A service-security-audit-based intelligent cognitive network control method and system
By constructing an intelligent cognitive network control system based on business, security, and auditing, the problems of data silos and slow response speed in network management systems have been solved. It has achieved end-to-end intelligent auditing and real-time security defense, improved network performance optimization and compliance auditing efficiency, and has the ability to quickly locate the source of abnormal operations and self-evolve.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- 北京建恒信安科技有限公司
- Filing Date
- 2026-03-27
- Publication Date
- 2026-07-03
AI Technical Summary
Existing network management systems suffer from data silos, lack of end-to-end auditing capabilities, and slow response times during their intelligent evolution, making it difficult to meet the compliance requirements of enterprises in terms of information security.
We construct an intelligent cognitive network control system based on business, security, and audit. By deploying three cognitive engines—business, security, and audit—in parallel, we build a unified intelligent knowledge base and arbitration center to achieve end-to-end intelligent auditing and real-time security defense. This system has the ability to quickly locate the source of abnormal operations and achieves self-evolution of audit strategies through closed-loop learning.
It achieves network performance optimization, improved security response speed, and enhanced compliance audit efficiency. It can quickly locate the source of abnormal operations within 10 seconds. The system has self-evolution capabilities and significantly improves operation and maintenance transparency and security response speed.
Smart Images

Figure CN122339956A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network information technology, specifically to an intelligent network system that integrates artificial intelligence and big data analysis, and more particularly to a network control method and system with integrated cognitive capabilities of business optimization, proactive security, and intelligent auditing. Background Technology
[0002] As enterprises deepen their digital transformation, the complexity and security requirements of network operations and maintenance are increasing. Traditional network management systems, even in their intelligent evolution, still suffer from the following pain points: First, network performance optimization, security protection, and operations and maintenance auditing are often implemented by independent systems, creating "data silos" and "policy chimneys" that cannot coordinate responses; second, existing security solutions mostly focus on real-time blocking, lacking the ability to accurately trace the entire operational chain, resulting in time-consuming and laborious post-incident investigations, making it difficult to meet the timeliness requirements of compliance with information security standards; finally, traditional log auditing systems rely on manual rules and offline analysis, resulting in slow response times and an inability to quickly locate the root cause of anomalies from massive amounts of logs.
[0003] Existing technologies (such as prior art document CN114167760A) propose intent-driven network management methods that use artificial intelligence to generate policies to optimize network operations and maintenance. However, this approach does not address end-to-end auditing and intelligent traceability of operational processes, and its knowledge base does not cover auditing knowledge and models. Therefore, how to build a network system that deeply integrates business optimization, proactive security, and intelligent auditing capabilities, and achieves self-evolving audit cognition, has become an urgent technical problem to be solved. Summary of the Invention
[0004] This invention aims to provide an intelligent cognitive network control method and system based on business, security, and auditing. Its purpose is to achieve deep collaboration and intrinsic integration of network performance optimization, real-time security defense, and end-to-end intelligent auditing by deploying three cognitive engines (business, security, and auditing) in parallel on the cognitive plane and constructing a unified intelligent knowledge base and arbitration center. Specifically, its auditing cognitive engine has the ability to quickly locate the source of abnormal operations within 10 seconds and can achieve self-evolution of auditing strategies through closed-loop learning, greatly improving operational transparency, security response speed, and compliance auditing efficiency, thus addressing the shortcomings of existing technologies. The technical problem to be solved by this invention is achieved through the following technical solutions.
[0005] In a first aspect, the present invention provides an intelligent cognitive network control method based on business-security-audit, characterized by comprising the following steps: Step S1: In the cognitive plane of the system, the audit cognitive engine collects full-link operation and maintenance logs from the infrastructure plane in real time. The logs include at least login information, operation command sequence, access resource information and exit information. Step S2: The audit cognitive engine performs multi-dimensional correlation analysis on the logs and constructs an operation chain relationship diagram with "people-operations-resources-time" as the core. Step S3: Perform abnormal pattern matching and dynamic compliance verification on the operation chain relationship graph based on the audit knowledge graph; Step S4: When an abnormal operation is detected, quickly locate the source of the abnormal operation and generate a traceability report that includes a visual representation of the entire operation chain; Step S5: Based on the verification feedback of the traceability report, update the audit knowledge graph and anomaly detection model to drive the self-evolution of audit cognitive capabilities.
[0006] Secondly, the present invention provides an intelligent cognitive network control system based on business-security-audit, characterized in that it includes: an application plane, a cognitive plane, a management and control plane, and an infrastructure plane; The cognitive plane includes a business cognitive engine, a security cognitive engine, and an audit cognitive engine that run in parallel; The business cognition engine is used to generate network optimization strategies based on network performance data and user business intent. The security cognition engine is used to perform risk reasoning based on real-time user operation behavior data and behavior baseline profiles, and generate proactive security protection strategies. The audit cognitive engine includes: The intelligent log collection module is used to collect and normalize the entire chain of operation and maintenance logs in real time; The operation chain analysis module is used to construct an operation chain relationship diagram of "people-operation-resource-time" and perform correlation analysis; The rapid tracing and location module is used to quickly locate the source of the abnormal operation when an anomaly is detected. The compliance verification module is used to perform dynamic compliance verification on operations based on the compliance rule base. The knowledge base is used to store business strategy knowledge, security behavior profiles and risk characteristics, and audit knowledge graphs. The verification and optimization module is used to receive execution feedback from the infrastructure plane, evaluate and optimize the strategies and models generated by the business cognition engine, security cognition engine and audit cognition engine, and feed the optimized knowledge back to the knowledge base; The infrastructure plane includes a full-link log collection layer, used to collect raw operation logs from bastion hosts, database auditing systems, and network devices; The audit cognitive engine, the security cognitive engine, and the business cognitive engine are respectively connected to the knowledge base and the verification optimization module, forming a cognitive self-evolution closed loop.
[0007] Thirdly, the present invention provides an electronic device including a processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the steps of the above-described system or method.
[0008] Fourthly, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the above-described system or method.
[0009] Fifthly, the present invention provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the above-described system or method.
[0010] Compared with the prior art, the present invention has the following significant advantages: Deep integration of capabilities: Through a "three-in-one" cognitive architecture, the barriers between business, security, and auditing are broken down, enabling intelligent strategic collaboration and data value sharing.
[0011] Revolutionary speedup in audit traceability: By leveraging indexing and graphing technologies, the time to locate the source of abnormal operations has been reduced from several hours of traditional manual analysis to less than 10 seconds, improving the efficiency of incident response and compliance auditing.
[0012] Dynamic intelligent compliance assurance: Through a built-in compliance rule base and dynamic verification engine, it can detect violations of permissions, timing and other violations in real time, automatically generate compliance reports, and significantly reduce compliance costs.
[0013] The system possesses self-evolving intelligence: the audit cognitive engine can learn from each traceability analysis, continuously enriching the audit knowledge graph and anomaly pattern library, enabling the system's audit capabilities to dynamically evolve with operational practices and become increasingly accurate. Attached Figure Description
[0014] Figure 1 This is a schematic diagram of the architecture of the intelligent network control system in an embodiment of the present invention.
[0015] Figure 2 This is a schematic diagram of the audit cognition closed loop in an embodiment of the present invention. Detailed Implementation
[0016] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.
[0017] refer to Figure 1The intelligent cognitive network control system provided in this embodiment adopts a four-layer planar architecture. The core innovation lies in the cognitive plane, which deploys a business cognitive engine, a security cognitive engine, and an audit cognitive engine in parallel. These three engines share an intelligent knowledge base (containing three sub-graphs: business, security, and audit) and a verification and optimization module. A policy arbitration center is responsible for receiving and arbitrating instructions from the three engines, ensuring that security and audit policies take precedence in case of conflict. In addition to traditional network and security devices, the infrastructure plane enhances the end-to-end log collection layer, collecting standardized logs from key nodes such as bastion hosts and databases through distributed probes.
[0018] The cognitive plane includes a business cognitive engine, a security cognitive engine, and an audit cognitive engine that run in parallel; The business cognition engine is used to generate network optimization strategies based on network performance data and user business intent. The security cognition engine is used to perform risk reasoning based on real-time user operation behavior data and behavior baseline profiles, and generate proactive security protection strategies. The audit cognitive engine includes: The intelligent log collection module is used to collect and normalize the entire chain of operation and maintenance logs in real time; The operation chain analysis module is used to construct an operation chain relationship diagram of "people-operation-resource-time" and perform correlation analysis; The rapid tracing and location module is used to quickly locate the source of the abnormal operation when an anomaly is detected. The compliance verification module is used to perform dynamic compliance verification on operations based on the compliance rule base. The knowledge base is used to store business strategy knowledge, security behavior profiles and risk characteristics, and audit knowledge graphs. The verification and optimization module is used to receive execution feedback from the infrastructure plane, evaluate and optimize the strategies and models generated by the business cognition engine, security cognition engine and audit cognition engine, and feed the optimized knowledge back to the knowledge base; The infrastructure plane includes a full-link log collection layer, used to collect raw operation logs from bastion hosts, database auditing systems, and network devices; The audit cognitive engine, the security cognitive engine, and the business cognitive engine are respectively connected to the knowledge base and the verification optimization module, forming a cognitive self-evolution closed loop.
[0019] refer to Figure 2 The workflow of the audit cognitive engine forms a complete closed loop, as follows: The first step is real-time collection and normalization of end-to-end logs. When operations personnel log in to the server through the bastion host to perform operations, the intelligent log collection module of the audit cognitive engine will acquire all logs generated by this session on the bastion host, target server, and potentially accessed databases in real time through the collector on the infrastructure plane. These heterogeneous logs are normalized in real time into a unified format event stream, containing key fields such as "timestamp, operator, source IP, operation type, target resource, and command details".
[0020] The second step is operation chain correlation analysis and graph construction. The operation chain analysis module receives event streams and aggregates discrete log events into a complete "operation chain" through session IDs, time continuity, resource correlation, etc. For example, "User A logs into the bastion host from IP1 -> executes command B on server S at 10:01 -> accesses table T in database D at 10:02" is associated as a transaction. Subsequently, a four-dimensional operation chain relationship graph of "person-operation-resource-time" is constructed and stored in the graph database.
[0021] The third step is intelligent analysis and compliance verification. The compliance verification module calls upon compliance rules from the audit knowledge graph in real time (such as "unauthorized access to the core database is prohibited" and "operation commands must comply with the principle of least privilege") to dynamically scan the operation chain relationship graph that is being constructed. At the same time, the operation chain analysis module uses a built-in anomaly detection model (such as an LSTM-based sequence anomaly model) to compare the current operation chain with historical normal patterns and known attack patterns, and calculates anomaly scores.
[0022] The fourth step is rapid tracing and location within 10 seconds. Once the anomaly score exceeds the threshold or a compliance rule is triggered, the rapid tracing and location module is immediately activated. This module first utilizes the inverted index built for hot data to retrieve all original logs related to the anomaly within milliseconds. Then, based on a graph database, it performs rapid traversal and reverse tracing of the constructed operation chain relationship graph to locate the origin of the abnormal operation (such as the specific user, login terminal, and start time). The entire retrieval, analysis, and location process is strictly controlled and completed within a 10-second time window. The location results and a complete visualized operation chain are packaged into an anomaly operation tracing report.
[0023] The fifth step is feedback verification and knowledge self-evolution. The generated report and handling results (such as whether it was confirmed as a real attack or violation) are fed back to the verification and optimization module. This module evaluates the accuracy of the audit analysis. If it is confirmed as a valid discovery, the pattern characteristics of this abnormal operation chain are extracted and stored as a new "risk pattern" in the audit knowledge graph, and used to optimize the parameters of the anomaly detection model. If it is a false alarm, the model threshold or rules are adjusted. Through this closed loop, the audit cognitive engine achieves continuous knowledge accumulation and autonomous capability evolution.
[0024] Throughout the process, the audit awareness engine and the security awareness engine work closely together. For example, if the audit engine discovers a new, slow lateral movement attack pattern that may not trigger the security engine's real-time blocking threshold, the audit engine can share this pattern as new knowledge. The security engine can then immediately adjust its behavioral profiling model to intercept such behaviors in real time in the future, creating a collaborative defense effect of "audit discovery, security immunity."
[0025] Through the above embodiments, the present invention constructs an intelligent network system that can not only intelligently optimize and actively defend, but also see clearly, investigate thoroughly, and learn quickly, laying a solid foundation for realizing a truly autonomous network.
[0026] This embodiment provides an electronic device, including a processor, a memory, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it can implement the system functions described in Embodiment 1 or 2, or execute corresponding security control methods. The method flow naturally includes the collaborative steps of each module of the system.
[0027] This embodiment provides a computer-readable storage medium, such as ROM, RAM, disk, or optical disk, on which a computer program is stored. When the program is executed by a processor, it can implement the system functions described in Embodiment 1 or 2, or execute corresponding security control methods.
[0028] It should be noted that the above detailed descriptions are exemplary and intended to provide further explanation of this application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains.
[0029] It should be noted that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the exemplary embodiments described in this application. As used herein, the singular form is intended to include the plural form as well, unless the context clearly indicates otherwise. Furthermore, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0030] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that the embodiments of this application described herein can be implemented in sequences other than those illustrated or described herein.
[0031] Furthermore, the terms “comprising” and “having”, and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to such process, method, product, or apparatus.
[0032] For ease of description, spatial relative terms such as "above," "on top of," "on the upper surface of," "above," etc., are used herein to describe the spatial positional relationship of a device or feature as shown in the figures to other devices or features. It should be understood that spatial relative terms are intended to encompass different orientations in use or operation beyond the orientation of the device as described in the figures. For example, if the device in the figures were inverted, a device described as "above" or "on top of" other devices or structures would subsequently be positioned as "below" or "under" other devices or structures. Thus, the exemplary term "above" can include both "above" and "below." The device may also be positioned in other different ways, such as rotated 90 degrees or in other orientations, and the spatial relative descriptions used herein will be interpreted accordingly.
[0033] In the detailed description above, reference has been made to the accompanying drawings, which form part of this document. In the drawings, similar symbols typically identify similar parts unless the context otherwise indicates otherwise. The illustrated embodiments described in the detailed specification, drawings, and claims are not intended to be limiting. Other embodiments may be used and other changes may be made without departing from the spirit or scope of the subject matter presented herein.
[0034] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A service-security-audit based intelligent cognitive network control method, characterized by, Includes the following steps: Step S1: In the cognitive plane of the system, the audit cognitive engine collects the full-link operation and maintenance logs from the infrastructure plane in real time. The logs include at least login information, operation command sequence, access resource information and exit information. Step S2: The audit cognitive engine performs multi-dimensional correlation analysis on the logs and constructs an operation chain relationship diagram with "people-operations-resources-time" as the core. Step S3: Perform abnormal pattern matching and dynamic compliance verification on the operation chain relationship graph based on the audit knowledge graph; Step S4: When an abnormal operation is detected, quickly locate the source of the abnormal operation and generate a traceability report that includes a visual representation of the entire operation chain; Step S5: Based on the verification feedback of the traceability report, update the audit knowledge graph and anomaly detection model to drive the self-evolution of audit cognitive capabilities.
2. The method of claim 1, wherein, In step S1, the real-time collection includes: normalizing heterogeneous logs through distributed collectors deployed on bastion hosts, database auditing systems, and network devices, and then aggregating them in real time using a stream processing framework.
3. The method according to claim 1, characterized in that, In step S3, the dynamic compliance verification includes: comparing the operation chain relationship graph with the compliance rule base based on the information security requirements in real time, and automatically identifying permission violations, timing violations and resource violations.
4. The method according to claim 1, characterized in that, In step S4, the rapid location of the abnormal operation source specifically includes: using a pre-built log inverted index and time series index for millisecond-level retrieval, combining a graph database to perform real-time traversal and root cause analysis of the operation chain relationship graph, and outputting the operator, source device, timestamp, and complete command sequence of the abnormal operation within a 10-second time window.
5. A smart cognitive network control system based on business-security-audit, characterized in that, include: Application plane, cognitive plane, management and control plane, and infrastructure plane; The cognitive plane includes a business cognitive engine, a security cognitive engine, and an audit cognitive engine that run in parallel; The business cognition engine is used to generate network optimization strategies based on network performance data and user business intent. The security cognition engine is used to perform risk reasoning based on real-time user operation behavior data and behavior baseline profiles, and generate proactive security protection strategies. The audit cognitive engine includes: The intelligent log collection module is used to collect and normalize the entire chain of operation and maintenance logs in real time; The operation chain analysis module is used to construct an operation chain relationship diagram of "people-operation-resources-time" and perform correlation analysis; The rapid tracing and location module is used to quickly locate the source of the abnormal operation when an anomaly is detected. The compliance verification module is used to perform dynamic compliance verification on operations based on the compliance rule base. The knowledge base is used to store business strategy knowledge, security behavior profiles and risk characteristics, and audit knowledge graphs. The verification and optimization module is used to receive execution feedback from the infrastructure plane, evaluate and optimize the strategies and models generated by the business cognition engine, security cognition engine and audit cognition engine, and feed the optimized knowledge back to the knowledge base; The infrastructure plane includes a full-link log collection layer, used to collect raw operation logs from bastion hosts, database auditing systems, and network devices; The audit cognitive engine, the security cognitive engine, and the business cognitive engine are respectively connected to the knowledge base and the verification optimization module, forming a cognitive self-evolution closed loop.
6. The system according to claim 5, characterized in that, The cognitive plane also includes a policy arbitration center, which is used to arbitrate and integrate policies from the business cognitive engine, security cognitive engine and audit cognitive engine, among which security blocking instructions and major violation audit instructions have the highest priority.
7. The system according to claim 5, characterized in that, The system also includes an audit knowledge graph, which stores operational entity relationships, compliance rules, and historical audit cases, and provides knowledge support for the operation chain analysis module and the compliance verification module.
8. The system according to claim 5, characterized in that, The rapid tracing and positioning module adopts a combination of indexing and graph technology, specifically including an inverted index component for millisecond-level log retrieval and a graph database component for storing and traversing operation chain relationships.
9. A computer-readable storage medium storing a computer program thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 4.
10. A computer program product, comprising a computer program, characterized in that, When executed by a processor, the computer program implements the steps of the method as described in any one of claims 1 to 4.
Citation Information
Patent Citations
Intention-driven network management system and method
CN114167760A