Computer security system based on artificial intelligence

Through an artificial intelligence-based computer security system, deep learning and genetic algorithms are used to identify normal and abnormal behaviors, automatically generate and optimize security rules, solve the problem of misjudging risky behaviors in existing technologies, and achieve more efficient security monitoring and management.

CN120639434AInactive Publication Date: 2025-09-12CHONGQING CHEM IND VOCATIONAL COLLEGE
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510947353.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-10
Publication Date
2025-09-12
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In the existing technology, although the system determines risks and authenticates through complex comparisons and calculations, it may still misjudge normal behaviors as risky behaviors and fail to identify real risky behaviors in a timely manner, resulting in unnecessary warnings and potential safety hazards.

Method used

It adopts an artificial intelligence-based computer security system, including a security monitoring platform, a behavior pattern analysis module, an intelligent rule engine, a call management module, a risk assessment module and an intelligent assistant. It uses deep learning and genetic algorithms to identify normal and abnormal behaviors, automatically generate and optimize security rules, and provide intelligent security defense and decision support.

Benefits of technology

It effectively reduces the false alarm and missed alarm rates, improves the accuracy of identifying risky behaviors, enhances the system's security defense capabilities, and provides comprehensive security management support.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639434A_ABST
    Figure CN120639434A_ABST
Patent Text Reader

Abstract

The invention discloses a computer security system based on artificial intelligence, and the system comprises a security monitoring platform which is responsible for receiving data from all modules, carrying out the centralized processing, and providing a user interface for a manager to monitor and operate; the behavior mode analysis module is responsible for identifying normal and abnormal behavior modes through deep analysis of user behavior data and providing an important basis for safety monitoring; the intelligent rule engine is responsible for automatically generating and optimizing a security rule according to the security policy and the real-time threat information; the calling management module is used for adding an AI-assisted security analysis function while ensuring information calling; according to the invention, the behavior pattern analysis module uses the LSTM to learn and model the historical behaviors of the user, identifies the characteristics of the normal behaviors and the abnormal behaviors, and judges whether the current access behavior is abnormal or not according to the characteristics in real-time monitoring, thereby reducing the false alarm rate and the missing report rate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer security technology, and in particular to a computer security system based on artificial intelligence. Background Art

[0002] With the rapid development of information technology, information security issues have become increasingly prominent. In the Internet era, protecting information security has become the focus of attention in various fields. As a means of protecting computer information security, information security technology and its important parameters are crucial to ensuring the security of information systems.

[0003] After searching, the invention patent with Chinese patent number CN117312096A discloses a computer information security monitoring system based on data analysis, which belongs to the field of information security technology. In order to solve the problem that computer information security monitoring systems in the prior art usually use encryption algorithms to encrypt information, making it difficult to be illegally obtained during transmission and storage, and the access control mechanism uses means such as permission management and identity authentication to ensure that only users with legal permissions can access relevant information; however, the prior art cannot monitor the risky behavior of legal users, resulting in the security of data cannot be guaranteed during the legal user call process. The system includes a security monitoring platform, which is connected to an authentication analysis module, a call management module, a risk assessment module and a storage module; the authentication analysis module is used to authenticate and analyze the user's computer information access rights: when the security monitoring platform receives a computer information access request, it retrieves the legal access user set corresponding to the computer information and sends it to the authentication analysis module.

[0004] Compared with the existing technology, this invention patent with Chinese patent number CN117312096A can perform authentication analysis on the user's computer information access rights, compare the user's entered username and password with the set of legal access users, and mark risky behavior based on authentication failure characteristics when the user does not have access legitimacy.

[0005] However, during the above-mentioned use, although the system determines risks and authenticates through complex comparisons and calculations, it may still misjudge normal behaviors as risky behaviors and fail to identify real risky behaviors in a timely manner, which leads to unnecessary warnings and potential safety hazards. Therefore, a computer security system based on artificial intelligence is proposed. Summary of the Invention

[0006] The purpose of the present invention is to solve the shortcomings of the prior art, that is, although the system determines risks and authenticates through complex comparisons and calculations, it may still misjudge normal behaviors as risky behaviors and fail to identify real risky behaviors in a timely manner, which leads to unnecessary warnings and potential safety hazards. A computer security system based on artificial intelligence is proposed to solve the shortcomings of the prior art, that is, although the system determines risks and authenticates through complex comparisons and calculations, it may still misjudge normal behaviors as risky behaviors and fail to identify real risky behaviors in a timely manner, which leads to unnecessary warnings and potential safety hazards.

[0007] In order to achieve the above object, the present invention adopts the following technical solutions:

[0008] A computer security system based on artificial intelligence, comprising:

[0009] Security monitoring platform: responsible for receiving data from various modules, centrally processing it, and providing a user interface for management personnel to monitor and operate;

[0010] Behavior pattern analysis module: responsible for identifying normal and abnormal behavior patterns through in-depth analysis of user behavior data, providing important basis for security monitoring;

[0011] Intelligent rule engine: Responsible for automatically generating and optimizing security rules based on security policies and real-time threat information to achieve intelligent security defense;

[0012] Call management module: While ensuring information access, it also adds AI-assisted security analysis capabilities;

[0013] Risk assessment module: responsible for risk assessment of the overall security status of the computer system;

[0014] Intelligent Assistant: Responsible for providing comprehensive services such as security command execution, query response, and decision support;

[0015] The security monitoring platform receives user behavior analysis results from the behavior pattern analysis module, including normal behavior baselines and abnormal behavior reports. The user behavior analysis results are used to trigger alarms, evaluate the system security status, and provide input for the intelligent rule engine. The new rules generated by the intelligent rule engine are also fed back to the security monitoring platform. When the user makes an information call, the security monitoring platform forwards the call request to the call management module for processing and receives the security assessment results returned by the call management module. The security monitoring platform provides system status data to the risk assessment module regularly or on demand. When processing information calls, the call management module records the relevant call behavior data and sends it to the risk assessment module for security assessment. The intelligent assistant interacts with each module to obtain necessary information and execute instructions. For example, the intelligent assistant queries the risk assessment module for the latest security assessment report, requests the intelligent rule engine to execute specific security rules, or sends an alarm notification to the security monitoring platform.

[0016] The above technical solution further includes:

[0017] Furthermore, the security monitoring platform receives data from each module (such as user behavior data, security incident reports, risk assessment results, etc.) and distributes this data to the corresponding processing units. The security monitoring platform provides an intuitive and easy-to-use user interface, allowing managers to easily view system status, receive alarm notifications, and perform security policy adjustments.

[0018] Furthermore, the behavior pattern analysis module includes a data collection unit, a data processing unit, a behavior modeling unit and a real-time monitoring unit. The data collection unit is responsible for capturing user behavior data from various data sources. The data collection unit passes the collected raw data to the data processing unit for processing. The data processing unit is responsible for performing pre-processing operations such as cleaning, deduplication and standardization on the raw data. The data processing unit receives data from the data collection unit, and passes the clean and standardized data to the behavior modeling unit after processing. The behavior modeling unit is responsible for using machine learning algorithms to model user historical behaviors and form a normal behavior baseline. The behavior modeling unit receives data from the data processing unit, and after modeling analysis, passes the model parameters and baseline data to the real-time monitoring unit. The real-time monitoring unit is responsible for real-time analysis of user behavior, and compares it with the behavior model to evaluate the degree of abnormality. The real-time monitoring unit receives the behavior model and baseline data from the behavior modeling unit, and at the same time receives the current user behavior data (which may come from the data processing unit or directly obtained from the data source). After comparison and analysis, the abnormal alarm and report are passed to the security monitoring platform.

[0019] Furthermore, the intelligent rule engine includes a rule base management unit, a rule generation and optimization unit, and a rule execution unit. The rule base management unit is responsible for the creation, maintenance, and management of the rule base. The rule base management unit receives rule update requests from the rule generation unit and the rule execution unit, and synchronizes the updated rule base data to the rule generation unit and the rule execution unit. At the same time, the rule base management unit is responsible for reporting the status information of the rule base (such as the number of rules, version information, etc.) to the security monitoring platform. The rule generation and optimization unit uses machine learning algorithms to analyze historical data and current threat trends to generate and optimize security rules. The rule generation and optimization unit generates and optimizes security rules from the rule base. The library management unit obtains the basic rule set as an initial reference, obtains the latest security events and user behavior data from the security monitoring platform as input, and sends the newly generated rules or rule optimization suggestions to the rule library management unit for updating. The rule execution unit executes security response measures according to the real-time monitoring results and the rules in the rule library. The rule execution unit receives security events and user behavior data from the security monitoring platform, and the rule library management unit obtains the latest rule set, matches and judges the event data according to the rule set, and sends the security response measures that need to be executed to the corresponding security equipment or system (such as firewalls, intrusion detection systems, etc.). At the same time, the execution results and feedback information are reported to the security monitoring platform.

[0020] Furthermore, the call management module includes a call request unit, an information storage unit, a security verification unit and a call management unit. The call request unit initiates a request for information call and sends the call request information to the call management unit. The call request unit receives the call result or security verification request returned by the call management unit. The information storage unit is responsible for storing original data and backup data and providing data support for the call management unit. The information storage unit receives the call information sent by the call management unit and performs backup and comparison operations. The security verification unit executes additional security verification procedures according to the instructions of the call management unit and returns the verification results to the call management unit, which decides whether to allow the call request to pass. The call management unit receives the call request from the call request unit, performs a security assessment on the call request, and executes corresponding security measures (such as information backup and comparison, security verification, restriction measures, etc.) according to the assessment results, and returns the call result or security verification request to the call request unit to complete the entire call process.

[0021] Furthermore, the risk assessment module receives data and information from the behavior pattern analysis module and the intelligent rule engine to conduct a comprehensive risk assessment. The risk assessment module integrates data and information from different security modules, such as the user behavior characteristics of the behavior pattern analysis module, the security rule triggering status of the intelligent rule engine, etc., so as to conduct a more comprehensive and accurate risk assessment. When potential security risks are discovered, the risk assessment module automatically triggers the early warning mechanism and sends risk warning notifications to managers via email, text messages, etc.

[0022] Furthermore, the intelligent assistant includes an input unit, a natural language processing unit, a decision support unit, a knowledge base unit and a knowledge base unit. The input unit is responsible for receiving instructions and queries input by managers through voice or text. The input unit passes the received input data to the natural language processing unit for processing. The natural language processing unit is responsible for parsing and understanding the data passed by the input unit, converting the natural language into commands or query statements that can be recognized by the system. The natural language processing unit passes the parsed commands or query statements to the decision support unit for processing. At the same time, the interactive data is passed to the continuous learning unit for learning and optimization. The decision support unit provides processing suggestions or automatically executes emergency response processes for managers based on the commands or query statements passed by the natural language processing unit and combined with the information in the knowledge base. The decision support unit passes the interactive data to the continuous learning unit for learning and optimization. The knowledge base unit stores information related to security event types, urgency, processing suggestions and emergency response processes. The knowledge base unit provides information support to the decision support unit and, at the same time, receives optimization suggestions from the continuous learning unit to update and improve the knowledge base.

[0023] Furthermore, the behavior modeling unit uses LSTM to train, test, and infer the data from the data processing unit, including the following steps:

[0024] Data preparation:

[0025] Collect feature data related to the target task and divide the dataset into training set, validation set and test set with a ratio of 70%, 15% and 15%;

[0026] Model construction:

[0027] Building a model using LSTM:

[0028] Forget gate: f t =σ(W f ·[h t-1 ,x t ]+b f )

[0029] Among them, Wf is the weight matrix of the forget gate, b f is the bias term, σ is the sigmoid function, [h t-1 ,x t ] means h t-1 and x t Splice into a vector;

[0030] Input gate: The input gate is responsible for updating the cell state. The input gate consists of two parts: a sigmoid layer that determines which information will be updated; and a tanh layer that creates a new candidate value vector. The new candidate value vector is added to the cell state. Finally, the two information are multiplied to update the cell state.

[0031] Sigmoid layer: i t =σ(W i ·[h t-1 ,x t ]+b i );

[0032] tanh layer:

[0033] Cell status update:

[0034] Output gate: The output gate determines which part of the information based on the cell state is used for output, according to the current input The state of the hidden layer at the previous moment h t-1 And the latest cell state C t , through the combined action of sigmoid function and tanh function, the output h at the current moment is determined t ;

[0035] Sigmoid layer: o t =σ(W o ·[h t-1 ,x t ]+b o );

[0036] Output hidden state: h t =o t *tanh(C t );

[0037] Training process:

[0038] Forward propagation: For each time step of input, the hidden state and output are calculated according to the RNN;

[0039] Calculate loss: Use a loss function to measure the difference between the model prediction and the actual label;

[0040] Backpropagation: Calculate the gradient of loss with respect to model parameters through the time backpropagation algorithm;

[0041] Parameter update: Use Adam to update model parameters according to the gradient;

[0042] Testing and Reasoning:

[0043] The model performance is evaluated on the test set. During inference, the data to be classified is input into the trained model. The model outputs the probability distribution of each category, and the category with the highest probability is taken as the classification result.

[0044] Furthermore, the rule generation and optimization unit uses a genetic algorithm to analyze historical data and current threat trends to generate and optimize security rules. The specific steps are:

[0045] Initialization: Encoding security rules (such as firewall rules and intrusion detection system signatures) into a genotype form for genetic algorithm processing. This involves converting the different parameters of the rules (such as source IP address range, port number, protocol type, etc.) into binary strings or other encoding methods, and randomly generating an initial population of multiple individuals, each of which represents a potential set of security rules;

[0046] Evaluate fitness: Collect historical security event data, user behavior pattern data, and current threat intelligence data. For each individual in the population (i.e., each rule set), use this data to evaluate its fitness. The fitness function should be designed to reflect the performance of the rule set in identifying real threats and avoiding false positives. Based on the evaluation results, assign a fitness value to each individual. A higher value indicates better performance of the rule set.

[0047] Selection: Roulette wheel selection selects individuals based on their fitness values. Individuals with high fitness are more likely to be selected, which ensures that the characteristics of the excellent rule set can be inherited to the next generation. At the same time, the sampling elite retention strategy directly copies the individuals with the highest fitness in the current population to the next generation to avoid the loss of excellent individuals in the inheritance process.

[0048] Crossover: Randomly select two individuals from the current population as parents, exchange rule parameters between the parent individuals to generate new offspring individuals. The crossover operation can introduce new rule combinations and increase the diversity of the population.

[0049] Mutation: Randomly select an individual from the population and randomly modify the rule parameters to simulate the process of gene mutation. The mutation operation helps explore new areas in the solution space and prevent the algorithm from falling into local optimality.

[0050] Iteration: Repeat the fitness evaluation, selection, crossover, and mutation until the predetermined number of iterations is reached or other stopping conditions are met (such as the fitness value no longer significantly improves);

[0051] Termination and output: When the predetermined number of iterations is reached, the fitness value reaches the preset threshold, or the fitness changes of individuals in the population tend to be stable, the algorithm terminates, and the individual with the highest fitness is selected from the final population as the optimal rule set, which is decoded into practical and usable security rules.

[0052] Furthermore, the continuous learning unit optimizes its own response logic and decision-making capabilities by continuously analyzing the interaction data between managers and the system (including voice commands, text queries, response results, etc.). The specific steps are:

[0053] Data Collection: Captures network traffic data in real time and records user firewall configuration changes, rule additions / deletions, and other operational actions.

[0054] Preprocessing: Perform protocol parsing and session reconstruction on traffic data to extract key information such as IP address, port number, and protocol type. At the same time, clean and format user operation records.

[0055] Model training: Use machine learning algorithms to train pre-processed data to identify malicious traffic patterns and abnormal user behavior;

[0056] Online learning and optimization: Analyze newly captured traffic data in real time and dynamically adjust firewall rules based on model predictions. Simultaneously, the model is continuously optimized based on user feedback and system performance metrics (such as false positive rate and false negative rate).

[0057] Knowledge base update: Regularly obtain the latest threat information and security strategies from security communities, threat intelligence sources, and other channels, and update them to the system's knowledge base to improve defense capabilities against emerging threats.

[0058] The present invention has the following beneficial effects:

[0059] 1. In the present invention, the behavior pattern analysis module uses LSTM to learn and model the user's historical behavior, identify the characteristics of normal behavior and abnormal behavior, and in real-time monitoring, judge whether the current access behavior is abnormal based on these characteristics, thereby reducing the false alarm and missed alarm rates.

[0060] 2. In the present invention, an intelligent rule engine is constructed, and a genetic algorithm is used to analyze historical data and current threat trends, automatically updating and optimizing security rules to more accurately identify risky behaviors.

[0061] 3. In the present invention, an intelligent assistant is developed to assist managers in making decisions and handling security incidents. Through natural language processing technology, managers can interact with the intelligent assistant to obtain processing suggestions or perform specific operations. The intelligent assistant optimizes its own response logic and decision-making capabilities by continuously analyzing the interaction data between managers and the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] Figure 1 This is a system block diagram of an artificial intelligence-based computer security system proposed by the present invention. DETAILED DESCRIPTION

[0063] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0064] See also Figure 1 As shown, the present invention is a computer security system based on artificial intelligence, comprising:

[0065] Security monitoring platform: responsible for receiving data from various modules, centrally processing it, and providing a user interface for management personnel to monitor and operate;

[0066] Behavior pattern analysis module: responsible for identifying normal and abnormal behavior patterns through in-depth analysis of user behavior data, providing important basis for security monitoring;

[0067] Intelligent rule engine: Responsible for automatically generating and optimizing security rules based on security policies and real-time threat information to achieve intelligent security defense;

[0068] Call management module: While ensuring information access, it also adds AI-assisted security analysis capabilities;

[0069] Risk assessment module: responsible for risk assessment of the overall security status of the computer system;

[0070] Intelligent Assistant: Responsible for providing comprehensive services such as security command execution, query response, and decision support;

[0071] The security monitoring platform receives user behavior analysis results from the behavior pattern analysis module, including normal behavior baselines and abnormal behavior reports. These user behavior analysis results are used to trigger alerts, assess system security status, and provide input to the intelligent rule engine. New rules generated by the intelligent rule engine are also fed back to the security monitoring platform. When a user makes an information call, the security monitoring platform forwards the call request to the call management module for processing and receives the security assessment results returned by the call management module. The security monitoring platform provides system status data to the risk assessment module periodically or on demand. When processing information calls, the call management module records the relevant call behavior data and sends it to the risk assessment module for security assessment. The intelligent assistant interacts with each module to obtain necessary information and execute instructions. For example, the intelligent assistant queries the risk assessment module for the latest security assessment report, requests the intelligent rule engine to execute specific security rules, or sends alert notifications to the security monitoring platform.

[0072] The working principle of the artificial intelligence-based computer security system proposed in this invention is as follows: first, various data sources (such as user behavior logs, system logs, network traffic, etc.) are configured to send data to the security monitoring platform. The security monitoring platform receives the data from various data sources and performs preliminary data cleaning, formatting and normalization processing;

[0073] The behavior pattern analysis module conducts in-depth analysis of pre-processed user behavior data, using machine learning algorithms to identify normal behavior baselines and abnormal behavior patterns. The analysis results (including normal behavior baselines and abnormal behavior reports) are transmitted to the security monitoring platform. The security monitoring platform triggers alarms based on the abnormal behavior reports provided by the behavior pattern analysis module and notifies managers or intelligent assistants. The security monitoring platform uses the behavior analysis results to assess the current system security status and provide a basis for subsequent operations.

[0074] The intelligent rule engine automatically generates or optimizes security rules based on security policies, real-time threat information, and behavioral pattern analysis results. The generated new or updated rules are fed back to the security monitoring platform to enhance the system's security defense capabilities.

[0075] When a user or system issues an information call request, the security monitoring platform forwards the request to the call management module. When processing the call request, the call management module uses AI technology to perform security analysis to ensure the legitimacy and security of the call. The call management module returns the processing results and security assessment results to the security monitoring platform. The security monitoring platform provides system status data to the risk assessment module regularly or on demand, including user behavior data, system configuration, security logs, etc. The risk assessment module uses this data to assess the overall security status of the system and generate an assessment report;

[0076] Based on the administrator's instructions or automatically triggered events, the intelligent assistant queries each module for information (such as the latest security assessment report), requests the execution of specific security rules (through the intelligent rule engine), or sends alarm notifications to the security monitoring platform.

[0077] In one embodiment, for the above-mentioned security monitoring platform, the security monitoring platform receives data from each module (such as user behavior data, security incident reports, risk assessment results, etc.) and distributes this data to the corresponding processing units. The security monitoring platform provides an intuitive and easy-to-use user interface, allowing managers to easily view system status, receive alarm notifications, and perform security policy adjustments.

[0078] In one embodiment, for the above-mentioned behavior pattern analysis module, the behavior pattern analysis module includes a data collection unit, a data processing unit, a behavior modeling unit and a real-time monitoring unit. The data collection unit is responsible for capturing user behavior data from various data sources. The data collection unit passes the collected raw data to the data processing unit for processing. The data processing unit is responsible for performing pre-processing operations such as cleaning, deduplication, and standardization on the raw data. The data processing unit receives data from the data collection unit, and after processing, passes the clean and standardized data to the behavior modeling unit. The behavior modeling unit is responsible for using machine learning algorithms to model user historical behaviors and form a normal behavior baseline. The behavior modeling unit receives data from the data processing unit, and after modeling analysis, passes the model parameters and baseline data to the real-time monitoring unit. The real-time monitoring unit is responsible for real-time analysis of user behavior and comparing it with the behavior model to evaluate the degree of abnormality. The real-time monitoring unit receives the behavior model and baseline data from the behavior modeling unit, and at the same time receives the current user behavior data (which may come from the data processing unit or directly obtained from the data source). After comparison and analysis, the abnormal alarm and report are passed to the security monitoring platform.

[0079] In one embodiment, for the above-mentioned intelligent rule engine, the intelligent rule engine includes a rule base management unit, a rule generation and optimization unit, and a rule execution unit. The rule base management unit is responsible for the creation, maintenance, and management of the rule base. The rule base management unit receives rule update requests from the rule generation unit and the rule execution unit, and synchronizes the updated rule base data to the rule generation unit and the rule execution unit. At the same time, the rule base management unit is responsible for reporting the status information of the rule base (such as the number of rules, version information, etc.) to the security monitoring platform. The rule generation and optimization unit uses machine learning algorithms to analyze historical data and current threat trends to generate and optimize security rules. The meta-unit obtains the basic rule set from the rule base management unit as an initial reference, obtains the latest security events and user behavior data from the security monitoring platform as input, and sends the newly generated rules or rule optimization suggestions to the rule base management unit for updating. The rule execution unit executes security response measures based on real-time monitoring results and rules in the rule base. The rule execution unit receives security events and user behavior data from the security monitoring platform, and the rule base management unit obtains the latest rule set, matches and judges the event data according to the rule set, and sends the security response measures that need to be executed to the corresponding security devices or systems (such as firewalls, intrusion detection systems, etc.). At the same time, the execution results and feedback information are reported to the security monitoring platform.

[0080] In one embodiment, for the above-mentioned call management module, the call management module includes a call request unit, an information storage unit, a security verification unit and a call management unit. The call request unit initiates a request for information call and sends the call request information to the call management unit. The call request unit receives the call result or security verification request returned by the call management unit. The information storage unit is responsible for storing original data and backup data and providing data support for the call management unit. The information storage unit receives the call information sent by the call management unit and performs backup and comparison operations. The security verification unit executes additional security verification processes according to the instructions of the call management unit and returns the verification results to the call management unit, which decides whether to allow the call request to pass. The call management unit receives the call request from the call request unit, performs a security assessment on the call request, and executes corresponding security measures (such as information backup and comparison, security verification, restriction measures, etc.) according to the assessment results. The call result or security verification request is returned to the call request unit to complete the entire call process.

[0081] In one embodiment, for the above-mentioned risk assessment module, the risk assessment module receives data and information from the behavior pattern analysis module and the intelligent rule engine to perform a comprehensive risk assessment. The risk assessment module integrates data and information from different security modules, such as the user behavior characteristics of the behavior pattern analysis module, the security rule triggering status of the intelligent rule engine, etc., so as to perform a more comprehensive and accurate risk assessment. When potential security risks are discovered, the risk assessment module automatically triggers the early warning mechanism and sends risk warning notifications to managers via email, text messages, etc.

[0082] In one embodiment, for the above-mentioned intelligent assistant, the intelligent assistant includes an input unit, a natural language processing unit, a decision support unit, a knowledge base unit, and a knowledge base unit. The input unit is responsible for receiving instructions and queries input by managers through voice or text. The input unit passes the received input data to the natural language processing unit for processing. The natural language processing unit is responsible for parsing and understanding the data passed by the input unit, converting the natural language into commands or query statements that can be recognized by the system. The natural language processing unit passes the parsed commands or query statements to the decision support unit for processing. At the same time, the interaction data is passed to the continuous learning unit for learning and optimization. The decision support unit provides processing suggestions or automatically executes the emergency response process for the manager based on the commands or query statements passed by the natural language processing unit and the information in the knowledge base. The decision support unit passes the interaction data to the continuous learning unit for learning and optimization. The knowledge base unit stores information related to the type, urgency, processing suggestions and emergency response process of security incidents. The knowledge base unit provides information support to the decision support unit and receives optimization suggestions from the continuous learning unit to update and improve the knowledge base.

[0083] In one embodiment, for the above-mentioned behavior modeling unit, the behavior modeling unit uses LSTM to train, test, and infer data from the data processing unit, including the following steps:

[0084] Data preparation:

[0085] Collect feature data related to the target task and divide the dataset into training set, validation set and test set with a ratio of 70%, 15% and 15%;

[0086] Model construction:

[0087] Building a model using LSTM:

[0088] Forget gate: f t =σ(W f ·[h t-1 ,x t ]+b f )

[0089] Among them, W f is the weight matrix of the forget gate, b f is the bias term, σ is the sigmoid function, [h t-1 ,x t ] means h t-1 and x t Splice into a vector;

[0090] Input gate: The input gate is responsible for updating the cell state. The input gate consists of two parts: a sigmoid layer that determines which information will be updated; and a tanh layer that creates a new candidate value vector. The new candidate value vector is added to the cell state. Finally, the two information are multiplied to update the cell state.

[0091] Sigmoid layer: i t =σ(W i ·[h t-1 ,x t ]+b i );

[0092] tanh layer:

[0093] Cell status update:

[0094] Output gate: The output gate determines which part of the information based on the cell state is used for output, according to the current input The state of the hidden layer at the previous moment h t-1 And the latest cell state C t , through the combined action of sigmoid function and tanh function, the output h at the current moment is determined t ;

[0095] Sigmoid layer: o t =σ(W o ·[h t-1 ,x t ]+b o );

[0096] Output hidden state: h t =o t *tanh(C t );

[0097] Training process:

[0098] Forward propagation: For each time step of input, the hidden state and output are calculated according to the RNN;

[0099] Calculate loss: Use a loss function to measure the difference between the model prediction and the actual label;

[0100] Backpropagation: Calculate the gradient of loss with respect to model parameters through the time backpropagation algorithm;

[0101] Parameter update: Use Adam to update model parameters according to the gradient;

[0102] Testing and Reasoning:

[0103] The model performance is evaluated on the test set. During inference, the data to be classified is input into the trained model. The model outputs the probability distribution of each category, and the category with the highest probability is taken as the classification result.

[0104] In one embodiment, the rule generation and optimization unit uses a genetic algorithm to analyze historical data and current threat trends to generate and optimize security rules. Specifically, the following steps are performed:

[0105] Initialization: Encoding security rules (such as firewall rules and intrusion detection system signatures) into a genotype form for genetic algorithm processing. This involves converting the different parameters of the rules (such as source IP address range, port number, protocol type, etc.) into binary strings or other encoding methods, and randomly generating an initial population of multiple individuals, each of which represents a potential set of security rules;

[0106] Evaluate fitness: Collect historical security event data, user behavior pattern data, and current threat intelligence data. For each individual in the population (i.e., each rule set), use this data to evaluate its fitness. The fitness function should be designed to reflect the performance of the rule set in identifying real threats and avoiding false positives. Based on the evaluation results, assign a fitness value to each individual. A higher value indicates better performance of the rule set.

[0107] Selection: Roulette wheel selection selects individuals based on their fitness values. Individuals with high fitness are more likely to be selected, which ensures that the characteristics of the excellent rule set can be inherited to the next generation. At the same time, the sampling elite retention strategy directly copies the individuals with the highest fitness in the current population to the next generation to avoid the loss of excellent individuals in the inheritance process.

[0108] Crossover: Randomly select two individuals from the current population as parents, exchange rule parameters between the parent individuals to generate new offspring individuals. The crossover operation can introduce new rule combinations and increase the diversity of the population.

[0109] Mutation: Randomly select an individual from the population and randomly modify the rule parameters to simulate the process of gene mutation. The mutation operation helps explore new areas in the solution space and prevent the algorithm from falling into local optimality.

[0110] Iteration: Repeat the fitness evaluation, selection, crossover, and mutation until the predetermined number of iterations is reached or other stopping conditions are met (such as the fitness value no longer significantly improves);

[0111] Termination and output: When the predetermined number of iterations is reached, the fitness value reaches the preset threshold, or the fitness changes of individuals in the population tend to be stable, the algorithm terminates, and the individual with the highest fitness is selected from the final population as the optimal rule set, which is decoded into practical and usable security rules.

[0112] In one embodiment, the continuous learning unit optimizes its response logic and decision-making capabilities by continuously analyzing the interaction data between managers and the system (including voice commands, text queries, response results, etc.). The specific steps are as follows:

[0113] Data Collection: Captures network traffic data in real time and records user firewall configuration changes, rule additions / deletions, and other operational actions.

[0114] Preprocessing: Perform protocol parsing and session reconstruction on traffic data to extract key information such as IP address, port number, and protocol type. At the same time, clean and format user operation records.

[0115] Model training: Use machine learning algorithms to train pre-processed data to identify malicious traffic patterns and abnormal user behavior;

[0116] Online learning and optimization: Analyze newly captured traffic data in real time and dynamically adjust firewall rules based on model predictions. Simultaneously, the model is continuously optimized based on user feedback and system performance metrics (such as false positive rate and false negative rate).

[0117] Knowledge base update: Regularly obtain the latest threat information and security strategies from security communities, threat intelligence sources, and other channels, and update them to the system's knowledge base to improve defense capabilities against emerging threats.

[0118] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. A computer security system based on artificial intelligence, characterized in that: include: Security monitoring platform: responsible for receiving data from various modules, centrally processing it, and providing a user interface for management personnel to monitor and operate; Behavior pattern analysis module: responsible for identifying normal and abnormal behavior patterns through in-depth analysis of user behavior data, providing important basis for security monitoring; Intelligent rule engine: responsible for automatically generating and optimizing security rules based on security policies and real-time threat information; Call management module: While ensuring information access, it also adds AI-assisted security analysis capabilities; Risk assessment module: responsible for risk assessment of the overall security status of the computer system; Intelligent assistant: responsible for providing comprehensive services; The security monitoring platform receives user behavior analysis results from the behavior pattern analysis module. The user behavior analysis results are used to trigger alarms, evaluate the system security status, and provide input for the intelligent rule engine. The new rules generated by the intelligent rule engine will also be fed back to the security monitoring platform. When the user makes an information call, the security monitoring platform forwards the call request to the call management module for processing, and receives the security assessment results returned by the call management module. The security monitoring platform provides system status data to the risk assessment module regularly or on demand. When processing information calls, the call management module will record relevant call behavior data and send it to the risk assessment module for security assessment. The intelligent assistant interacts with each module to obtain necessary information and execute instructions.

2. The computer security system based on artificial intelligence according to claim 1, characterized in that: The security monitoring platform receives data from each module and distributes the data to the corresponding processing units. The security monitoring platform provides a user interface so that managers can view system status, receive alarm notifications, and perform security policy adjustments.

3. The computer security system based on artificial intelligence according to claim 1, characterized in that: The behavior pattern analysis module includes a data collection unit, a data processing unit, a behavior modeling unit and a real-time monitoring unit. The data collection unit is responsible for capturing user behavior data from various data sources. The data collection unit passes the collected raw data to the data processing unit for processing. The data processing unit is responsible for performing pre-processing operations on the raw data. The data processing unit receives data from the data collection unit, and passes the clean and standardized data to the behavior modeling unit after processing. The behavior modeling unit is responsible for using machine learning algorithms to model user historical behaviors and form a normal behavior baseline. The behavior modeling unit receives data from the data processing unit, and after modeling analysis, passes the model parameters and baseline data to the real-time monitoring unit. The real-time monitoring unit is responsible for real-time analysis of user behavior, and compares it with the behavior model to evaluate the degree of abnormality. The real-time monitoring unit receives the behavior model and baseline data from the behavior modeling unit, and at the same time receives the current user behavior data. After comparison and analysis, the abnormal alarm and report are passed to the security monitoring platform.

4. The computer security system based on artificial intelligence according to claim 3, characterized in that: The intelligent rule engine includes a rule base management unit, a rule generation and optimization unit, and a rule execution unit. The rule base management unit is responsible for creating, maintaining, and managing the rule base. The rule base management unit receives rule update requests from the rule generation unit and the rule execution unit, and synchronizes the updated rule base data to the rule generation unit and the rule execution unit. At the same time, the rule base management unit is responsible for reporting the status information of the rule base to the security monitoring platform. The rule generation and optimization unit uses a machine learning algorithm to analyze historical data and current threat trends to generate and optimize security rules. The rule generation and optimization unit obtains a basic rule set from the rule base management unit as an initial reference, obtains the latest security event and user behavior data from the security monitoring platform as input, and sends the newly generated rules or rule optimization suggestions to the rule base management unit for updating. The rule execution unit executes security response measures based on real-time monitoring results and rules in the rule base. The rule execution unit receives security event and user behavior data from the security monitoring platform. The rule base management unit obtains the latest rule set, matches and judges the event data based on the rule set, and sends the security response measures that need to be executed to the corresponding security devices or systems. At the same time, it also reports the execution results and feedback information to the security monitoring platform.

5. The computer security system based on artificial intelligence according to claim 4, characterized in that: The call management module includes a call request unit, an information storage unit, a security verification unit and a call management unit. The call request unit initiates a request for information call and sends the call request information to the call management unit. The call request unit receives the call result or security verification request returned by the call management unit. The information storage unit is responsible for storing original data and backup data and providing data support for the call management unit. The information storage unit receives the call information sent by the call management unit and performs backup and comparison operations. The security verification unit executes additional security verification processes according to the instructions of the call management unit and returns the verification results to the call management unit, which decides whether to allow the call request to pass. The call management unit receives the call request from the call request unit, performs a security assessment on the call request, executes corresponding security measures based on the assessment results, and returns the call result or security verification request to the call request unit to complete the entire call process.

6. The computer security system based on artificial intelligence according to claim 1, characterized in that: The risk assessment module receives data and information from the behavior pattern analysis module and the intelligent rule engine to perform a comprehensive risk assessment. The risk assessment module integrates data and information from different security modules. When potential security risks are discovered, the risk assessment module automatically triggers an early warning mechanism and sends a risk warning notification to management personnel.

7. The computer security system based on artificial intelligence according to claim 6, characterized in that: The intelligent assistant includes an input unit, a natural language processing unit, a decision support unit, a knowledge base unit, and a continuous learning unit. The input unit is responsible for receiving instructions and queries input by managers through voice or text. The input unit passes the received input data to the natural language processing unit for processing. The natural language processing unit is responsible for parsing and understanding the data passed by the input unit and converting natural language into commands or query statements that can be recognized by the system. The natural language processing unit passes the parsed commands or query statements to the decision support unit for processing. At the same time, the interactive data is passed to the continuous learning unit for learning and optimization. The decision support unit provides processing suggestions or automatically executes emergency response processes for managers based on the commands or query statements passed by the natural language processing unit and combined with information in the knowledge base. The decision support unit passes the interactive data to the continuous learning unit for learning and optimization. The knowledge base unit stores information related to security event types, urgency, processing suggestions, and emergency response processes. The knowledge base unit provides information support to the decision support unit and receives optimization suggestions from the continuous learning unit to update and improve the knowledge base.

8. The computer security system based on artificial intelligence according to claim 3, characterized in that: The behavior modeling unit uses LSTM to train, test, and infer the data from the data processing unit, including the following steps: Data preparation: Collect feature data related to the target task and divide the dataset into training set, validation set and test set with a ratio of 70%, 15% and 15%; Model construction: Building a model using LSTM: Forget gate: f t =σ(W f ·[h t-1 ,x t ]+b f ) Among them, W f is the weight matrix of the forget gate, b f is the bias term, σ is the sigmoid function, [h t-1 ,x t ] means h t-1 and x t Splice into a vector; Input gate: The input gate is responsible for updating the cell state. The input gate consists of two parts: a sigmoid layer that determines which information will be updated; and a tanh layer that creates a new candidate value vector. The new candidate value vector is added to the cell state. Finally, the two information are multiplied to update the cell state. Sigmoid layer: i t = σ(W i · [h t-1 , x t + b i ); tanh layer: Cell status update: Output gate: The output gate determines which part of the information based on the cell state is used for output, according to the current input tx t , the state of the hidden layer at the previous moment h t-1 And the latest cell state C t , through the combined action of sigmoid function and tanh function, the output h at the current moment is determined t ; Sigmoid layer: o t = σ(W o · [h t-1 , x t + b o ); Output hidden state: h t =o t *tanh(C t ); Training process: Forward propagation: For each time step of input, the hidden state and output are calculated according to the RNN; Calculate loss: Use a loss function to measure the difference between the model prediction and the actual label; Backpropagation: Calculate the gradient of loss with respect to model parameters through the time backpropagation algorithm; Parameter update: Use Adam to update model parameters according to the gradient; Testing and Reasoning: The model performance is evaluated on the test set. During inference, the data to be classified is input into the trained model. The model outputs the probability distribution of each category, and the category with the highest probability is taken as the classification result.

9. The computer security system based on artificial intelligence according to claim 4, characterized in that: The rule generation and optimization unit uses a genetic algorithm to analyze historical data and current threat trends to generate and optimize security rules. The specific steps are as follows: Initialization: Encode the safety rules into the genotype form processed by the genetic algorithm and randomly generate an initial population of multiple individuals; Fitness assessment: Collect historical security event data, user behavior pattern data, and current threat intelligence data. For each individual in the population, use this data to assess its fitness. Based on the assessment results, assign a fitness value to each individual. Selection: Roulette wheel selection, which selects individuals based on their fitness values. Individuals with higher fitness are more likely to be selected. At the same time, the sampling elite retention strategy directly copies the individuals with the highest fitness in the current population to the next generation. Crossover: Randomly select two individuals from the current population as parents, exchange rule parameters between the parent individuals to generate new offspring individuals; Mutation: Randomly select an individual from the population and randomly modify the rule parameters to simulate the process of gene mutation; Iteration: Repeat the evaluation of fitness, selection, crossover, and mutation until the predetermined number of iterations is reached or other stopping conditions are met; Termination and output: When the predetermined number of iterations is reached, the fitness value reaches the preset threshold, or the fitness changes of individuals in the population tend to be stable, the algorithm terminates, and the individual with the highest fitness is selected from the final population as the optimal rule set, which is decoded into practical and usable security rules.

10. The computer security system based on artificial intelligence according to claim 7, characterized in that: The continuous learning unit optimizes its response logic and decision-making capabilities by continuously analyzing the interaction data between managers and the system. The specific steps are: Data collection: Capture network traffic data in real time and record user operations. Preprocessing: Perform protocol analysis and session reconstruction on traffic data to extract key information. At the same time, clean and format user operation records. Model training: training on pre-processed data to identify malicious traffic patterns and abnormal user behavior; Online learning and optimization: Analyze newly captured traffic data in real time and dynamically adjust firewall rules based on model predictions. Simultaneously, the model is continuously optimized based on user feedback and system performance indicators. Knowledge base update: Regularly obtain the latest threat information and security policies and update them to the system's knowledge base.

Citation Information

Patent Citations

  • Computer information security monitoring system based on data analysis

    CN117312096A