This application belongs to the field of
industrial internet security technology and relates to a method for constructing an
industrial internet security risk
knowledge graph, aiming to solve the problems of missing industrial features, poor dynamism, and
risk assessment being detached from process in existing technologies. The method includes: acquiring and preprocessing multi-source heterogeneous data to generate equipment association identifiers,
vulnerability association identifiers, and process node identifiers, forming a standardized dataset; extracting initial triples based on the standardized dataset and performing a two-stage entity merging; validating the merged triples according to process rules to obtain valid triples; writing the valid triples into a
graph database and writing runtime sequence data into a time-series
database; establishing a mapping between entities and runtime sequence data through equipment association identifiers to generate an
industrial internet security risk
knowledge graph. This application achieves unified
data association, accurate entity fusion, and graph-time-series collaborative storage, improving the accuracy of graph construction and
risk assessment capabilities.