The invention discloses a social
engineering self-adaptive dynamic protection method based on post
risk assessment, relates to the technical field of
network security, and solves the problem that in the prior art, the aspects of employee
security awareness modeling, multi-
modal data fusion and personalized
security policy recommendation still have obvious deficiencies. The method comprises the following steps: firstly, constructing an
electric power post
knowledge graph, and carrying out structured modeling on four entities of posts, permissions, assets and vulnerabilities and association relationships thereof to form a global
semantic network; secondly, a post risk
baseline model is established, a normal behavior mode is defined by quantifying inherent risks of posts and analyzing historical operation logs, and a static and dynamic combined risk reference is formed; and finally, designing a post exclusive feature extractor, fusing personal behavior data of the employees with semantic constraints and risk baselines of the
knowledge graph, and generating highly personalized feature vectors, thereby laying a foundation for subsequent real-time monitoring of abnormal behaviors of the employees, quantification of safety
consciousness and providing of differentiated protection.