High-end equipment information security risk assessment method based on self-attention layer
By applying a neural network model based on the self-attention layer in high-end equipment, the problem of information security risk assessment in complex systems is solved, and more efficient and accurate security threat identification and response are achieved.
Patent Information
- Application Number
- CN202510323058.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-06-13
AI Technical Summary
It is difficult for the prior art to effectively evaluate and respond to information security risks in high-end equipment, especially when facing complex and dynamic security threats.
Using a neural network model based on the self-attention layer, we can create a knowledge base for attack behavior for threat analysis and risk assessment, establish and train threat detection models, evaluate risks, and safely reinforce high-end equipment.
It improves the accuracy and efficiency of information security risk assessment, can more accurately identify potential threats in complex systems, dynamically track security trends, and achieve rapid response and repair through self-attention mechanisms.
Smart Images

Figure CN120145398A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of intelligent connected vehicles and information security detection, and particularly relates to a method for information security risk assessment of high-end equipment based on a self-attention layer. Background Art
[0002] With the continuous progress of technology, especially in the application of high-end equipment, the intelligence and informatization levels of modern equipment have been greatly improved, which provides a more efficient and convenient operation platform for the intelligent connected vehicle industry. However, as these equipment increasingly rely on network connections and data exchanges, they also face more complex security threats. The systems involved in high-end equipment are usually very complex and highly integrated with numerous external systems and networks, resulting in more severe information security problems, especially potential risks such as cyberattacks, data leaks, and equipment failures. Traditional security detection methods often rely on rule setting or static analysis, making it difficult to adapt to dynamically changing security threats and lacking sufficient response capabilities for large-scale and high-complexity systems.
[0003] With the continuous deepening of intelligence and informatization, high-end equipment faces not only the risk of external cyberattacks but also potential vulnerabilities in internal systems and equipment failures. The complexity and integration of these systems make security problems more difficult to predict and solve, and traditional security protection methods seem inadequate. Therefore, researching how to improve the security protection capabilities of modern high-end equipment has become an important topic in current technological development. Summary of the Invention
[0004] The technical problem to be solved by the present invention is how to improve the accuracy and efficiency of information security risk assessment for high-end equipment.
[0005] To solve the above technical problem, the technical solution adopted by the present invention is: a method for information security risk assessment of high-end equipment based on a self-attention layer, which is characterized by including the following steps:
[0006] Create a knowledge base for threat analysis and risk assessment of attack behaviors;
[0007] Establish a threat detection model;
[0008] Train the threat detection model;
[0009] Evaluate risks according to the threat prediction results of the model;
[0010] Perform security reinforcement on high-end equipment and information systems.
[0011] A further technical solution lies in that the method for creating the knowledge base for threat analysis and risk assessment of attack behaviors is as follows:
[0012] When creating a knowledge base of threats and attack behaviors, it is necessary to first widely collect data on historical attack events in the core controllers of intelligent connected vehicles, including various types such as cyber attacks and physical attacks. These data sources can include security incident reports, vulnerability databases, network traffic analysis, attack tracing reports, etc. Through in-depth analysis of these historical cases, the patterns of different attack types and the behavior patterns of attackers can be identified, helping to predict potential future security threats. Each attack pattern should not only describe the basic characteristics of the attack, but also analyze the conditions under which it occurs, common attack tools and technical means, and changes in the attack path, etc.
[0013] While recording the attack patterns, it is also necessary to record in detail the specific targets of the attacks, which may be specific operating systems, applications, databases, network devices, etc. Tracking the attack path is particularly important, as it helps security experts understand how attackers bypass firewalls, intrude into the system and gradually obtain sensitive information or control.
[0014] A further technical solution is as follows: the method for establishing a threat detection model is as follows:
[0015] Construct a neural network model based on the self-attention layer. The model can adopt the self-attention layer structure, and through layer-by-layer deep learning, capture the long-term dependencies in the data. The network layers can be adjusted according to the complexity of the problem to optimize the performance. Use the self-attention mechanism to extract important features in the data, identify the temporal and spatial relationships therein. Through self-attention calculation on the data, extract key feature information to better understand the behavior patterns of the equipment system and enhance the detection ability of the model.
[0016] The CNN-BiLSTM-BiGRU network based on the self-attention layer includes three convolutional layers, one BiLSTM layer, one bidirectional GRU layer, one self-attention layer, two fully connected layers and one dropout layer. Add one batch normalization layer and one Relu activation layer after each convolutional layer to form a residual block, enabling the network to learn the complex patterns of the threat and attack behavior dataset, improving the accuracy of feature extraction, and capturing the potential patterns and changing trends in the threat and attack behavior data. Then add the input and output as the output of the residual block, and this structure is beneficial for the network to learn the residuals to better adapt to complex data distributions.
[0017] A further technical solution is as follows: the method for training a threat detection model is as follows:
[0018] In the input layer, define the threat and attack behavior data sequence at times 1 to q as M = {m 1 , m 2 , …, m q}, then the divided training set is represented as M tr = {m 1, m 2 , …, m p}, and the test set is denoted as M te = {m p+1 , m p+2 , …, m q}, satisfying the constraint conditions p < q and p, q ∈ N. Then, the classical min - max formula is used to normalize the data in the training set, and the normalized training set is shown in Equation (1):
[0019] M′ tr = {m′ 1 , m′ 2 , …, m′ p} (1)
[0020] Let the input of the model be shown in Equation (2):
[0021] X = {X 1 , X 2 , … X q} (2)
[0022] The corresponding theoretical output is shown in Equation (3):
[0023] Y = {Y 1 , Y 2 , … Y q} (3)
[0024] In Equation (3), Y i = {Y xi} or Y i = {Y zi}, and the theoretical outputs of the training set and the test set are Y tr and Y te .
[0025] Input the training set X tr into the hidden layer, and the output of X tr after passing through the hidden layer is shown in Equation (4):
[0026] Y′ tr = {Y 1 ′, Y 2 ′, … Y′ p} (4)
[0027] The loss function is set according to RMSE, and the minimum of the loss function is set as the optimization objective. The loss function in the training process is shown in Equation (5):
[0028]
[0029] Furthermore, the technical solution lies in that the method for evaluating risks according to the threat prediction results of the model is as follows:
[0030] The output result of the test set is shown in Equation (6):
[0031] Y′ te ={Y′ p+1 ,Y′ p+2 ,…Y′ q}}(6)
[0032] By performing min-max inverse normalization (denoted as de_minmax) on Y′ tr and Y′ te , the final prediction sequences P tr and P te corresponding to the training set and the test set are obtained, as shown in Equations (7) and (8):
[0033] P tr = de_minmax(Y tr ) = {P 1 ,P 2 ,…,P p}}(7)
[0034] P te = de_minmax(Y te ) = {P p+1 ,P p+2 ,…,P q}}(8)
[0035] The prediction error E of the network model is calculated by Equation (9) as follows:
[0036] E = Y te - P te (9)
[0037] After the threat prediction model gives the prediction result, the severity, impact range, and possibility of the threat are evaluated. The evaluation indicators include but are not limited to the potential loss of the attack, the value of the affected assets, the feasibility of the attack, and the recovery time after the attack, etc. According to these evaluation indicators, the risk value of each threat is calculated.
[0038] A further technical solution lies in the following method for security reinforcement of high-end equipment and information systems:
[0039] Comprehensively reinforce the security of the high-end equipment in combination with the hardware layer, operating system layer, application layer, and network layer. Each layer monitors and protects the internal communication, data processing, and external interaction of the system through the self-attention mechanism to ensure multi-level and all-round protection capabilities. When a security vulnerability or attack behavior is detected, the system can quickly identify the source of the problem through the self-attention algorithm and automatically start the repair program to reduce human intervention and improve the response speed and repair efficiency of the system.
[0040] The beneficial effects of adopting the above technical solution are as follows: The self-attention mechanism has a powerful feature capture ability. It can automatically identify important patterns and abnormal behaviors in a large amount of security data, helping to discover potential security risks. This enables the evaluation model to more accurately identify threats. Especially when facing complex multi-dimensional information, it can adaptively focus on key parts and avoid information omission that may occur in traditional methods. At the same time, this method can efficiently process time-series data, dynamically track and predict security trends during system operation, thereby providing an effective basis for preventing future threats. Through comprehensive analysis of historical data and real-time data, the self-attention mechanism can capture potential attack patterns and evolution processes, thus giving early warnings and taking countermeasures. The model based on the self-attention layer has good scalability and can automatically adjust and optimize its own evaluation ability as the data volume grows and the system complexity increases. Description of the Drawings
[0041] The present invention will be further described in detail below in conjunction with the drawings and specific embodiments.
[0042] Figure 1 is the flowchart of the method described in the embodiment of the present invention;
[0043] Figure 2 is the flowchart of the optimization of the self-attention layer in the method described in the embodiment of the present invention.
[0044] Figure 3 is the flowchart of the training and prediction of the network model in the method described in the embodiment of the present invention; Specific Embodiments
[0045] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0046] Many specific details are set forth in the following description in order to provide a thorough understanding of the present invention. However, the present invention may be practiced in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0047] As Figure 1 shown, the embodiment of the present invention discloses a high-end equipment information security risk assessment method based on a self-attention layer. The method includes the following steps:
[0048] Step 1): Create a knowledge base for threat analysis and risk assessment of attack behaviors;
[0049] Step 2): Establish a threat detection model;
[0050] Step 3): Train the threat detection model;
[0051] Step 4): Evaluate risks based on the threat prediction results of the model;
[0052] Step 5): Securely reinforce high-end equipment and information systems.
[0053] The above steps are described below in combination with specific methods:
[0054] The method for creating the knowledge base for threat analysis and risk assessment of attack behaviors in Step 1) is as follows:
[0055] When creating a knowledge base of threats and attack behaviors, first, data on historical attack events in the core controllers of intelligent connected vehicles should be widely collected, including various types such as cyber attacks and physical attacks. These data sources can include security event reports, vulnerability databases, network traffic analysis, attack tracing reports, etc. Through in-depth analysis of these historical cases, the patterns of different attack types and the behavior patterns of attackers can be identified, helping to predict potential future security threats. Each attack pattern should not only describe the basic characteristics of the attack but also analyze its occurrence conditions, common attack tools and technical means, and changes in the attack path, etc.
[0056] While recording the attack patterns, the specific targets of the attacks also need to be detailed, which may be specific operating systems, applications, databases, network devices, etc. Tracking the attack path is particularly important as it helps security experts understand how attackers bypass firewalls, intrude into the system, and gradually obtain sensitive information or control rights.
[0057] As Figure 2 shown, the method for establishing the threat detection model in Step 2) is as follows:
[0058] Build a neural network model based on the self-attention layer. The model can adopt a self-attention layer structure. Through layer-by-layer deep learning, long-term dependencies in the data can be captured. The network layers can be adjusted according to the complexity of the problem to optimize performance. Use the self-attention mechanism to extract important features in the data, identify the temporal and spatial relationships therein. Through self-attention calculation of the data, key feature information is extracted to better understand the behavior patterns of the equipment system and enhance the detection ability of the model.
[0059] The CNN-BiLSTM-BiGRU network based on the self-attention layer includes three convolutional layers, one BiLSTM layer, one bidirectional GRU layer, one self-attention layer, two fully connected layers, and one dropout layer. A batch normalization layer and a Relu activation layer are added after each convolutional layer to form a residual block, enabling the network to learn the complex patterns of the threat and attack behavior dataset, improving the accuracy of feature extraction, and capturing the potential rules and changing trends in the threat and attack behavior data. Then, the input and output are added together as the output of the residual block, and this structure is beneficial for the network to learn the residuals to better adapt to complex data distributions.
[0060] As Figure 3 shown, the method for training the threat detection model in step 3) is as follows:
[0061] In the input layer, define the threat and attack behavior data sequences at times 1 to q as M = {m 1 , m 2 , …, m q}. Then the divided training set is represented as M tr = {m 1 , m 2 , …, m p}, and the test set is represented as M te = {m p+1 , m p+2 , …, m q}, satisfying the constraint conditions p < q and p, q ∈ N. Then, the classical min-max formula is used to normalize the data in the training set, and the normalized training set is as shown in Equation (1):
[0062] M t ′ r = {m 1 ′, m′ 2 , …, m′ p} (1)
[0063] Let the input of the model be as shown in Equation (2):
[0064] X = {X 1 , X 2 , … X q} (2)
[0065] The corresponding theoretical output is as shown in Equation (3):
[0066] Y = {Y 1 , Y 2 , … Y q} (3)
[0067] In Equation (3), Y i = {Y xi} or Yi = {Y zi}, The theoretical outputs of the training set and the test set are Y tr and Y te .
[0068] Input the training set X tr into the hidden layer. The output of X tr after passing through the hidden layer is shown in Equation (4):
[0069] Y tr ' = {Y 1 ', Y 2 ', … Y p '}(4)
[0070] The loss function is set according to RMSE, and the minimum of the loss function is set as the optimization goal. The loss function in the training process is shown in Equation (5):
[0071]
[0072] The method for evaluating the risk according to the threat prediction result of the model in step 4) is as follows:
[0073] The output result of the test set is shown in Equation (6):
[0074] Y te ' = {Y p ', +1 Y p ', +2 , … Y q '}(6)
[0075] By performing min-max denormalization (denoted as de_minmax) on Y tr ' and Y te ', the final prediction sequences P tr , P te corresponding to the training set and the test set are obtained, as shown in Equations (7) and (8):
[0076] P tr = de_minmax(Y tr ) = {P 1 , P 2 , …, P p}(7)
[0077] P te = de_minmax(Y te ) = {P p+1 , P p+2 , …, P q}(8)
[0078] The prediction error E of the network model is calculated by Equation (9) as follows:
[0079] E = Y te - P te (9)
[0080] After the threat prediction model gives the prediction result, the severity, impact scope, and possibility of the threat are evaluated. The evaluation indicators include but are not limited to the potential loss of the attack, the value of the affected assets, the feasibility of the attack, and the recovery time after the attack, etc. According to these evaluation indicators, the risk value of each threat is calculated.
[0081] The method for security reinforcement of high-end equipment and information systems in step 5) is as follows:
[0082] Comprehensively reinforce the security of the high-end equipment in combination with the hardware layer, operating system layer, application layer, and network layer. Each layer monitors and protects the internal communication, data processing, and external interaction of the system through the self-attention mechanism to ensure multi-level and all-round protection capabilities. When a security vulnerability or attack behavior is detected, the system can quickly identify the source of the problem through the self-attention algorithm and automatically start the repair program to reduce human intervention and improve the response speed and repair efficiency of the system.
Claims
1. A high-end equipment information security risk assessment method based on self-attention layer, characterized by The steps include: Create a knowledge base of attack behaviors for threat analysis and risk assessment; Building threat detection models; Training threat detection models; Assess risk based on the model’s threat predictions; Provide security reinforcement for high-end equipment and information systems.
2. The high-end equipment information security risk assessment method based on the self-attention layer according to claim 1 is characterized in that: The methods for creating a threat analysis and risk assessment attack behavior knowledge base are as follows: When creating a knowledge base of threats and attack behaviors, we must first collect data on historical attack events on the core controllers of intelligent connected vehicles, including various types such as network attacks and physical attacks. These data sources can include security incident reports, vulnerability databases, network traffic analysis, attack tracing reports, etc. Through in-depth analysis of these historical cases, we can identify the laws of different attack types and the behavior patterns of attackers, helping to predict potential security threats in the future. Each attack pattern should not only describe the basic characteristics of the attack, but also analyze the conditions under which it occurs, common attack tools and technical means, changes in attack paths, etc. While recording the attack pattern, it is also necessary to record the specific targets of the attack in detail, which may be specific operating systems, applications, databases, network devices, etc.
3. The high-end equipment information security risk assessment method based on the self-attention layer as claimed in claim 2 is characterized in that: The method to build a threat detection model is as follows: Build a neural network model based on the self-attention layer. The model can use the self-attention layer structure to capture long-term dependencies in the data through layer-by-layer deep learning. The network hierarchy can be adjusted according to the complexity of the problem to optimize performance. The self-attention mechanism is used to extract important features in the data and identify the temporal and spatial relationships. By performing self-attention calculations on the data, key feature information is extracted to better understand the behavior patterns of the equipment system and enhance the detection capabilities of the model. The CNN-BiLSTM-BiGRU network based on the self-attention layer includes three convolutional layers, one BiLSTM layer, one bidirectional GRU layer, one self-attention layer, two fully connected layers, and one random dropout layer. A batch normalization layer and a Relu activation layer are added after each convolutional layer to form a residual block, which enables the network to learn the complex patterns of threat and attack behavior data sets, improve the accuracy of feature extraction, and capture the potential laws and changing trends in threat and attack behavior data. The input and output are then added as the output of the residual block. This structure is conducive to the network learning residuals so that it can better adapt to complex data distributions.
4. The high-end equipment information security risk assessment method based on the self-attention layer as claimed in claim 3 is characterized in that: The method for training a threat detection model is as follows: In the input layer, the threat and attack behavior data sequence from time 1 to time q is defined as M = {m1,m2,…,m q }, then the divided training set is represented as M tr ={m1,m2,…,m p }, the test set is denoted as M te ={m p+1 ,m p+2 ,…,m q }, satisfying the constraints p<q and p,q∈N. Then the classic min-max formula is used to normalize the data in the training set. The normalized training set is shown in formula (1): M t ′ r ={m1′,m′2,…,m′ p } (1) Let the model input be as shown in formula (2): X={X1,X2,…X q } (2) The corresponding theoretical output is shown in formula (3): Y={Y1,Y2,…Y q } (3) In formula (3), Y i = {Y xi } or Y i = {Y zi }, the theoretical output of the training set and test set is Y tr and Y te . The training set X tr Input hidden layer, X tr The output after the hidden layer is shown in formula (4): Y tr ′={Y1′,Y2′,…Y p ′} (4) The loss function is set based on RMSE, and the minimum loss function is set as the optimization goal. The loss function of the training process is shown in formula (5):
5. The high-end equipment information security risk assessment method based on the self-attention layer as claimed in claim 4 is characterized in that: The method for assessing risk based on the threat prediction results of the model is as follows: The output result of the test set is shown in formula (6): AND te ′={And p ′ +1 ,AND p ′ +2 ,…AND q ′} (6) Through Y tr ′ and Y te ′ Perform min-max denormalization (expressed as de_minmax) to obtain the final prediction sequence P corresponding to the training set and test set tr , P te As shown in formula (7) and (8): P tr =de_minmax(Y tr )={P1,P2,…,P p } (7) P te =de_minmax(Y te )={P p+1 ,P p+2 ,…,P q } (8) The prediction error E of the network model is calculated by formula (9): E=Y te -P te (9) After the threat prediction model gives the prediction results, the severity, scope of impact and possibility of the threat are evaluated. The evaluation indicators include but are not limited to the potential loss of the attack, the value of the affected assets, the feasibility of the attack and the recovery time after the attack. Based on these evaluation indicators, the risk value of each threat is calculated.
6. The high-end equipment information security risk assessment method based on self-attention layer according to claim 5, characterized in that: The methods for security reinforcement of high-end equipment and information systems are as follows: Comprehensive security reinforcement is carried out by combining the hardware layer, operating system layer, application layer and network layer of high-end equipment. Each layer monitors and protects the internal communication, data processing and external interaction of the system through the self-attention mechanism to ensure multi-level and comprehensive protection capabilities. When a security vulnerability or attack behavior is detected, the system can quickly identify the source of the problem through the self-attention algorithm and automatically start the repair program, reducing human intervention and improving the system's response speed and repair efficiency.
Citation Information
Cited By
Unmanned aerial vehicle navigation signal collaborative blocking system based on quantum key distribution
CN120614081A
Cooperative blocking system for drone navigation signals based on quantum key distribution
CN120614081B