response mechanism: First-line analysts are responsible for alarm sorting and initial handling; second-line experts conduct in-depth analysis and source tracing; and third-line teams are responsible for attack and defense drills and strategy optimization. Threat Hunting: Senior personnel proactively search for unknown threats based on the ATT&CK model, such as lateral movement and privilege escalation attacks. Knowledge Accumulation: Personnel transform their handling experience into an internal knowledge base for subsequent alarm analysis and automation rule optimization; Outsourcing and Collaboration: SMEs can acquire expert capabilities through cloud-based (managed security services) services, forming a hybrid "internal + external" operation model.

[0071] Specific applications of the process include: Standardized emergency response procedures: Develop emergency plans to ensure rapid response to incidents such as phishing emails, weak password brute-force attacks, and virus infections; Automated closed-loop process: The SOAR platform automates alarm classification, work order dispatch, handling actions, and result feedback, thereby reducing MTTR (Mean Time To Be Received). Vulnerability management process: From asset identification, vulnerability scanning, priority assessment to patching, forming an automated closed loop to reduce the attack window period; Continuous process optimization: Based on indicators such as false alarm rate, false negative rate, and processing time, the process rules and detection thresholds are adjusted regularly.

[0072] Specific applications of the tool include: Security Operations Platform System + GPT Combination: Responsible for centralized log analysis and correlation analysis, providing visibility of endpoints and network behavior, and enabling automated response; Threat Intelligence: Aggregates internal and external threat intelligence to help analysts quickly determine attackers' intentions and methods; Automated scanning and remediation: Integrates tools such as OWASPZAP and Burp to automatically detect web vulnerabilities and link with the patching system for remediation; Abnormal behavior detection: UEBA is used to identify abnormal employee access behavior, such as accessing the core database late at night or downloading sensitive files in batches.

[0073] Specific applications of the service include: Managed Security Services (Cloud): Provides 24 / 7 SOC services, including alert monitoring, incident response, vulnerability management, threat intelligence, etc. Safety training services: Through methods such as simulated fishing platforms and safety awareness courses, we quantify employees' safety awareness and incorporate it into performance evaluations; Operational support platform services: Integrating strategies, personnel, tools, and processes to form a unified delivery capability.

[0074] In this embodiment, the telemetry data structures and semantics of the network and terminals are different, and the event types of different terminal operating systems are also different. How to detect, analyze, and trace attacks more quickly and accurately through deep integration of network telemetry data is the core capability of the security operations platform system. The first step is to establish a unified data model, integrating multi-source heterogeneous data from the network to accurately describe events occurring in cyberspace. Subsequent analysis, detection, tracing, and display will all be based on this unified data model, which is one of the innovations of the security operations platform system compared to traditional SOCs and SIEMs. The telemetry data processed by the security operations platform system has three main characteristics: Multi-source: E (endpoint side) + N (network side) + X (extension); Heterogeneous: Inconsistent data types / fields; Tiered: Probe-side analysis / XDR platform correlation / Cloud analysis.

[0075] Traditional approaches to alarm classification based on local data are limited by their difficulty in understanding attacker intent and their heavy reliance on professional analysis. Threat intelligence and contextual understanding, on the other hand, provide a more direct understanding of attacker intent and the potential harm of attacks, offering a more automated and accurate classification capability.

[0076] The security operations platform system uses a Provenance Graph (also known as a Dependency Graph) as the basic architecture for its data model. This graph is not a traditional picture, but a topological graph composed of countless nodes and edges. For data collected from the endpoint, nodes are processes, files, registry entries, IP addresses, DNS servers, memory, scheduled tasks, etc., while edges are system-level events. For data collected from the network, nodes are cloud, network, and endpoint nodes within the network topology, while edges are interconnected network traffic. The Provenance Graph records all behaviors occurring in the user's environment in chronological order, essentially stringing all data in the user's network into a single graph.

[0077] The security operations platform system uses FlinkCEP (ComplexEventProcessing) technology as the core of its underlying data processing, combining various association rule templates to achieve complex CEP semantics. CEP is an analysis technology based on event streams in dynamic environments, where events typically represent meaningful state changes. By analyzing the relationships between events and utilizing techniques such as filtering, association, and aggregation, detection rules are formulated based on the temporal and aggregation relationships between events. This continuously retrieves matching event sequences from the event stream, ultimately leading to more complex composite events. CEP can also enable the creation of complex attack detection rules across terminals and networks, continuously providing attack detection rules for different attack scenarios, resulting in security effects far exceeding those of independent endpoint and network components. The mutual corroboration of network-side and endpoint-side data improves the accuracy of most alarm assessments, thus solving the operational challenges of massive false alarms and overwhelming response times associated with traditional single-point security components. Simultaneously, the complementary information from both sides provides a foundation for enriching security event data, allowing security events to display more dimensions of data and information, thereby making the assessment and response of operations personnel more efficient and effective.

[0078] The security operations platform system achieves seamless fusion of alarms according to security semantics. It incorporates hundreds of fine-grained alarm fusion strategies by combining user network topology, assets, vulnerabilities, patches, weak configurations, and whitelisted service access relationships. During the fusion process, it provides layer-by-layer causal evidence and elastic aggregation to highlight truly high-risk attacks. This facilitates timely and closed-loop handling of genuine risks, thereby eliminating alarm fatigue, significantly reducing the workload of incident handling, improving handling efficiency, and enhancing the ability to make decisions and command regarding security threats.

[0079] It has the capability to reduce and merge multi-source alarms, and can perform deep aggregation and merging of alarms based on dimensions such as payload similarity, similar attacks launched by a single attack source against multiple targets, and similar attacks launched by multiple attack sources against a single target. For the same attack behavior, multiple security alarms generated by different security devices can be associated and merged into a single alarm. Clicking on the alarm will show multiple third-party sub-alarms. Alarms that are scattered across the end and network at different stages of the same security event can be aggregated into a single event. The evidence page of the merged security alarm can display evidence fields from different data sources.

[0080] The security operations platform system is also configured with Alarm merging technology: The overall strategy for alarm merging is to first refine and compress the effective information, and then provide richer contextual evidence through multi-dimensional data to achieve the ultimate noise reduction effect; Network-side alarm merging technology: (1) Relationship between security logs and security alarms Security Log: A security log is generated every time a rule is triggered; Security alerts: Large amounts of security logs are difficult to analyze. To improve efficiency, multiple security logs are merged into a single alert. The merging strategy uses two dimensions: IP address and rules. For example, if A->B initiates SQL injection multiple times, generating multiple security logs, these multiple triggers can be merged into a single A->B SQL injection alert. Traditionally, the source IP, destination IP, and rule ID are used as the merging key. For example, if A triggers rule 1 SQL injection on B, and C triggers rule 1 SQL injection on B, another alarm will be generated. If A triggers rule 2 SQL injection on B, another alarm will be generated.

[0081] Terminal-side alarm merging technology: Noise reduction on the terminal side can be divided into two main categories: traditional virus detection and removal, and advanced threat detection. 1. Traditional virus scanning: Only provides virus scan alerts, with key factors including virus path, virus name, and virus file hash. Similar to the aggregation logic of network-side alerts, it is divided into two cases: unique hash and unique virus category.

[0082] a) Unique HASH: Most viruses, such as mining viruses and Trojans, can be aggregated using HASH + file path as a unique identifier, so that the same virus file will not be repeatedly alerted. b) Unique Virus Category: Infectious viruses can affect multiple normal files or programs during the infection process, causing traditional antivirus software to issue numerous alerts, leading to alert fatigue and difficulty in identifying the key viruses. Such viruses require aggregation using both asset and virus category as unique identifiers, thus relying on accurate virus category identification.

[0083] 2. Advanced Threat Alerts: Advanced threat alerts are presented to users in the form of a "process tree," possessing a certain degree of temporal and spatial uniqueness. Therefore, the tracing and growth process of the process tree is itself part of noise reduction, associating discrete behavioral information in the environment into a tree, giving discrete behaviors a higher level of semantics. Secondly, this "process tree" will continue to grow over time, so how to handle "growth" is also one of the key points of noise reduction. If a node on a process tree performs a suspicious behavior, the corresponding "tree" position needs to be found on the client side, attached, and sent to XDR. XDR needs to process the differences between this tree and the original tree and merge them, presenting the overall "growth" effect, ultimately presenting only a complete process tree to the user.

[0084] 3. Advanced threat + traditional virus scanning: If a node in the process tree also triggers a traditional virus scan, the scan alert will be merged into this process tree, ultimately achieving a unified system. You only need to check this process tree to know what threats have occurred on the client.

[0085] Invalid Log Filtering: Alarms generated by security devices can be categorized into three types. The first type is frequent, recurring alarms caused by internal network services triggering security device detection rules. For example, improper business design may result in business requests containing SQL statements, which can easily trigger false SQL injection attacks. The second type is massive scanning and vulnerability probing traffic initiated by botnet hosts on the internet. The third type is real attacks, but the sheer volume of the first two types of alarms often overwhelms the presence of genuine attacks.

[0086] In this embodiment, the security operations platform system incorporates a behavioral baseline learning engine and a time-series anomaly detection engine. It automatically learns the alarm triggering patterns of each business system, and based on these learned patterns, it establishes a baseline for the time and alarm behavior of the document server. Alarms conforming to this baseline are highly likely to be non-attack alarms triggered by normal business operations, while those deviating from the baseline are highly likely to be attack alarms. Through this method, business-triggered alarms can be quickly filtered out, significantly improving operational efficiency.

[0087] For the foregoing embodiments, in order to simplify the description, they are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, because according to this application, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to this application.

[0088] The above embodiments describe the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Modifications and variations made by those skilled in the art without departing from the spirit and scope of the invention should be within the protection scope of the appended claims.

Claims

1. A security operation platform system based on a four-dimensional closed loop, which connects the operation team, operation processes, and operation services to construct a four-dimensional closed loop, characterized in that, The system is built on a five-layer network architecture and includes the following modules: Data acquisition module: Collects network-side telemetry data, terminal-side telemetry data, and third-party data respectively, and transmits and reports the collected data in JSON or file format; Data storage module: A data lake is built based on message queue middleware, distributed real-time analytical columnar storage database and distributed storage architecture to store and manage massive amounts of data; Threat detection module: performs threat detection on terminal-side capabilities, network-side capabilities, and platform capabilities respectively, and performs correlation analysis. It combines data collected from the terminal-side and network-side with cloud factors to perform timeline correlation and causal inference, and generates related events on the platform side. Business security module: Centralizes all isolated endpoint network security events and threat alerts for unified management, enables retrieval of security events based on multiple filtering criteria, and provides a security visualization center with charts and graphs; Platform open module: Based on API interface, it forms three modes of data exchange with third-party components: data reporting, linkage handling and distribution, and event alarm external transmission, and uses the App center to manage the application life cycle; Platform security module: Based on local and cloud deployment methods, it sets up three layers of protection: data isolation, access isolation, and transmission isolation. The authentication interface and data transmission interface are set up independently. The data upload of components obtains a token through the authentication interface.

2. The security operation platform system based on a four-dimensional closed loop as described in claim 1, characterized in that, The five-layer network architecture includes, in sequence: Enablement layer: Configures security GPT, cloud capability center and cloud operation center to provide the system with a variety of models, intelligence and services; Application layer: Configure security monitoring, detection response, risk management, asset center, SOAR, work order, APP center and configuration strategy center; Logic layer: Provides the system with asset and vulnerability identification capabilities, detection and investigation capabilities, response and handling capabilities, and ecosystem openness capabilities; Engine layer: Configured with a multi-level engine, including a level 1 threat alert engine, a level 2 alert aggregation engine, and a level 3 event recovery engine; Data layer: Implements system metadata management and storage management based on interfaces; Security Component Layer: Configures various security components, including perimeter security components, endpoint security components, network security components, host security components, application security components, and data security components.

3. The four-dimensional closed-loop-based security operation platform system as described in claim 2, characterized in that, The data acquisition module specifically comprises: API Access Submodule: Runs a distributed microservice architecture based on the access gateway and integrated API interfaces; Data transmission submodule: Configure data transmission protocols for data reporting and component linkage respectively; configure the telemetry data reporting of network-side and terminal-side components with HTTP / 2 and TLS encryption protocols; configure gRPC bidirectional stream protocol based on HTTP / 2 for component linkage, and set a unique component ID for authentication; The data enrichment submodule configures parsing operators, logical processing operators, and labeling operators to parse and standardize the various forms of data uploaded by users to the system. At the same time, it performs preliminary screening, transformation, and storage of basic raw data collected from the network side based on the data lake.

4. The four-dimensional closed-loop-based security operation platform system as described in claim 2, characterized in that, The data storage module specifically comprises: Message middleware submodule: Based on Pulsar middleware, a three-layer message queue is built, consisting of raw JSON data, enriched JSON data, and serialized data converted to AVRO format and finally stored in the database. The data persistence submodule uses a distributed, real-time analytical columnar storage database to store hot data and provides multi-level retrieval and approximate queries. The file object storage submodule stores cold data based on a distributed storage architecture and performs file object storage, backup, and disaster recovery.

5. A safety operation platform system based on a four-dimensional closed loop as described in claim 2, characterized in that, The threat detection capabilities of each side in the threat detection module specifically include: Terminal-side capabilities: Collect comprehensive data from the terminal side, perform local layering and aggregate effective data before uploading it to the platform, combine it with the user's real environment to perform strong contextual correlation analysis, and use a funnel-shaped three-level detection mechanism for behavior detection to output detection results; the three-level detection mechanism includes the first level of single terminal event detection, the second level of multi-alarm correlation detection, and the third level of cross-terminal multi-source detection. Network-side capabilities: Based on traffic and log collection, configure multiple rules for preliminary analysis, data labeling, and feature detection; use threat detection models to quickly locate scenario threats; perform full backtracking and correlation based on the entire session traffic to locate abnormal risks; and configure feature-based optimization detection based on optimization algorithm models. Platform capabilities include alarm correlation analysis of network and endpoints, linking endpoint, network and cloud telemetry data through storylines to build a complete, high-quality, scenario-based data chain, and empowering the platform by delivering cloud-based threat intelligence and expert capabilities to user networks and endpoints.

6. A safety operation platform system based on a four-dimensional closed loop as described in claim 2, characterized in that, In the platform open module: The data reporting is based on the logs, alarms, and events reported by third-party components, and is used to analyze the display scenarios. The coordinated handling dispatch is used by the platform system to dispatch handling strategies to the terminal and network side components when the event handling is closed-loop; The event alarm external transmission is used for the platform system to connect with other operating platforms or data centers to transmit alarms or events to third-party platforms; The application management in the App Center includes the entire application process. It adds a redirect to a third-party application on the front end. Users select the corresponding application to subscribe to, and after clicking the redirect, they are directly taken to the page of the third-party application. At the same time, the event is synchronized to the third-party application.

7. A safety operation platform system based on a four-dimensional closed loop as described in claim 2, characterized in that, The platform security module's three layers of protection are as follows: Data isolation: The result data of different tenants is isolated through database namespaces. The platform system's raw logs are written to a distributed real-time analytical columnar storage database, and different tenants are isolated through different tables and partitions. Access isolation: Different tenants access their own data through different web applications and services. Security capabilities ensure that different tenants use different paths to isolate tenants when consuming data from the data lake. Transport isolation: During transmission, logs from different tenants carry tenant IDs and enter the message queue using different tenant paths.

8. A safety operation platform system based on a four-dimensional closed loop as described in claim 2, characterized in that, The system is also configured with a variety of components, including: network traffic collection tools, endpoint behavior collection tools, other telemetry point collection tools, other optional response components, and third-party components.