Task-driven feature selection based cyber space probing method

By constructing a task-driven cyberspace detection method and utilizing artificial intelligence feature selection technology to automatically orchestrate detection methods, the shortcomings of existing cyberspace detection methods in high-level tasks are addressed, achieving efficient and accurate detection and data fusion analysis.

CN116781352BActive Publication Date: 2026-05-19NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
Filing Date
2023-06-25
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing cyberspace detection and analysis efforts suffer from weak targeting of detection strategies, lack of integrated multi-detection mechanism, poor dynamic adaptability, and low information fusion efficiency when faced with tasks involving high-level information identification and in-depth knowledge extraction. These shortcomings make it difficult to meet the demands of flexible, knowledge-intensive cyber detection tasks.

Method used

We construct a task-driven, feature-selection-based cyberspace detection method. Through a systematic detection and analysis model oriented towards high-level task requirements, we employ artificial intelligence feature selection technology to automatically orchestrate multiple detection methods and perform data fusion analysis, thereby achieving intelligent selection and orchestration of detection actions.

Benefits of technology

It improves the targeting and flexibility of cyberspace detection and analysis, enhances the efficiency and accuracy of detection work, reduces redundant detection costs, is highly adaptable, and can efficiently complete high-level data fusion and analysis tasks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116781352B_ABST
    Figure CN116781352B_ABST
Patent Text Reader

Abstract

The application provides a task-driven feature selection-based network space detection method, belongs to the technical field of network security and network analysis, and solves the limitation problem of the existing method when facing high-level information judgment and deep knowledge refining tasks; the method comprises the following steps: network space pre-detection and detection data set construction for different tasks; through pre-detection, the final conclusion of the corresponding feature vector is formed for the target task and is stored in the detection data set; task-guided network space detection action arrangement based on artificial intelligence feature selection; the artificial intelligence model is trained through the detection data set to generate a detection action sequence and obtain a task-detection action sequence relationship table; task-driven network space detection action execution and data fusion analysis; the actual final conclusion is obtained for the target task input by the user; and the application provides strong support for fusing network space multi-dimensional detection technology and assisting end users to complete target tasks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security and network analysis technology, specifically a task-driven, feature-selective network space detection method. Background Technology

[0002] Over the years, significant progress has been made in existing cyberspace detection and analysis. In asset detection, active detection methods are used to detect, identify, and characterize information such as device types, transmission protocols, port status, and service names of network entities connected to and communicating with the network. This information can then be extended to network intelligence, including vulnerabilities and organizational structures. Passive traffic analysis is used to perform non-interactive network asset information detection methods. By monitoring data traffic sent to the Internet by targets at different levels, such as data packets, network flows, and behavioral characteristics, the characteristic information carried by these traffic flows is analyzed. Alternatively, fingerprint information contained in flow characteristics can be used to identify various entity attributes. In topology detection, network topology measurements at the IP, router, point of presence (PoP), and Autonomous System (AS) levels provide insights into network structure and performance, enabling better network management and optimization to ensure secure, reliable, stable, and efficient operation. Simultaneously, network topology reflects the most basic link relationships between various entities in cyberspace and serves as the fundamental data source for topology attribute extraction and key node identification. Network topology analysis relies on techniques such as complex network analysis, selecting one or more indicators to analyze and rank the importance of network nodes according to different application requirements.

[0003] With the changing times, the current cybersecurity situation is becoming increasingly severe and tense, with more and more deep-seated and complex problems emerging, requiring solutions through cyberspace detection and analysis. Examples include: calculating the overall security posture indicators of a company's network equipment; providing a probability list of the organizers behind an anonymous network; identifying vulnerable attack points and types in a network region; and quantifying the defensive obfuscation capabilities of a target network adversary. Solving these complex problems typically requires targeting multiple objectives, utilizing different detection methods, and integrating multi-source data for in-depth analysis and mining. Current cyberspace detection and analysis methods, when faced with these high-level information assessment and in-depth knowledge extraction tasks, exhibit shortcomings such as weak targeting of detection strategies, a lack of integrated multi-detection method orchestration mechanisms, poor dynamic adaptability, low information fusion efficiency, and insufficient data fusion analysis and knowledge extraction capabilities. Therefore, existing technologies are no longer sufficient to meet the demands of increasingly flexible and knowledge-intensive network detection tasks. Summary of the Invention

[0004] The purpose of this invention is to solve, in whole or at least in part, the limitations of existing cyberspace detection methods mentioned in the background art, and therefore a task-driven feature selection-based cyberspace detection method is proposed.

[0005] This invention constructs a systematic detection and analysis model for high-level task requirements, targeting task sequences. It designs data extraction and structured storage methods for detection actions, feature vectors, and final conclusions for different tasks, forming a detection dataset. Based on this dataset, it proposes a task-guided, AI-based feature selection-driven cyberspace detection action orchestration mechanism. This mechanism effectively uncovers the interrelationships and synergies between different detection actions and results for specific tasks, automatically executing the orchestration of detection actions that integrate multiple detection methods. Furthermore, based on the orchestration scheme, it describes a task-driven cyberspace detection action execution and data fusion analysis method. Therefore, this invention provides strong support for integrating multi-dimensional cyberspace detection technologies and assisting end-users in completing target tasks.

[0006] The present invention employs the following technical solutions to achieve its objective:

[0007] A task-driven, feature-selective network space exploration method, comprising three main steps, as follows:

[0008] S1. Network space pre-probing and probing dataset construction for different tasks: In this step, based on the target task, the relevant network space is pre-probing, the probing actions and corresponding probing results are recorded, and multiple probing samples are obtained. Each probing sample corresponds to one feature vector. Then, for the target task, the final conclusion of the corresponding feature vector is formed and stored in the probing dataset.

[0009] S2. Task-guided, AI-based feature selection-based cyberspace probing action orchestration: In this step, the probing dataset constructed in step S1 is loaded, the AI ​​model is trained, and the importance of features is ranked by the degree of influence of different features on the judgment results generated by the AI ​​model. A sequence of probing actions is generated, and a table showing the relationship between the task and the probing action sequence is obtained, thus completing the orchestration process.

[0010] S3. Task-driven execution of cyberspace exploration actions and data fusion analysis: In this step, based on the task and exploration action sequence relationship table obtained in step S2, the corresponding exploration actions are executed for the target task actually input by the user, and the actual exploration results of cyberspace exploration are obtained. After data fusion analysis of the actual exploration results, the actual final conclusion is obtained.

[0011] Furthermore, the specific content of step S1 includes:

[0012] S11. The target tasks are arranged into a task sequence; the target tasks include the final target after a whole round of detection and analysis work is completed;

[0013] S12. Extract a new task from the task sequence and designate it as the current task; denot the current task as... , The current task number;

[0014] S13. Perform pre-probing on the current task, and record the probing actions and corresponding pre-probing results; during the pre-probing process, incorporate a broad probing process for the current task; record the probing actions as... , The action number is denoted as and the corresponding pre-detection result is denoted as . ;

[0015] S14. Based on the current task and pre-detection results, perform intermediate data analysis and generate intermediate results; record the intermediate results as follows: , The result sequence number is used; the pre-detection results are combined with the intermediate results to form a feature vector;

[0016] S15. Based on the feature vector, generate the final conclusion of the current task; the final conclusion includes category, value, vector, and distribution, and is denoted as... , The feature vector index;

[0017] S16. Summarize the process data generated in the above steps and store it in the detection dataset.

[0018] Specifically, in step S12, the new task is a probe task in the task sequence for which no probe dataset has yet been built. This task is taken out and used as the current task. Steps S12 to S16 are repeated until there are no new tasks in the task sequence, at which point the process of cyberspace pre-probe and probe dataset construction ends.

[0019] Furthermore, in step S14, shallow data fusion analysis is performed for the current task to generate intermediate results, and the preliminary detection actions required to obtain the intermediate results are recorded.

[0020] Furthermore, the intermediate results are obtained by fusing and analyzing multiple pre-detection results, and the detection actions corresponding to the intermediate results constitute a set; the intermediate results... The corresponding set of detection actions is denoted as Then, let the feature vector of the current task be denoted as... .

[0021] Furthermore, in step S16, the detection actions, feature vectors, and final conclusions generated in steps S13 to S15 are stored in the detection dataset. In the detection dataset, data from different tasks are stored in partitions. Each task partition contains two structured data structures: a mapping table between feature components and detection actions, and a table between feature vectors and final conclusions. The feature components are the feature vectors of the current task. The vector elements; each time the process goes through steps S13 to S15, a probe sample is generated, which corresponds to a row in the relationship table between the feature vector and the final conclusion.

[0022] Furthermore, the specific content of step S2 includes:

[0023] S21. Load the probe dataset constructed in step S1;

[0024] S22. Take a new task as the current task and read the data of the current task;

[0025] S23. Train the artificial intelligence model and generate a list of ranked features by importance;

[0026] S24. Determine the threshold based on importance, perform feature selection, and select multiple feature components;

[0027] S25. Sort the selected feature components in descending order of importance to generate a detection action sequence;

[0028] S26. Split the set of probe action sequences into a group of probe actions and store them back into the action sequence to complete the "flattening" operation; then perform the "duplicate" operation on the duplicate parts of the probe action sequences to generate the merged and deduplicated probe action sequences.

[0029] S27. Store the detection action sequence generated in step S26 into the task and detection action sequence relationship table.

[0030] Furthermore, in step S22, tasks that have not yet undergone feature selection in the probe dataset, i.e., new tasks, are extracted and taken as the current task. The feature components of the task are extracted into a mapping table between the probe actions and a table between the feature vectors and the final conclusions. In step S23, based on the feature vectors and the final conclusions of the current task, an artificial intelligence model is trained using the feature vectors as features and the final conclusions as labels, and a feature importance ranking list is generated. According to the specific application scenario of the task, the corresponding artificial intelligence model is selected for training. The categories of artificial intelligence models include: decision trees, random forests, logistic regression, linear regression, Naive Bayes, and neural networks.

[0031] Furthermore, in step S24, an importance judgment threshold is selected based on feature importance evaluation criteria, task application requirements, and the infrastructure conditions necessary to complete the task; and based on the importance judgment threshold, the most important features are selected. n Each feature component; in step S25, the components are sorted in descending order of importance. n The feature components are sorted; the mapping relationship table between the feature components and the detection actions is extracted, the detection action corresponding to the selected feature component is found, and the detection action sequence is generated.

[0032] Specifically, step S3 includes the following:

[0033] S31. The user inputs the target task for the actual detection and analysis work;

[0034] S32. Load the task and detection action sequence relationship table obtained in step S2;

[0035] S33. Based on the target task input by the user, read the corresponding detection action sequence in the task and detection action sequence relationship table;

[0036] S34. Based on the read sequence of detection actions, arrange the actual detection actions to be executed, and obtain the detection results of the target task after execution;

[0037] S35. Obtain the detection results, perform data fusion analysis, and obtain the final conclusion of the actual target mission.

[0038] In summary, due to the adoption of this technical solution, the beneficial effects of this invention are as follows:

[0039] In this invention, a systematic model of the cyberspace detection process and data organization is performed for the task sequence. Cyberspace pre-detection and detection dataset construction are carried out for different tasks, and detection work plans are formulated, improving the targeting and flexibility of cyberspace detection and analysis for task objectives. Subsequently, guided by tasks, cyberspace detection actions are screened and arranged based on artificial intelligence feature selection technology, realizing intelligent selection and automated arrangement of diversified detection technologies for tasks. This not only helps to explore the interrelationships and synergistic effects of different detection technologies and strengthen cross-support for unified task objectives, but also improves the efficiency of detection work planning and reduces the execution cost of redundant detection. Finally, cyberspace detection actions and data fusion analysis are executed with tasks as the driving force, and cyberspace detection resources are adaptively mobilized according to actual task requirements, which helps to improve the accuracy, efficiency, and real-time performance of task execution.

[0040] Therefore, the method of the present invention provides a solution for organizing network space detection data, arranging detection actions, executing detection, and analyzing data to meet the high-level data fusion and analysis needs that have emerged now and will continue to increase in the future. This provides support for integrating multi-dimensional network space detection technologies and assisting end users in completing their target tasks. Attached Figure Description

[0041] Figure 1 This is a schematic diagram of the overall steps of the method of the present invention;

[0042] Figure 2 A schematic diagram of the data flow for constructing pre-scanning and probing datasets in cyberspace;

[0043] Figure 3 A flowchart illustrating the process of pre-detection and detection dataset construction in cyberspace;

[0044] Figure 4 A flowchart illustrating the process of orchestrating cyberspace detection actions based on artificial intelligence feature selection;

[0045] Figure 5 A schematic diagram illustrating the process of generating and deduplicating detection action sequences;

[0046] Figure 6 A flowchart illustrating the process of executing cyberspace detection actions and fusing and analyzing data. Detailed Implementation

[0047] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.

[0048] Therefore, the following detailed description of the embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.

[0049] Example

[0050] A task-driven, feature-selective network space exploration method, consisting of three main steps, as follows: Figure 1 As shown, they are in the following order:

[0051] S1. Network space pre-probing and probing dataset construction for different tasks: In this step, based on the target task, the relevant network space is pre-probing, the probing actions and corresponding probing results are recorded, and multiple probing samples are obtained. Each probing sample corresponds to one feature vector. Then, for the target task, the final conclusion of the corresponding feature vector is formed and stored in the probing dataset.

[0052] S2. Task-guided, AI-based feature selection-based cyberspace probing action orchestration: In this step, the probing dataset constructed in step S1 is loaded, the AI ​​model is trained, and the importance of features is ranked by the degree of influence of different features on the judgment results generated by the AI ​​model. A sequence of probing actions is generated, and a table showing the relationship between the task and the probing action sequence is obtained, thus completing the orchestration process.

[0053] S3. Task-driven execution of cyberspace exploration actions and data fusion analysis: In this step, based on the task and exploration action sequence relationship table obtained in step S2, the corresponding exploration actions are executed for the target task actually input by the user, and the actual exploration results of cyberspace exploration are obtained. After data fusion analysis of the actual exploration results, the actual final conclusion is obtained.

[0054] This embodiment will describe the detailed process and features of each step in the order of the method steps.

[0055] I. Construction of Cyberspace Pre-detection and Detection Datasets for Different Tasks

[0056] For the data flow and process outlined in this step, please refer to [link / reference]. Figure 2 and Figure 3 The illustration is as follows:

[0057] S11. Organize the target tasks into a task sequence;

[0058] In this embodiment, the target task refers to the final objective after a full round of detection and analysis, aiming to obtain information and knowledge that can directly assist decision-makers in their decisions. Examples include: a probability list of organizers behind an anonymous network; security posture assessment indicators for a company's network equipment; vulnerable attack points and types in a regional network; and the defensive obfuscation strategies of adversaries on the target network.

[0059] S12. Select a new task as the current task;

[0060] If a task in the task sequence does not yet have a probe dataset built for it, a new task is selected as the current task; otherwise, the pre-probing and probe dataset construction process ends. Since the final generated probe dataset is organized into blocks according to different tasks, each task in the task sequence undergoes isolated cyberspace probing, intermediate data analysis, information determination, and knowledge extraction processes until the probe dataset for that task is constructed. In this embodiment, the formal expression of the probe task, i.e., the selected current task, is denoted as... , This is the current task number.

[0061] S13. Perform pre-detection and record the detection actions and corresponding detection results;

[0062] For the current task, relevant cyberspace pre-probing is performed based on experience or prior knowledge, and the probing actions and corresponding pre-probing results are recorded. In this step, a wide range of probing processes whose results may influence the final conclusion should be included to enrich the original feature vectors in the subsequent feature selection process. In this embodiment, the probing actions are denoted as... , The action number is denoted as and the corresponding pre-detection result is denoted as . .

[0063] S14. Perform intermediate data analysis and generate intermediate results;

[0064] Perform shallow data fusion analysis for the current task to generate intermediate results, record the preliminary detection actions required to obtain the intermediate results, and combine the pre-detection results from the previous step with the intermediate results to form a feature vector.

[0065] Here, intermediate results represent data that supports deeper reasoning and refinement, but do not involve high-level information judgment or knowledge extraction. Examples of intermediate results include network entity attribute identification results such as device and service type, centrality calculation results based on complex networks, mapping results from IP links to AS-level links, correlation results between asset information and vulnerability information, and mapping results between IP addresses and physical addresses.

[0066] In this embodiment, the intermediate result is denoted as , This is the result sequence number; since intermediate results may be obtained by fusing and analyzing multiple pre-detection results, the corresponding detection action is a set, and the intermediate results are... The corresponding set of detection actions is denoted as Then, let the feature vector of the current task be denoted as... A task can have many probe samples, and each sample has one feature vector.

[0067] S15. Generate the final conclusion of the current task;

[0068] Using feature vectors as input, information is determined and knowledge is extracted, and a final conclusion corresponding to the feature vector is formed for the current task. The final conclusion can be a category, a numerical value, a vector, a distribution, etc., and is denoted as... , This is the eigenvector index.

[0069] S16. Summarize the above process data and store it in the detection dataset;

[0070] The detection actions, feature vectors, and final conclusions generated during steps S13 to S15 are stored in the detection dataset. Within the detection dataset, data from different tasks are stored in partitions, as shown below. Figure 2 This is an illustration. Each task partition stores two structured data structures: a mapping table between feature components and detection actions, and a table between feature vectors and final conclusions; where the feature components are the feature vectors of the current task. Vector elements.

[0071] The feature component and detection action mapping table stores the mapping relationship between each feature component of the feature vector and the corresponding detection action. An example of the content is shown in Table 1 below.

[0072] Table 1. Example of the mapping relationship between feature components and detection actions.

[0073]

[0074] The Feature Vector and Final Conclusion Relationship Table stores the association between the feature vectors and the final conclusions of each task. An example of the content is shown in Table 2 below.

[0075] Table 2. Example of the relationship between feature vectors and final conclusions.

[0076]

[0077] Each round of detection and analysis from steps S13 to S15 generates a detection sample, corresponding to a row in the feature vector and final conclusion relationship table. Depending on the application requirements of different tasks, a certain number of detection samples are needed. Therefore, based on the specific application scenario, multiple rounds of steps S13 to S15 need to be repeated, and the samples are stored accordingly in step S16 until the requirements for building the artificial intelligence model for the current task are met.

[0078] After the probe dataset for the current task is constructed, return to step S12 to process the next task in the task queue.

[0079] II. Task-guided choreography of cyberspace exploration actions based on AI feature selection.

[0080] The purpose of this step is to generate a sequence of probe actions for each task in the probe dataset. For a detailed flowchart, please refer to [link / reference needed]. Figure 4 The illustration includes the following steps in sequence:

[0081] S21. Load the probe dataset;

[0082] Load the probe dataset that was built in the first major step.

[0083] S22. Select a new task as the current task and read the task data;

[0084] If there are tasks in the probe dataset that have not yet performed feature selection, then a new task is taken out as the current task, and the task data is read, namely the mapping table between the feature components and the probe actions of the task and the mapping table between the feature vector and the final conclusion.

[0085] S23. Train the artificial intelligence model and generate a list of ranked features by importance;

[0086] A relationship table between feature vectors and final conclusions is extracted. Using feature vectors as features and final conclusions as labels, an artificial intelligence model is trained, generating a ranking list of feature importance. Based on the specific application scenario of the task, an appropriate artificial intelligence model is selected for training. Types of artificial intelligence models include algorithms such as decision trees, random forests, logistic regression, linear regression, Naive Bayes, and neural networks. Based on the selected artificial intelligence model, applicable importance evaluation criteria are chosen to rank feature importance. Importance evaluation criteria include geometric or probabilistic distance metrics such as Euclidean distance, Mingian distance, Bhattacharyya, and Kullback-Liebler; consistency metrics such as inconsistency factor, focus, and LVF; dependency metrics such as f-test, t-test, Pearson correlation coefficient, and Fisher score; information metrics such as mutual information and information gain; and classification accuracy or classification error rate metrics.

[0087] S24. Determine the threshold based on importance and perform feature selection;

[0088] Based on importance evaluation criteria, task application requirements, and the available infrastructure to complete the task, an appropriate importance threshold is selected to identify the most important tasks. n Each feature component.

[0089] S25. Generate a sequence of detection actions;

[0090] Based on the feature components selected in step S24, they are sorted from highest to lowest importance. Next, a mapping table between feature components and detection actions is extracted, the detection actions corresponding to the selected features are found, and they are arranged in their original order of importance to generate a sequence of detection actions.

[0091] S26. Merge and deduplicatize the detection action sequences;

[0092] Due to the intermediate results constituting the detection components This corresponds to the set of detection actions. The detection action sequence needs to be broken down into a set of detection actions and then stored back into the action sequence to obtain a "flattened" detection action sequence. Simultaneously, since different feature components may correspond to the same detection action, repetitions will occur in the detection action sequence, requiring a "duplicate removal" operation. After the "flattening" and "duplicate removal" operations, a fused and deduplicated detection action sequence is generated. The overall process of steps S25 and S26 can be found in [link to documentation]. Figure 5 The illustration.

[0093] S27. Store the relationship table between the task and the detection action sequence;

[0094] The fused and deduplicated detection action sequence output in step S26 is stored in the task and detection action sequence relationship table. An example of the contents of the task and detection action sequence relationship table is shown in Table 3 below.

[0095] Table 3. Example of the relationship between task and probe action sequence.

[0096]

[0097] III. Task-driven execution of cyberspace exploration actions and data fusion analysis.

[0098] The flowchart for this step is as follows: Figure 6 As shown, the specific content is as follows:

[0099] S31. Input the target task;

[0100] The target task of user input detection and analysis is...

[0101] S32, Relationship table between loading mission and detection action sequence;

[0102] Load the task and probe action sequence relationship table generated in the second major step.

[0103] S33. Read the detection action sequence;

[0104] Based on the target task input by the user, the corresponding detection action sequence is read from the task and detection action sequence relationship table.

[0105] S34. Perform the detection action;

[0106] The detection actions are executed according to the sequence of detection actions.

[0107] S35, Perform data analysis;

[0108] After obtaining the actual detection results from the detection actions performed in step S34, data fusion analysis is performed to obtain the final conclusion. If the analysis requires the results of deleted detection actions, corresponding default values ​​are given according to the task situation. Since the features involved in the deleted detection actions have low importance, they will not have a significant impact on the final conclusion.

[0109] In summary, the method of this embodiment is task-driven, performing cyberspace detection actions and data fusion analysis, and adaptively allocating cyberspace detection resources according to actual task requirements, which helps to improve the accuracy, efficiency and real-time performance of task execution.

Claims

1. A task-driven, feature-selective network space exploration method, characterized in that: The method consists of three main steps, as follows: S1. Network space pre-probing and probing dataset construction for different tasks: In this step, based on the target task, the relevant network space is pre-probing, the probing actions and corresponding probing results are recorded, multiple probing samples and corresponding feature vectors are obtained, and then the final conclusion of the corresponding feature vectors is formed for the target task and stored in the probing dataset. S2. Task-guided, AI-based feature selection-based cyberspace probing action orchestration: In this step, the probing dataset constructed in step S1 is loaded, the AI ​​model is trained, and the importance of features is ranked by the degree of influence of different features on the judgment results generated by the AI ​​model. A sequence of probing actions is generated, and a table showing the relationship between the task and the probing action sequence is obtained, thus completing the orchestration process. S3. Task-driven execution of cyberspace exploration actions and data fusion analysis: In this step, for the target task actually input by the user, according to the task and exploration action sequence relationship table obtained in step S2, the corresponding exploration actions are executed to obtain the actual exploration results of cyberspace exploration. After data fusion analysis of the actual exploration results, the actual final conclusion is obtained. The specific content of step S1 includes: S11. The target tasks are arranged into a task sequence; the target tasks include the final target after a whole round of detection and analysis work is completed; S12. Extract a new task from the task sequence and designate it as the current task; denot the current task as... , The current task number; S13. Perform pre-probing on the current task, and record the probing actions and corresponding pre-probing results; during the pre-probing process, incorporate a broad probing process for the current task; record the probing actions as... , The action number is denoted as and the corresponding pre-detection result is denoted as . ; S14. Based on the current task and pre-detection results, perform intermediate data analysis and generate intermediate results; record the intermediate results as follows: , The result sequence number is used; the pre-detection results are combined with the intermediate results to form a feature vector; S15. Based on the feature vector, generate the final conclusion of the current task; the final conclusion includes category, value, vector, and distribution, and is denoted as... , The feature vector index; S16. Summarize the process data generated in the above steps and store it in the detection dataset; In the probe dataset, data for different tasks are stored in a partitioned manner; each task partition contains two structured data structures: one is a mapping table between feature components and probe actions, and the other is a table between feature vectors and final conclusions. The specific content of step S2 includes: S21. Load the probe dataset constructed in step S1; S22. Take a new task as the current task and read the data of the current task; S23. Train the artificial intelligence model and generate a list of ranked features by importance; S24. Determine the threshold based on importance, perform feature selection, and select multiple feature components; S25. Sort the selected feature components in descending order of importance to generate a detection action sequence; S26. Split the set of probe action sequences into a group of probe actions and store them back into the action sequence to complete the "flattening" operation; then perform the "duplicate" operation on the duplicate parts of the probe action sequences to generate the merged and deduplicated probe action sequences. S27. Store the detection action sequence generated in step S26 into the task and detection action sequence relationship table.

2. The task-driven, feature-selective network space exploration method according to claim 1, characterized in that: In step S12, the new task is a probe task in the task sequence for which no probe dataset has yet been built. This task is taken out and used as the current task. The process of steps S12 to S16 is repeated until there are no new tasks in the task sequence, and then the process of cyberspace pre-probe and probe dataset construction ends.

3. The task-driven, feature-selective network space exploration method according to claim 1, characterized in that: In step S14, shallow data fusion analysis is performed for the current task to generate intermediate results, and the preliminary detection actions required to obtain the intermediate results are recorded.

4. The task-driven, feature-selective network space exploration method according to claim 3, characterized in that: The intermediate results are obtained through the fusion analysis of multiple pre-detection results, and the detection actions corresponding to the intermediate results constitute a set; the intermediate results... The corresponding set of detection actions is denoted as Then, let the feature vector of the current task be denoted as... .

5. The task-driven, feature-selective network space exploration method according to claim 4, characterized in that: In step S16, the detection actions, feature vectors, and final conclusions generated in steps S13 to S15 are stored in the detection dataset; the feature components are the feature vectors of the current task. The vector elements; each time the process goes through steps S13 to S15, a probe sample is generated, which corresponds to a row in the relationship table between the feature vector and the final conclusion.

6. The task-driven, feature-selective network space exploration method according to claim 1, characterized in that: In step S22, tasks that have not yet performed feature selection in the detection dataset are taken out, i.e., new tasks, and they are taken as the current tasks. The feature components of the task are extracted into a mapping table between the detection action and the feature vectors and the final conclusions. In step S23, based on the feature vectors and the final conclusions of the current task, the artificial intelligence model is trained with the feature vectors as features and the final conclusions as labels, and a feature importance ranking list is generated. Based on the specific application scenario of the task, the corresponding artificial intelligence model is selected for training. The categories of artificial intelligence models include: decision tree, random forest, logistic regression, linear regression, Naive Bayes and neural network.

7. The task-driven, feature-selective network space exploration method according to claim 6, characterized in that: In step S24, the importance judgment threshold is selected based on the feature importance evaluation criteria, task application requirements, and the basic facilities that can provide the necessary conditions to complete the task; and the most important n feature components are selected based on the importance judgment threshold. In step S25, the first n feature components are sorted in descending order of importance; Extract the mapping table between feature components and detection actions, find the detection action corresponding to the selected feature component, and generate a sequence of detection actions.

8. The task-driven, feature-selective network space exploration method according to claim 1, characterized in that, The specific content of step S3 includes: S31. The user inputs the target task for the actual detection and analysis work; S32. Load the task and detection action sequence relationship table obtained in step S2; S33. Based on the target task input by the user, read the corresponding detection action sequence in the task and detection action sequence relationship table; S34. Based on the read sequence of detection actions, arrange the actual detection actions to be executed, and obtain the detection results of the target task after execution; S35. Obtain the detection results, perform data fusion analysis, and obtain the final conclusion of the actual target mission.