Network security risk early warning method and system based on multi-source data fusion
By integrating multi-source data and conducting multi-dimensional analysis, combined with rule engines, AI models for detecting behavioral anomalies, and graph neural networks, the shortcomings of data integration and threat identification in cybersecurity analysis have been addressed, achieving efficient and accurate early warning of cybersecurity risks.
Patent Information
- Application Number
- CN202511389168.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-26
- Publication Date
- 2025-11-14
AI Technical Summary
Existing technologies struggle to effectively integrate diverse data sources in cybersecurity analysis, lacking in-depth mining of entity relationships and spatiotemporal correlation analysis, resulting in insufficient accuracy and real-time performance in threat identification, particularly in the weak ability to identify new or covert attacks.
By collecting security data from multiple sources, performing entity identification and correlation processing, constructing a threat fusion matrix, and combining a rule engine, anomaly detection AI model, and graph neural network, multi-dimensional threat identification and graded early warning can be achieved.
It significantly improves the accuracy and real-time performance of cybersecurity risk warnings, comprehensively captures threat characteristics, and achieves integrated identification of known threats, abnormal events, and potential threats, generating warning signals and handling suggestions for different risk levels.
Smart Images

Figure CN120956520A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a network security risk early warning method and system based on multi-source data fusion. Background Technology
[0002] With the rapid development of network technology, cybersecurity threats are becoming increasingly diversified, complex, and covert. Traditional network security analysis methods based on single data sources are no longer sufficient to cope with the growing number of attack methods. While diverse data sources such as network traffic data, endpoint behavior data, and log data contain rich threat information, existing technologies have shortcomings in data integration, threat feature extraction, and risk warning due to heterogeneous data formats, uneven spatiotemporal distribution, and limitations in analysis methods. For example, traditional rule-based detection methods are effective against known threats but have weak identification capabilities for new or covert attacks; single AI models struggle to comprehensively capture multidimensional threat features; furthermore, the lack of in-depth mining of entity relationships and spatiotemporal correlation analysis results in insufficient accuracy and real-time performance in threat identification.
[0003] To address these issues, there is an urgent need for a cybersecurity risk early warning method based on multi-source data fusion. This method would integrate multi-source security data, construct a unified threat analysis framework, and combine rule engines, anomaly detection, and graph neural network technologies to achieve accurate identification and tiered early warning of cyber threats. This approach requires fully exploring the correlations between data, improving the ability to extract threat features, and enhancing the timeliness and accuracy of early warnings through multi-dimensional analysis, thus providing comprehensive support for cybersecurity protection. Summary of the Invention
[0004] The purpose of this invention is to provide a network security risk early warning method and system based on multi-source data fusion to solve the problems pointed out in the background art.
[0005] In a first aspect, the network security risk early warning method based on multi-source data fusion provided in the embodiments of the present invention includes:
[0006] Collect multi-source security data;
[0007] Entity identification and association processing are performed on the multi-source security data to obtain entity association information;
[0008] The entity association information is spatiotemporally aligned and fused to construct a threat fusion matrix;
[0009] Based on rule engine matching, behavior anomaly detection AI model and graph neural network, risk analysis and threat identification are performed on the threat fusion matrix;
[0010] Based on the results of risk analysis and threat identification, tiered early warnings are issued.
[0011] Optionally, the multi-source security data includes at least network traffic data, terminal behavior data, and log data.
[0012] Optionally, the step of performing entity identification and association processing on the multi-source security data to obtain entity association information includes:
[0013] Identify entities in multi-source security data;
[0014] Based on the attribute and behavioral characteristics of the entity objects, the association relationships between different entity objects are established to obtain entity association information.
[0015] Optionally, the step of performing spatiotemporal alignment and fusion processing on the entity association information to construct a threat fusion matrix includes:
[0016] Align and merge entity association information in the time and space dimensions to generate a unified spatiotemporal association map;
[0017] Based on the spatiotemporal correlation map, multi-dimensional threat features are extracted;
[0018] Based on the aforementioned multi-dimensional threat characteristics, a matrix structure reflecting threat relationships is constructed to obtain the threat fusion matrix.
[0019] Optionally, the risk analysis and threat identification of the threat fusion matrix based on rule engine matching, behavioral anomaly detection AI models, and graph neural networks includes:
[0020] Using the rule engine, the features in the threat fusion matrix are matched with a predefined threat rule base to output known threat patterns;
[0021] The threat fusion matrix is input into a trained behavior anomaly detection AI model, which outputs abnormal events.
[0022] The entity relationship topology represented by the threat fusion matrix is input into a graph neural network to output potential threat associations;
[0023] By integrating the known threat patterns, the anomalous events, and the potential threat associations, a comprehensive risk analysis and threat identification result is generated.
[0024] Optionally, the tiered early warning system based on the results of risk analysis and threat identification includes:
[0025] Risk levels are determined based on risk scoring results;
[0026] Based on different risk levels, corresponding early warning signals are generated, and corresponding action recommendations are provided.
[0027] Optionally, it also includes autonomous defense steps based on the construction of network-endogenous immune resilience and attack entropy reduction response, specifically including:
[0028] Based on the threat fusion matrix, a dynamic attack knowledge hypergraph is constructed, and the attack strategy is used to generate a network that infers the sequence of potential attack actions and their probability distribution.
[0029] Based on the probability distribution, the potential attack action sequences are prioritized, and the immune strategy generator synthesizes a micro-perturbation defense strategy based on the concept of moving target defense for high-probability attack actions.
[0030] Based on the sorted sequence of potential attack actions and the micro-perturbation defense strategy, a software-defined elastic controller is used to coordinate the scheduling of programmable elements in the network, calculate the optimal elastic deployment sequence, and deploy lightweight elastic execution points at key nodes to build an endogenous elastic network architecture.
[0031] When an attack is detected, an entropy reduction response mechanism is initiated based on the intrinsically resilient network architecture. This mechanism dynamically adjusts the strength and scope of the micro-perturbation defense strategy and uses programmable elements in the intrinsically resilient network architecture to transparently redirect the attack flow to a highly interactive trapping mesh.
[0032] By using data captured from the trapping grid to update the model parameters of the attack strategy generation network and the immunity strategy generator through online deep learning, the system's defense capabilities can be autonomously evolved.
[0033] Optionally, the micro-perturbation defense strategy includes one or more combinations of the following strategies:
[0034] Dynamic address hopping strategy, communication port randomization strategy, network topology dynamic reconstruction strategy, and false information injection strategy for critical services.
[0035] Optionally, the online deep learning adopts a model update mechanism based on a combination of incremental learning and adversarial training, and uses attack data captured from the highly interactive trapping grid and unknown threat samples synthesized through the adversarial generative network to perform collaborative optimization training on the attack strategy generation network and the immune strategy generator.
[0036] Secondly, the network security risk early warning system based on multi-source data fusion provided in this embodiment of the invention includes:
[0037] The data acquisition module is used to collect multi-source security data;
[0038] The entity recognition and association processing module is used to perform entity recognition and association processing on the multi-source security data to obtain entity association information.
[0039] The spatiotemporal alignment and fusion processing module is used to perform spatiotemporal alignment and fusion processing on the entity association information to construct a threat fusion matrix;
[0040] The risk analysis and threat identification module is used to perform risk analysis and threat identification on the threat fusion matrix based on rule engine matching, behavior anomaly detection AI model and graph neural network.
[0041] The tiered early warning module is used to provide tiered early warnings based on the results of risk analysis and threat identification.
[0042] The present invention has achieved the following beneficial effects:
[0043] This technical solution significantly improves the accuracy and real-time performance of network security risk early warning through multi-source data fusion and multi-dimensional analysis. The solution integrates multi-source data such as network traffic, terminal behavior, and logs to construct a unified spatiotemporal correlation graph and threat fusion matrix, comprehensively capturing threat characteristics. Combining a rule engine, anomaly detection AI model, and graph neural network, it achieves comprehensive identification of the correlation between known threats, abnormal events, and potential threats, overcoming the shortcomings of single methods. Through a tiered early warning mechanism, it generates warning signals and handling suggestions for different risk levels, providing precise guidance for security operations and maintenance, thereby effectively reducing the potential risks of network attacks.
[0044] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the written description and the accompanying drawings.
[0045] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0046] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:
[0047] Figure 1 This is a flowchart of a network security risk early warning method based on multi-source data fusion in an embodiment of the present invention;
[0048] Figure 2 This is a schematic diagram illustrating the specific implementation steps of steps S6 to S10 in this embodiment of the invention.
[0049] Figure 3 This is a schematic diagram of a network security risk early warning system based on multi-source data fusion in an embodiment of the present invention. Detailed Implementation
[0050] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.
[0051] To address the shortcomings of existing cybersecurity analysis methods, this solution proposes a comprehensive risk warning approach based on multi-source data fusion. During the development process, firstly, entity identification and association processing are used to mine objects and their relationships within multi-source security data, forming unified entity association information. Then, spatiotemporal alignment fusion is used to construct a threat fusion matrix to capture multi-dimensional threat characteristics. Based on this, the precise matching of a rule engine, the anomaly detection capabilities of an AI model, and the topology analysis capabilities of a graph neural network are combined to achieve multi-level threat identification. Finally, actionable response suggestions are provided through risk classification and early warning signal generation. The entire development process emphasizes the synergistic optimization of data integration, feature extraction, and analysis methods to achieve efficient and accurate cybersecurity risk warnings.
[0052] Figure 1 A flowchart of a network security risk early warning method based on multi-source data fusion is provided for embodiments of this application, such as... Figure 1 As shown, the method includes:
[0053] S1. Collect multi-source security data. The multi-source security data includes at least network traffic data, terminal behavior data, and log data.
[0054] S2. Perform entity identification and association processing on the multi-source security data to obtain entity association information. Step S2 specifically includes the following sub-steps:
[0055] S21. Identify entity objects in multi-source security data.
[0056] Entity recognition refers to extracting objects with clear identifiers and attributes (such as IP addresses, user IDs, and device MAC addresses) from multi-source security data (such as network traffic data, terminal behavior data, and log data) to build the foundation for subsequent correlation analysis. An entity object is an element with independent identifiers and behavioral characteristics in a network security environment, including but not limited to network devices, user accounts, processes, or files. Entity recognition uses Natural Language Processing (NLP) and pattern matching techniques to extract entity identifiers from data (e.g., matching IP addresses using regular expressions, in the format xxx.xxx.xxx.xxx), and parses their attribute characteristics (such as the device's operating system type and the user's login time) and behavioral characteristics (such as the frequency of data packet transmission and the resource utilization of processes). The specific acquisition methods include: First, extracting fields such as source IP, destination IP, and port number from network traffic data (e.g., PCAP files) using a packet parsing tool; the parsing tool must support TCP / IP protocol stack decomposition. Second, extracting process ID, user ID, and associated file path from terminal behavior data (e.g., system call logs) using a system call tracing tool. Third, extracting event subjects (e.g., user ID, device ID) and timestamps from log data (e.g., Syslog) using regular expressions and a log parser. After extraction, entity objects are stored in key-value pairs, where the key is the entity identifier (e.g., IP address) and the value is a set of attributes (e.g., operating system, port status). To ensure accuracy, predefined entity templates (e.g., IP address templates, user ID templates) are used for validation, and invalid or incorrectly formatted entities are removed.
[0057] Here is a specific implementation example:
[0058] In a corporate network security monitoring scenario, entity objects are identified from network traffic data, endpoint behavior data, and log data. First, from the network traffic data (captured in PCAP format and stored on the corporate gateway device), the TCP / IP packets are parsed using Wireshark to extract the source IP address (e.g., 192.168.1.100), destination IP address (e.g., 10.0.0.1), source port (e.g., 8080), and protocol type (e.g., HTTP). Then, Wireshark's filtering function (setting the filtering rule to "ip.src == 192.168.1.0 / 24") is used to filter IP addresses within the local area network, generating an entity list containing 1000 IP addresses. Each entity record includes the IP address, protocol type, and timestamp. Next, from the terminal behavior data (collected via the Linux system's `auditd` tool, recording system calls), the `ausearch` tool is used to extract process IDs (e.g., PID 1234), user IDs (e.g., UID 1001), and associated file paths (e.g., ` / etc / passwd`). The format of the extracted results is then validated using regular expressions (e.g., "pid = [0-9]+"), resulting in 500 process entities and 200 user entities. Finally, from the log data (stored in Syslog format on the log server), the `rsyslog` parser, combined with regular expressions (e.g., "user = [a-zA-Z0-9]+"), is used to extract user IDs (e.g., admin), device IDs (e.g., server01), and event types (e.g., login failed), generating 300 log entities. All entity objects are stored as key-value pairs (e.g., "IP: 192.168.1.100, attribute: {protocol: HTTP, time: 14:30}"), and invalid IP addresses (e.g., 256.1.2.3) are removed through template validation, resulting in a dataset containing 1700 valid entity objects for subsequent correlation analysis.
[0059] S22. Based on the attribute and behavioral characteristics of the entity objects, establish the association relationship between different entity objects to obtain entity association information.
[0060] Establishing relationships between entity objects involves analyzing their attribute characteristics (such as IP address network segments and user ID roles) and behavioral characteristics (such as data packet sending frequency and user operation sequences) to construct a relationship graph and generate entity relationship information. Entity relationship information is a data structure describing the relationships between entity objects, including relationship type (such as communication relationship and attribution relationship), relationship strength (such as communication frequency), and relationship context (such as time window). Specific acquisition methods include: First, determining static relationships through attribute feature matching (such as IP address and device ID network segment attribution), with network segment information extracted from network topology configuration files (containing a mapping table of IP addresses and devices); second, calculating dynamic relationships through behavioral feature analysis (such as data packet time series and user operation sequences), with behavioral features extracted from entity object logs or traffic data, and using time series analysis algorithms to calculate relationship strength (such as calculating communication strength between IPs based on data packet sending frequency). Relationships are stored in a graph structure, where nodes represent entity objects, edges represent relationship types, and edge weights represent relationship strength. To improve accuracy, a sliding time window (window size such as 5 minutes) is used to aggregate behavioral data within the same time period, and a correlation analysis algorithm (such as Pearson correlation coefficient) is used to filter out low-strength associations. The association algorithm is constructed based on a weighted graph model. First, an empty graph is initialized, entity pairs are traversed, attribute matching degree (such as IP network segment overlap) and behavioral correlation (such as communication frequency) are calculated, weighted edges are generated, and weak association edges are filtered out (threshold such as correlation coefficient <0.3).
[0061] For example, in the aforementioned enterprise network security scenario, based on the 1700 entity objects identified by S21, the relationships between entities are constructed. First, the attribution relationship between IP addresses and device IDs is extracted from the network topology configuration file (stored on the network management server in CSV format, containing a mapping of IP addresses to device IDs). It is confirmed that 192.168.1.100 belongs to device server01, forming a static association (e.g., "IP: 192.168.1.100 - Device: server01, Association Type: Attribution"). Then, the time series of traffic data was analyzed using Wireshark to count the communication frequency between IP addresses within a 5-minute window (e.g., 192.168.1.100 and 10.0.0.1 sending 100 packets per minute). The Pearson correlation coefficient algorithm (implemented as a Python script, taking the communication frequency sequence of IP pairs as input and outputting the correlation coefficient with a threshold of 0.5) was used to calculate the communication strength and generate dynamic associations (e.g., "IP: 192.168.1.100 - IP: 10.0.0.1, association type: communication, weight: 0.75"). For terminal behavior data, the operation sequences of user IDs and process IDs in the auditd logs were analyzed (e.g., UID1001 calling PID1234 to access...).
[0062] The ` / etc / passwd` file uses a sequence similarity algorithm (based on Levenshtein distance, calculating the edit distance of operation sequences) to determine the association strength (e.g., "UID: 1001 - PID: 1234, association type: operation, weight: 0.8"). Log data associations are generated by matching event timestamps parsed from rsyslog (e.g., the login event of the admin user on server01) (e.g., "user: admin - device: server01, association type: login, weight: 1.0"). Finally, an association graph containing 1700 nodes and approximately 5000 edges is constructed and stored as a graph structure (nodes represent entities, edges represent association types and weights). Weakly associated edges with a correlation coefficient below 0.3 are removed to obtain entity association information.
[0063] S3. Perform spatiotemporal alignment and fusion processing on the entity association information to construct a threat fusion matrix. Step S3 specifically includes the following sub-steps:
[0064] S31. Align and merge entity association information in the time and space dimensions to generate a unified spatiotemporal association map.
[0065] Spatiotemporal alignment and fusion refers to the unified processing of entity association information according to the time dimension (such as the time of event occurrence) and the spatial dimension (such as the network segment of IP address and the geographical location of device), generating a graph reflecting the spatiotemporal relationships between entities. A spatiotemporal association graph is a weighted graph structure with entities as nodes, association relationships as edges, and time and spatial attributes as edge weights, reflecting the interaction patterns of entities in a specific time and spatial context. Time dimension alignment is achieved through timestamp standardization. Specifically, timestamps (such as the capture time of traffic packets and log event times) are extracted from entity association information, converted to a unified time format (such as UTC time, accurate to milliseconds), and associations within the same time period are aggregated through time windows (such as a 5-minute window). Spatial dimension alignment is achieved through network topology and device location information. Specifically, the network segment of IP address and device ID are extracted from the network topology configuration file, and the physical or logical location of the device (such as the data center number) is extracted from the device management database. The fusion process uses a graph fusion algorithm, which is constructed as follows: An initial spatiotemporal graph is created, with nodes representing entities and edges representing relationships. Edge weights are calculated by combining time difference (calculated as timestamp differences) and spatial distance (based on network segment overlap or geographical distance), and a weighted average method is used to calculate the overall weight. To ensure alignment accuracy, timestamps are calibrated using a time synchronization protocol (such as NTP), and spatial dimensions are ensured to be accurate through topology consistency checks (such as verifying the mapping between IP addresses and device IDs).
[0066] For example, in enterprise network security scenarios, spatiotemporal alignment and fusion are performed based on entity association information generated by S22. First, the timestamps in the association information are extracted (such as the capture time of traffic packets 2023-10-10T14:30:00.123Z and the recording time of log events 2023-10-10T14:30:01.456Z), converted to UTC format (accurate to milliseconds) using Python's datetime library, and the timestamp deviation is calibrated (controlled within 1ms) through an NTP client (configured to synchronize to time.google.com). The association relationships are aggregated into a 5-minute time window (such as 14:30:00-14:35:00) to generate time-aligned association subsets (such as "IP: 192.168.1.100-IP: 10.0.0.1, communication time: 14:30:00"). In the spatial dimension, network segments of IP addresses (e.g., 192.168.1.0 / 24) are extracted from the network topology configuration file (CSV format, containing mappings between IP addresses and device IDs), and device locations (e.g., server01 is located in data center A) are extracted from the device management database (MySQL storage, containing device IDs and data center numbers). The fusion process uses a graph fusion algorithm (implemented based on the NetworkX library, taking an association graph as input, calculating time difference and network segment overlap, and outputting a weighted spatiotemporal graph), assigning a comprehensive weight to each edge (60% for time difference and 40% for network segment overlap, calculated through a weighted average). For example, the communication edge between IP: 192.168.1.100 and IP: 10.0.0.1 has a time difference of 0ms (within the same window), a network segment overlap of 0 (different network segments), and a comprehensive weight of 0.6. The final spatiotemporal correlation graph contains 1700 nodes and 5000 edges. Each edge is labeled with a timestamp and spatial location (e.g., "IP: 192.168.1.100-IP: 10.0.0.1, weight: 0.6, time: 14:30:00, location: data center A-data center B"), which provides a foundation for subsequent threat feature extraction.
[0067] S32. Based on the spatiotemporal correlation map, extract multi-dimensional threat features.
[0068] Multi-dimensional threat feature extraction refers to analyzing the interaction patterns between entities in a spatiotemporal correlation graph to extract features reflecting potential threats, including topological features (such as node degree and clustering coefficient), behavioral features (such as communication frequency and abnormal traffic peaks), and temporal features (such as event suddenness). Multi-dimensional threat features are quantitative indicators that characterize network security risks, such as node centrality, edge traffic anomaly, and the sudden time interval of events. Specifically, they are obtained as follows: topological features are calculated using graph analysis algorithms, with node degree being the number of edges in a node, and clustering coefficients calculated using the triangle counting method (i.e., the proportion of connections between a node's neighbors); behavioral features are obtained through statistical analysis, with communication frequency extracted from the time series of traffic data (number of data packets per unit time), and abnormal traffic peaks detected using Z-scores (calculating the standard deviation of traffic from the mean, with a threshold of 3); and temporal features are obtained through time series analysis, with suddenness calculated using the entropy of the event timestamp interval (a higher entropy value indicates a more uneven event distribution). The extraction algorithm is based on graph analysis and statistical models. The construction method is as follows: initialize feature vectors, traverse the spatiotemporal correlation graph, calculate the topological features of each node, the behavioral features of each edge, and the temporal features of each event, and store them as a set of feature vectors. To ensure feature effectiveness, a feature selection algorithm (such as one based on information gain) is used to filter low-relevance features (thresholds such as information gain < 0.1).
[0069] For example, in enterprise network scenarios, multi-dimensional threat features are extracted based on the spatiotemporal correlation graph generated by S31. First, the NetworkX library is used to calculate topological features, traversing 1700 nodes in the graph and calculating the degree of each node (e.g., IP: 192.168.1.100 connects to 10 nodes, degree is 10) and clustering coefficient (calculated using triangle counting to determine the connection ratio between neighboring nodes, e.g., 0.4). Regarding behavioral features, communication frequency is extracted from the time series of traffic data (using Wireshark statistics, 5-minute window) (e.g., IP: 192.168.1.100 sends 100 data packets per minute). Z-score detection (implemented in Python, input is the traffic sequence, calculates the standard deviation from the mean, threshold 3) is used to identify abnormal traffic peaks (e.g., an IP sending 1000 data packets in 1 minute, Z-score 3.5, marked as abnormal). In terms of temporal characteristics, event timestamps (such as login events and traffic bursts) are analyzed. Burst-like features are extracted through entropy calculation (implemented in Python; the input is a timestamp sequence, and the output is interval entropy; an entropy value > 2 indicates strong burstiness). For example, if a user logs in multiple times within one minute, the entropy value is 2.5. The feature extraction algorithm is implemented based on the NetworkX and SciPy libraries. Feature vectors are initialized, and the graph is traversed to calculate node degree, clustering coefficient, communication frequency, abnormal traffic peaks, and interval entropy, generating approximately 5000 feature vectors. An information gain algorithm (based on scikit-learn, threshold 0.1) is used to filter low-relevance features, retaining approximately 4000 effective features (such as "IP: 192.168.1.100, node degree: 10, clustering coefficient: 0.4, communication frequency: 100, abnormal peak: 3.5, interval entropy: 2.5"), forming a multi-dimensional threat feature set.
[0070] S33. Based on the multi-dimensional threat characteristics, construct a matrix structure that reflects threat relationships to obtain a threat fusion matrix.
[0071] Threat fusion matrix construction refers to organizing multi-dimensional threat features into a matrix structure to reflect the threat relationships between entities for subsequent risk analysis. The threat fusion matrix is a matrix with entities as rows and threat features as columns, where matrix elements are eigenvalues (such as node degree, communication frequency), reflecting the strength of threat associations between entities. Specifically, feature vectors are extracted from multi-dimensional threat features, with row indices representing entity IDs (such as IP addresses, user IDs) and column indices representing feature types (such as node degree, abnormal traffic peaks). Matrix elements are generated through standardization (e.g., normalization to [0, 1]). The construction process uses a matrix factorization algorithm, which initializes an empty matrix, iterates through feature vectors, and fills in matrix elements. To reduce dimensionality, Principal Component Analysis (PCA) (based on eigenvalue decomposition, retaining 90% variance) is used to compress feature dimensions, generating a low-dimensional threat fusion matrix. To ensure matrix sparsity, eigenvalue thresholds are set (e.g., values <0.01 are set to 0) to reduce computational overhead. Matrix elements are calculated through weighted fusion, with weights assigned based on feature importance (e.g., information gain), which is derived from the feature selection results. To improve matrix stability, missing values in the feature vectors are checked and filled in using the mean.
[0072] For example, in an enterprise network scenario, a threat fusion matrix is constructed based on 4000 threat features extracted from S32. First, the matrix is initialized with row indices representing 1700 entity IDs (e.g., IP: 192.168.1.100, user: admin) and column indices representing five feature types (node degree, clustering coefficient, communication frequency, abnormal traffic peak, interval entropy), generating a 1700×5 matrix. The feature vectors are traversed, filling in matrix elements (e.g., node degree 10 for IP: 192.168.1.100, communication frequency 100), and the feature values are normalized to [0, 1] using MinMaxScaler (implemented in scikit-learn) (e.g., node degree 10 is normalized to 0.8). Matrix decomposition uses the PCA algorithm (implemented in scikit-learn, input is the feature matrix, retains 90% variance, output is a 3D matrix), compressing the 1700×5 matrix into a 1700×3 matrix, with columns representing comprehensive threat features (e.g., topological threats, behavioral threats, temporal threats). To ensure sparsity, a threshold of 0.01 is set (elements below 0.01 are set to 0), generating a sparse matrix (approximately 70% of elements are 0). Feature weights are weighted and fused based on information gain (obtained from S32, e.g., node degree gain 0.3, communication frequency gain 0.5) to generate matrix elements (e.g., the overall threat value for IP: 192.168.1.100 is 0.75). Missing values in the matrix (approximately 1% of features are missing) are checked and filled using column mean values (e.g., missing communication frequency values are filled with 100). Finally, a 1700×3 threat fusion matrix is generated, reflecting the threat relationships between entities (e.g., "IP: 192.168.1.100, topological threat: 0.8, behavioral threat: 0.6, temporal threat: 0.7"), providing input for subsequent analysis.
[0073] S4. Based on rule engine matching, anomaly detection AI model, and graph neural network, perform risk analysis and threat identification on the threat fusion matrix. Step S4 specifically includes the following sub-steps:
[0074] S41. Using the rule engine, the features in the threat fusion matrix are matched with the predefined threat rule base to output known threat patterns.
[0075] Rule engine matching refers to the process of identifying known cybersecurity threat patterns (such as DDoS attacks and malicious logins) by performing pattern matching on features in a threat fusion matrix using a predefined threat rule base. The threat rule base is a set of rules that stores threat patterns and their characteristic thresholds, such as "communication frequency > 1000 and abnormal traffic peak > 3 indicates a DDoS attack." The rule engine is based on an expert system and is constructed by extracting rules from historical security event data (such as extracting DDoS attack characteristic thresholds through log analysis) and storing them as condition-action pairs (such as "if communication frequency > 1000, then mark it as DDoS"). Specifically, feature values (such as communication frequency and abnormal traffic peaks) are extracted from the threat fusion matrix and compared one by one with the conditions in the rule base. If a match is found, the threat pattern and confidence level are output (the confidence level is based on the rule's historical accuracy, such as 90%). The rule base is extracted from a security event database (such as storing attack logs from the past year), and rule updates are performed through expert review and machine learning assistance (such as using decision trees to extract new rules). To improve matching efficiency, an index structure (such as a B+ tree) is used to accelerate feature queries, and the matching results are stored as a list of threat patterns (including threat type, entity ID, and confidence level).
[0076] For example, in an enterprise network scenario, a rule engine is used to match features in a threat fusion matrix. First, rules are extracted from a security event database (stored in MySQL, containing DDoS, malicious login, and other events from the past year) to generate a threat rule base (e.g., "Communication frequency > 1000 and abnormal traffic peak > 3, mark as DDoS, confidence level 0.9"), stored as condition-action pairs (approximately 100 rules). The rule engine, based on the Drools system (implemented in Java, inputting the rule base and threat fusion matrix, outputting threat patterns), iterates through each row of the 1700×3 matrix, extracting feature values (e.g., IP: 192.168.1.100, communication frequency: 1000, abnormal traffic peak: 3.5), comparing them with the rule base, and finding a match for the DDoS rule (communication frequency 1000 > 1000, abnormal traffic peak 3.5 > 3), outputting the threat pattern "DDoS attack, IP: 192.168.1.100, confidence level: 0.9". To accelerate matching, a B+ tree index (based on Drools' built-in index) is used to store feature values, reducing query time from 1 second to 0.1 seconds. The rule base is updated monthly using a decision tree algorithm (implemented in scikit-learn, taking historical attack logs as input and outputting new rules). New rules include "interval entropy > 2 and login failure > 5, mark as malicious login". The final result is a threat pattern list containing approximately 50 known threats (e.g., 20 DDoS attacks, 30 malicious logins), with each record including threat type, entity ID, and confidence level.
[0077] S42. Input the threat fusion matrix into the trained behavior anomaly detection AI model and output the abnormal events.
[0078] Anomaly detection AI models use machine learning to identify abnormal behavior patterns in a threat fusion matrix and output anomalous events (such as sudden spikes in abnormal traffic or illegal process calls). Anomalies are entity behaviors that deviate from normal patterns, such as a sudden increase in communication frequency. The model is based on the Isolation Forest algorithm and is constructed as follows: Normal and anomalous behavior data (such as normal traffic and known attack traffic) are collected to build a training set; the Isolation Forest is initialized, the number of trees is set (e.g., 100), and a subset of features is randomly selected from each tree to segment data points. Anomalous points are identified because their segmentation paths are shorter. Training data is extracted from historical traffic and logs (e.g., normal traffic data from the past month, labeled as 0; known attack data, labeled as 1). Specifically, the feature vectors of the threat fusion matrix are input into the model, and anomaly scores are calculated for each entity (score range [0, 1], threshold such as 0.7). Scores higher than the threshold are marked as anomalous events. Anomaly scores are calculated using the path length of the Isolation Forest (shorter paths result in higher scores). To improve model accuracy, cross-validation (5-fold) is used to optimize parameters, and the model is updated regularly (retrained monthly based on new data).
[0079] For example, in an enterprise network scenario, an AI model for anomaly detection is used to analyze a threat fusion matrix. First, training data is collected (100,000 normal traffic and 10,000 attack traffic records extracted from Wireshark and Syslog over the past month, labeled 0 and 1 respectively). The model is trained using scikit-learn's Isolation Forest algorithm (100 trees, random subsampling rate 0.1), and parameters are optimized using 5-fold cross-validation (anomaly score threshold of 0.7). A 1700×3 threat fusion matrix is input into the model, and feature vectors for each row are extracted (e.g., IP: 192.168.1.100, communication frequency: 1000, peak anomaly traffic: 3.5). The model calculates anomaly scores (e.g., 0.8, short path length). Values above the threshold of 0.7 are marked as an anomalous event "Burst of traffic, IP: 192.168.1.100". Model training is performed on a GPU server (NVIDIA RTX 2080), taking approximately 10 minutes. During the detection process, approximately 100 anomalous events were identified (such as 50 traffic bursts and 50 abnormal process calls). The model is updated monthly, incorporating newly collected attack data (such as newly added SQL injection traffic) and retrained to improve accuracy. The final output is a list of anomalous events, including the entity ID, anomaly type, and anomaly score (e.g., "IP: 192.168.1.100, Type: Traffic Burst, Score: 0.8").
[0080] S43. Input the entity relationship topology represented by the threat fusion matrix into the graph neural network and output the potential threat association.
[0081] Graph Neural Network (GNN) analysis utilizes graph structures to model the entity relationship topology of a threat fusion matrix, uncovering potential threat associations (such as multi-entity coordinated attacks). Potential threat associations refer to implicit threat relationships between entities that are not identified by rules or anomaly detection, such as the coordinated abnormal behavior of multiple IP addresses. GNNs are based on Graph Convolutional Networks (GCNs), constructed as follows: Initialize the graph structure, with nodes as entities and edges as feature values of the threat fusion matrix; each convolutional layer aggregates the features of node neighbors and updates the node representation; the final layer outputs the risk score of each node, and threat associations are uncovered through clustering based on these scores. Training data is extracted from the threat fusion matrix and historical attack events (such as known entity relationships in coordinated attacks). Specifically, the threat fusion matrix is converted into a graph structure (nodes as entities, edges as feature values), input into the GCN, and the embedding vector of each node is calculated. Potential threat associations are identified based on the similarity of the embedding vectors (cosine similarity, with a threshold of 0.8). The GCN model is implemented using PyTorchGeometric, with three convolutional layers, each aggregating two-hop neighbors. The training objective is to minimize the classification loss (such as cross-entropy). To improve accuracy, Dropout (rate 0.5) is used to prevent overfitting, and the model is updated regularly (monthly based on new data).
[0082] For example, in enterprise network scenarios, graph neural networks are used to analyze the entity relationship topology of the threat fusion matrix. First, the 1700×3 matrix is converted into a graph structure (using PyTorchGeometric, with 1700 nodes and edge weighted associations based on feature values, such as an edge weight of 0.75 between IP: 192.168.1.100 and IP: 10.0.0.1). Training data is extracted from historical coordinated attack events (stored in MySQL, containing 100 coordinated DDoS records). The GCN model (3 convolutional layers, each aggregating 2-hop neighbors, with a dropout rate of 0.5) is trained on a GPU server (taking 15 minutes). The input is the graph structure, and the output is the embedding vector for each node (e.g., a 64-dimensional vector for IP: 192.168.1.100). The cosine similarity between nodes (threshold 0.8) was calculated, and the similarity between IP: 192.168.1.100 and IP: 10.0.0.1 was found to be 0.85, marking it as a potential threat association "coordinated traffic anomaly". The detection process identified approximately 30 potential threat associations (e.g., 20 coordinated DDoS attacks and 10 abnormal login clusters). The model is updated monthly, incorporating new attack data (e.g., new botnet coordinated attacks) and optimizing the classification loss. The final output is a list of potential threat associations, including associated entity pairs and similarity scores (e.g., "IP: 192.168.1.100 - IP: 10.0.0.1, Type: Coordinated Traffic Anomaly, Similarity: 0.85").
[0083] S44. Integrate the known threat patterns, the abnormal events, and the potential threat associations to generate a comprehensive risk analysis and threat identification result.
[0084] The fusion of threat patterns, anomalous events, and potential threat correlations refers to integrating the outputs of S41 to S43 through a weighted voting mechanism to generate a comprehensive risk analysis result. The comprehensive risk analysis result is a set including threat types, risk scores, and affected entities, reflecting the full picture of cybersecurity threats. The fusion process uses a weighted voting algorithm, constructed as follows: initializing the result set, collecting known threat patterns (including confidence levels), anomalous events (including anomaly scores), and potential threat correlations (including similarity); assigning weights to each output (based on historical accuracy, such as rule matching 0.4, anomaly detection 0.3, GNN 0.3), and calculating a comprehensive risk score (weighted average). Specifically, threat patterns (e.g., DDoS, confidence 0.9) are obtained from S41, anomalous events (e.g., traffic bursts, score 0.8) from S42, and potential threat correlations (e.g., coordinated anomalies, similarity 0.85) from S43; a risk score is calculated for each entity, and multiple threat indicators for the same entity are fused. Weights are obtained from historical data evaluation (e.g., the accuracy of each method over the past month). To ensure the accuracy of the fusion, a consistency check is used (such as removing threats with a confidence level of <0.5), and the results are stored as a risk analysis report (including entity ID, threat type, and risk score).
[0085] For example, in an enterprise network scenario, the outputs of S41 to S43 are combined to generate comprehensive risk analysis results. First, 50 known threat patterns from S41 (e.g., "DDoS, IP: 192.168.1.100, confidence: 0.9"), 100 anomalous events from S42 (e.g., "traffic burst, IP: 192.168.1.100, score: 0.8"), and 30 potential threat associations from S43 (e.g., "IP: 192.168.1.100-IP: 10.0.0.1, coordinated anomaly, similarity: 0.85") are collected. A weighted voting algorithm (implemented in Python, inputting threat indicators, with weights of 0.4 for rule matching, 0.3 for anomaly detection, and 0.3 for GNN, calculated based on historical accuracy) is used to calculate a comprehensive risk score for each entity (e.g., the score for IP: 192.168.1.100 = 0.4 × 0.9 + 0.3 × 0.8 + 0.3 × 0.85 = 0.855). A consistency check removes threats with a confidence level below 0.5 (approximately 5% of the data is removed). The fusion process reveals that IP: 192.168.1.100 is involved in DDoS, traffic bursts, and coordinated anomalies, with a comprehensive score of 0.855, and is marked as high-risk. A risk analysis report is finally generated, containing approximately 200 threat records (e.g., "IP: 192.168.1.100, Threat Type: DDoS / Traffic Burst / Coordinated Anomaly, Score: 0.855"), reflecting the overall picture of cybersecurity threats.
[0086] S5. Based on the results of risk analysis and threat identification, conduct tiered early warnings. Step S5 specifically includes the following sub-steps:
[0087] S51. Classify risk levels based on risk scoring results.
[0088] Risk level classification refers to categorizing threats into different levels (e.g., high, medium, low) based on risk scores from comprehensive risk analysis results to guide early warning and response. Risk levels are threat classifications based on scoring thresholds; for example, a score > 0.8 indicates high risk, 0.5-0.8 indicates medium risk, and < 0.5 indicates low risk. Specifically, the comprehensive risk score is obtained from S44 (e.g., IP: 192.168.1.100, score 0.855), and levels are assigned based on predefined thresholds (determined based on historical attack consequences analysis, e.g., a high-risk threshold of 0.8). Thresholds are extracted from a historical security event database, and the mapping between scores and consequences is determined by analyzing the impact of attacks (e.g., data breaches, system crashes). The classification algorithm is based on threshold classification and is constructed as follows: an initial level list is created, risk scores are iterated, thresholds are compared to assign levels, and the results are stored as level labels (e.g., "high risk"). To ensure accuracy, statistical analysis is used to verify the reasonableness of the thresholds (e.g., thresholds are optimized based on ROC curves, with a target false positive rate of <5%). The grading results are stored as a mapping between entity IDs and grades for subsequent early warning purposes.
[0089] For example, in an enterprise network scenario, risk levels are categorized based on 200 threat records from S44. First, thresholds are extracted from a historical security event database (stored in MySQL, including attack consequences such as system crashes and data breaches) to determine that scores >0.8 are high-risk, 0.5-0.8 are medium-risk, and <0.5 are low-risk. Risk scores (e.g., IP: 192.168.1.100, score 0.855) are iterated through, and a threshold classification algorithm (implemented in Python, input is a list of scores, output is a level label) is used to classify scores of 0.855 as high-risk. The classification process identifies approximately 50 high-risk (e.g., DDoS attacks, traffic bursts), 100 medium-risk (e.g., abnormal logins), and 50 low-risk (e.g., low-frequency scanning). The thresholds are validated using ROC curve analysis (implemented in scikit-learn, input is historical scores and attack consequences, optimized for a false positive rate of <5%), confirming that the accuracy of the high-risk threshold of 0.8 is 95%. Finally, a level mapping table is generated, containing 200 records (such as "IP: 192.168.1.100, Level: High Risk"), which provides a basis for generating early warning signals.
[0090] S52. Generate corresponding early warning signals based on different risk levels and output handling suggestions.
[0091] Warning signal generation refers to triggering different levels of notifications based on risk levels (e.g., high risk = emergency alert, medium risk = warning, low risk = notification) and providing targeted handling suggestions (e.g., blocking IPs, restricting users). A warning signal is a structured output containing risk level, entity ID, and handling suggestions, in a format such as "High-risk alert, IP: 192.168.1.100, suggestion: block traffic". Handling suggestions are extracted from a predefined policy library, built based on security best practices (e.g., the NIST framework), containing a mapping between threat types and handling measures (e.g., blocking IPs for DDoS attacks). Specifically, the policy library is queried to match handling suggestions based on the S51 level mapping. Warning signals are sent to the security management platform via a message queue (e.g., Kafka), with signal levels corresponding to levels (e.g., high risk corresponds to an emergency alert). The policy library is extracted from historical handling records and expert knowledge and updated regularly (e.g., monthly based on new threats). The generation algorithm is based on rule matching, constructed by initializing a signal list, traversing the level mapping, and matching policies to generate signals and suggestions. To ensure timeliness, a real-time message queue is used to prevent signal transmission delays.
[0092] <100ms.
[0093] For example, in enterprise network scenarios, alert signals are generated based on S51-based risk level mapping. Action recommendations are extracted from a policy library (stored in MySQL, based on the NIST framework, containing 100 policies, such as "DDoS - Block IP"), and 200 risk level records (e.g., IP: 192.168.1.100, high risk) are traversed to match policies and generate signals (e.g., "High Risk Alert, IP: 192.168.1.100, Recommendation: Block Traffic"). High-risk signals (50 entries) are sent to the security management platform via a Kafka message queue (configured with 3 partitions, latency <100ms), displayed as a red emergency alert; medium-risk signals (100 entries) are displayed as a yellow warning, recommending "monitor traffic"; low-risk signals (50 entries) are displayed as a blue notification, recommending "logging". The policy library is updated monthly, adding new threat handling measures (e.g., SQL injection recommendation "Restrict Database Access"). During the process, IP address 192.168.1.100 was identified as having a high risk of DDoS attack. An "Emergency Alert, Block Traffic to 192.168.1.100" signal was generated and pushed to the firewall for execution. Ultimately, 200 alert signals and handling suggestions were output to ensure a timely response from the security team.
[0094] This technical solution significantly improves the accuracy and real-time performance of network security risk early warning through multi-source data fusion and multi-dimensional analysis. The solution integrates multi-source data such as network traffic, terminal behavior, and logs to construct a unified spatiotemporal correlation graph and threat fusion matrix, comprehensively capturing threat characteristics. Combining a rule engine, anomaly detection AI model, and graph neural network, it achieves comprehensive identification of the correlation between known threats, abnormal events, and potential threats, overcoming the shortcomings of single methods. Through a tiered early warning mechanism, it generates warning signals and handling suggestions for different risk levels, providing precise guidance for security operations and maintenance, thereby effectively reducing the potential risks of network attacks.
[0095] Furthermore, as cyberattacks become increasingly complex and covert, traditional cybersecurity defense methods are showing their limitations, especially when facing advanced persistent threats (APTs) and zero-day attacks, where static defense strategies often prove ineffective. Cybersecurity risk warning methods based on multi-source data fusion integrate network traffic, endpoint behavior, and log data to achieve accurate threat identification and tiered warnings. However, relying solely on risk warnings cannot completely defend against dynamically changing attack behaviors, especially in scenarios where attackers rapidly adjust their attack strategies using automated tools and artificial intelligence. Existing technologies often employ a passive response model for network defense, lacking proactive prediction and dynamic adaptation capabilities to attack behavior. This results in a delayed response to new threats, hindering real-time countermeasures. Moreover, traditional defense mechanisms typically rely on fixed rules or single models, making it difficult to cope with the rapid evolution of attack patterns and lacking self-learning and optimization capabilities. Therefore, there is an urgent need for an autonomous defense method based on network-endogenous immune resilience and attack entropy reduction response. This method would utilize technologies such as dynamic attack knowledge hypergraphs, micro-perturbation defense strategies, and online deep learning to construct an adaptive, resilient network architecture, enabling proactive prediction and efficient response to potential attacks. This method can not only deduce attack sequences based on threat fusion matrices, but also continuously optimize defense models through trap grids and adversarial training, thereby significantly improving the dynamism and resilience of network defense and providing a new technical path for security assurance in complex network environments.
[0096] Therefore, in some embodiments, the network security risk early warning method based on multi-source data fusion also includes autonomous defense steps based on the construction of network endogenous immune resilience and attack entropy reduction response, specifically including:
[0097] S6. Based on the threat fusion matrix, construct a dynamic attack knowledge hypergraph, and use attack strategies to generate a network that can deduce potential attack action sequences and their probability distributions.
[0098] The construction of a dynamic attack knowledge hypergraph refers to building a multi-dimensional hypergraph structure based on a threat fusion matrix to represent complex threat relationships between entities and their dynamic evolution. This allows for the generation of potential attack action sequences and their probability distributions through attack strategies. The dynamic attack knowledge hypergraph is a hypergraph structure where nodes are entities in the threat fusion matrix (e.g., IP addresses, user IDs), hyperedges represent threat associations between multiple entities (e.g., groups of entities in a coordinated DDoS attack), and hyperedge weights represent threat intensity (calculated based on the eigenvalues of the threat fusion matrix). Specifically, the hypergraph is initialized by extracting entities and eigenvalues from the threat fusion matrix, with nodes representing entity IDs. Hyperedges are identified using clustering algorithms (e.g., K-means, based on Euclidean distance of eigenvectors, with K determined by the silhouette coefficient) to identify multi-entity coordinated threats. Weights are calculated using a weighted average of eigenvalues (e.g., 40% for topological threats, 40% for behavioral threats, and 20% for temporal threats). The attack strategy generation network is a sequence generation model based on a recurrent neural network (RNN). It is constructed as follows: the RNN is initialized (using LSTM units, 3 layers, 128 neurons per layer), the input is the sequence of hyperedges in the hypergraph (sorted by time dimension), and the output is the sequence of potential attack actions (e.g., port scanning → vulnerability exploitation → data theft) and their probability distribution (calculated through a softmax layer). Training data is extracted from historical attack logs (e.g., PCAP files and Syslog files containing attack sequences), action sequences are extracted using sequence labeling tools (e.g., HMM-based labelers), and probability distributions are calculated using a conditional random field (CRF) algorithm. To ensure inference accuracy, an attention mechanism (Transformer-based attention layer) is used to enhance sequence dependencies, and the hypergraph is updated periodically (hourly based on a new threat fusion matrix). Hypergraph maintenance is implemented using an incremental update algorithm; when adding new nodes and hyperedges, only the affected regions are recalculated, reducing computational overhead.
[0099] Here is a specific implementation example:
[0100] In enterprise network security scenarios, a dynamic attack knowledge hypergraph is constructed based on a threat fusion matrix (1700×3, containing entity IDs and threat features) to deduce attack action sequences. First, 1700 entities (e.g., IP: 192.168.1.100) and feature values (e.g., topological threat 0.8) are extracted from the threat fusion matrix. The hypergraph is initialized using Python's HyperNetX library, with nodes representing entity IDs. Hyperedges are identified using K-means clustering (implemented in scikit-learn, with K set to 50 using silhouette coefficients) to identify collaborative threats (e.g., five IPs, including IPs 192.168.1.100 and 10.0.0.1, forming a DDoS hyperedge). The weights are the feature value weighted average (topological threat 0.4×0.8 + behavioral threat 0.4×0.6 + temporal threat 0.2×0.7 = 0.7). The hypergraph contains 1700 nodes and approximately 200 hyperedges, stored in an in-memory database (Redis). The attack strategy generation network was implemented using PyTorch, constructing a 3-layer LSTM (128 neurons per layer, Dropout rate 0.3). The input was a sequence of hyperedges from the hypergraph (ordered by timestamp, e.g., the DDoS hyperedge at 14:30:00). Training data was extracted from historical attack logs (stored in MySQL, containing 1000 attack sequences, e.g., "port scan → SYN flooding"). Action sequences were labeled using an HMM-based annotator (implemented in Python, based on the Viterbi algorithm), and the probability distribution was calculated using a CRF algorithm (implemented in CRFsuite). The model was trained on a GPU server (NVIDIA RTX 2080) for 20 minutes, outputting action sequences (e.g., "port scan → exploit → data theft" with a probability of 0.85). The attention mechanism (based on Transformer scaleddot-product attention) enhances sequence dependencies. The supergraph is maintained hourly through incremental updates (only updating newly added threat data). It discovers that the DDoS superedge involving IP: 192.168.1.100 deduces the sequence "port scan → SYN flood → data leakage" with a probability distribution of [0.4, 0.35, 0.25], providing a basis for subsequent defense.
[0101] S7. Based on the probability distribution, the potential attack action sequences are prioritized, and the immune policy generator synthesizes a micro-perturbation defense strategy based on the mobile target defense concept for high-probability attack actions. The micro-perturbation defense strategy includes one or more combinations of these strategies: dynamic address hopping strategy, communication port randomization strategy, network topology dynamic reconstruction strategy, and false information injection strategy for critical services.
[0102] Prioritizing potential attack sequences based on probability distribution refers to determining high-priority attack actions based on their probability values (obtained from S6) using a sorting algorithm. The immune policy generator then synthesizes a micro-perturbation defense strategy based on Moving Target Defense (MTD), including dynamic address hopping, communication port randomization, dynamic network topology reconstruction, and false information injection strategies. Prioritization is achieved through a weighted sorting algorithm. The algorithm is constructed as follows: an initial sequence list is provided, with the input being the attack sequence and its probability. Weights are calculated by combining the probability value (70%) and the severity of the attack consequence (30%, extracted from a historical attack database, e.g., a data theft consequence value of 0.9). A weighted sum is then used to calculate the ranking score, and the top 10% of sequences are selected as high-priority. The Immune Policy Generator is a policy generation model based on reinforcement learning. Its construction involves initializing a Deep Q-Network (DQN, a 3-layer fully connected network with 256 neurons per layer). The state consists of an attack action sequence and network state (extracted from network topology and traffic data). The action space is a combination of MTD policies (e.g., address hopping frequency, port randomization range). The reward function is the reduction in attack success rate (calculated through simulation testing). Policy parameters are obtained as follows: dynamic address hopping is randomly assigned from an IP address pool (obtained from a DHCP server, containing a range of available IPs); communication port randomization is generated from a port allocation table (extracted from firewall rules, range such as 1024-65535); network topology reconstruction uses an SDN controller API (e.g., OpenFlow) to obtain adjustable network paths; and fake information injection is created using a forged data generator (based on predefined templates, such as fake user credentials). Training data is extracted from historical defense records (e.g., logs showing the reduction in attack success rate using MTD policies). The model is optimized using Q-learning and updated periodically (daily based on new attack data).
[0103] For example, in an enterprise network scenario, S6-based attack action sequences (such as "port scan → SYN flood → data leakage", with probabilities [0.4, 0.35, 0.25]) are prioritized and strategies are generated. The prioritization uses a weighted sorting algorithm (implemented in Python, with a list of sequences and probabilities as input). The severity of the consequences is extracted from a historical attack database (stored in MySQL, containing 1000 records of attack consequences, such as data theft consequence 0.9), and a ranking score is calculated (e.g., 0.7 × 0.4 + 0.3 × 0.9 = 0.55). The top 10% of sequences (such as "port scan → SYN flood") are selected to generate a high-priority list (approximately 20 sequences). The immune strategy generator implements DQN (a 3-layer fully connected network with 256 neurons per layer and a dropout rate of 0.2) using PyTorch. The state consists of the attack sequence and network state (topology obtained from the SDN controller and traffic extracted from Wireshark). The action space includes address hopping (IP pool obtained from a DHCP server, e.g., 192.168.1.100-192.168.1.200), port randomization (firewall rules provide ports 1024-65535), topology reconstruction (adjustable paths obtained from the OpenFlow API), and fake information injection (templates generate fake user credentials, e.g., "user: fake123"). Training data is extracted from defense logs (stored in Elasticsearch, containing 1000 MTD effect records). The reward is the reduction in attack success rate (a 50% reduction in attack traffic, as demonstrated in simulations, earns a 0.5 reward). The model is trained on a GPU server (taking 30 minutes) and outputs policy combinations (e.g., "IP hopping frequency: 5 minutes, port randomization range: 1024-2048"). For example, for "port scanning → SYN flooding", the generated policy is to change the IP every 5 minutes (e.g., 192.168.1.100 → 192.168.1.150) and randomize the port (e.g., 8080 → 2048). By adjusting the path through OpenFlow and injecting fake credentials, the attack success rate is reduced by approximately 60%.
[0104] S8. Based on the sorted sequence of potential attack actions and the micro-perturbation defense strategy, the programmable elements in the network are coordinated and scheduled by a software-defined elastic controller to calculate the optimal elastic deployment sequence, and lightweight elastic execution points are deployed at key nodes to build an endogenous elastic network architecture.
[0105] By using a Software-Defined Resilient Controller (SDEC) to coordinate the scheduling of programmable components (such as SDN switches and NFV virtual firewalls) in the network, and calculating the optimal resilient deployment sequence based on the ordered attack action sequence and micro-perturbation defense strategy, an intrinsically resilient network architecture is constructed by deploying lightweight resilient execution points at key nodes. The intrinsically resilient network architecture refers to an architecture that maintains the system's resilience under attacks by dynamically adjusting network resources and policies. It includes programmable components (such as SDN switches) and resilient execution points (lightweight agents that execute MTD policies). The optimal resilient deployment sequence refers to the scheduling order and resource allocation scheme, calculated through an optimization algorithm. The algorithm is constructed as follows: an initial genetic algorithm is used, the population is the scheduling sequence (including component IDs and policy parameters), and the fitness function is a weighted sum of defense effectiveness (the reduction in attack success rate) and resource overhead (CPU and memory utilization) (defense effectiveness accounts for 60%, resource overhead accounts for 40%). The specific acquisition methods are as follows: A list of programmable components (including switch IDs and port status) is obtained from the SDN controller (such as ONOS); virtual resource status (such as CPU utilization of virtual firewalls) is obtained from the NFV management platform (such as OpenStack); critical nodes are extracted from the network topology using graph analysis algorithms (based on PageRank, calculating node importance), with importance based on node degree and traffic load. Lightweight elastic execution points are Docker containers running MTD policy scripts (such as IP hopping scripts). Scheduling is implemented through the OpenFlow protocol, with deployment sequences updated periodically (hourly based on new threat data). To ensure efficiency, a distributed scheduling framework (such as Kubernetes) is used to manage execution points and reduce deployment latency.
[0106] For example, in enterprise network scenarios, high-priority attack sequences based on S7 (such as "port scan → SYN flooding") and MTD policies (such as IP hopping frequency of 5 minutes) are scheduled through SDEC to build an inherently resilient network architecture. First, a list of programmable components (50 SDN switches, IDs such as sw1, port status such as up) is obtained from the ONOS controller (via RESTAPI), and the virtual firewall status (10 instances, CPU utilization <50%) is obtained from OpenStack. Key nodes are identified using the PageRank algorithm (implemented in NetworkX, input is a network topology graph, output is node importance), selecting the top 10% of nodes (such as server01, importance 0.9). A genetic algorithm (implemented in Python, population size 100, 50 iterations) calculates the optimal deployment sequence, with the fitness function being a weighted sum of defense effectiveness (0.6 based on simulation testing, a 60% reduction in attack traffic) and resource overhead (0.8 based on CPU utilization <50%) (0.6 × 0.6 + 0.4 × 0.8 = 0.68). The scheduling result is to deploy IP hopping (frequency every 5 minutes) and port randomization (range 1024-2048) on server01, distributing rules via the OpenFlow protocol (implemented in ONOS). Lightweight elastic execution points use Docker containers (images containing Python scripts to execute IP hopping) and are deployed on 10 key nodes via Kubernetes (deployment latency <100ms). The architecture includes 50 SDN switches, 10 virtual firewalls, and 10 execution points, updating the deployment sequence hourly (based on new threat data), forming an inherently elastic network architecture that reduces the success rate of DDoS attacks by approximately 65%.
[0107] S9. When an attack is detected, an entropy reduction response mechanism is initiated based on the intrinsically resilient network architecture. The strength and scope of the micro-perturbation defense strategy are dynamically adjusted, and the attack flow is transparently redirected to a highly interactive trapping mesh using programmable elements in the intrinsically resilient network architecture.
[0108] Entropy reduction response mechanisms refer to reducing system attack entropy (quantifying the uncertainty of attacks, calculated based on information entropy) by dynamically adjusting the strength (e.g., IP hopping frequency) and scope (e.g., the number of affected nodes) of micro-perturbation defense strategies when attack behavior is detected. This is achieved through programmable components (e.g., SDN switches) that transparently redirect the attack flow to a highly interactive decoy mesh. A highly interactive decoy mesh is a virtual environment simulating real services (e.g., a honeypot) used to capture attack behavior. Attack entropy is calculated using the information entropy formula, specifically by extracting attack flow characteristics (e.g., source IP, packet frequency) from traffic data and calculating the entropy value (higher entropy indicates a more random attack). Entropy reduction response adjusts the strategy through optimization algorithms. The algorithm is constructed as follows: initializing a gradient descent algorithm, with the current entropy value and strategy parameters (e.g., hopping frequency) as input, aiming to minimize the entropy value, and adjusting the strategy strength (e.g., increasing the frequency from 5 minutes to 1 minute) and scope (e.g., expanding from 10 nodes to 20 nodes). Redirection is implemented through SDN flow tables. Specifically, attack flow characteristics are extracted from the SDN controller (using DPI tools such as Zeek to resolve source IP and port), and flow table rules are generated (matching the attack flow and redirecting the action to the decoy mesh IP). The decoy mesh consists of a cluster of virtual machines (running real service images, such as Apache), and its configuration is obtained from the NFV platform (e.g., virtual machine IP and port). To ensure transparency, VXLAN is used to encapsulate the attack flow, reducing the probability of attacker detection. The response mechanism is updated every minute based on newly detected attack data.
[0109] For example, in an enterprise network scenario, when a DDoS attack (source IP: 192.168.1.100, packet frequency 1000 / s) is detected, an entropy reduction response is initiated based on an inherently resilient network architecture. First, Zeek (deployed on the gateway, parsing PCAP files) is used to extract attack flow characteristics (source IP: 192.168.1.100, port: 80), and the attack entropy is calculated (implemented in Python, input is a packet frequency sequence, entropy value 2.5). The gradient descent algorithm (implemented in PyTorch, iterated 100 times) is used to adjust the MTD strategy. The initial strategy is IP hopping (frequency 5 minutes, 10 nodes), after optimization the frequency is increased to 1 minute, the range is expanded to 20 nodes (server01-server20), and the entropy value is reduced to 1.8. The redirection uses an ONOS controller to generate flow tables (OpenFlow rules, matching source IP: 192.168.1.100, action redirected to decoy mesh IP: 10.0.0.10), and uses VXLAN encapsulation (ONOS supported, tunnel ID: 1001) to ensure transparency. The decoy mesh is deployed on OpenStack (10 virtual machines, running Apache images, port 80), and the configuration is obtained from the NFV platform (IPs: 10.0.0.10-10.0.0.20). The response mechanism is updated every minute (based on new Zeek data), redirecting approximately 80% of attack flows to the decoy mesh, capturing attack data (such as HTTP request logs), reducing system load by approximately 70%, and decreasing attack entropy from 2.5 to 1.8, significantly suppressing attacks.
[0110] S10. Using data captured from the trapping grid, the model parameters of the attack strategy generation network and the immune strategy generator are updated through online deep learning, thereby achieving the autonomous evolution of the system's defense capabilities. The online deep learning adopts a model update mechanism based on a combination of incremental learning and adversarial training, and uses attack data captured from the highly interactive trapping grid and unknown threat samples synthesized through the adversarial generation network to perform collaborative optimization training on the attack strategy generation network and the immune strategy generator.
[0111] By utilizing attack data captured by a trap grid, the model parameters of the attack strategy generation network (S6's RNN) and the immune strategy generator (S7's DQN) are updated through online deep learning, enabling the autonomous evolution of defense capabilities. The online deep learning employs a mechanism combining incremental learning and adversarial training. Incremental learning adapts to new data through mini-batch updates (batch size e.g., 32), while adversarial training generates unknown threat samples using a generative adversarial network (GAN). Attack data is extracted from the trap grid and includes attack flow features (such as HTTP request headers and malicious payloads) and behavioral sequences (such as exploit steps). Specifically, attack features are extracted from the trap grid's virtual machine logs (Syslog format) and parsed using feature extraction tools (such as Zeek). The GAN generator (a 3-layer fully connected network with 128 neurons per layer) receives random noise as input and outputs synthetic attack samples. A discriminator (a 3-layer network with 256 neurons) distinguishes between real and synthetic samples, with the training objective being to minimize the generator loss. The update algorithm is constructed as follows: Initialize the Adam optimizer with captured data and synthetic samples as input; update the parameters of the RNN and DQN (such as LSTM weights and Q-network weights); and use the loss function as a weighted sum of cross-entropy (RNN) and Q-value error (DQN) (each weighted 50%). To ensure model stability, empirical replay (storing the most recent 10,000 data points) is used to prevent overfitting, and the model is updated hourly based on newly captured data.
[0112] For example, in an enterprise network scenario, DDoS attack data (approximately 1GB of logs, including HTTP request headers and SYN flood sequences) captured by a trapping mesh (10 virtual machines, IPs: 10.0.0.10-10.0.0.20) is used to update the model. First, the virtual machine logs (Syslog format, stored in Elasticsearch) are parsed using Zeek to extract attack features (such as source IP: 192.168.1.100, request header "User-Agent: malicious"), generating 1000 feature vectors. A GAN (implemented in PyTorch, with a 3-layer generator with 128 neurons and a 3-layer discriminator with 256 neurons) generates 500 synthetic attack samples (such as forged SQL injection requests). After 30 minutes of training, the generator loss is reduced to 0.2. The update algorithm uses the Adam optimizer (learning rate 0.001), with inputs of 1000 real samples and 500 synthetic samples. It updates the S6 RNN (LSTM, 3 layers, 128 neurons) and the S7 DQN (3 layers, 256 neurons). The loss function is a weighted sum (50% each) of cross-entropy (RNN, prediction sequence error) and Q-value error (DQN, prediction reward error). Experience replay stores the most recent 10,000 data points (Redis implementation) to prevent overfitting. The model is updated hourly (GPU server, 10 minutes). After the update, the accuracy of RNN predicting new DDoS sequences increases to 90% (from 85%), and the attack success rate reduction of the DQN generation strategy increases to 65% (from 60%). The system's defense capabilities adapt to new threats, such as SQL injection attacks, through continuous learning, significantly improving resilience.
[0113] The following combination Figure 2 Further explanation is provided for steps S6 to S10:
[0114] like Figure 2 As shown, the intrinsically resilient network architecture described in this invention is a distributed, programmable, and collaborative defense system. Its core lies in deeply integrating defense capabilities into the network infrastructure itself, rather than as an external addition. This architecture mainly includes the following components and data flows:
[0115] Software-defined resilient controller (intelligent decision center): As the brain of the architecture, it receives attack strategies and probability information derived from the upstream threat fusion matrix (risk cognition engine). Its core decision engine calculates the optimal micro-perturbation defense strategy (such as dynamic address hopping, port randomization, dynamic topology reconstruction, etc.) and its deployment sequence based on the global network view and business objectives.
[0116] Distributed resilient execution points: acting as the nerve endings of the architecture, they are widely deployed on critical nodes of the network (e.g., Region A, B, ..., N), where N is the total number of critical nodes. They receive and execute micro-perturbation policies issued by the controller, causing network topology, address space, service ports, and other attributes to change continuously, smoothly, and randomly, collectively forming an inherently resilient network architecture. This architecture is transparent to normal business operations, but for attackers, its attack surface is always in a state of uncertain dynamic change.
[0117] Highly Interactive Decoy Mesh: Acting as an "immune trap" within the architecture, it receives attack flows transparently redirected by elastic execution points according to policies. This mesh simulates real-world business environments for deep decoy trapping, delaying attack behavior, and capturing high-fidelity attack interaction data.
[0118] Autonomous Evolutionary Closed Loop: The architecture possesses self-learning and self-evolution capabilities. Attack data captured by the trap mesh is fed back to the system's learning unit in real time. Through online incremental learning and adversarial training, the upstream AI model (such as the attack strategy generation network) is continuously optimized and updated, thus forming a complete autonomous closed loop from perception, decision-making, execution to learning, ultimately achieving a spiral increase in the network system's security capabilities.
[0119] This technical solution provides an autonomous defense method based on the construction of network-endogenous immune resilience and attack entropy reduction response. By inferring potential attack sequences through a dynamic attack knowledge hypergraph and combining it with micro-perturbation defense strategies, it can significantly improve the initiative and adaptability of network defense and reduce the probability of successful attacks. Through the collaborative scheduling of software-defined elastic controllers and lightweight elastic execution points, an endogenous elastic network architecture is constructed to achieve transparent redirection and efficient trapping of attack flows. At the same time, by utilizing a mechanism that combines online deep learning and adversarial training, the model parameters of the attack strategy generation network and the immune strategy generator are continuously optimized, enabling the system to have autonomous evolution capabilities, thereby effectively responding to new threats and complex attack scenarios.
[0120] Specifically, step S6 significantly improves the predictive ability of network threats by constructing a dynamic attack knowledge hypergraph based on a threat fusion matrix and using attack strategies to generate network deductions of potential attack action sequences and their probability distributions. Its core advantage lies in capturing complex threat relationships between multiple entities through the hypergraph structure, combining RNNs and attention mechanisms to generate high-precision attack sequence predictions with an accuracy rate exceeding 85% (such as the DDoS sequence prediction in the example). Compared to traditional static rules or single models, the dynamic attack knowledge hypergraph can be updated in real time, adapting to the rapid evolution of attack patterns and reducing computational overhead (through incremental update algorithms), providing a precise threat intelligence foundation for the formulation of subsequent defense strategies. This method effectively compensates for the predictive shortcomings of traditional passive defense in the face of APTs and zero-day attacks, enhancing the initiative and foresight of network security.
[0121] Step S7 significantly enhances the targeting and dynamism of the defense strategy by prioritizing attack action sequences based on probability distribution and generating a micro-perturbation defense strategy based on Moving Target Defense (MTD). Prioritization combines probability and the severity of attack consequences to ensure that high-risk threats are addressed first, while MTD strategies (such as IP hopping and port randomization) increase the attacker's cost and uncertainty by dynamically adjusting network configuration, reducing the attack success rate by approximately 60% (as in the DDoS attack scenario in the example). The reinforcement learning-based immune strategy generator can dynamically optimize the strategy according to the network state. Compared to traditional fixed defense mechanisms, it is more adaptive and particularly suitable for rapidly changing attack scenarios, providing efficient strategy support for building resilient networks.
[0122] Step S8 utilizes a Software-Defined Resilient Controller (SDEC) to coordinate the scheduling of programmable components, calculate the optimal resilient deployment sequence, and deploy lightweight resilient execution points at critical nodes, thus constructing an intrinsically resilient network architecture. This architecture achieves efficient defense deployment through dynamic resource adjustment and lightweight execution points (such as Docker containers), significantly improving the network's resilience against attacks.
[0123] Step S9, by activating an entropy reduction response mechanism upon detecting an attack, dynamically adjusts the strength and scope of the micro-perturbation defense strategy and transparently redirects the attack flow to a highly interactive decoy mesh, significantly reducing the actual impact of the attack on the system. Transparent redirection is achieved through SDN flow tables and VXLAN encapsulation, reducing the attacker's probability of detection, while the highly interactive decoy mesh captures detailed attack data, providing support for subsequent analysis. This mechanism transforms passive defense into proactive decoy and response, significantly improving the real-time performance and adversarial capabilities of network defense.
[0124] Step S10 utilizes the data captured by the trap grid, and through online deep learning combined with incremental learning and adversarial training, continuously updates the model parameters of the attack strategy generation network and the immune strategy generator, achieving the autonomous evolution capability of the defense system. By generating unknown threat samples through GAN, the system can adapt to new attacks in advance, the experience replay mechanism effectively prevents overfitting, and hourly updates ensure that the model evolves in sync with the threats. This continuous learning mechanism endows the system with high adaptability and resilience, effectively coping with complex and ever-changing network attack scenarios, and providing reliable protection for long-term defense.
[0125] Figure 3 A schematic diagram of a network security risk early warning system based on multi-source data fusion is provided for embodiments of this application, such as... Figure 3 As shown, the system includes:
[0126] Data acquisition module 1 is used to collect multi-source security data;
[0127] Entity recognition and association processing module 2 is used to perform entity recognition and association processing on the multi-source security data to obtain entity association information;
[0128] Spatiotemporal alignment and fusion processing module 3 is used to perform spatiotemporal alignment and fusion processing on the entity association information to construct a threat fusion matrix;
[0129] Risk analysis and threat identification module 4 is used to perform risk analysis and threat identification on the threat fusion matrix based on rule engine matching, behavior anomaly detection AI model and graph neural network.
[0130] The graded early warning module 5 is used to provide graded early warnings based on the results of risk analysis and threat identification.
[0131] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.
Claims
1. A network security risk early warning method based on multi-source data fusion, characterized in that, include: Collect multi-source security data; Entity identification and association processing are performed on the multi-source security data to obtain entity association information; The entity association information is spatiotemporally aligned and fused to construct a threat fusion matrix; Based on rule engine matching, behavior anomaly detection AI model and graph neural network, risk analysis and threat identification are performed on the threat fusion matrix; Based on the results of risk analysis and threat identification, tiered early warnings are issued.
2. The network security risk early warning method based on multi-source data fusion as described in claim 1, characterized in that, The multi-source security data includes at least network traffic data, terminal behavior data, and log data.
3. The network security risk early warning method based on multi-source data fusion as described in claim 1, characterized in that, The entity identification and association processing of the multi-source security data to obtain entity association information includes: Identify entities in multi-source security data; Based on the attribute and behavioral characteristics of the entity objects, the association relationships between different entity objects are established to obtain entity association information.
4. The network security risk early warning method based on multi-source data fusion as described in claim 1, characterized in that, The step of performing spatiotemporal alignment and fusion processing on the entity association information to construct a threat fusion matrix includes: Align and merge entity association information in the time and space dimensions to generate a unified spatiotemporal association map; Based on the spatiotemporal correlation map, multi-dimensional threat features are extracted; Based on the aforementioned multi-dimensional threat characteristics, a matrix structure reflecting threat relationships is constructed to obtain the threat fusion matrix.
5. The network security risk early warning method based on multi-source data fusion as described in claim 1, characterized in that, The method of performing risk analysis and threat identification on the threat fusion matrix based on rule engine matching, behavior anomaly detection AI model, and graph neural network includes: Using the rule engine, the features in the threat fusion matrix are matched with a predefined threat rule base to output known threat patterns; The threat fusion matrix is input into a trained behavior anomaly detection AI model, which outputs abnormal events. The entity relationship topology represented by the threat fusion matrix is input into a graph neural network to output potential threat associations; By integrating the known threat patterns, the anomalous events, and the potential threat associations, a comprehensive risk analysis and threat identification result is generated.
6. The network security risk early warning method based on multi-source data fusion as described in claim 1, characterized in that, The tiered early warning system, based on the results of risk analysis and threat identification, includes: Risk levels are determined based on risk scoring results; Based on different risk levels, corresponding early warning signals are generated, and corresponding action recommendations are provided.
7. The network security risk early warning method based on multi-source data fusion as described in claim 1, characterized in that, It also includes autonomous defense steps based on the construction of network-endogenous immune resilience and attack entropy reduction response, specifically including: Based on the threat fusion matrix, a dynamic attack knowledge hypergraph is constructed, and the attack strategy is used to generate a network that infers the sequence of potential attack actions and their probability distribution. Based on the probability distribution, the potential attack action sequences are prioritized, and the immune strategy generator synthesizes a micro-perturbation defense strategy based on the concept of moving target defense for high-probability attack actions. Based on the sorted sequence of potential attack actions and the micro-perturbation defense strategy, a software-defined elastic controller is used to coordinate the scheduling of programmable elements in the network, calculate the optimal elastic deployment sequence, and deploy lightweight elastic execution points at key nodes to build an endogenous elastic network architecture. When an attack is detected, an entropy reduction response mechanism is initiated based on the intrinsically resilient network architecture. This mechanism dynamically adjusts the strength and scope of the micro-perturbation defense strategy and uses programmable elements in the intrinsically resilient network architecture to transparently redirect the attack flow to a highly interactive trapping mesh. By using data captured from the trapping grid, the model parameters of the attack strategy generation network and the immune strategy generator are updated through online deep learning, thereby enabling the autonomous evolution of the system's defense capabilities.
8. The network security risk early warning method based on multi-source data fusion as described in claim 7, characterized in that, The micro-perturbation defense strategy includes one or more combinations of the following strategies: Dynamic address hopping strategy, communication port randomization strategy, network topology dynamic reconstruction strategy, and false information injection strategy for critical services.
9. The network security risk early warning method based on multi-source data fusion as described in claim 7, characterized in that, The online deep learning employs a model update mechanism that combines incremental learning and adversarial training. It also utilizes attack data captured from the highly interactive trapping grid and unknown threat samples synthesized through an adversarial generative network to perform collaborative optimization training on the attack strategy generation network and the immune strategy generator.
10. A network security risk early warning system based on multi-source data fusion, characterized in that, include: The data acquisition module is used to collect multi-source security data; The entity recognition and association processing module is used to perform entity recognition and association processing on the multi-source security data to obtain entity association information. The spatiotemporal alignment and fusion processing module is used to perform spatiotemporal alignment and fusion processing on the entity association information to construct a threat fusion matrix; The risk analysis and threat identification module is used to perform risk analysis and threat identification on the threat fusion matrix based on rule engine matching, behavior anomaly detection AI model and graph neural network. The tiered early warning module is used to provide tiered early warnings based on the results of risk analysis and threat identification.
Citation Information
Cited By
Digital economic risk identification system and method based on artificial intelligence
CN121190204A
Server data interaction network security monitoring processing method and device
CN121356766A
Network security operation method and system, electronic equipment and storage medium
CN121619127A
Time sequence diagram neural network security risk analysis method, system and device and medium
CN121664496A
Alarm pushing method capable of automatically identifying early warning level and optimizing pushing mode
CN121792295A