The invention discloses a self-
adaptive security policy evolution method,
system and device and a storage medium. Collecting heterogeneous
log data, and mapping the heterogeneous
log data into standard tetrad data; analyzing the streaming security events through a PCMCI and NOTEARS mixed causal discovery
algorithm, identifying a time-
lag causal relationship between
attack behaviors, and constructing a dynamic causal map; fusing external asset attribute information, performing risk propagation prediction by using a
time sequence diagram neural network, and outputting a future attacked probability of each node; inserting the
security policy into the atlas, constructing a heterogeneous graph containing risks and policy nodes, optimizing a
reinforcement learning model based on a constraint policy, and generating a policy
adjustment action; a strategy is defined as an infrastructure code, security execution is carried out through a gray release mechanism, and automatic
rollback of a monitoring index is realized; and finally, collecting feedback data, and carrying out online updating on the prediction and
decision model to form a closed-loop self-evolution
system. According to the invention, rapid, automatic and precise closed-loop evolution of the
security policy is realized.