Artificial intelligence network security system based on multi-modal large model training

Through the artificial intelligence network security system trained by multimodal large model, multidimensional data correlation problems in hardware fault diagnosis, network attack detection, endpoint security monitoring and key management are solved, and fault prediction accuracy is improved, attack detection accuracy is improved and security adaptability is enhanced, and the problems of identification lag, misjudgment and insufficient threat perception in the existing technology are solved.

CN120281550AActive Publication Date: 2025-07-08SHENZHEN JINCHAO CLOUD CONTROL TECH CO LTD

Patent Information

Application Number
CN202510512409.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-07-08
Estimated Expiration
2045-04-23

AI Technical Summary

Technical Problem

The existing technology does not fully consider the correlation of multidimensional data in hardware fault diagnosis, resulting in lag in fault identification; it is difficult to quickly identify new attack patterns in network attack detection, and the risk of misjudgment is high; endpoint security monitoring dynamic behavior recognition is limited, and attack traceability is weak; key management adaptive adjustment capabilities are poor, making it difficult to deal with security challenges in complex environments; overall threat assessment lacks comprehensive multi-level data analysis, and threat perception is insufficient.

Method used

The artificial intelligence network security system based on multimodal large model training, through the server fault diagnosis module, network attack detection module, endpoint security monitoring module and key management optimization module, combined with multi-dimensional data analysis, improves the accuracy of fault prediction, improves the accuracy of attack detection, enhances attack traceability, dynamically adjusts key strategies, integrates multi-level data to calculate threat behavior and attack fit, and enhances the precision of threat evaluation and response speed.

Benefits of technology

Reduce business interruptions caused by hardware failures, improve attack detection accuracy, enhance attack traceability, improve security adaptability, reduce the risk of policy lag, and improve global security situation awareness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281550A_ABST
    Figure CN120281550A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of intelligent security operation and maintenance, in particular to an artificial intelligence network security system based on multi-modal large model training, which comprises a server fault diagnosis module, a network attack detection module, an endpoint security monitoring module, a key management optimization module and a threat analysis feedback module. According to the method, the fault prediction accuracy is improved through multi-dimensional data analysis, service interruption caused by sudden hardware faults is reduced, the network access frequency, source and instruction features are evaluated based on the server abnormality, the attack detection accuracy is improved, the misjudgment risk is reduced, the endpoint equipment execution behavior, resource calling and behavior sequence are extracted, and the service performance of the terminal equipment is improved. Fine-grained security monitoring is realized, attack traceability is enhanced, a key strategy is dynamically adjusted, security adaptability is improved, strategy lag risk is reduced, multi-level data is integrated to calculate threat behavior and attack fitting degree, threat assessment fineness and response speed are enhanced, and global security situation awareness is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of intelligent security operation and maintenance, and particularly to an artificial intelligence network security system based on multi-modal large model training. Background Art

[0002] The technical field of intelligent security operation and maintenance includes multiple aspects such as data center operation and maintenance management, network security protection, and system resource optimization. The core content of this technical field involves real-time monitoring, analysis, and optimization of hardware devices, network traffic, application systems, etc. in the data center through artificial intelligence and automation means to improve operation and maintenance efficiency and security. This technical field includes hardware fault diagnosis technology based on log analysis, network attack recognition technology combined with security threat intelligence, resource scheduling technology for load balancing, and multi-level security policy execution technology. Overall, this technical field improves the stability and security of the data center in a complex environment through data collection, modeling analysis, policy optimization, etc.

[0003] Among them, the artificial intelligence network security system based on multi-modal large model training refers to a system that uses multi-modal data such as natural language, images, logs, traffic, etc., and combines deep learning models for network security risk identification and management. For hardware device fault identification, this system extracts time series features using server operation logs, sensor data, etc., and makes predictions using historical anomaly pattern comparison and analysis. For network attack detection, it establishes an attack chain model using the MITRE ATT&CK knowledge base and matches attack behavior patterns through traffic feature decomposition. For resource scheduling optimization, it dynamically adjusts server load, storage allocation, etc. based on reinforcement learning strategies. This system also includes a security policy execution mechanism that uses digital signature technology to verify the integrity of iptables rules and performs rule parsing and distributed execution through DPU devices. In addition, this system uses a threshold signature method to construct a multi-administrator approval mechanism for joint signature authentication of critical security configuration changes to ensure the credibility of policy execution.

[0004] In the aspect of hardware fault diagnosis in the prior art, anomaly detection mainly relies on log analysis, but the correlation of multi-dimensional data is not fully considered, resulting in a lag in the identification of potential faults and making it difficult to detect abnormal trends in a timely manner. In network attack detection, the method of matching traffic characteristics based on the attack chain model is limited by the update speed of the rule library, making it difficult to quickly identify new attack patterns. At the same time, the judgment of abnormal access frequency is relatively rough, and there is a risk of misjudgment. In terms of endpoint security monitoring, the current technology focuses more on static security policies, with limited identification of the dynamic behavior of endpoint devices and difficulty in accurately tracing the attack path, resulting in weak attack tracing ability. The key management mechanism mainly relies on preset policies, with poor adaptive adjustment ability to changes in key access behavior and difficulty in effectively coping with security challenges in complex environments. In addition, in the overall threat assessment process, there is a lack of comprehensive analysis ability for multi-level data, resulting in insufficient comprehensiveness of threat perception and difficulty in achieving full-link tracing and accurate response to attack behaviors. Summary of the Invention

[0005] The object of the present invention is to solve the deficiencies existing in the prior art and propose an artificial intelligence network security system based on multi-modal large model training.

[0006] To achieve the above object, the present invention adopts the following technical solutions: The artificial intelligence network security system based on multi-modal large model training includes: The server fault diagnosis module obtains logs, fault codes, and combines hardware performance, task scheduling, and load balancing to analyze the time dependence of logs, and combines fault cases and device status to evaluate the operation deviation, and determines the degree of server anomaly; The network attack detection module, based on the degree of server anomaly, collects network packet addresses, protocol types, packet sizes, and timestamps, analyzes the trend of access behavior, identifies abnormal access paths, judges the possibility of attacks, parses the content of packets, matches suspicious instruction features, marks suspicious sources, calculates the attack activity, and analyzes and obtains the scope of attack influence; The endpoint security monitoring module, based on the scope of attack influence, monitors the execution behavior of endpoint devices, extracts the operating environment, resource calls, and behavior sequences, calculates the matching degree between the behavior pattern and the attack sample, identifies abnormal behavior chains and analyzes the scope of influence, and generates the degree of endpoint threat; The key management optimization module, based on the degree of endpoint threat, sets the key life cycle and records the usage and access sources, analyzes the stability of key calls, adjusts the encryption strength, triggers re-verification of permissions, analyzes changes in key access behavior, and obtains the key security change rate.

[0007] As a further solution of the present invention, the server anomaly degree includes the time correlation of the log sequence, the server temperature, the server voltage, the device operation stability, and the deviation degree between the current state and the fault sample. The network attack activity degree includes the network sources with abnormal access times, the matching degree between the instruction features and the attack patterns, the suspicious network sources, and the attack influence range. The endpoint threat degree includes the execution behavior of the endpoint device, the operating environment, the resource invocation, the matching degree between the behavior pattern and the attack sample, the abnormal behavior chain, and the abnormal influence range. The key security change rate includes the key life cycle, the key usage, the access source, the call stability, the encryption strength, the permission re-verification, and the change of the access behavior.

[0008] As a further solution of the present invention, the server fault diagnosis module includes: The log acquisition sub-module acquires the server operation logs, extracts the time records, fault codes, processor load, memory occupancy, and disk read / write rate, filters the log sequences in the abnormal time period, calculates the time interval distribution, analyzes the change characteristics, and obtains the log time interval characteristic value; The fault analysis sub-module extracts the task scheduling, load distribution, and hardware operation status in the corresponding time period based on the log time interval characteristic value, calculates the scheduling change rate, load deviation degree, and hardware fluctuation amplitude, and compares with the fault case library to obtain the fault matching parameter deviation value; The stability calculation sub-module calculates the deviation trend of the operation parameters according to the fault matching parameter deviation value, combines the current device operation situation of the server, calculates the deviation amplitude of the operation state, and calculates the deviation between the server operation stability and the stability reference value in the fault case library to obtain the server anomaly degree.

[0009] As a further solution of the present invention, the specific calculation formula for calculating the deviation trend of the operation parameters is: ; Calculate the deviation trend of the operation parameters , combine the current device operation situation of the server, calculate the deviation amplitude of the operation state, calculate the deviation between the server operation stability and the stability reference value in the fault case library to obtain the server anomaly degree; Wherein, represents the deviation trend of the operation parameters, represents the operation parameter value of the server in the current th time period, represents the parameter reference value in the normal operation state of the server, represents the total number of sampling time periods, represents the operation weight coefficient of the th device of the server, represents the The deviation degree of the current operating state of a device Represents the total number of server devices.

[0010] As a further solution of the present invention, the network attack detection module includes: The network traffic analysis sub-module combines the server anomaly degree, collects the source address, target address, protocol type, packet size and timestamp of network data packets, calculates the request quantity and total traffic volume of the source address, analyzes the protocol type distribution, extracts the change trend of the request distribution, calculates the request density and protocol balance degree, compares the change situation of time periods, and obtains the traffic distribution offset; The abnormal access recognition sub-module, based on the traffic distribution offset, extracts the high-frequency access addresses and request numbers, calculates the access path jump amplitude, analyzes the path change trend, filters the abnormal access paths, parses the packet instruction types, matches the suspicious instruction feature library, and obtains the suspicious path recognition degree; The attack activity evaluation sub-module, based on the suspicious path recognition degree, calculates the request frequency and duration of suspicious sources, analyzes the request fluctuation trend, evaluates the duration of attack behaviors, calculates the change of the attack target access frequency and the abnormal traffic ratio, and obtains the attack influence range.

[0011] As a further solution of the present invention, the endpoint security monitoring module includes: The behavior extraction sub-module monitors the execution behaviors of endpoint devices according to the attack influence range, obtains the operating environment information, resource call sequence and behavior sequence of the monitored endpoint devices, filters the operation items of inter-process interaction and file access in the behavior sequence, analyzes the relevance of the resource call sequence, and generates the resource call correlation degree; The abnormal recognition sub-module, based on the resource call correlation degree, combines the execution behavior data of the endpoint devices, analyzes the offset trend of the current behavior sequence, calculates the behavior sequence offset amplitude, judges the abnormal influence range, and generates the abnormal behavior offset degree; The threat evaluation sub-module calculates the coverage range and influence intensity of the abnormal behavior chain according to the abnormal behavior offset degree, extracts the endpoint resource call characteristics within the influence range, calculates the distribution of affected resources, and analyzes the endpoint threat degree according to the distribution of affected resources.

[0012] As a further solution of the present invention, the key management optimization module includes: The key life cycle setting sub-module, based on the endpoint threat degree, obtains the initial usage time, call times and access sources of the key, calculates the remaining life cycle and call stability of the key, compares the call frequency of the key with the set life cycle range, judges whether it is necessary to adjust the life cycle of the key, and if the call stability deviation exceeds the life cycle range, modifies the time of the key and records the adjustment result to obtain the key life cycle parameter; The key call analysis sub-module analyzes the access source, call times, and access device information in the key usage record according to the key life cycle parameters, calculates the stability change value of key calls, compares the change value with the normal key call status. If it exceeds the normal range, it adjusts the encryption strength and marks the key risk level, and obtains the stability change value of key calls. The key access behavior adjustment sub-module combines the stability change value of key calls, analyzes the change trend of key access behavior, calculates the change rate and range of access behavior, and determines whether the change amplitude of access behavior is abnormal. If it exceeds the set range, it triggers re-verification of permissions and adjusts the key permission level according to the access source, and obtains the key security change rate.

[0013] As a further solution of the present invention, the specific calculation formula for calculating the change rate and range of access behavior is: ; Calculate the change rate of access behavior, determine whether the change amplitude of access behavior is abnormal. If it exceeds the set range, trigger re-verification of permissions and adjust the key permission level according to the access source, and obtain the key security change rate.

[0014] Among them, represents the change rate of access behavior, represents the number of accesses within the statistical time window, represents the th time interval of access, represents the average access time interval of this key within the historical time window, represents the th time interval of access within the corresponding historical window, represents the cumulative calculation of all access behavior data, represents taking the absolute value, represents the square root operation.

[0015] As a further solution of the present invention, the system further includes a threat analysis feedback module: The threat analysis feedback module integrates server logs, network traffic, endpoint behavior, and key life cycle data based on the key security change rate, calculates the current threat behavior and attack fitness, associates suspicious access sources, and generates a network security threat assessment result. The network security threat assessment result includes server logs, network traffic, endpoint behavior, key life cycle data, current threat behavior and attack fitness, and suspicious access sources.

[0016] As a further solution of the present invention, the threat analysis feedback module includes: The key change analysis sub-module obtains the key security change rate, extracts the time series information in the server logs, key lifecycle data, and endpoint device key operation records, calculates the change frequencies of key creation, modification, and deletion, compares with the key security benchmark frequency, and determines the abnormal change rate. The access behavior correlation sub-module, based on the abnormal change rate, extracts the network traffic data for the corresponding time period, calculates the distribution characteristics of the access source address, request path, and user identity information, compares with the access time pattern in the server logs, detects the abnormal change in the access request density, and obtains the suspicious access source ratio. The threat matching calculation sub-module, according to the suspicious access source ratio, matches attack events, extracts the access frequency, key operation type, and endpoint interaction mode characteristics, compares the matching degree between the current behavior pattern and the attack records, and generates the network security threat assessment result.

[0017] Compared with the prior art, the advantages and positive effects of the present invention are as follows: In the present invention, the fault prediction accuracy is improved through multi-dimensional data analysis, reducing the service interruption caused by sudden hardware failures. Based on the server abnormality, the network access frequency, source, and instruction characteristics are evaluated, improving the attack detection accuracy and reducing the risk of misjudgment. The execution behavior, resource invocation, and behavior sequence of the endpoint device are extracted to achieve fine-grained security monitoring, enhancing the attack traceability ability. The key policy is dynamically adjusted to improve security adaptability and reduce the risk of policy lag. The threat behavior and attack fitting degree are calculated by integrating multi-level data, enhancing the threat assessment fineness and response speed, and improving the global security situation awareness ability. Description of the Drawings

[0018] Figure 1 is the system flow chart of the present invention; Figure 2 is the sub-step flow chart of the present invention. Detailed Embodiments

[0019] In order to make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0020] In the description of the present invention, it should be understood that the orientation or positional relationship indicated by terms such as "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation to the present invention. In addition, in the description of the present invention, the meaning of "a plurality of" is two or more, unless otherwise specifically defined.

[0021] Please refer to Figure 1 , the artificial intelligence network security system based on multi-modal large model training includes: The server fault diagnosis module obtains server logs, fault codes, and analyzes the time dependence of the log sequence in combination with hardware performance, task scheduling, and load balancing conditions. Combining fault cases and device operating states, it calculates the deviation of running stability and determines the degree of server abnormality; The network attack detection module, based on the degree of server abnormality, collects the address, protocol, size, and timestamp of network data packets, analyzes the trend of access behavior, calculates the request abnormality degree, compares with the normal traffic pattern, identifies abnormal access paths, combines the traffic mutation trend to judge the possibility of attack, analyzes the content of the data packets, matches the suspicious instruction features, marks the suspicious sources, calculates the attack activity level, and analyzes and obtains the scope of attack influence; The endpoint security monitoring module, based on the scope of attack influence, monitors the execution behavior of endpoint devices, extracts the running environment, resource calls, and behavior sequences, calculates the matching degree between the behavior pattern and the attack samples, identifies abnormal behavior chains and analyzes the scope of abnormal influence, and generates the degree of endpoint threat; The key management optimization module, based on the degree of endpoint threat, sets the key lifecycle, records the key usage and access sources, evaluates the call stability, adjusts the encryption strength, triggers the re-verification of permissions, analyzes the changes in access behavior, and determines the key security change rate; The threat analysis feedback module, based on the key security change rate, integrates server logs, network traffic, endpoint behavior, and key lifecycle data, calculates the fitting degree between the current threat behavior and the attack, associates the suspicious access sources, and generates the network security threat assessment result.

[0022] The server anomaly degree includes the time correlation of the log sequence, server temperature, server voltage, device operation stability, and the deviation degree between the current state and the failure sample. The network attack activity includes the network sources with abnormal access times, the matching degree between instruction features and attack patterns, suspicious network sources, and the attack influence range. The endpoint threat degree includes the execution behavior, operating environment, resource calls, the matching degree between behavior patterns and attack samples, abnormal behavior chains, and abnormal influence ranges of endpoint devices. The key security change rate includes the key life cycle, key usage, access sources, call stability, encryption strength, permission re-verification, and access behavior changes. The network security threat assessment results include server logs, network traffic, endpoint behaviors, key life cycle data, the fitting degree between current threat behaviors and attacks, and suspicious access sources.

[0023] Please refer to Figure 2 , the server fault diagnosis module includes: The log acquisition sub-module acquires the server operation logs, extracts the time records, fault codes, processor load, memory occupancy, and disk read / write rate, filters the log sequences in abnormal time periods, calculates the time interval distribution, analyzes the change characteristics, and obtains the log time interval characteristic values; For the acquisition of server operation logs, first, a monitoring system must be established to monitor the running state of the server in real-time, including the load of the processor, the occupancy rate of the memory, and the disk read / write rate. These data will be recorded in real-time and stored in the form of logs. For example, the CPU load rate, memory usage, and disk I / O operation times per minute of the server can be recorded in a CSV file. To extract the log sequences in abnormal time periods, the system can set some thresholds, such as the CPU load exceeding 80%, the memory occupancy exceeding 90%, or the disk read / write rate suddenly increasing by more than twice. These thresholds can be set based on past performance monitoring data. Once any metric exceeds these thresholds, the relevant logs will be marked as abnormal. Next, the system needs to perform time interval analysis on these marked abnormal logs. The specific analysis method can adopt descriptive analysis in statistics to calculate the time difference between log records. For example, if the time intervals between records within a period are mainly concentrated within a few seconds, it can be judged that the system may encounter a short-term high load or failure. Finally, through the statistical distribution of these time intervals, the characteristic values of the log time intervals can be obtained, such as the average time interval, median time interval, and standard deviation of the time interval. These characteristic values help to further analyze the abnormal patterns in the log data and obtain the log time interval characteristic values.

[0024] The fault analysis sub-module extracts the task scheduling, load distribution, and hardware running state in the corresponding time period based on the log time interval characteristic values, calculates the scheduling change rate, load deviation degree, and hardware fluctuation amplitude, and compares with the fault case library to obtain the fault matching parameter deviation value; The operation of the fault analysis sub-module starts with extracting the task scheduling, load distribution, and hardware operation status for the corresponding time period. The acquisition of these data can be achieved by querying the system logs of the server and the records of the task scheduler. For example, the usage of CPU and memory of all currently running tasks can be obtained from the APIs provided by the operating system. To calculate the change rate of task scheduling, it can be estimated by comparing the lengths of the task queues at different time points. If the length of the task queue increases rapidly within a short period, it indicates a high scheduling change rate. To calculate the degree of load deviation, the standard deviation and coefficient of variation can be used to measure the load fluctuations during different time periods. The analysis of the hardware operation status requires checking the data recorded by the hardware performance monitoring tools, such as CPU temperature, fan speed, etc. If there are abnormal fluctuations in these indicators, it may indicate a hardware fault. Comparing the calculated parameters with the data in the fault case library, methods such as cosine similarity and Euclidean distance can be used to calculate the deviation values between the parameters. These deviation values will be used to evaluate the similarity between the current system status and the known fault cases, and finally, the fault matching parameter deviation value is obtained.

[0025] Based on the fault matching parameter deviation value and combined with the current operation status of the server devices, the stability calculation sub-module calculates the deviation trend of the operation parameters, determines the deviation amplitude of the operation status, calculates the deviation between the server operation stability and the stability benchmark value in the fault case library, and obtains the degree of server abnormality. The specific calculation formula for the deviation trend of the operation parameters is: ; Calculating the deviation trend of the operation parameters , combined with the current operation status of the server devices, calculates the deviation amplitude of the operation status, calculates the deviation between the server operation stability and the stability benchmark value in the fault case library, and obtains the degree of server abnormality. Among them, represents the deviation trend of the operation parameters, represents the operation parameter value of the server at the th time period, represents the parameter benchmark value under the normal operation status of the server, represents the total number of sampling time periods, represents the operation weight coefficient of the th device of the server, represents the deviation degree of the current operation status of the th device of the server, represents the total number of server devices, Calculating the deviation trend of the operation parameters

[0026] Collect operation parameter data: Use server performance monitoring tools (such as Zabbix, Nagios, etc.) to collect the key operation parameter values of the server in different time periods in real time, such as CPU usage rate, memory utilization rate, etc. Assume that in five time periods ( ), the collected CPU usage rate data is as follows: ; Determine the baseline value : Based on historical data or industry standards, set the baseline value of the CPU usage rate of the server in normal operation. Assume the baseline value is 50%.

[0027] Calculate the deviation value for each time period: ; ; ; ; ; Calculate the average deviation: ; Calculate the influence coefficient of device operation status Determine the total number of server devices : Assume the server includes 4 key devices ( ): CPU, memory, disk, and network interface.

[0028] Set the device weight coefficient : According to the influence degree of each device on the server performance, set the weight coefficient. The setting of the weight coefficient is based on the importance of the device in the overall performance and may be adjusted according to the change of the workload. Assume the weight coefficients are as follows: ; ; ; ; Quantify the deviation degree of device operation status : Through the monitoring tool, obtain the current operation status of each device and compare it with its normal status, and quantify it as the deviation degree. Assume the deviation degrees of each device are as follows: ; ; ; ; Calculate the weighted sum of squared deviations: ; Calculate the offset trend of operation parameters

[0029] Substitute into the formula: ; Calculate: ; ; Result interpretation: The calculated offset trend of operation parameters indicates that the current CPU usage rate of the server has a 1.76% offset relative to the benchmark value. This result shows that there is a certain deviation between the operating state of the server and the expected stable state, and further analysis and adjustment are required to maintain the stability and performance of the server.

[0030] Please refer to Figure 2 , the network attack detection module includes: The network traffic analysis sub-module combines the server anomaly level, collects the source address, destination address, protocol type, packet size, and timestamp of network packets, calculates the request quantity and total traffic volume of the source address, analyzes the protocol type distribution, extracts the change trend of request distribution, calculates the request density and protocol balance degree, compares the change situation of time periods, and obtains the traffic distribution offset; During the data collection process, first, use traffic capture tools (such as Wireshark or Tcpdump) to monitor the inbound and outbound traffic of the server in real-time, and parse the IP header information in the packets to extract the source address and destination address. At the same time, parse the TCP / UDP protocol headers to identify the protocol type, and read the payload size of the packets to obtain the packet size parameter. The timestamp information comes from the server's system time synchronization mechanism. Then, by counting all source addresses, count the number of requests for each source address, and accumulate the packet size corresponding to the source address to calculate its total traffic volume. The distribution of protocol types is obtained by classifying and counting the traffic proportion of different protocols. For example, within a specific time period, count the traffic proportions occupied by protocols such as HTTP, TCP, and UDP respectively, and observe the traffic changes between protocols. On this basis, set a fixed time window (such as 5 minutes or 1 hour). Within each time window, calculate the request quantity and packet size of all source addresses, and compare them with the values in the previous window to obtain the change trend of request distribution. For the calculation of request density, calculate its density based on the number of requests per unit time and perform trend analysis through data in consecutive time windows. The protocol balance degree is used to measure whether the traffic of different protocol types is evenly distributed. When the balance degree is high, it means that the traffic sources are relatively average. When the balance degree is low, it indicates that there is a bias in the traffic. Further, by comparing the change situations of the protocol traffic proportion, total request quantity, and traffic size in different time periods, calculate the traffic distribution offset. If the offset is large, there may be a sudden increase or decrease in abnormal traffic.

[0031] Based on the traffic distribution offset, the abnormal access recognition sub-module extracts the high-frequency access addresses and request counts, calculates the access path jump amplitude, analyzes the path change trend, filters out the abnormal access paths, parses the data packet instruction types, matches the suspicious instruction feature library, and obtains the suspicious path recognition degree; First, set the judgment criteria for high-frequency access. The average value and fluctuation range of the request counts of all IPs can be calculated based on the historical access data of the server, and a value higher than the average by a certain multiple is set as the high-frequency access threshold. If it exceeds this threshold, it is determined as a high-frequency access address. After obtaining the high-frequency access address, analyze its access path jump amplitude, extract the access records of this IP, and count the number of different URL paths it accesses. At the same time, calculate the range of path changes. If this IP frequently jumps between multiple different pages, it indicates that its path jump amplitude is large. Subsequently, calculate the path changes of the same source address in adjacent time periods, observe the path change trend, and evaluate whether there is abnormal access behavior. For the identification of abnormal paths, further parse the request types of the data packets, such as GET, POST, PUT, etc., and compare them with the known suspicious instruction features, such as common SQL injection statements and XSS script codes in web attacks. If the request content contains suspicious instructions, determine the abnormal degree of this access path and calculate its suspicious path recognition degree. Paths with a higher recognition degree may belong to malicious access.

[0032] Based on the suspicious path recognition degree, the attack activity assessment sub-module calculates the suspicious source request frequency and duration, analyzes the request fluctuation trend, evaluates the attack behavior duration, calculates the change in the access frequency of the attack target and the abnormal traffic ratio, and obtains the attack impact range; First, count the number of accesses to the suspicious path and calculate its access frequency per unit time. The access duration is calculated based on the time interval between the first access and the last access. Subsequently, analyze the fluctuation trend of the suspicious requests, set a fixed time window, and calculate the change in the number of requests in adjacent time periods. If the request fluctuation is large, it indicates that the attack behavior may be active. Further evaluate the duration of the attack behavior by calculating the average access interval of a certain suspicious IP. If the access interval is small, it indicates that the attack has strong continuity. Subsequently, calculate the change in the access frequency of the attack target, that is, the number of times a certain target is accessed per unit time, and analyze its change amplitude. At the same time, calculate the proportion of abnormal traffic, count the total traffic of the suspicious requests, and compare it with the total traffic of the server to calculate the abnormal traffic ratio. Finally, obtain the attack impact range, including the number of affected target IPs, the service types involved, and the attack duration.

[0033] Please refer to Figure 2 , the endpoint security monitoring module includes: The behavior extraction sub-module monitors the execution behavior of endpoint devices according to the attack impact range, obtains the running environment information, resource call sequence, and behavior sequence of the monitored endpoint devices, filters the operation items of inter-process interaction and file access in the behavior sequence, analyzes the relevance of the resource call sequence, and generates the resource call correlation degree. First, obtain the running environment information of the endpoint device, including the hardware status of the device, the operating system version, the process list, and the resource usage, such as CPU load, memory occupancy, disk I / O rate, etc. Subsequently, use a system call monitoring tool (such as Sysmon or Auditd) to capture the resource call sequence of the endpoint device in real time, including process API calls, file access, network communication, etc., and filter the behavior sequence, focusing on extracting the operation items of inter-process interaction and file access. During the recording of process interaction, obtain the interaction process ID, target process ID, call time, and call method. For example, if a process sends data to another process through shared memory, the data transfer rate and data length need to be recorded. During the file access monitoring process, focus on extracting the access method (read, write, execute), access path, access time, and file modification status. For example, if a process repeatedly modifies the system critical configuration file or accesses an abnormal directory, it is marked as high risk. Subsequently, perform correlation analysis on the resource call sequence, identify high-frequency access patterns and abnormal access behaviors, calculate the correlation between processes in combination with historical call data. For example, whether multiple processes often access the same file or call the same API, and finally form the resource call correlation degree. If a process frequently calls high-privilege APIs or modifies multiple key files within a short period of time, its correlation degree may be relatively high. Finally, determine the resource call pattern of the endpoint device to form a complete data correlation result.

[0034] The anomaly recognition sub-module, based on the resource call correlation degree, combines the execution behavior data of the endpoint device, analyzes the offset trend of the current behavior sequence, calculates the behavior sequence offset amplitude, determines the anomaly impact range, and generates the anomaly behavior offset degree. First, construct a behavior baseline under normal operating conditions, including the normal API call sequences of each process, file access paths, and access frequencies, and perform statistical analysis on historical data. For example, record when a certain process usually calls which APIs, and whether the file access pattern is stable. Subsequently, monitor the current behavior sequence through a sliding window mechanism and compare it with the historical baseline data to identify abnormal deviation trends. When calculating the deviation amplitude, focus on changes in resource calls. For example, if a certain process usually calls an API 10 times per minute, but the number of calls increases to 50 times within the current minute, it is considered that there is a large deviation. In addition, compare the behavior sequences in different time periods, analyze the duration and change trend of abnormal behaviors, such as whether it is a short-term abnormal fluctuation or a long-term abnormal pattern. Subsequently, determine the scope of abnormal influence, analyze the number of processes involved, file modification situations, and network communication status. For example, if an abnormal behavior causes multiple key system processes to terminate abnormally or multiple files to be tampered with, the scope of influence is large. Finally, calculate the deviation amplitude of the abnormal behavior and output the abnormal deviation result.

[0035] The threat assessment sub-module calculates the coverage and impact intensity of the abnormal behavior chain based on the abnormal behavior deviation degree, extracts the endpoint resource call characteristics within the scope of influence, calculates the distribution of affected resources, and analyzes the endpoint threat level based on the distribution of affected resources; First, extract the endpoint resource call characteristics involved, including the types, frequencies, and associated processes of abnormal API calls. For example, whether the APIs called by a certain process involve privilege escalation, process injection, or system tampering. Subsequently, analyze the resource distribution involved in the abnormal behavior chain. For example, if an abnormal behavior involves access to a large number of key system files, it may indicate a higher threat level. When calculating the distribution of affected resources, count the abnormal situations of different categories of resources, such as the proportion of API access, file modification, and process creation, and combine historical data to judge the threat level of the current abnormal behavior. For example, if the current abnormal behavior is highly similar to the behavior pattern of known malware, the threat level may be high. Finally, evaluate the threat level of the endpoint device based on the distribution characteristics and coverage of the abnormal behavior, and generate a complete threat assessment result.

[0036] Please refer to Figure 2 , the key management optimization module includes: The key lifecycle setting sub-module obtains the initial usage time, call times, and access sources of the key based on the endpoint threat level, calculates the remaining lifecycle and call stability of the key, compares the call frequency of the key with the set lifecycle range, and determines whether the key lifecycle needs to be adjusted. If the call stability deviation exceeds the lifecycle range, modify the key time and record the adjustment result to obtain the key lifecycle parameters; The key lifecycle setting sub-module first obtains the initial usage time, call count, and access source of the key. The initial usage time can be obtained through database records. Each time a key is generated, the system attaches a timestamp. The call count can be statistically analyzed through API access records in the server log. The access source needs to combine parameters such as IP address, device ID, and MAC address, and is parsed through a geographical location library and a device fingerprint analysis tool to determine whether the access behavior meets expectations. After obtaining these data, it is necessary to calculate the remaining lifecycle and call stability of the key. The remaining lifecycle can be obtained by subtracting the current usage time from the initially set duration, while the call stability is analyzed based on the change in the key call count over a period of time. The historical mean is calculated using a sliding window method, and the current call count is compared with the mean. If the change range of the current call count exceeds the set threshold, for example, the average daily call count of a certain key in the past week was 100 times, but the call count suddenly increased to 500 times in the most recent 24 hours, then calculate its change range. If it exceeds the set range, it is determined that the call stability deviation is relatively large. Subsequently, the calculated call stability deviation value is compared with the set lifecycle range of the key. If the key call frequency is continuously high but the lifecycle setting is too short, or the call frequency is low but the lifecycle setting is too long, then the lifecycle of the key needs to be adjusted. The adjustment method can adopt a dynamic adjustment mechanism, that is, according to the size of the call stability deviation, the lifecycle is appropriately extended or shortened. For example, if the call stability deviation exceeds 30%, then 5%-10% of the time can be added to the original lifecycle. If the call stability deviation is small, the original lifecycle remains unchanged. The adjusted key lifecycle will be recorded and stored in the database and used for subsequent optimization of the key management strategy, and finally the key lifecycle parameters are obtained.

[0037] The key call analysis sub-module analyzes the access source, call count, and access device information in the key usage record according to the key lifecycle parameters, calculates the change value of the key call stability, compares the change value with the normal call status of the key. If it exceeds the normal range, then adjust the encryption strength and mark the key risk level, and obtain the change value of the key call stability; The key call analysis sub-module first analyzes the key usage records according to the key life cycle parameters, including access sources, call times, and access device information. When analyzing access sources, geographical location, IP reputation, and historical access records need to be combined. If it is found that the historical call stability of a certain IP address is relatively low, for example, the average daily call times of this IP in the past month were 50 times, but suddenly increased to 200 times in the recent 5 days, then calculate its call change situation. If the change amplitude exceeds the set range, it is considered that the access behavior of this IP may be abnormal. Further analysis is carried out in combination with access device information. If the device fingerprint information of the access source does not match the historical record, there may be a risk of key sharing or abuse, and this behavior needs to be marked. At the same time, the key call analysis sub-module also needs to compare the current call change value with the normal call status of the key. The normal call status of the key can be obtained through historical data statistics, that is, a benchmark range is set. If the current call change exceeds this range, it is considered that the usage situation of the key has become abnormal. In this case, the encryption strength of the key needs to be adjusted. The adjustment method can be to increase the complexity of the encryption algorithm, for example, upgrading SHA-256 to SHA-512, or increasing the iteration times of PBKDF2, so as to enhance the security of the key. At the same time, in order to further manage the key security, the risk level of the key also needs to be marked. The risk level can be divided according to the size of the call stability change value. For example, if the call change amplitude is lower than 20%, the risk level is low; if the change amplitude is between 20% and 50%, the risk level is medium; if it exceeds 50%, the risk level is high. Finally, the key call stability change value is obtained.

[0038] The key access behavior adjustment sub-module combines the key call stability change value, analyzes the change trend of the key access behavior, calculates the change rate and range of the access behavior, judges whether the change amplitude of the access behavior is abnormal. If it exceeds the set range, it triggers the re-verification of permissions, and adjusts the key permission level according to the access source to obtain the key security change rate; The specific calculation formula for calculating the change rate and range of the access behavior is: ; Calculate the change rate of the access behavior, judge whether the change amplitude of the access behavior is abnormal. If it exceeds the set range, it triggers the re-verification of permissions, and adjusts the key permission level according to the access source to obtain the key security change rate.

[0039] Among them, represents the change rate of the access behavior, represents the number of accesses within the statistical time window, represents the th time interval of access, represents the average access time interval of this key within the historical time window, represents the The time interval of the next access within the corresponding historical window Represents the cumulative calculation of all access behavior data Represents taking the absolute value Represents the square root operation This formula is used to calculate the change rate of access behavior , which is calculated by the change of the time interval obtained through actual data monitoring and collection. Specifically, the time interval of each access is obtained through the access log, where represents the access event number within a specific time window. In an actual example, assume that within a certain monitoring period, times of access are recorded, and the actual interval times (unit: minutes) of each access are 30, 45, 30, 35, 50 respectively

[0040] The average access time interval within the historical time window is obtained by averaging the same number of past access records and is set to minutes. The time interval of each historical access is also obtained through the log record. Assume the historical records are 35, 40, 42, 37, 45 minutes

[0041] The calculation process of substituting into the formula is as follows Calculate the sum of the absolute values of the differences between each access and the average time interval ; Calculate the sum of the squares of the differences between each current access and the historical access ; Calculate the sum of the absolute values of the differences between each current access and the historical access ; Calculate the change rate : ; This result indicates that considering the changes in historical data and current data, the change rate of access behavior is 0.87, indicating that the current access behavior has a relatively large change compared with the historical behavior. This numerical result indicates that it is necessary to further analyze the abnormality of access behavior and may need to trigger the re-verification of permissions, and further adjust the key permission level according to the access source to ensure system security

[0042] Please refer to Figure 2 , the threat analysis feedback module includes The key change analysis sub-module obtains the key security change rate, extracts the time series information from server logs, key life cycle data, and endpoint device key operation records, calculates the change frequencies of key creation, modification, and deletion, compares with the key security benchmark frequency, and determines the abnormal change rate; First, extract server logs, key life cycle data, and endpoint device key operation records. Server logs include information such as timestamps, operation types (creation, modification, deletion), and operating user IDs. Key life cycle data covers the generation time, activation time, expiration time, etc. of keys. Endpoint device key operation records contain the call records of keys by different terminals and their corresponding operation times. By performing time series analysis on these data, the time distribution curve of key changes is sorted out. For example, on a certain day, the time points of key creation operations are {10:05, 12:15, 16:30}, the time points of modification operations are {11:20, 14:45, 18:00}, and the time points of deletion operations are {9:00, 17:20}. Then, calculate the change frequencies of key creation, modification, and deletion. Using the sliding window method, the time span of each window is 1 hour, and count the number of key changes in each time period. For example, within the time period from 10:00 to 11:00, 1 key is created, 1 key is modified, and 0 keys are deleted, obtaining the time series change curve. Then compare it with the key security benchmark frequency. The benchmark frequency can be calculated from historical data. For example, the average key change frequency in the same time period in the past 30 days is used as the benchmark value. If the change frequency in the current time period exceeds twice the benchmark frequency, it is determined as an abnormal change rate. Suppose the benchmark change frequency is 1 time / hour, and the actually observed change frequency is 3 times / hour, then the calculated abnormal change rate is (3 - 1) / 1 = 200%. Finally, the time distribution data of the abnormal change rate is obtained.

[0043] The access behavior association sub-module, based on the abnormal change rate, extracts the network traffic data for the corresponding time period, calculates the distribution characteristics of access source addresses, request paths, and user identity information, compares with the access time rules in the server logs, detects abnormal changes in the access request density, and obtains the suspicious access source ratio; Including the access source IP address, request path, user identity information, access time, etc., calculate the distribution characteristics of these data. First, count the access times of different source IPs. Suppose that during the abnormal change period, IP address A accessed the server 15 times, IP address B accessed 20 times, and IP address C accessed 5 times, while the historical average in the normal period was IP address A: 5 times, IP address B: 6 times, IP address C: 3 times. Then calculate the access growth rate of each IP, which are (15 - 5) / 5 = 200%, (20 - 6) / 6 = 233.3%, (5 - 3) / 3 = 66.7% respectively. Next, calculate the access frequency distribution of user identity information, and extract the concentration degree of the request path. Suppose the request path X was accessed 30 times during this period, and the historical average was 10 times, then the access growth rate of the request path is (30 - 10) / 10 = 200%. Then, use the access time rule in the server log as the comparison benchmark. For example, under normal circumstances, the average distribution of access requests per hour is 100 times, while the access requests during the abnormal period reach 250 times. Then calculate the abnormal change rate of the access request density as (250 - 100) / 100 = 150%. Finally, count the ratio of suspicious access sources, and mark the IP addresses with access growth rates exceeding the benchmark as suspicious sources. Suppose the total number of accessed IPs is 50, and the access growth rates of 15 IPs exceed 200%, then the ratio of suspicious access sources is 15 / 50 = 30%.

[0044] The threat matching calculation sub-module matches attack events according to the ratio of suspicious access sources, extracts the access frequency, key operation type, and endpoint interaction mode characteristics, compares the matching degree of the current behavior pattern with the attack records, and generates the network security threat assessment result; First, based on the suspicious access source ratio, a list of suspicious IP addresses is screened out, and the access frequencies of these IPs are counted. For example, if an IP address accesses the server 60 times within 1 hour, while the average access frequency of normal users is 20 times, then the abnormal access frequency ratio of this IP is calculated as 60 / 20 = 3.0, which is more than 3 times the benchmark. Next, the key operation types are analyzed, and the key operation categories involved by the suspicious IP addresses are counted. For example, a certain suspicious IP address performs 3 key creations, 5 modifications, and 2 deletions within a short period of time, while the historical benchmark averages are 1 time, 2 times, and 1 time respectively. Then the abnormal key operation ratios are calculated as 3 / 1 = 3.0, 5 / 2 = 2.5, and 2 / 1 = 2.0 respectively. Further analyze the endpoint interaction pattern characteristics, and count the endpoint device types and interaction patterns of the suspicious IPs. For example, if it is found that an IP address logs in on terminal devices in different geographical locations at the same time, or switches multiple devices for key operations within a short period of time, it is marked as an abnormal interaction pattern. Finally, these features are matched with the behavior patterns in the historical attack records. For example, in past attack events, when the abnormal access frequency exceeded 2.5 times and the abnormal key operation ratio exceeded 2.0 times, 80% of the events were confirmed as attack events. Therefore, the matching degree of the current behavior pattern can be calculated as (3.0 + 2.5 + 2.0) / 3 = 2.5. Since it exceeds the threshold of 2.0, the current event is determined to be a suspected cybersecurity threat, and finally a cybersecurity threat assessment result is generated.

[0045] The above are only the preferred embodiments of the present invention, and do not limit the present invention in other forms. Any person skilled in the art may use the technical content disclosed above to make changes or modifications into equivalent embodiments with equivalent changes and apply them to other fields. However, as long as it does not depart from the technical solution content of the present invention, any simple modification, equivalent change, and modification made to the above embodiments based on the technical essence of the present invention still fall within the protection scope of the technical solution of the present invention.

Claims

1. An artificial intelligence network security system based on the training of a multimodal large model, characterized in that: The system includes: The server fault diagnosis module obtains logs, fault codes, and combines hardware performance, task scheduling, and load balancing to analyze the time dependence of the logs, and combines fault cases and device status to evaluate the operation deviation, and determines the degree of server abnormality; Based on the degree of server abnormality, the network attack detection module collects network packet addresses, protocol types, packet sizes, and timestamps, analyzes the access behavior trend, identifies abnormal access paths, judges the possibility of attacks, parses the packet content, matches suspicious instruction features, marks suspicious sources, calculates the attack activity, and analyzes and obtains the attack impact range; Based on the attack impact range, the endpoint security monitoring module monitors the execution behavior of endpoint devices, extracts the running environment, resource calls, and behavior sequences, calculates the matching degree between the behavior pattern and the attack sample, identifies abnormal behavior chains and analyzes the impact range, and generates the endpoint threat level; Based on the endpoint threat level, the key management optimization module sets the key lifecycle and records the usage and access sources, analyzes the stability of key calls, adjusts the encryption strength, triggers permission re-verification, analyzes the changes in key access behavior, and obtains the key security change rate.

2. The artificial intelligence network security system based on multi-modal large model training according to claim 1, characterized in that: The server abnormality degree includes the time correlation of the log sequence, server temperature, server voltage, device operation stability, and the deviation degree between the current state and the fault sample. The network attack activity includes the network sources with abnormal access times, the matching degree between the instruction features and the attack mode, suspicious network sources, and the attack impact range. The endpoint threat level includes the execution behavior, running environment, resource calls, the matching degree between the behavior pattern and the attack sample, abnormal behavior chains, and abnormal impact range of endpoint devices. The key security change rate includes the key lifecycle, key usage, access sources, call stability, encryption strength, permission re-verification, and access behavior changes.

3. The artificial intelligence network security system based on multi-modal large model training according to claim 1, wherein: The server fault diagnosis module includes: The log acquisition sub-module obtains the server running logs, extracts time records, fault codes, processor load, memory occupancy, and disk read / write rate, filters the log sequences in abnormal time periods, calculates the time interval distribution, analyzes the change characteristics, and obtains the log time interval characteristic value; Based on the log time interval characteristic value, the fault analysis sub-module extracts the task scheduling, load distribution, and hardware operation status in the corresponding time period, calculates the scheduling change rate, load deviation degree, and hardware fluctuation range, and compares the fault case library to obtain the fault matching parameter deviation value; Based on the fault matching parameter deviation value, the stability calculation sub-module combines the current device operation situation of the server, calculates the deviation trend of the operation parameters, determines the deviation amplitude of the operation state, calculates the deviation between the server operation stability and the stability reference value in the fault case library, and obtains the degree of server abnormality.

4. The artificial intelligence network security system based on multi-modal large model training according to claim 3, characterized in that: The specific calculation formula for the offset trend of the calculation operation parameters is as follows: ; Calculate the offset trend of operating parameters , combined with the current operating conditions of the server equipment, calculate the offset amplitude of the operating state, calculate the deviation between the server operating stability and the stability reference value in the fault case library, and obtain the server abnormality degree; Among them, represents the offset trend of the operating parameters, represents the operating parameter value of the server in the current time period, represents the parameter reference value under the normal operating state of the server, represents the total number of sampling time periods, represents the operating weight coefficient of the th device of the server, represents the deviation degree of the current operating state of the th device of the server, represents the total number of server devices.

5. The artificial intelligence network security system based on multi-modal large model training according to claim 1, characterized in that: The network attack detection module includes: The network traffic analysis sub-module collects the source address, destination address, protocol type, packet size, and timestamp of network data packets in combination with the server anomaly level, calculates the request quantity and total traffic volume of the source address, analyzes the protocol type distribution, extracts the change trend of the request distribution, calculates the request density and protocol balance degree, compares the change situation of time periods, and obtains the traffic distribution offset; The abnormal access recognition sub-module extracts the high-frequency access addresses and request quantities based on the traffic distribution offset, calculates the jump amplitude of the access path, analyzes the path change trend, filters the abnormal access paths, analyzes the instruction types of the data packets, matches the suspicious instruction feature library, and obtains the suspicious path recognition degree; The attack activity assessment sub-module calculates the request frequency and duration of suspicious sources based on the suspicious path recognition degree, analyzes the request fluctuation trend, evaluates the duration of attack behaviors, calculates the change in the access frequency of attack targets and the abnormal traffic ratio, and obtains the attack impact range.

6. The artificial intelligence network security system based on multi-modal large model training according to claim 1, characterized in that: The endpoint security monitoring module includes: The behavior extraction sub-module monitors the execution behaviors of endpoint devices according to the attack impact range, obtains the running environment information, resource call sequence, and behavior sequence of the monitored endpoint devices, filters the operation items of inter-process interaction and file access in the behavior sequence, analyzes the relevance of the resource call sequence, and generates the resource call correlation degree; The anomaly recognition sub-module analyzes the offset trend of the current behavior sequence based on the resource call correlation degree in combination with the execution behavior data of the endpoint device, calculates the offset amplitude of the behavior sequence, determines the anomaly impact range, and generates the anomaly behavior offset degree; The threat assessment sub-module calculates the coverage range and impact intensity of the abnormal behavior chain according to the abnormal behavior offset degree, extracts the endpoint resource call characteristics within the impact range, calculates the distribution of affected resources, and analyzes the endpoint threat level based on the distribution of affected resources.

7. The artificial intelligence network security system based on multi-modal large model training according to claim 1, wherein: The key management optimization module includes: The key life cycle setting sub-module obtains the initial usage time, call times, and access sources of the key based on the endpoint threat level, calculates the remaining life cycle and call stability of the key, compares the call frequency of the key with the set life cycle range, determines whether the key life cycle needs to be adjusted, and if the call stability deviation exceeds the life cycle range, modifies the time of the key and records the adjustment result to obtain the key life cycle parameters; The key call analysis sub-module analyzes the access sources, call times, and access device information in the key usage records according to the key life cycle parameters, calculates the change value of the key call stability, compares the change value with the normal key call status, and if it exceeds the normal range, adjusts the encryption strength and marks the key risk level to obtain the key call stability change value; The key access behavior adjustment sub-module analyzes the change trend of the key access behavior in combination with the key call stability change value, calculates the change rate and range of the access behavior, determines whether the change amplitude of the access behavior is abnormal, and if it exceeds the set range, triggers the re-verification of permissions and adjusts the key permission level according to the access source to obtain the key security change rate.

8. The artificial intelligence network security system based on multi-modal large model training according to claim 7, characterized in that: The specific calculation formula for calculating the change rate and range of the access behavior is: ; Calculate the change rate of access behavior, determine whether the change amplitude of the access behavior is abnormal. If it exceeds the set range, trigger the re-verification of permissions, and adjust the key permission level according to the access source to obtain the key security change rate; Among them, represents the change rate of access behavior, represents the number of accesses within the statistical time window, represents the time interval of the th access, represents the average access time interval of the key within the historical time window, represents the th access within the corresponding historical window, represents the cumulative calculation of all access behavior data, represents taking the absolute value, represents the square root operation.

9. The artificial intelligence network security system based on multimodal large model training according to claim 1, characterized in that: The system further includes a threat analysis feedback module: Based on the key security change rate, the threat analysis feedback module integrates server logs, network traffic, endpoint behavior, and key lifecycle data, calculates the fitting degree of the current threat behavior and the attack, correlates the suspicious access sources, and generates a network security threat assessment result. The network security threat assessment result includes server logs, network traffic, endpoint behavior, key lifecycle data, the fitting degree of the current threat behavior and the attack, and suspicious access sources.

10. The artificial intelligence network security system based on multi-modal large model training according to claim 9, wherein: The threat analysis feedback module includes: The key change analysis sub-module obtains the key security change rate, extracts the time series information from the server logs, key lifecycle data, and endpoint device key operation records, calculates the change frequencies of key creation, modification, and deletion, and compares with the key security benchmark frequency to determine the abnormal change rate; Based on the abnormal change rate, the access behavior correlation sub-module extracts the network traffic data for the corresponding time period, calculates the distribution characteristics of the access source address, request path, and user identity information, compares with the access time pattern in the server logs, and detects the abnormal change of the access request density to obtain the suspicious access source ratio; According to the suspicious access source ratio, the threat matching calculation sub-module matches the attack events, extracts the access frequency, key operation type, and endpoint interaction mode characteristics, compares the matching degree of the current behavior pattern and the attack records, and generates a network security threat assessment result.

Citation Information

Patent Citations

  • Hybrid encryption method based on industrial bus

    CN119363455A

  • Unmanned inspection and intelligent fault judgment method

    CN119728211A

  • Network security monitoring system based on big data analysis

    CN119728279A

  • Anomalous vehicle detection server and anomalous vehicle detection method

    US20210349997A1

Cited By

  • Emergency broadcast intelligent early warning system applied to disaster prevention and reduction

    CN120659037A

  • Security event early warning and response method based on operator-level network

    CN120710781A

  • A security event early warning and response method based on an operator-level network

    CN120710781B

  • Safe operation method and system of smart power grid

    CN120750589A

  • Information encryption management method and system

    CN120785659A