A Forensics Method and System Based on Virtual Knowledge Graph and Big Data
By adopting evidence forensics based on virtual knowledge graphs and big data in the cloud environment, the complexity of data forensics in the cloud environment is solved, efficient and accurate evidence collection and analysis are achieved, and powerful technical support is provided for judicial appraisal and other fields.
Patent Information
- Application Number
- CN202411676050.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-22
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2044-11-22
AI Technical Summary
Data forensics in the cloud environment faces problems such as wide distribution of data, diverse formats, dynamic changes and privacy protection, and traditional forensics technology is difficult to effectively conduct comprehensive evidence analysis.
Using the forensics method based on virtual knowledge graphs and big data, by constructing a domain knowledge graph in the field of forensics, multiple sources of data are obtained and mapping sets are established, evidence extraction and analysis rules are constructed based on the map sets, evidence collection requests are divided, answer sets are determined, and answer sets are converted into knowledge graph format.
It realizes multi-level and dynamic evidence collection and analysis, improves the efficiency, accuracy and reliability of evidence collection, and ensures the interpretability of evidence collection results, providing strong technical support for judicial appraisal and other fields.
Smart Images

Figure CN119168052B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of electronic virtual forensics, and specifically relates to a forensics method and system based on virtual knowledge graph and big data. Background Art
[0002] With the acceleration of the digitalization process and the widespread use of cloud computing, more and more data is stored in the cloud. In the cloud computing environment, the storage and transmission of data span multiple layers such as the virtual layer, application layer, and service layer, and user behaviors also show complex and variable characteristics. This makes data forensics in the cloud environment face many challenges, such as widespread data distribution, diverse formats, dynamic changes, and privacy protection. Traditional forensics technologies have multiple problems when facing the cloud environment, such as difficult evidence collection, scattered data, and complex storage. Existing technologies are difficult to effectively conduct comprehensive forensics analysis in the cloud environment. Therefore, there is an urgent need for a new forensics method that can integrate multiple data sources to meet the multi-level and complex forensics requirements in the cloud environment. Summary of the Invention
[0003] To solve the above technical problems, the present invention provides a forensics method and system based on virtual knowledge graph and big data to solve the technical problems in the prior art.
[0004] On the one hand, the present invention provides the following technical solution. A forensics method based on virtual knowledge graph and big data includes:
[0005] Construct a domain knowledge graph for the forensics field, obtain the data sources involved in the forensics, and establish a mapping set between the domain knowledge graph and the data sources;
[0006] Construct evidence extraction and analysis rules based on the mapping set;
[0007] Obtain a forensics request issued by a user, and divide the forensics request based on the domain knowledge graph to obtain several sub-forensics requests;
[0008] Determine an answer set based on the several sub-forensics requests, and convert the answer set into the format of a knowledge graph to obtain a forensics set.
[0009] Compared with the prior art, the beneficial effects of the present invention are as follows: the present invention maps multi-source, heterogeneous and distributed data sources related to forensics to a unified knowledge graph. Forensic personnel can obtain data related to forensics through the knowledge graph, establish semantic associations between data, and mine implicit and contradictory information in the data source through the reasoning ability of the knowledge graph. In addition, the constructed rule base related to forensics can help forensics personnel perform automatic forensics operations, establish evidence chain analysis, and generate forensics reports. The present invention realizes multi-level and dynamic evidence collection and analysis through a unified semantic layer, which can effectively solve the main problems faced in the prior art to improve the efficiency, accuracy and reliability of forensics, and ensure the interpretability of forensics results. It can also provide accurate and comprehensive results in multi-level evidence analysis, provide strong technical support for fields such as forensic identification, and has broad application prospects.
[0010] Preferably, the steps of constructing the domain knowledge graph in the field of forensics are specifically as follows:
[0011] Construct several prompt templates, continuously send the prompt templates to the large language model, extract the semantic relations in the forensic field, iteratively repeat the prompt template sending and semantic relation extraction process to obtain the domain knowledge graph.
[0012] Preferably, the semantic relationship includes semantic relationship between concepts in the field of forensics, semantic relationship between attributes in the field of forensics, and semantic relationship between concepts and attributes in the field of forensics.
[0013] Preferably, the mapping set for:
[0014] ;
[0015] ;
[0016] In the formula, It is shaped like The set of mappings of Map the data in each data source to the domain knowledge graph. Indicates that for The query statement of a data source, Represents a class or attribute in a domain knowledge graph, Represents a transformation function, which describes how to transform data in the data source into entities or objects in the knowledge graph.
[0017] Preferably, the step of constructing evidence extraction and analysis rules based on the mapping set is specifically as follows:
[0018] Express the rules for reviewing and judging evidence described in natural language in legal documents in a formalized manner based on the vocabulary in the domain knowledge graph to obtain evidence extraction and analysis rules:
[0019] ;
[0020] In the formula, represents the antecedent or reasoning premise of the evidence extraction and analysis rules, represents the consequent or reasoning conclusion of the evidence extraction and analysis rules.
[0021] Preferably, the steps of obtaining the forensic evidence request issued by the user and splitting the forensic evidence request based on the domain knowledge graph to obtain a number of sub-forensic evidence requests include:
[0022] Obtain the forensic evidence request issued by the user , rewrite the forensic evidence request and encode the knowledge of the domain knowledge graph to obtain a rewritten request ;
[0023] According to the mapping between each data source in the mapping set and the domain knowledge graph, split the rewritten request into a number of sub-forensic evidence requests .
[0024] Preferably, the steps of determining an answer set based on a number of the sub-forensic evidence requests, converting the answer set into the format of a knowledge graph to obtain a forensic evidence set include:
[0025] Convert the sub-forensic evidence requests into requests supported by the corresponding data sources through the mapping set to obtain converted requests;
[0026] Answer the converted requests on the corresponding data sources according to the evidence extraction and analysis rules to obtain a sub-answer set;
[0027] Fuse a number of sub-answer sets according to the splitting method of the forensic evidence request to obtain an answer set;
[0028] Obtain the response traceability information of each sub-answer set in each answer set, and convert the response traceability information and the answer set into the format corresponding to the domain knowledge graph to obtain a forensic evidence set.
[0029] In a second aspect, the present invention provides the following technical solution, a forensic evidence system based on a virtual knowledge graph and big data, the system includes:
[0030] A construction module, configured to construct a domain knowledge graph of the forensic evidence field, obtain data sources involved in the forensic evidence, and establish a mapping set between the domain knowledge graph and the data sources;
[0031] A rule module, configured to build evidence extraction and analysis rules based on the mapping set;
[0032] A segmentation module, configured to obtain a forensic request issued by a user, and segment the forensic request based on the domain knowledge graph to obtain a plurality of sub-forensic requests;
[0033] A forensic module, configured to determine an answer set based on the plurality of sub-forensic requests, and convert the answer set into a format of a knowledge graph to obtain a forensic set.
[0034] In a third aspect, the present invention provides the following technical solution. A computer includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the forensic method based on the virtual knowledge graph and big data as described above is implemented.
[0035] In a fourth aspect, the present invention provides the following technical solution. A storage medium stores a computer program, and when the computer program is executed by a processor, the forensic method based on the virtual knowledge graph and big data as described above is implemented. Description of the Drawings
[0036] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0037] Figure 1 It is a flowchart of the forensic method based on the virtual knowledge graph and big data provided in Embodiment 1 of the present invention;
[0038] Figure 2 It is a structural block diagram of the forensic system based on the virtual knowledge graph and big data provided in Embodiment 2 of the present invention;
[0039] Figure 3 It is a schematic diagram of the hardware structure of a computer provided in another embodiment of the present invention.
[0040] The following will further describe the embodiments of the present invention with reference to the drawings. Detailed Embodiments
[0041] Embodiments of the present invention will be described in detail below. Examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the accompanying drawings are exemplary and are intended to explain the embodiments of the present invention, and should not be construed as limiting the present invention.
[0042] In the description of the embodiments of the present invention, it should be understood that the orientation or positional relationships indicated by the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. are based on the orientation or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the embodiments of the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as limiting the present invention.
[0043] In addition, the terms "first" and "second" are only used for descriptive purposes and should not be construed as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the embodiments of the present invention, the meaning of "a plurality" is two or more unless otherwise specifically defined.
[0044] In the embodiments of the present invention, unless otherwise clearly specified and limited, the terms "mounted", "connected", "connected", "fixed", etc. should be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or integrated; it may be a mechanical connection or an electrical connection; it may be directly connected or indirectly connected through an intermediate medium, and it may be the communication inside two elements or the interaction relationship between two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the embodiments of the present invention can be understood according to specific circumstances.
[0045] Embodiment 1
[0046] In Embodiment 1 of the present invention, as Figure 1 shown, a forensics method based on a virtual knowledge graph and big data includes:
[0047] S1. Construct a domain knowledge graph for forensics, obtain the data sources involved in forensics, and establish a mapping set between the domain knowledge graph and the data sources;
[0048] Specifically, the step S1 is specifically as follows:
[0049] Construct a number of prompt templates, continuously send the prompt templates into the large language model, extract the semantic relationships in the forensic field, and iterate and repeat the process of sending prompt templates and extracting semantic relationships to obtain a domain knowledge graph;
[0050] Among them, the semantic relationships include the semantic relationships between concepts in the forensic field, the semantic relationships between attributes in the forensic field, and the semantic relationships between concepts and attributes in the forensic field.
[0051] It should be noted that the prompt templates can be generated from the literature, books, legal documents, and cases in the forensic field. Combined with the large language model, the prompt templates are input into the large language model for repeated training, enabling the large language model to repeatedly extract concepts and attributes in the forensic field and establish corresponding semantic relationships. For example, "physical evidence evidence", "testimonial evidence evidence", "physical evidence testimonial evidence", where " " represents a subcategory relationship, and " " represents a disjoint relationship. Until this process terminates, the corresponding domain knowledge graph can be generated. The obtained domain knowledge graph provides a unified semantic view for the multi-source, heterogeneous, and distributed data sources involved in forensics. In addition, this domain knowledge graph also provides a unified standard semantic vocabulary set for the forensic field and forensic personnel, as well as a structured description of the knowledge in the forensic field.
[0052] At the same time, in the process of collecting and determining the data sources involved in forensics , in the context of big data, in order to ensure the diversity and richness of evidence, it is necessary to obtain evidence information from multiple data sources, such as log files and user behavior data. In addition, it is necessary to record the access methods of each data source, laying a foundation for dynamically and real-time accessing the data in the data sources through the domain knowledge graph in the future. For example, if the data source is a database, it is necessary to record information such as the username, URL, and password for accessing the database. At the same time, in order to establish a unified semantic view, it is necessary to construct a mapping relationship between the domain knowledge graph and the data sources, that is, a mapping set. This mapping relationship formally describes how to map the data in each data source to the concepts and attributes in the domain knowledge graph, which is the core of realizing the dynamic and real-time acquisition of evidence-related data from the domain knowledge graph, that is, the unified semantic view, from multi-source, heterogeneous, and distributed data sources. In addition, this mapping relationship is also the key to enhancing the semantic association and interoperability of data in different data sources through the domain knowledge graph.
[0053] Among them, the mapping set is:
[0054] ;
[0055] ;
[0056] In the formula, is a set of mappings in the form of , which depicts how to map the data in the th data source to the domain knowledge graph. represents the query statement for the th data source. represents a class or property in the domain knowledge graph. represents a conversion function, which depicts how to convert the data in the data source into entities or objects in the knowledge graph.
[0057] It should be noted that only the data that needs to be accessed in the data source needs to be mapped to the domain knowledge graph, rather than all the data in it, that is, the data irrelevant to the forensics field does not need to be mapped.
[0058] S2. Construct evidence extraction and analysis rules based on the mapping set;
[0059] Specifically, in order to automatically review and analyze the authenticity, legality, relevance, etc. of the forensics results, the corresponding evidence extraction and analysis rules can be determined based on the domain knowledge graph, data source, and mapping set. The specific steps of S2 include:
[0060] Express the review and judgment rules of evidence described in natural language in legal documents in a formalized manner based on the vocabulary in the domain knowledge graph to obtain evidence extraction and analysis rules:
[0061] ;
[0062] In the formula, represents the antecedent or reasoning premise of the evidence extraction and analysis rule. represents the consequent or reasoning conclusion of the evidence extraction and analysis rule.
[0063] Among them, the review and judgment rules are the authenticity, legality, and relevance of the evidence. And when the reasoning premise is satisfied, the reasoning conclusion can be obtained.
[0064] S3. Obtain the forensics request issued by the user, and split the forensics request based on the domain knowledge graph to obtain several sub-forensics requests;
[0065] Among them, the step S3 includes:
[0066] S31. Obtain the forensic evidence request sent by the user , rewrite the forensic evidence request and encode the knowledge in the domain knowledge graph to obtain a rewritten request ;
[0067] Specifically, for the rewritten request, the knowledge in the knowledge graph is encoded therein. For example, if the forensic evidence request is to query "evidence", after passing through the knowledge in the domain knowledge graph, the rewritten request will also query "testimony", "physical evidence", etc.
[0068] S32. According to the mapping between each data source in the mapping set and the domain knowledge graph, split the rewritten request into several sub-forensic evidence requests ;
[0069] Specifically, for the evidence information that meets the rewritten request, it may be distributed in several different data sources, that is, the corresponding evidence information cannot be obtained by answering the forensic evidence request on a certain data source. Therefore, it is necessary to split the rewritten request into several sub-forensic evidence requests according to the mapping between each data source in the mapping set and the domain knowledge graph, so that each sub-forensic evidence request can be independently answered on a certain data source or several data sources.
[0070] S4. Determine an answer set based on several of the sub-forensic evidence requests, and convert the answer set into the format of the knowledge graph to obtain a forensic evidence set;
[0071] Among them, step S4 includes:
[0072] S41. Convert the sub-forensic evidence request into a request supported by the corresponding data source through the mapping set to obtain a converted request.
[0073] S42. Answer the converted request on the corresponding data source according to the evidence extraction and analysis rules to obtain a sub-answer set.
[0074] S43. Integrate several sub-answer sets according to the splitting method of the forensic evidence request to obtain an answer set.
[0075] S44. Obtain the response traceability information of each sub-answer set in each answer set, and convert the response traceability information and the answer set into the format corresponding to the domain knowledge graph to obtain a forensic evidence set;
[0076] Specifically, in order to facilitate the presentation of forensic results in a graphical form to help forensic personnel intuitively understand the relationship between data and evidence, the traceability information of each data source is recorded, including which data source each data source comes from and how the data is obtained. The information is then converted together with the answer set into a format corresponding to the domain knowledge graph, that is, a set of RDF triples, and the corresponding forensic set can be output.
[0077] It should be noted that after obtaining the evidence collection set, it is necessary to combine the domain knowledge graph and the evidence extraction and analysis rules to verify whether there is contradictory information in the evidence collection set. For example, in the big data scenario, the information of the same person will be distributed in multiple data sources. Through the unified knowledge graph, the relevant information distributed in multiple data sources will be extracted. It is necessary to verify whether there is a conflict between these information through the pre-built evidence extraction and analysis rules and knowledge graph. For example, the same person cannot appear in two different physical locations at the same time. In addition, it is also necessary to review and analyze the legality and authenticity of the knowledge graph corresponding to the evidence collection results through the evidence extraction and analysis rules, knowledge graph and data source, and establish a chain of evidence. Finally, the pre-defined evidence report template is used to automatically generate a forensic report. In addition to recording the evidence collection process and results in detail, the report will also generate a complete and traceable chain of evidence, providing strong support for legal proceedings and case investigations.
[0078] The first embodiment of the present invention provides a forensics method based on a virtual knowledge graph and big data. The present invention maps multi-source, heterogeneous and distributed data sources related to forensics to a unified knowledge graph. Forensics personnel can obtain data related to forensics through the knowledge graph, establish semantic associations between data, and mine implicit and contradictory information in the data source through the reasoning ability of the knowledge graph. In addition, the constructed rule base related to forensics can help forensics personnel perform automatic forensics operations, establish evidence chain analysis, and generate forensics reports. The present invention realizes multi-level and dynamic evidence collection and analysis through a unified semantic layer, which can effectively solve the main problems faced in the prior art to improve the efficiency, accuracy and reliability of forensics, and ensure the interpretability of forensics results. It can also provide accurate and comprehensive results in multi-level evidence analysis, provide strong technical support for forensic identification and other fields, and has broad application prospects.
[0079] Embodiment 2
[0080] like Figure 2 As shown, in the second embodiment of the present invention, a forensics system based on virtual knowledge graph and big data is provided, and the system includes:
[0081] Building module 1, which is used to build a domain knowledge graph in the field of forensic evidence, obtain data sources involved in forensic evidence, and establish a mapping set between the domain knowledge graph and the data sources;
[0082] Rule module 2, which is used to build evidence extraction and analysis rules based on the mapping set;
[0083] Segmentation module 3, which is used to obtain a forensic evidence request issued by a user, segment the forensic evidence request based on the domain knowledge graph to obtain a number of sub-forensic evidence requests;
[0084] Forensic evidence module 4, which is used to determine an answer set based on a number of the sub-forensic evidence requests, and convert the answer set into the format of a knowledge graph to obtain a forensic evidence set;
[0085] The building module 1 is specifically used for:
[0086] Build a number of prompt templates, continuously send the prompt templates to a large language model, extract semantic relationships in the field of forensic evidence, and iteratively repeat the process of sending prompt templates and extracting semantic relationships to obtain a domain knowledge graph.
[0087] The rule module 2 is specifically used for:
[0088] Express the rules for examining and judging evidence described in natural language in a legal document in a formalized manner based on the vocabulary in the domain knowledge graph to obtain evidence extraction and analysis rules:
[0089] ;
[0090] In the formula, represents the antecedent or reasoning premise of the evidence extraction and analysis rule, represents the consequent or reasoning conclusion of the evidence extraction and analysis rule.
[0091] The segmentation module 3 includes:
[0092] Coding sub-module, which is used to obtain a forensic evidence request issued by a user , rewrite the forensic evidence request and code the knowledge of the domain knowledge graph to obtain a rewritten request ;
[0093] Segmentation sub-module, which is used to segment the rewritten request into a number of sub-forensic evidence requests according to the mapping between each data source and the domain knowledge graph in the mapping set .
[0094] The forensic evidence module 4 includes:
[0095] A conversion sub-module, configured to convert the sub-forensics request into a request supported by the corresponding data source through the mapping set to obtain a conversion request;
[0096] A response sub-module, configured to respond to the conversion request on the corresponding data source according to the evidence extraction and analysis rules to obtain a set of sub-answers;
[0097] A fusion sub-module, configured to fuse a plurality of sets of sub-answers according to the segmentation method of the forensics request to obtain a set of answers;
[0098] An output sub-module, configured to obtain the response traceability information of each sub-answer set in each answer set, and convert the response traceability information and the answer set into a format corresponding to the domain knowledge graph to obtain a forensics set.
[0099] In some other embodiments of the present invention, the present invention provides the following technical solution. A computer includes a memory 102, a processor 101, and a computer program stored on the memory 102 and executable on the processor 101. When the processor 101 executes the computer program, the forensics method based on the virtual knowledge graph and big data as described above is implemented.
[0100] Specifically, the above-mentioned processor 101 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured as one or more integrated circuits for implementing the embodiments of the present invention.
[0101] Among them, the memory 102 may include a mass storage for data or instructions. By way of example and not limitation, the memory 102 may include a hard disk drive (HDD), a floppy disk drive, a solid state drive (SSD), a flash memory, an optical disc, a magneto-optical disc, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. In suitable cases, the memory 102 may include removable or non-removable (or fixed) media. In suitable cases, the memory 102 may be internal or external to the data processing device. In a particular embodiment, the memory 102 is non-volatile memory. In a particular embodiment, the memory 102 includes a read-only memory (ROM) and a random access memory (RAM). In suitable cases, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically alterable ROM (EAROM), or a flash memory, or a combination of two or more of these. In suitable cases, the RAM may be a static random-access memory (SRAM) or a dynamic random access memory (DRAM), where the DRAM may be a fast page mode dynamic random access memory (FPMDRAM), an extended data out dynamic random access memory (EDODRAM), a synchronous dynamic random-access memory (SDRAM), etc.
[0102] The memory 102 can be used to store or cache various data files required for processing and / or communication, as well as possible computer program instructions executed by the processor 101.
[0103] The processor 101 reads and executes the computer program instructions stored in the memory 102 to implement the above-mentioned forensics method based on the virtual knowledge graph and big data.
[0104] In some embodiments, the computer may further include a communication interface 103 and a bus 100. Among them, as Figure 3 shown, the processor 101, the memory 102, and the communication interface 103 are connected through the bus 100 and complete communication with each other.
[0105] The communication interface 103 is used to implement communication between various modules, devices, units, and / or devices in the embodiments of the present invention. The communication interface 103 can also implement data communication with other components such as external devices, image / data acquisition devices, databases, external storage, and image / data processing workstations.
[0106] Bus 100 includes hardware, software, or both, and couples components of a computer device to each other. Bus 100 includes, but is not limited to, at least one of the following: Data Bus, Address Bus, Control Bus, Expansion Bus, Local Bus. By way of example and not limitation, Bus 100 may include an Accelerated Graphics Port (AGP) or other graphics bus, an Extended Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a Memory Bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Bus (VLB) bus, or other suitable bus or a combination of two or more of these. In suitable cases, Bus 100 may include one or more buses. Although embodiments of the present invention describe and illustrate specific buses, the present invention contemplates any suitable bus or interconnect.
[0107] The computer may execute the forensic method based on a virtual knowledge graph and big data of the present invention based on a forensic system based on a virtual knowledge graph and big data obtained, thereby implementing forensic based on a virtual knowledge graph and big data.
[0108] In some further embodiments of the present invention, in combination with the above-mentioned forensic method based on a virtual knowledge graph and big data, embodiments of the present invention provide the following technical solution: a storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the above-mentioned forensic method based on a virtual knowledge graph and big data is implemented.
[0109] Those skilled in the art can understand that the logic and / or steps represented in the flowchart or described in other ways herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or in combination with these instruction execution systems, apparatuses, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in combination with an instruction execution system, apparatus, or device.
[0110] More specific examples (a non-exhaustive list) of the readable medium include the following: an electrical connection part (electronic device) having one or more wirings, a portable computer disk cartridge (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, the computer-readable medium can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpretation, or other suitable processing as necessary, and then stored in a computer memory.
[0111] It should be understood that various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application-specific integrated circuits having suitable combinational logic gate circuits, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0112] The technical features of the above-described embodiments can be combined arbitrarily. For the sake of brevity in description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as falling within the scope described in this specification.
[0113] The above-described embodiments merely represent several implementation manners of the present invention. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all fall within the protection scope of the present invention. Therefore, the protection scope of the present invention patent shall be subject to the appended claims.
Claims
1. A forensics method based on virtual knowledge graph and big data, characterized in that: include: Construct a domain knowledge graph in the field of forensics, obtain the data source involved in forensics and establish a mapping set between the domain knowledge graph and the data source; constructing evidence extraction and analysis rules based on the mapping set; Obtaining a forensic request issued by a user, and dividing the forensic request based on the domain knowledge graph to obtain a plurality of sub-forensic requests; Determine an answer set based on the plurality of sub-forensic requests, and convert the answer set into a format of a knowledge graph to obtain a forensic set; Among them, the mapping set for: ; ; In the formula, It is shaped like The set of mappings of Map the data in each data source to the domain knowledge graph. Indicates that for The query statement of a data source, Represents a class or attribute in a domain knowledge graph, Represents the conversion function, which describes how to convert data in the data source into entities or objects in the knowledge graph; The step of obtaining a forensic request issued by a user and dividing the forensic request based on the domain knowledge graph to obtain a plurality of sub-forensic requests includes: Get the evidence collection request issued by the user , rewrite the evidence collection request and encode the knowledge of the domain knowledge graph to obtain a rewritten request ; The rewrite request is mapped according to the mapping between each data source and the domain knowledge graph in the mapping set. Split into several sub-forensic requests ; The steps of constructing the domain knowledge graph in the field of forensics are specifically as follows: Constructing several prompt templates, continuously sending the prompt templates to the large language model, extracting semantic relations in the forensic domain, and iteratively repeating the prompt template sending and semantic relation extraction process to obtain a domain knowledge graph; The semantic relationship includes the semantic relationship between concepts in the field of forensics, the semantic relationship between attributes in the field of forensics, and the semantic relationship between concepts and attributes in the field of forensics; The step of constructing evidence extraction and analysis rules based on the mapping set is specifically as follows: Based on the vocabulary in the domain knowledge graph, the review and judgment rules of evidence described in natural language in legal documents are formalized to obtain evidence extraction and analysis rules: ; In the formula, Represents the antecedents or reasoning premises of evidence extraction and analysis rules, Represents the consequent or reasoning conclusion of the evidence extraction and analysis rules.
2. The forensics method based on virtual knowledge graph and big data according to claim 1 is characterized in that: The step of determining an answer set based on the plurality of sub-forensic requests and converting the answer set into a knowledge graph format to obtain a forensic set includes: Converting the sub-forensic request into a request supported by the corresponding data source through the mapping set to obtain a converted request; Responding to the conversion request on the corresponding data source according to the evidence extraction and analysis rules to obtain a sub-answer set; Merging a plurality of sub-answer sets according to the segmentation method of the evidence collection request to obtain an answer set; The answer tracing information of each of the sub-answer sets in each of the answer sets is obtained, and the answer tracing information and the answer set are converted into a format corresponding to the domain knowledge graph to obtain a forensics set.
3. A forensics system based on virtual knowledge graph and big data, the system adopts the forensics method based on virtual knowledge graph and big data as claimed in claim 1, characterized in that: The system comprises: A construction module is used to construct a domain knowledge graph in the field of forensics, obtain the data source involved in forensics and establish a mapping set between the domain knowledge graph and the data source; A rule module, used for constructing evidence extraction and analysis rules based on the mapping set; A segmentation module is used to obtain a forensic request issued by a user, and segment the forensic request based on the domain knowledge graph to obtain a plurality of sub-forensic requests; The forensics module is used to determine an answer set based on the plurality of forensics sub-requests, and convert the answer set into a format of a knowledge graph to obtain a forensics set.
4. A computer comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the forensics method based on virtual knowledge graph and big data as described in any one of claims 1 to 2 is implemented.
5. A storage medium, characterized in that: The storage medium stores a computer program, which, when executed by a processor, implements the forensics method based on virtual knowledge graph and big data as described in any one of claims 1 to 2.
Citation Information
Patent Citations
Network security domain knowledge graph construction method and device for dynamic threat analysis
CN110113314A
Evidence chain construction method and device based on non-structural data and storage medium
CN116502715A
Entity relationship extraction method based on large model and dynamic prompt
CN118779468A
Domain knowledge session method, system and device based on large model and multistage reasoning
CN118964538A