An automated cyber-attack proactive emergency response system
The automated proactive emergency response system for network attacks solves the problem of insufficient perception of deep network topology deformation in existing technologies, realizes the forward prediction and efficient defense against potential multi-step attacks, generates a stable response strategy that balances defense effectiveness and business continuity, and ensures the collaborative defense and response reliability of network devices.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING TAIJI HUAQING INFORMATION SYST CO LTD
- Filing Date
- 2026-03-31
- Publication Date
- 2026-06-12
Smart Images

Figure CN122204491A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, and in particular to an automated proactive emergency response system for network attacks. Background Technology
[0002] As cyberattack methods become increasingly sophisticated, modern network security defense systems typically deploy multiple data acquisition nodes across the target network environment to simultaneously acquire heterogeneous network communication packets and terminal host operation logs. Traditional defense mechanisms primarily rely on shallow statistical feature extraction and static rule base matching of network traffic data. By monitoring conventional dimensions such as packet arrival rate and payload length, combined with known threat signatures, abnormal communication is identified, generating single-point security alert events. Finally, these events are handed over to the security orchestration system to execute preset network isolation or action interception commands.
[0003] However, existing technologies lack effective perception of the geometric deformation of deep network communication connections, making it difficult to capture structural mutations in concealed abnormal traffic. Furthermore, they fail to establish mathematical models that characterize the causal relationship and spatiotemporal decay characteristics among heterogeneous security alarms, thus severing the cascading evolution of multi-step network attacks and limiting themselves to passive interception after the fact, making it difficult to make forward-looking predictions of the probability of target nodes being attacked. Summary of the Invention
[0004] To overcome the above shortcomings, this invention provides an automated proactive emergency response system for network attacks, aiming to improve the problem of existing technologies lacking deep perception of network topology deformation.
[0005] This invention provides the following technical solution: an automated proactive emergency response system for network attacks, comprising:
[0006] The data acquisition module is used to acquire heterogeneous security alarm data and network traffic data in the target network environment;
[0007] The topology feature extraction module is used to perform topology data analysis on the network traffic data and extract the continuous homology parameters of the network traffic data in a multi-layer feature space.
[0008] The attack probability prediction module is used to fuse the heterogeneous security alarm data with the continuous coherence parameter into a discrete event sequence, input a preset multidimensional Hawkes process model, calculate the topological excitation matrix and time decay factor between the discrete event sequences, and generate the expected probability distribution of network nodes in the target network environment that will be attacked within a preset time window.
[0009] The game model construction module is used to construct an asymmetric evolutionary game model based on the expected probability distribution and initialize a strategy population containing multiple candidate response scenarios.
[0010] The strategy evolution optimization module is used to calculate the fitness function value based on the blocking success rate and service interruption loss corresponding to the multiple candidate response scripts, and use the replier dynamic equation to iteratively update the adoption probability of each candidate response script in the strategy population based on the fitness function value to obtain the converged evolutionary stable strategy.
[0011] An automated orchestration execution module is used to generate automated orchestration instructions based on the evolutionary stabilization strategy, and drive network devices in the target network environment to execute the defensive actions indicated by the evolutionary stabilization strategy.
[0012] Preferably, in the data acquisition module, the step of acquiring heterogeneous security alarm data and network traffic data in the target network environment includes:
[0013] Deploy multi-source data acquisition nodes to synchronize network communication packets in the target network environment with the security operation logs of terminal hosts in the target network environment according to a preset acquisition cycle;
[0014] The time synchronization protocol is used to align the timestamps of the collected multi-source heterogeneous data, and the data format is standardized and noise is removed according to preset rules.
[0015] A unified feature mapping space is constructed, and the standardized security alarm information and network traffic data are encapsulated into a structured initial feature matrix to complete the acquisition of the heterogeneous security alarm data and network traffic data.
[0016] Preferably, in the topology feature extraction module, the step of extracting the continuous homology parameters of the network traffic data in a multi-layer feature space includes:
[0017] The network traffic data is projected into a point cloud set within the multi-layer feature space, and the corresponding multi-layer simplex is constructed based on the discrete extended connected radius threshold sequence.
[0018] The homology groups of the multilayer simplex at different connectivity radius scales are calculated using algebraic topology algorithms, and a continuous bar chart is generated to record the life cycle of the network's geometric structure evolution.
[0019] Feature extraction encoding is performed on the persistent bar graph to quantify the lifetime span and distribution density of the cohomology generators, and the persistent cohomology parameters are output to characterize the topological deformation of the communication network.
[0020] Preferably, in the attack probability prediction module, the step of fusing the heterogeneous security alarm data with the continuous coherence parameter into a discrete event sequence includes:
[0021] The continuous coherence parameters are sampled in the time domain based on a dynamic time window mechanism to quantitatively evaluate the dynamic mutation rate of network topology features between adjacent time windows.
[0022] A sensitivity threshold is set for the dynamic mutation rate. When the gradient of the dynamic mutation rate crosses the sensitivity threshold, a topological anomaly event stamp representing the characteristics of abnormal network connections is generated.
[0023] Based on the time sequence of occurrence, the topological anomaly event stamps and the heterogeneous security alarm data are aligned and logically concatenated according to the time dimension features to construct the discrete event sequence containing multi-dimensional threat features.
[0024] Preferably, in the attack probability prediction module, the step of calculating the topological excitation matrix and time decay factor among the discrete event sequences includes:
[0025] Establish a multivariate conditional strength function to characterize the effect of security alarm data that has occurred on the induction of subsequent heterogeneous events, and initialize a baseline strength vector that characterizes the basic anomaly frequency of the target network environment;
[0026] By introducing a network node spatial distance parameter and an exponential decay function, a time decay factor is constructed to measure the decay rate of alarm impact over time and space.
[0027] The multivariate conditional intensity function is fitted with parameters using a parameter optimization algorithm to solve for the topological excitation matrix that quantifies the probability of causal association between heterogeneous network attack events.
[0028] Preferably, in the game model construction module, the step of constructing an asymmetric evolutionary game model based on the expected probability distribution includes:
[0029] Define a hybrid strategy space containing multiple adversarial paths, and map the expected probability distribution to an initial probability vector of the attacker taking different network attack paths;
[0030] Based on the asset value and node vulnerability exploitation difficulty of the target network environment, the gain and cost parameters of each adversarial path in the hybrid strategy space are quantitatively allocated.
[0031] A mathematical payoff matrix for the defense side is established, and the payoff matrix is mapped and integrated with the strategy population and the initial probability vector to complete the construction of the asymmetric evolutionary game model.
[0032] Preferably, in the strategy evolution optimization module, the step of calculating the fitness function value based on the blocking success rate and service interruption loss corresponding to the multiple candidate response scripts includes:
[0033] By combining a pre-set external threat intelligence database and network node access control policies, the interception effectiveness of each candidate response script on the predicted attack path is evaluated through simulation, and a quantified blocking success rate is generated.
[0034] Traverse the service dependency graph of the target network environment, calculate the number of service interruption nodes of associated nodes caused by the execution of isolation operations of each candidate response script, and convert it into the quantified service interruption loss;
[0035] A nonlinear benefit evaluation equation is constructed, and the security gain brought by the blocking success rate and the penalty caused by the business interruption loss are weighted and summed to output the fitness function value of each candidate response script.
[0036] Preferably, in the strategy evolution optimization module, the step of iteratively updating the adoption probability of each candidate response script in the strategy population based on the fitness function value using the replicon dynamic equation includes:
[0037] Based on the current adoption probability of each candidate response script in the strategy population and its corresponding fitness function value, calculate the overall average fitness expectation of the defense strategy population.
[0038] The representation strategy is constructed using the dynamic equation of the replier whose probability evolves over time, so that the adoption probability of candidate response scripts whose fitness function value is higher than the expected comprehensive average fitness value shows a positive increase.
[0039] The dynamic equation of the replicator is solved iteratively in discrete time steps using a numerical integral approximation algorithm until the probability change rate of the policy population converges to near zero, thus completing the iterative update of the adoption probability.
[0040] Preferably, in the automated orchestration and execution module, the step of driving network devices in the target network environment to execute the defensive actions indicated by the evolutionary stabilization policy includes:
[0041] Semantic parsing is performed on candidate response scripts whose response probability weights in the evolutionary stabilization strategy meet the preset threshold conditions, and they are translated into machine-readable configuration scripts compatible with the standard interface of the network device.
[0042] The machine-readable configuration script is concurrently distributed to the hardware firewall and host terminal deployed at the boundary of the target network environment and the preset subnet segment via a preset message middleware bus.
[0043] A status monitoring process is established to monitor the network device's action execution confirmation receipt in real time. If execution is blocked, a preset configuration rollback operation is triggered to restore the network communication link status and complete the driving of the defense action.
[0044] The present invention has the following beneficial effects:
[0045] 1. In this invention, by integrating topological data analysis under multi-layer feature space with multi-dimensional Hawkes process, the geometric mutation characteristics of hidden network traffic are extracted, the causal cascade and spatiotemporal decay relationship between heterogeneous security alarm events is effectively quantified, the limitations of traditional passive defense are broken, and efficient forward prediction of the probability of potential multi-step attacks in the target network is achieved.
[0046] 2. In this invention, an asymmetric evolutionary game model and a replicator dynamic equation are introduced to quantify and map the value of network assets and the difficulty of exploiting vulnerabilities to a payoff matrix. When optimizing a strategy, the gains from security blocking and the costs of business interruption are comprehensively weighed, thereby automatically deducing an evolutionary stable response strategy that balances the highest defense effectiveness and business continuity under complex threat situations.
[0047] 3. In this invention, an automated orchestration and execution workflow is constructed from policy parsing to concurrent command issuance. The defense policy is accurately translated into a script readable by the underlying network device. With the addition of status monitoring and configuration rollback mechanisms, it not only ensures efficient collaborative defense response of heterogeneous security devices, but also avoids the business risk of basic network paralysis due to obstruction of action execution. Attached Figure Description
[0048] Figure 1 This is an architecture diagram of an automated proactive emergency response system for network attacks proposed in this invention. Detailed Implementation
[0049] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0050] In embodiments of the present invention, the present invention provides an automated proactive emergency response system for network attacks, such as... Figure 1 As shown, it includes:
[0051] The data acquisition module is used to acquire heterogeneous security alarm data and network traffic data in the target network environment;
[0052] Furthermore, in the data acquisition module, the steps for acquiring heterogeneous security alarm data and network traffic data in the target network environment include: deploying multi-source data acquisition nodes, synchronizing network communication packets and security operation logs of terminal hosts in the target network environment according to a preset acquisition cycle; aligning the timestamps of the acquired multi-source heterogeneous data using a time synchronization protocol, and performing data format standardization and noise reduction processing according to preset rules; constructing a unified feature mapping space, encapsulating the standardized security alarm information and network traffic data into a structured initial feature matrix, and completing the acquisition of heterogeneous security alarm data and network traffic data.
[0053] Specifically, multi-source data acquisition nodes are deployed at the border gateways, aggregation switches, and various terminal hosts in the target network environment. Network communication packets are collected through port mirroring of the switches or network traffic sampling protocols to achieve bypass monitoring. Security operation logs of the terminal hosts are captured through the operating system's built-in log collection service or a separately deployed agent. The system sets a fixed time span as the preset acquisition period. The multi-source data acquisition nodes truncate the continuously generated data stream into discrete data batches according to this preset acquisition period and send them synchronously to the centralized data processing terminal.
[0054] The receiving end uses Network Time Protocol (NTP) to timestamp-align the collected multi-source heterogeneous data, uniformly converting the raw time records generated by different network node devices into Coordinated Universal Time (UTC) to eliminate clock drift errors between devices. Subsequently, noise reduction and data format standardization are performed according to preset rules. Noise reduction involves filtering out common Address Resolution Protocol (ARP) broadcast packets and routine operational status heartbeat logs from the local area network using static rule matching. Data format standardization involves extracting key data fields from the complex raw heterogeneous data, including source and destination Internet Protocol (IP) addresses, network port numbers, network layer protocol types, security event risk levels, and operation command categories.
[0055] A unified feature mapping space is constructed, encapsulating standardized security alert information and network traffic data into a structured initial feature matrix. The characteristics existing in the target network environment are defined. For each network node, within a preset acquisition period time window, the feature mapping process is represented by a mapping function. Vectorization transformation of node data. Let the first... The standardized network traffic feature vector of each network node within the current time window is: The data includes quantified values for message arrival rate, average payload length, and connection duration, arranged in sequence; the corresponding standardized security alarm feature vector is... The data includes, in order, quantified values for the frequency of high-risk alarm triggers and the number of abnormal login attempts. A comprehensive feature vector for this network node is constructed through feature fusion. The calculation formula is as follows:
[0056] ;
[0057] In the formula, Indicates the first The comprehensive feature vector of each network node. Represents a standardized network traffic feature vector. Represents a standardized security alarm feature vector, with the symbol... This represents the vector concatenation operation. This represents the preset alarm weight scaling factor, used to balance the differences in dimensions and impact levels between traffic characteristics and alarm characteristics. It iterates through all... Each network node generates a composite feature vector, which is then stacked row-wise according to the node number to ultimately generate a structured initial feature matrix. Its matrix expression is:
[0058] ;
[0059] In the formula, This represents the structured initial feature matrix generated within the preset acquisition period time window. This represents the total number of network nodes in the target network environment. Indicates the first The comprehensive feature vector of each network node.
[0060] This step effectively integrates multi-source heterogeneous raw information from the underlying network environment and realizes the structured mapping of multi-dimensional data, providing high-quality data input with consistent standards and time series alignment for subsequent topology feature extraction.
[0061] The topology feature extraction module is used to perform topology data analysis on network traffic data and extract the continuous homology parameters of network traffic data in multiple feature spaces.
[0062] Furthermore, in the topology feature extraction module, the step of extracting the persistent homology parameters of network traffic data in a multi-layer feature space includes: projecting the network traffic data into a point cloud set in a multi-layer feature space, and constructing the corresponding multi-layer simplex based on a discrete extended connected radius threshold sequence; using an algebraic topology algorithm to calculate the homology group of the multi-layer simplex at different connected radius scales, generating a persistent bar chart that records the lifecycle of the network geometric structure evolution; performing feature extraction encoding on the persistent bar chart, quantifying the lifetime span and distribution density of the homology generators, and outputting persistent homology parameters used to characterize the topological deformation of the communication network.
[0063] Specifically, each row vector in the structured initial feature matrix output by the data acquisition module is mapped to a data point in a high-dimensional multi-layer feature space. All data points corresponding to network nodes collectively constitute a point cloud set representing the current network state. A discrete expansion connectivity radius threshold sequence is set, starting at zero and increasing sequentially to a preset maximum connectivity radius. For each given threshold in the connectivity radius threshold sequence, the Euclidean distance between any two data points in the point cloud set is calculated. When the distance is less than or equal to the given threshold, a topological edge is added between the corresponding two network nodes. Based on this connection rule, as the connectivity radius threshold gradually increases, a multi-layered simplex complex structure composed of vertices, edges, triangles, and high-dimensional polyhedra continuously grows and contains each other, forming a simplex complex filtering sequence representing the evolution of the tightness of network space communication connections. Let the point cloud set be... The connectivity radius threshold is The constructed simple complex The formula for determining this is:
[0064] ;
[0065] In the formula, This indicates that the connectivity radius threshold is... Simple complexes constructed at that time, Represents a set of point clouds Simplex subsets in and Let represent the feature vectors of any two network nodes in the simplex subset. This represents the Euclidean distance between the two feature vectors in the multi-layer feature space.
[0066] The boundary matrix of the aforementioned simplex filtering sequence is calculated using matrix reduction algorithms in algebraic topology, solving for the homology groups of various orders under different connectivity radius scales in the multi-layer simplex. This process mainly focuses on the zero-order homology group representing isolated network terminals and clustered states, and the first-order homology group representing anomalous communication loops. As the connectivity radius increases, the initial connectivity radius of each topological feature structure is recorded as the birth time of the homology generator, and the connectivity radius when the topological feature structure merges and disappears with other structures is recorded as the extinction time. The birth and extinction times of all homology generators are mapped to a set of line segments on a two-dimensional plane, generating a continuous bar graph recording the life cycle of the network geometric structure evolution.
[0067] Feature extraction encoding is performed on the generated persistent bar chart to quantify topological deformation. Let the first... The first homology group The time of birth of each homogeneous generator is The time of extinction was The lifetime span of the cohomology generator is calculated, and extremely short segments with lifetime spans below a preset noise threshold are removed to filter out interference from normal network fluctuations. Then, the sum of the lifetime spans and lifetime distribution density of the remaining cohomology generators after filtering are calculated and combined into a continuous cohomology parameter. The quantization calculation formula is defined as follows:
[0068] ;
[0069] ;
[0070] ;
[0071] In the formula, Indicates the first The lifetime span of a homology generator. Indicates the time of birth. Indicates the time of extinction. This indicates the number of elements retained after noise filtering. The total number of homohomological generators of order 1, Indicates the first The cumulative topological deformation energy of a homology group is the sum of its lifetime span. Indicates the first The distribution density parameters of the homology group of order [order] within its effective lifetime. Finally, [the distribution density parameters of the homology group of the specified order] will be... and The features are concatenated into a continuous feature vector, and the output is a continuous cohomology parameter used to characterize the topological deformation of the communication network.
[0072] This step extracts the geometric connectivity features of network traffic in deep space, enabling a numerical representation of global topological anomalies caused by complex and covert network attack behaviors.
[0073] The attack probability prediction module is used to fuse heterogeneous security alarm data with continuous coherence parameters into discrete event sequences. It inputs a preset multidimensional Hawkes process model, calculates the topological excitation matrix and time decay factor between discrete event sequences, and generates the expected probability distribution of network nodes in the target network environment that will be attacked within a preset time window.
[0074] Furthermore, in the attack probability prediction module, the step of fusing heterogeneous security alarm data with continuous coherence parameters into a discrete event sequence includes: performing time-domain slicing sampling on the continuous coherence parameters based on a dynamic time window mechanism to quantitatively evaluate the dynamic mutation rate of network topology features between adjacent time windows; setting a sensitivity threshold for the dynamic mutation rate, and generating a topology anomaly event stamp characterizing abnormal network connection features when the gradient of the dynamic mutation rate crosses the sensitivity threshold; and aligning and logically concatenating the topology anomaly event stamp with the heterogeneous security alarm data in the time dimension according to the time occurrence sequence to construct a discrete event sequence containing multi-dimensional threat features.
[0075] Furthermore, in the attack probability prediction module, the steps for calculating the topological excitation matrix and time decay factor between discrete event sequences include: establishing a multivariate conditional strength function characterizing the effect of existing security alarm data on the induction of subsequent heterogeneous events, and initializing a baseline strength vector representing the basic anomaly frequency of the target network environment; introducing a network node spatial distance parameter and an exponential decay function to construct a time decay factor to measure the decay rate of alarm impact over time and space; and using a parameter optimization algorithm to fit the parameters of the multivariate conditional strength function to solve for the topological excitation matrix that quantifies the causal correlation trigger probability between heterogeneous network attack events.
[0076] Specifically, based on a dynamic time window mechanism, the continuous coherence parameters output by the front-end module are sampled in the time domain, dividing the continuously running network time into a fixed-length time slice sequence. For two adjacent time windows, the dynamic mutation rate of the network topology characteristics is quantitatively evaluated. Let the current time window be... The continuous cohomology parameter vector extracted from each time window is: The previous one The continuous cohomology parameter vector extracted from each time window is: Construct dynamic mutation rate The calculation formula is:
[0077] ;
[0078] in the formula This represents the dynamic mutation rate of network topology features within the current time window. This represents the persistent cohomology parameter vector for the current time window. This represents the continuous cohomological parameter vector of the previous time window, and the double vertical bar symbol indicates that the Euclidean norm of the parameter vector is taken.
[0079] A sensitivity threshold is set for the dynamic mutation rate, and the system monitors the gradient of the dynamic mutation rate in real time. When the calculated dynamic mutation rate crosses the preset sensitivity threshold, the system determines that the current network geometry has undergone abnormal deformation, and generates a topology anomaly event stamp characterizing the abnormal network connection. Subsequently, according to the real-world time sequence, the generated topology anomaly event stamp is aligned and logically concatenated with heterogeneous security alert data such as firewall interception logs and host intrusion detection alarms obtained from the network environment. Each record includes the occurrence time, event type, and the identifier of the network node to which it belongs, thereby constructing a discrete event sequence containing multi-dimensional threat characteristics.
[0080] The constructed discrete event sequence is input into a pre-defined multidimensional Hawkes process model. A multivariate conditional strength function is established to characterize the effect of existing security alert data on the induction of subsequent heterogeneous events, and a baseline strength vector characterizing the basic anomaly frequency of the target network environment is initialized. Multiple attack and anomaly event types are defined in the system, and the first... Class events at time And located in network nodes The conditional intensity function at the location is The calculation formula is as follows:
[0081] ;
[0082] in the formula Represents the multivariate conditional strength function. Represents network nodes The occurrence of the first The baseline strength vector parameter of a class of events is the base attack frequency. Representing historical events The time of occurrence, Representing historical events Security incident types, Representing historical events The source network node where it occurred, This indicates the type of quantization preceding event in the topological excitation matrix to be solved. Types of events that trigger subsequent events Probability matrix elements, This represents the time decay factor function.
[0083] By introducing a network node spatial distance parameter and an exponential decay function, a time decay factor is constructed to measure the rate at which the impact of alarms propagates and decays over time and space. Let the time interval be... Spatial distance parameters Characterizing network nodes With network nodes Shortest route hop count and time decay factor in network topology. The calculation formula is:
[0084] ;
[0085] in the formula Indicates the time decay factor. This represents the time difference between the current moment and the moment a historical event occurred. This represents the spatial hop distance between two network nodes. This is a time decay parameter that indicates how the impact of an alarm decreases over time. This refers to the spatial attenuation parameter, which indicates how the impact of control alarms decreases with the network's spatial span. This represents an exponential function with the natural constant as its base.
[0086] A parameter optimization algorithm based on maximum likelihood estimation is used to fit the parameters of a multivariate conditional strength function. The model parameters are iteratively optimized based on the input discrete event sequence, ultimately solving for the topological excitation matrix that quantifies the causal correlation triggering probability between heterogeneous network attack events. Based on this, integral operations are used to generate the expected probability distribution of network attacks occurring on each network node in the target network environment within a future preset time window. Let the length of the future preset time window be... Network nodes The first time window will occur in the future Expected probability of network-like attacks The calculation formula is:
[0087] ;
[0088] in the formula This represents the specific probability value of the expected probability distribution. This indicates the length of the preset time window for predicting the future. This represents the fitted multivariate conditional strength function. This represents the time integral variable.
[0089] This step enables mathematical modeling of the cascading effects of network attacks, quantifies the causal relationships and spatiotemporal decay characteristics among different security events, and outputs forward-looking attack probability distribution data.
[0090] The game model construction module is used to construct an asymmetric evolutionary game model based on the expected probability distribution and initialize a policy population containing multiple candidate response scenarios.
[0091] Furthermore, in the game model construction module, the steps for constructing an asymmetric evolutionary game model based on the expected probability distribution include: defining a hybrid strategy space containing multiple adversarial paths, and mapping the expected probability distribution to the initial probability vectors of different network attack paths taken by the attacker; combining the asset value of the target network environment and the difficulty of exploiting node vulnerabilities, quantifying and allocating the gain and cost parameters for each adversarial path in the hybrid strategy space; establishing a mathematical payoff matrix for the defense side, and mapping and integrating the payoff matrix with the strategy population and the initial probability vectors to complete the construction of the asymmetric evolutionary game model.
[0092] Specifically, the expected probability distribution data output by the front-end module is received, and a hybrid policy space containing multiple adversarial paths is defined. In the target network environment, the network topology map and node access control list are extracted, and the set of all possible network attack paths an attacker might take to penetrate from the external boundary to the core data area is enumerated to form the attack-side policy space. Simultaneously, multiple candidate response scripts, including port blocking, routing blackhole redirection, and process isolation actions, are extracted from the security device configuration library to form the defense-side policy population. The expected probability distribution is mapped to an initial probability vector of the attacker taking different network attack paths. Assume the attack side has... One possible network attack path, number The initial probability of an attack path being selected is Its value is directly taken from the joint expected probability of a network attack occurring at a key node on the corresponding path within a preset time window, thus forming the initial hybrid strategy probability vector of the attacking side. , expressed as:
[0093] ;
[0094] In the formula, This represents the initial hybrid policy probability vector on the attacking side. This indicates that the attacker chose the first The initial probability of a network attack path. This represents the total number of network attack paths. This represents the vector transpose operation.
[0095] Combining the asset value of the target network environment with the difficulty of exploiting node vulnerabilities, the gain and cost parameters are quantified and allocated to each adversarial path in the hybrid strategy space. The business importance score of each network node is obtained from the asset management database as the base asset value, and the vulnerability exploitation difficulty is quantified by combining it with the vulnerability exploitation complexity score given by a general vulnerability scoring system. For the attacker, successfully compromising a node will yield a gain equivalent to the asset value of that node, while incurring an intrusion computational resource cost positively correlated with the vulnerability exploitation difficulty. For the defender, successfully intercepting the attack by executing candidate response scripts will yield a gain of protecting assets from loss, but will also incur system overhead and potential business interruption costs due to strategy implementation. Let's assume that for the One attack path, the defense side adopts the first There are 10 candidate response scripts, among which Belongs to the inclusion The strategy population of each scenario is defined as the security gain on the defensive side. The cost is Construct the net payoff of the defense side in a single game under this adversarial scenario. The calculation formula is:
[0096] ;
[0097] In the formula, Indicating the first When attacking the first path, take the first... Net payoff for a single game on the defensive side of each candidate response scenario This indicates the security gain from successfully protecting the target network node from intrusion. This indicates the cost of security equipment resource usage and related service interruptions incurred when executing the candidate response script.
[0098] Construct a mathematical payoff matrix oriented towards the defense side. Traverse all possible strategies in the hybrid policy space. Network attack paths and defense strategies in the population Given *n* candidate response scenarios, calculate the net payoff for each possible strategy adversarial combination under all possible game-time combinations, and arrange them in a manner where rows represent candidate response scenarios on the defensive side and columns represent network attack paths on the attacking side. The generation dimension is... Revenue payment matrix Its matrix representation is as follows:
[0099] ;
[0100] In the formula, This represents the mathematical payoff matrix for the defense side. This represents the total number of candidate response scenarios in the strategy population. This represents the total number of network attack paths. Indicating the first The attack path adopts the first The net payoff for each candidate response scenario in a single game. This payoff matrix is then used to calculate the payoff. The initial policy population generated and the initial probability vector representing the attack side preference. By performing mapping and integration, the defense side can dynamically assess the overall fitness of its various response scenarios based on the attacker's expected intrusion probability on each path, thus completing the construction of an asymmetric evolutionary game model.
[0101] This step transforms the complex network attack and defense process into a quantifiable mathematical game model, providing a numerical calculation environment for the system to automatically optimize and generate the best defense decisions.
[0102] The strategy evolution optimization module is used to calculate the fitness function value based on the blocking success rate and service interruption loss corresponding to multiple candidate response scripts. It uses the replier dynamic equation to iteratively update the adoption probability of each candidate response script in the strategy population based on the fitness function value, and obtains the converged evolutionary stable strategy.
[0103] Furthermore, in the strategy evolution optimization module, the steps of calculating the fitness function value based on the blocking success rate and service interruption loss corresponding to multiple candidate response scripts include: combining a preset external threat intelligence database and network node access control policies, simulating and evaluating the interception effectiveness of each candidate response script on the predicted attack path, and generating a quantified blocking success rate; traversing the service dependency graph of the target network environment, calculating the number of service interruption nodes of related nodes caused by the isolation operation of each candidate response script, and converting it into a quantified service interruption loss; constructing a nonlinear benefit evaluation equation, weighting and summing the security gain brought by the blocking success rate and the penalty caused by the service interruption loss, and outputting the fitness function value of each candidate response script.
[0104] Furthermore, in the strategy evolution optimization module, the step of iteratively updating the adoption probability of each candidate response script in the strategy population based on the fitness function value using the replier dynamic equation includes: calculating the comprehensive average fitness expectation of the defense strategy population based on the current adoption probability of each candidate response script in the strategy population and its corresponding fitness function value; constructing a replier dynamic equation representing the evolution of the strategy adoption probability over time, such that the adoption probability of candidate response scripts with their own fitness function value is higher than the comprehensive average fitness expectation shows a positive increase; and using a numerical integral approximation algorithm to perform discretized time-step iterative solution of the replier dynamic equation until the probability change rate of the strategy population converges to close to zero, thus completing the iterative update of the adoption probability.
[0105] Specifically, combining a pre-set external threat intelligence database with network node access control policies in the target network environment, and targeting the hybrid policy space output by the game model construction module, the interception effectiveness of each candidate response script in the policy population against predicted attack paths is simulated and evaluated. The matching degree between the attack signatures recorded in the external threat intelligence database and the defense rules invoked in the candidate response scripts is calculated to generate a quantified blocking success rate. The service dependency graph of the target network environment is traversed, and a graph search algorithm is used to count the number of related nodes experiencing service interruptions due to communication link disruptions after each candidate response script performs port blocking or host isolation operations, converting this into a quantified service interruption loss. A nonlinear benefit evaluation equation is constructed, weighted and summed to calculate the security gain from the blocking success rate and the penalty caused by the service interruption loss. Let the... The blocking success rate of each candidate response script is The business interruption loss is The preset basic gain for safety protection is Its fitness function value The nonlinear calculation formula is as follows:
[0106] ;
[0107] in the formula Indicates the first The fitness function value of each candidate response script. This represents the positive weighting coefficient that characterizes the importance of security gain. This represents the penalty weighting coefficient that characterizes the importance of business continuity. It represents an exponential penalty factor that controls the non-linear growth trend of business interruption losses, and its value is strictly greater than one.
[0108] Calculate the overall average expected fitness of the defense strategy population based on the current adoption probability of each candidate response play in the strategy population and its corresponding fitness function value. Assume the strategy population contains... The candidate response script, the first The candidate response scripts at the current moment The probability of adoption is Overall average fitness expectation The calculation formula is:
[0109] ;
[0110] in the formula This represents the expected overall average fitness of the population employing the current defense strategy. This represents the total number of candidate response scenarios in the strategy population.
[0111] The representation strategy employs a replier dynamic equation whose probability evolves over time, resulting in a positive increase in the adoption probability of candidate response scripts whose fitness function value is higher than the expected average fitness value. The continuous-time differential expression of the replier dynamic equation is:
[0112] ;
[0113] in the formula Indicates the first Each candidate response scenario employs a probability rate of change over time. The Euler numerical integral approximation algorithm is used to perform discretized time-step iterative solutions to the dynamic equation of the replicator. Let the discrete iteration time step size be... The discretization iterative update formula is:
[0114] ;
[0115] The discretized time-step iterative process is continuously executed, and the adoption probabilities of all policy populations are normalized after each iteration. The probability change between adjacent iterations is calculated in real time until the probability change rate of all candidate response scenarios is less than the preset convergence threshold, i.e., the probability change rate of the policy population converges to near zero. At this point, the iteration is terminated, and the converged adoption probability distribution is used as the obtained evolutionarily stable policy, completing the iterative update of the adoption probability.
[0116] This step enables dynamic optimization of the defense response strategy, accurately finding the optimal network response scheme that balances security blocking effectiveness and business continuity at the mathematical calculation level.
[0117] The automated orchestration execution module is used to generate automated orchestration instructions based on the evolutionary stabilization policy, driving network devices in the target network environment to execute the defensive actions indicated by the evolutionary stabilization policy.
[0118] Furthermore, in the automated orchestration and execution module, the steps for driving network devices in the target network environment to execute the defensive actions indicated by the evolution stabilization policy include: semantically parsing candidate response scripts whose response probability weights in the evolution stabilization policy meet preset threshold conditions, and translating them into machine-readable configuration scripts compatible with the standard interfaces of network devices; concurrently distributing the machine-readable configuration scripts to hardware firewalls and host terminals deployed at the boundary of the target network environment and preset subnets via a preset message middleware bus; establishing a state monitoring process to monitor the network devices' action execution confirmation receipts in real time, and triggering a preset configuration rollback operation to restore the network communication link state if execution is detected to complete the driving of the defensive actions.
[0119] Specifically, the converged evolutionarily stable policy output by the policy evolution optimization module is received, and the final adoption probability distribution of each candidate response script is extracted. A preset response probability weight threshold is set to conditionally filter the candidate response scripts in the evolutionarily stable policy. Let the policy population set be... The total number of candidate response scripts included is , No. Each candidate response script is represented as The corresponding response probability weight is The preset response probability weight threshold is Select a subset of execution scripts that meet the criteria. The calculation formula is as follows:
[0120] ;
[0121] in the formula This represents the subset of candidate response scripts selected for execution. Indicates the first One candidate response script Indicates the first The response probability weights of each candidate response script. This represents the preset probability weight threshold. Semantic parsing is performed on the defensive actions in the selected subset of execution scripts. Advanced security defense logic, such as blocking malicious Internet Protocol addresses and isolating specific network ports, is translated into machine-readable configuration scripts compatible with the target network device's standard interfaces. Specifically, this is transformed into machine-executable scripts in the format of Network Configuration Protocol Extensible Markup Language payload or Representational State Transition Application Programming Interface.
[0122] The translated, machine-readable configuration scripts are concurrently distributed via a pre-defined message middleware bus using a publish-subscribe mechanism. The scripts are targeted at hardware firewalls deployed at the external boundary of the target network environment and host terminal systems deployed in pre-defined internal subnets. The message middleware bus ensures that multiple network devices can simultaneously receive network isolation and interception commands within a very short time window.
[0123] Establish an independently running state monitoring process to monitor in real time the action execution confirmation receipts returned by the hardware firewall and host terminals after executing machine-readable configuration scripts. Define the expected device execution state matrix under ideal conditions as follows. The actual device status feedback matrix returned by the monitoring is as follows: Calculate the deviation value of the action execution state. The calculation formula is as follows:
[0124] ;
[0125] in the formula This indicates the deviation value of the action execution status. This represents the expected normal execution status matrix after all target network device commands are issued. This represents the assembled matrix of status codes returned by each device actually monitored, with the subscript at the bottom right. This represents the calculation of the Frobenius norm over the state difference matrix. The system continuously assesses the state deviation value of action execution. If a node returns an execution failure error code or a network response timeout occurs, the state deviation value will be adjusted accordingly. If the error exceeds the preset fault tolerance threshold, the execution action corresponding to the current defense strategy is determined to be blocked. At this time, the system automatically triggers a preset configuration rollback operation, and concurrently sends a reverse recovery script, which is the opposite of the original action, to the affected network nodes through the message middleware bus. This cancels the abnormal access control policy to restore the basic network communication link state, completing the closed-loop drive of the entire defense action.
[0126] This step enables the automated translation and reliable distribution of defense strategies from mathematical models to physical network devices, and provides automatic rollback protection in the event of device failure, ensuring the accurate implementation of security defense actions and the stable operation of the business network.
[0127] Finally, it should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. An automated proactive emergency response system for network attacks, characterized in that, include: The data acquisition module is used to acquire heterogeneous security alarm data and network traffic data in the target network environment; The topology feature extraction module is used to perform topology data analysis on the network traffic data and extract the continuous homology parameters of the network traffic data in a multi-layer feature space. The attack probability prediction module is used to fuse the heterogeneous security alarm data with the continuous coherence parameter into a discrete event sequence, input a preset multidimensional Hawkes process model, calculate the topological excitation matrix and time decay factor between the discrete event sequences, and generate the expected probability distribution of network nodes in the target network environment that will be attacked within a preset time window. The game model construction module is used to construct an asymmetric evolutionary game model based on the expected probability distribution and initialize a strategy population containing multiple candidate response scenarios. The strategy evolution optimization module is used to calculate the fitness function value based on the blocking success rate and service interruption loss corresponding to the multiple candidate response scripts, and use the replier dynamic equation to iteratively update the adoption probability of each candidate response script in the strategy population based on the fitness function value to obtain the converged evolutionary stable strategy. An automated orchestration execution module is used to generate automated orchestration instructions based on the evolutionary stabilization strategy, and drive network devices in the target network environment to execute the defensive actions indicated by the evolutionary stabilization strategy.
2. The automated proactive emergency response system for network attacks according to claim 1, characterized in that, In the data acquisition module, the steps of acquiring heterogeneous security alarm data and network traffic data in the target network environment include: Deploy multi-source data acquisition nodes to synchronize network communication packets in the target network environment with the security operation logs of terminal hosts in the target network environment according to a preset acquisition cycle; The time synchronization protocol is used to align the timestamps of the collected multi-source heterogeneous data, and the data format is standardized and noise is removed according to preset rules. A unified feature mapping space is constructed, and the standardized security alarm information and network traffic data are encapsulated into a structured initial feature matrix to complete the acquisition of the heterogeneous security alarm data and network traffic data.
3. The automated proactive emergency response system for network attacks according to claim 1, characterized in that, In the topology feature extraction module, the step of extracting the continuous homology parameters of the network traffic data in a multi-layer feature space includes: The network traffic data is projected into a point cloud set within the multi-layer feature space, and the corresponding multi-layer simplex is constructed based on the discrete extended connected radius threshold sequence. The homology groups of the multilayer simplex at different connectivity radius scales are calculated using algebraic topology algorithms, and a continuous bar chart is generated to record the life cycle of the network's geometric structure evolution. Feature extraction encoding is performed on the persistent bar graph to quantify the lifetime span and distribution density of the cohomology generators, and the persistent cohomology parameters are output to characterize the topological deformation of the communication network.
4. The automated proactive emergency response system for network attacks according to claim 1, characterized in that, In the attack probability prediction module, the step of fusing the heterogeneous security alarm data with the continuous coherence parameter into a discrete event sequence includes: The continuous coherence parameters are sampled in the time domain based on a dynamic time window mechanism to quantitatively evaluate the dynamic mutation rate of network topology features between adjacent time windows. A sensitivity threshold is set for the dynamic mutation rate. When the gradient of the dynamic mutation rate crosses the sensitivity threshold, a topological anomaly event stamp representing the characteristics of abnormal network connections is generated. Based on the time sequence of occurrence, the topological anomaly event stamps and the heterogeneous security alarm data are aligned and logically concatenated according to the time dimension features to construct the discrete event sequence containing multi-dimensional threat features.
5. The automated proactive emergency response system for network attacks according to claim 1, characterized in that, In the attack probability prediction module, the step of calculating the topological excitation matrix and time decay factor between the discrete event sequences includes: Establish a multivariate conditional strength function to characterize the effect of security alarm data that has occurred on the induction of subsequent heterogeneous events, and initialize a baseline strength vector that characterizes the basic anomaly frequency of the target network environment; By introducing a network node spatial distance parameter and an exponential decay function, a time decay factor is constructed to measure the decay rate of alarm impact over time and space. The multivariate conditional intensity function is fitted with parameters using a parameter optimization algorithm to solve for the topological excitation matrix that quantifies the probability of causal association between heterogeneous network attack events.
6. The automated proactive emergency response system for network attacks according to claim 1, characterized in that, In the game model construction module, the step of constructing an asymmetric evolutionary game model based on the expected probability distribution includes: Define a hybrid strategy space containing multiple adversarial paths, and map the expected probability distribution to an initial probability vector of the attacker taking different network attack paths; Based on the asset value and node vulnerability exploitation difficulty of the target network environment, the gain and cost parameters of each adversarial path in the hybrid strategy space are quantitatively allocated. A mathematical payoff matrix for the defense side is established, and the payoff matrix is mapped and integrated with the strategy population and the initial probability vector to complete the construction of the asymmetric evolutionary game model.
7. The automated proactive emergency response system for network attacks according to claim 1, characterized in that, In the strategy evolution optimization module, the step of calculating the fitness function value based on the blocking success rate and service interruption loss corresponding to the multiple candidate response scripts includes: By combining a pre-set external threat intelligence database and network node access control policies, the interception effectiveness of each candidate response script on the predicted attack path is evaluated through simulation, and a quantified blocking success rate is generated. Traverse the service dependency graph of the target network environment, calculate the number of service interruption nodes of associated nodes caused by the execution of isolation operations of each candidate response script, and convert it into the quantified service interruption loss; A nonlinear benefit evaluation equation is constructed, and the security gain brought by the blocking success rate and the penalty caused by the business interruption loss are weighted and summed to output the fitness function value of each candidate response script.
8. The automated proactive emergency response system for network attacks according to claim 1, characterized in that, In the strategy evolution optimization module, the step of iteratively updating the adoption probability of each candidate response script in the strategy population based on the fitness function value using the replicon dynamic equation includes: Based on the current adoption probability of each candidate response script in the strategy population and its corresponding fitness function value, calculate the overall average fitness expectation of the defense strategy population. The representation strategy is constructed using the dynamic equation of the replier whose probability evolves over time, so that the adoption probability of candidate response scripts whose fitness function value is higher than the expected comprehensive average fitness value shows a positive increase. The dynamic equation of the replicator is solved iteratively in discrete time steps using a numerical integral approximation algorithm until the probability change rate of the policy population converges to near zero, thus completing the iterative update of the adoption probability.
9. An automated proactive emergency response system for network attacks according to claim 1, characterized in that, In the automated orchestration and execution module, the step of driving network devices in the target network environment to execute the defensive actions indicated by the evolutionary stabilization policy includes: Semantic parsing is performed on candidate response scripts whose response probability weights in the evolutionary stabilization strategy meet the preset threshold conditions, and they are translated into machine-readable configuration scripts compatible with the standard interface of the network device. The machine-readable configuration script is concurrently distributed to the hardware firewall and host terminal deployed at the boundary of the target network environment and the preset subnet segment via a preset message middleware bus. A status monitoring process is established to monitor the network device's action execution confirmation receipt in real time. If execution is blocked, a preset configuration rollback operation is triggered to restore the network communication link status and complete the driving of the defense action.