Artificial intelligence-based network security automatic warning method, device and electronic equipment
By acquiring and analyzing historical intrusion incident data and network situation data, and using deep learning technology for feature extraction and correlation analysis, the problem of passive response of existing network security defense mechanisms is solved, and timely early warning and effective response to potential threats is achieved.
Patent Information
- Application Number
- CN202411398482.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-09
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2044-10-09
AI Technical Summary
Most of the existing network security defense mechanisms are passive and cannot respond to rapidly changing network threats in a timely manner. They require an active automatic network security warning method.
By obtaining historical intrusion incident data, network security data sets and current network situation data, using deep learning technology for feature extraction and correlation analysis, and using classifiers to determine whether a network security warning is issued.
It realizes timely early warning of potential security threats, can make security decisions and response strategies more effectively, and improves network security situation awareness and response capabilities.
Smart Images

Figure CN119276575B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security, and more specifically, to an artificial intelligence-based network security automatic early warning method, device, and electronic device. Background Art
[0002] Cybersecurity is the practice and technology of protecting computer systems, networks, and their data from attack, damage, or unauthorized access. It involves a multifaceted strategy, including firewalls, encryption, authentication, and user education, to ensure the confidentiality, integrity, and availability of information. With the acceleration of digitalization, cybersecurity has become increasingly important, becoming a key factor in protecting personal privacy and business secrets.
[0003] In the field of network security, technologies for preventing, detecting, and responding to intrusions have received widespread attention. However, current defense mechanisms are passive and require waiting for an attack to occur before responding.
[0004] Therefore, an artificial intelligence-based automatic network security early warning method, device and electronic device are desired. Summary of the Invention
[0005] In order to solve the above technical problems, the present application is proposed. The embodiments of the present application provide an artificial intelligence-based automatic network security early warning method, device, and electronic device. The method first obtains historical intrusion event data, network security data sets, and current network situation data, then uses deep learning technology to perform feature extraction and correlation analysis on the three, and finally uses a classifier to determine whether to issue a network security early warning alarm, thereby determining potential security threats, issuing early warnings in a timely manner, and making more effective security decisions and response strategies.
[0006] According to one aspect of the present application, there is provided an artificial intelligence-based automatic network security early warning method, which includes:
[0007] Obtain historical intrusion event data, network security datasets, and current network situation data;
[0008] Extracting a network security multimodal information association feature vector and a current network situation text semantic feature vector from the historical intrusion event data, the network security dataset, and the current network situation data;
[0009] Based on the network security multimodal information association feature vector and the current network situation text semantic feature vector, it is determined whether to issue a network security early warning alert.
[0010] According to another aspect of the present application, there is provided an artificial intelligence-based network security automatic early warning device, comprising:
[0011] Network security data acquisition module, used to obtain historical intrusion event data, network security data sets and current network situation data;
[0012] A network security data processing module is used to extract network security multimodal information association feature vectors and current network situation text semantic feature vectors from the historical intrusion event data, the network security data set and the current network situation data;
[0013] The network security early warning alarm judgment module is used to judge whether to issue a network security early warning alarm based on the network security multimodal information association feature vector and the current network situation text semantic feature vector.
[0014] According to another aspect of the present application, an electronic device is provided, comprising: a processor; and a memory, wherein computer program instructions are stored in the memory, and when the computer program instructions are executed by the processor, the processor executes the above-mentioned artificial intelligence-based automatic network security early warning device.
[0015] Compared with the existing technology, the present application provides an artificial intelligence-based automatic network security early warning method, device and electronic equipment, which first obtains historical intrusion event data, network security data set and current network situation data, and then uses deep learning technology to perform feature extraction and correlation analysis on the three. Finally, a classifier is used to determine whether to issue a network security early warning alarm, thereby judging potential security threats, issuing early warnings in a timely manner, and making more effective security decisions and response strategies. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] The above and other purposes, features, and advantages of the present application will become more apparent through a more detailed description of the embodiments of the present application in conjunction with the accompanying drawings. The accompanying drawings are intended to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present application and do not constitute a limitation of the present application. In the drawings, the same reference numerals generally represent the same components or steps.
[0017] Figure 1 This is a flowchart of an artificial intelligence-based automatic network security early warning method according to an embodiment of the present application.
[0018] Figure 2 The present invention provides a flowchart for extracting features from the historical intrusion event data to obtain a global feature vector of the historical intrusion event in an artificial intelligence-based automatic network security early warning method according to an embodiment of the present application.
[0019] Figure 3The present invention provides a flowchart for extracting features from the network security data set to obtain a network security data text understanding feature vector in an artificial intelligence-based network security automatic early warning method according to an embodiment of the present application.
[0020] Figure 4 The present invention provides a flowchart for extracting features from the current network situation data to obtain the semantic feature vector of the current network situation text in the artificial intelligence-based automatic network security warning method according to an embodiment of the present application.
[0021] Figure 5 This is a block diagram of an artificial intelligence-based automatic network security early warning device according to an embodiment of the present application. DETAILED DESCRIPTION
[0022] Below, the exemplary embodiments according to the present application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application, and it should be understood that the present application is not limited to the exemplary embodiments described herein.
[0023] Figure 1 Flowchart of the network security automatic warning method based on artificial intelligence according to the embodiment of the present application. Figure 1 As shown, according to the embodiment of the present application, the artificial intelligence-based automatic network security early warning method includes: S110, obtaining historical intrusion event data, network security data sets and current network situation data; S120, extracting network security multimodal information association feature vectors and current network situation text semantic feature vectors from the historical intrusion event data, the network security data sets and the current network situation data; S130, judging whether to issue a network security early warning alarm based on the network security multimodal information association feature vectors and the current network situation text semantic feature vectors.
[0024] In the above-mentioned AI-based automatic network security early warning method, step S110 obtains historical intrusion event data, a network security dataset, and current network status data. It should be understood that network security aims to protect computer systems, networks, and their data from attack, damage, or unauthorized access. It covers a variety of strategies and technical means, including firewalls, encryption measures, identity authentication, and user training, with the goal of maintaining the confidentiality, integrity, and availability of information. With the acceleration of digital transformation, the importance of network security has become increasingly prominent, becoming a key guarantee for protecting personal privacy and corporate secrets. In the field of network security, technologies for preventing, detecting, and responding to intrusions have received widespread attention. However, most current defense mechanisms are passive and require response only after an attack occurs. This is not timely and effective when responding to rapidly evolving network threats. Therefore, in the technical solution of this application, historical intrusion event data, a network security dataset, and current network status data are obtained, and combined with deep learning technology, potential security threats are assessed to determine whether to issue a network security early warning alert, so that alerts can be issued in a timely manner, thereby formulating more effective security decisions and response strategies.
[0025] Specifically, historical intrusion event data provides a detailed record of past cyberattacks, including information such as attacker behavior patterns, attack methods, and vulnerabilities of victim systems. This data helps security experts analyze and understand the evolution of attacks, identifying common tactics used by attackers and the weaknesses they target. Cybersecurity datasets typically include various malware samples, phishing websites, vulnerability information, and user behavior data. These datasets are not only useful for developing and testing security tools, but also help researchers evaluate the effectiveness of different security strategies. Current network situation data reflects the real-time state of network security, including detected attack activity, network traffic anomalies, and vulnerability exploitation. The real-time and dynamic nature of this data enables security teams to quickly identify and respond to potential cyber threats. By combining historical data, cybersecurity datasets, and current network situation data, organizations can develop a comprehensive security situational awareness system. This system not only strengthens prevention against known threats but also enhances adaptability to new attacks.
[0026] In the above-mentioned artificial intelligence-based automatic network security early warning method, step S120 extracts network security multimodal information association feature vectors and current network situation text semantic feature vectors from the historical intrusion event data, the network security dataset, and the current network situation data. It should be understood that extracting multimodal information association feature vectors and text semantic feature vectors from historical intrusion event data, the network security dataset, and the current network situation data helps to achieve more intelligent network security protection. This comprehensive analysis can not only provide more comprehensive situational awareness, but also provide rich training data for machine learning models, improving the model's predictive ability and response speed. By continuously optimizing the extraction and application of these feature vectors, organizations can continuously improve their network security situation perception and response capabilities, and effectively respond to complex and changing network security threats.
[0027] In a specific embodiment of the present application, step S120 includes: performing feature extraction on the historical intrusion event data to obtain a global feature vector of the historical intrusion event; performing feature extraction on the network security data set to obtain a network security data text understanding feature vector; associating the historical intrusion event global feature vector and the network security data text understanding feature vector to obtain the network security multimodal information association feature vector; performing feature extraction on the current network situation data to obtain the current network situation text semantic feature vector.
[0028] It's understandable that historical intrusion event data contains a wealth of attack information, including attacker behavior, tools used, attack vectors, victim system vulnerabilities, and ultimate impact. By extracting features from this data, we can extract a series of representative characteristics, such as attack type (e.g., phishing, denial of service attacks), attack duration, attack frequency, and impact range. These characteristics can be combined to form a global feature vector that reflects the overall characteristics and trends of past attacks, providing a foundation for subsequent analysis and decision-making.
[0029] Furthermore, network security datasets typically contain large amounts of unstructured text information, such as security reports, intrusion detection logs, malware descriptions, network traffic logs, and security advisories. These texts contain a wealth of information about security incidents, but due to their diverse forms and large size, manual processing is inefficient. Feature extraction can transform this text data into feature vectors, enabling them to be effectively utilized in machine learning or data analysis models. The process of extracting text understanding feature vectors involves extracting key words, phrases, and topics from this unstructured data, as well as modeling semantic relationships, enabling machines to understand and process this information. Feature extraction simplifies and summarizes large amounts of information. Text understanding feature vectors can help security systems identify key security threat signals from complex information and screen out important events or patterns.
[0030] Furthermore, the global feature vector of historical intrusion events provides structured information about past attack behaviors, including attack types, patterns, affected systems, and their vulnerabilities. Meanwhile, the network security data text understanding feature vector extracts crucial security event information from large amounts of unstructured text, such as attack descriptions, contextual context, and relevant security reports. By correlating these two feature vectors, the information complements and enhances each other. This combination not only enables the model to learn richer features but also helps it respond more quickly to new attacks based on historical patterns and current context.
[0031] In particular, current network situation data often contains a wealth of unstructured text information, such as security reports, log files, social media discussions, online announcements, and user feedback. This text information not only reflects the real-time dynamics of the network environment but also contains contextual information related to security incidents. Through feature extraction, this unstructured text can be converted into structured semantic feature vectors, enabling computers to more effectively process and analyze this data. Specifically, through natural language processing (NLP) technology, keywords, phrases, and topics in the text can be extracted to reveal important information such as potential attack activities, affected systems, and attackers' intentions. This information helps security experts more quickly understand the potential risks in the current network environment and respond in a timely manner.
[0032] Figure 2 The flowchart of the method for automatic network security early warning based on artificial intelligence according to the embodiment of the present application is to extract the features of the historical intrusion event data to obtain the global feature vector of the historical intrusion event. Figure 2As shown, in a specific embodiment of the present application, feature extraction is performed on the historical intrusion event data to obtain a global feature vector of the historical intrusion event, including: S210, resampling the historical intrusion event data to obtain historical intrusion event resampled data; S220, passing the historical intrusion event resampled data through a historical intrusion event resampled data generator based on a generative adversarial network to obtain historical intrusion event balanced text data; S230, passing the historical intrusion event balanced text data through a historical intrusion event balanced text context semantic encoder to obtain the global feature vector of the historical intrusion event.
[0033] It's understandable that historical intrusion event data may be imbalanced. Specifically, many types of network attacks occur infrequently, resulting in an imbalance in the ratio of positive and negative samples in the dataset. If raw data were used directly for analysis, the model might tend to learn more frequent attack patterns while neglecting rare but equally important attack types. Resampling can balance the number of different event types, enhancing the model's ability to identify various attack types. For example, oversampling can increase the number of minority class samples, while undersampling can reduce the number of majority class samples, thereby achieving data balance. Specifically, the network security environment is dynamic, and attack patterns and characteristics can vary significantly over time. Resampling allows us to select specific time windows from historical data to capture the characteristics and patterns of a specific period. This approach makes the dataset more timely and representative, helping to capture the true state of current network threats.
[0034] Furthermore, although the use of resampling technology can balance the data to a certain extent, it sometimes causes loss or duplication of information, making it difficult to fully capture the characteristics of minority class events. In the technical solution of the present application, the generative adversarial network is trained through two competing networks (generator and discriminator). The generator is responsible for generating new samples similar to the training data, while the discriminator is responsible for judging whether the sample is real data or generated data. Through this adversarial process, the generator continuously optimizes the samples it generates, so that the generated data is closer to the real attack events in terms of characteristics. This method can not only generate text data, but also introduce rich semantic features into the text, making the generated data more authentic and effective. In this way, the method based on the adversarial generative network can effectively increase the number of minority class samples by generating new data instances, thereby improving this imbalance problem.
[0035] Furthermore, after processing balanced text data of historical intrusion events using a generative adversarial network (GAN), it has achieved good diversity and representativeness. However, this text data is often unstructured, making it difficult to extract useful information from direct analysis. Therefore, using a contextual semantic encoder can transform this unstructured text data into structured feature vectors, enabling the model to understand and process the semantic information contained therein. Contextual semantic encoders (such as those based on the Transformer architecture) have a powerful ability to capture contextual relationships and deep semantic features in text. By encoding balanced text data, the model can identify the relationships between different events and the characteristics of various attack patterns. This capability enables the encoder to not only understand individual events but also take into account the correlations between events to generate a global feature vector. Specifically, the historical invasion event balanced text data is segmented to obtain a historical invasion word sequence; the embedding layer of the historical invasion event balanced text context semantic encoder is used to map each historical invasion word in the historical invasion word sequence into a word embedding vector to obtain a sequence of historical invasion word embedding vectors; the converter-based Bert model of the historical invasion event balanced text context semantic encoder is used to perform global context semantic encoding on the sequence of historical invasion word embedding vectors to obtain multiple historical invasion feature vectors; and the multiple historical invasion feature vectors are cascaded to obtain the global feature vector of the historical invasion event.
[0036] Figure 3 The flowchart of the network security data set is used to extract features in the network security automatic warning method based on artificial intelligence according to the embodiment of the present application to obtain the network security data text understanding feature vector. Figure 3 As shown, in a specific embodiment of the present application, feature extraction is performed on the network security data set to obtain a network security data text understanding feature vector, including: S310, word segmentation is performed on the network security data set and a network security data item embedding encoder is used to obtain a sequence of network security data item embedding vectors; S320, the sequence of network security data item embedding vectors is passed through a network security data item multi-scale neighborhood feature extraction module to obtain the network security data text understanding feature vector.
[0037] It's understandable that cybersecurity datasets often contain large amounts of unstructured data, such as log files, attack descriptions, and user behavior records. This data is diverse and complex, making it difficult to extract useful information directly from analysis. Therefore, word segmentation is necessary. Word segmentation breaks text data into meaningful units (such as words and phrases), making subsequent processing more efficient and accurate. Word segmentation provides a clearer understanding of the data's main content and structure. The word-segmented data requires further processing using a cybersecurity data item embedding encoder. The embedding encoder converts the word-segmented text into a low-dimensional, dense vector. This vectorized representation not only captures the semantic information of individual data items but also takes into account their contextual relationships within the entire dataset. For example, in attack logs, the same word may have different meanings in different contexts. The embedding encoder can learn these subtle nuances through training, generating more accurate vector representations. The serialization of the embedding vectors also enables the model to leverage sequential data for time series analysis, thereby improving the ability to identify and predict attack behavior.
[0038] Furthermore, the embedding vector of a cybersecurity data item is essentially a high-dimensional, dense representation of the raw data, effectively capturing the semantic features of the text. However, feature extraction at a single scale may not fully reflect the complex relationships and subtle differences in the data. For example, in attack logs, some attack patterns may appear very similar in a local context, but have significantly different characteristics in a global context. The multi-scale neighborhood feature extraction module simultaneously considers information at different scales, enabling the model to comprehensively consider local and global features, thereby achieving a more comprehensive understanding of the text content. The multi-scale feature extraction module processes the embedding vector using different convolution kernels or filters to extract information at different levels. For example, small-scale features may focus on subtle relationships between words, while large-scale features can identify patterns at the sentence or paragraph level. This hierarchical feature extraction method can enhance the depth of understanding of cybersecurity data and enable the model to identify complex attack patterns. Specifically, the network security data item multi-scale neighborhood feature extraction module includes: a first convolutional layer, a second convolutional layer running in parallel with the first convolutional layer, and a cascade layer connected to the first and second convolutional layers, wherein the first convolutional layer uses a one-dimensional convolution kernel of a first scale, and the second convolutional layer uses a one-dimensional convolution kernel of a second scale. More specifically, the first convolutional layer of the network security data item multi-scale neighborhood feature extraction module performs one-dimensional convolution encoding on the input data to obtain a first-scale feature vector; the second convolutional layer of the network security data item multi-scale neighborhood feature extraction module performs one-dimensional convolution encoding on the input data to obtain a second-scale feature vector; and the first-scale feature vector and the second-scale feature vector are cascaded to obtain the network security data text comprehension feature vector.
[0039] In a specific embodiment of the present application, associating the historical intrusion event global feature vector and the network security data text understanding feature vector to obtain the network security multimodal information association feature vector includes: obtaining the historical intrusion event global feature vector and the network security data text understanding feature vector in array form; serializing the historical intrusion event global feature vector and the network security data text understanding feature vector into byte streams respectively, and saving them to a file; using the ObjectInputStream mechanism to read the serialized historical intrusion event global feature vector and the serialized network security data text understanding feature vector from the file; after reading the serialized historical intrusion event global feature vector and the serialized network security data text understanding feature vector, calculating the product of the historical intrusion event global feature vector and the network security data text understanding feature vector to obtain the network security multimodal information association feature vector; serializing the calculated network security multimodal information association feature vector and saving it to a file.
[0040] As you can understand, ObjectInputStream is a class in the Java standard library used to read objects from an input stream. It works in conjunction with ObjectOutputStream to serialize and deserialize objects. The main advantage of ObjectInputStream is its ability to efficiently read complex data structures such as objects, arrays, and collections, and automatically handle object references to ensure data integrity and consistency. Furthermore, ObjectInputStream supports custom serialization logic, allowing developers to perform additional processing when reading objects, thereby increasing code flexibility and scalability.
[0041] Part of the deployment code is shown below.
[0042]
[0043]
[0044] Thus, a method for calculating network security multimodal information correlation feature vectors was implemented. This method primarily uses Java's serialization mechanisms (ObjectInputStream and ObjectOutputStream) to handle the reading and saving of feature vectors. This process involves data preparation, serializing feature vectors, reading serialized data, calculating products, and saving the results. Specifically, the global feature vectors of historical intrusion events and the network security data text comprehension feature vectors are obtained in array form, serialized into byte streams, and saved to a file. The feature vectors are then serialized into a byte stream using ObjectOutputStream and saved to a file. The serialized feature vectors are then read from the file using ObjectInputStream. This step ensures that the feature vectors can be transferred and shared between different systems or processes. Furthermore, by traversing the two feature vectors and calculating their element-by-element product, a new network security multimodal information correlation feature vector is obtained. This step is the core of the entire method and ensures the effective fusion of feature vectors. Finally, the calculated multimodal information correlation feature vectors are serialized and saved to a file for subsequent use. This step ensures the persistent storage of the calculation results.
[0045] In this way, the automatic calculation and storage of network security multimodal information correlation feature vectors are achieved. By using Java's serialization mechanism, the code can efficiently process large-scale feature vector data and ensure data integrity and consistency. Through the serialization and deserialization mechanism, the code can efficiently read and save feature vectors, reducing the overhead of data transmission and storage. The code achieves effective fusion of different feature vectors through element-by-element multiplication. This feature is particularly important in practical applications, especially when large amounts of data need to be stored and analyzed for a long time. The code has a clear structure and simple logic, making it easy to expand and maintain. For example, the robustness of the code can be improved by adding exception handling logic, or the computing efficiency can be improved by optimizing the calculation logic. Through Java's serialization mechanism, the automatic calculation and storage of network security multimodal information correlation feature vectors are achieved, which has the advantages of high efficiency, flexibility, and persistence, providing strong technical support for network security analysis.
[0046] Figure 4 The flowchart of the method for automatic network security warning based on artificial intelligence according to the embodiment of the present application is to extract the features of the current network situation data to obtain the semantic feature vector of the current network situation text. Figure 4 As shown, in a specific embodiment of the present application, feature extraction is performed on the current network situation data to obtain the current network situation text semantic feature vector, including: S410, passing the current network situation data through a converter-based current network situation data semantic encoder to obtain multiple current network situation text feature vectors; S420, splicing the multiple current network situation text feature vectors to obtain the current network situation text semantic feature vector.
[0047] It should be understood that network situation data is typically unstructured text and contains rich semantic information. Traditional feature extraction methods often require manual feature design, which is not only time-consuming but also prone to missing important information. Transformer-based encoders can automatically extract features, adapt to various forms of text data, and ensure that key information is effectively captured. Among them, transformer-based models (such as BERT, GPT, etc.) have powerful contextual understanding capabilities. Through the self-attention mechanism, the transformer architecture can effectively capture the relationship between words in the data, thereby better understanding the overall semantics of the text. In network situation data, the contextual relationships between different data items (such as log information, alerts, etc.) are often complex and diverse. Using transformers can more comprehensively extract key information and obtain accurate text feature vectors. Specifically, the embedding layer of the transformer-based current network situation data semantic encoder is used to convert the current network situation data into an embedding vector to obtain a sequence of network situation embedding vectors; and the transformer-based BERT model of the transformer-based current network situation data semantic encoder is used to perform global contextual semantic encoding on the sequence of network situation embedding vectors to obtain multiple current network situation text feature vectors.
[0048] Furthermore, transformer-based models (such as BERT and GPT) possess powerful contextual understanding capabilities. Through the self-attention mechanism, the transformer architecture can effectively capture the relationships between words in the data, thereby better understanding the overall semantics of the text. In network situational data, the contextual relationships between different data items (such as log information and alerts) are often complex and diverse. Using transformers can more comprehensively extract key information and obtain accurate text feature vectors.
[0049] In the aforementioned AI-based automatic network security early warning method, step S130 determines whether to issue a network security early warning alert based on the network security multimodal information correlation feature vector and the current network situation text semantic feature vector. It should be understood that the network security multimodal information correlation feature vector represents information from different data sources and types, including but not limited to network traffic, system logs, user behavior, and external threat intelligence. By integrating this multimodal information, the security system can obtain a more comprehensive view of the network situation. Each type of information provides a unique perspective. On the other hand, the current network situation text semantic feature vector focuses on analyzing and understanding the semantic information implicit in the network situation data. Using natural language processing technology, feature vectors extracted from security events, alerts, and logs can identify potential threat patterns and attack characteristics. When these two feature vectors are combined, the system can perform a deeper level of correlation analysis. This enables more accurate threat identification and response, thereby enhancing overall network security protection.
[0050] In a specific embodiment of the present application, step S130 includes: fusing the network security multimodal information association feature vector and the current network situation text semantic feature vector to obtain a warning alarm judgment classification feature vector; performing entropy degradation maximization optimization based on wandering pattern simulation on the warning alarm judgment classification feature vector to obtain a sparse optimized warning alarm judgment classification feature vector; passing the sparse optimized warning alarm judgment classification feature vector through a classifier to obtain a classification result, and the classification result is used to determine whether to issue a network security warning alarm.
[0051] It should be understood that fusing these two feature vectors can form a deeper and richer semantic representation in the classification feature vector. This fusion allows the system to more effectively leverage the advantages of multiple data sources, thereby improving the detection capabilities of network threats.
[0052] In particular, in the technical solutions of this application, the early warning alarm judgment classification feature vector is typically generated through multiple steps, including feature extraction from historical intrusion events, feature extraction from network security data text understanding, and fusion of current network situation features. These features carry a large amount of contextual information and semantic associations. Therefore, when the dimension of the early warning alarm judgment classification feature vector is high, it may contain some highly correlated or duplicate features. The classifier may over-rely on these redundant features during training, resulting in ineffective feature reinforcement during learning and reduced model generalization. In this case, even if there is valid information in the early warning alarm judgment classification feature vector, the model may confuse it with redundant information, making it difficult for the classifier to make accurate judgments. Furthermore, when features from different sources are fused, the semantic associations between features may interfere. In particular, when features come from different datasets, the scale, distribution, and meaning of the features may vary significantly, resulting in the classifier being unable to correctly identify which features are truly important during learning. In this case, the model may learn some noise or irrelevant features while ignoring the core discriminative features, resulting in overfitting in practical applications, and thus incorrectly identifying some features as important, affecting the accuracy of network security early warning alarms. Therefore, in the technical solution of the present application, the early warning alarm judgment classification feature vector is subjected to entropy degradation maximization optimization based on walk pattern simulation to obtain a sparse optimized early warning alarm judgment classification feature vector.
[0053] Among them, the early warning alarm judgment classification feature vector is subjected to entropy degradation maximization optimization based on walk pattern simulation to obtain a sparse optimized early warning alarm judgment classification feature vector, including: extracting each row vector of the learning parameter matrix in the classifier as a set of intrusion warning learning parameter row vectors; calculating the intrusion warning entropy degradation maximization simulation value between the early warning alarm judgment classification feature vector and each intrusion warning learning parameter row vector in the set of intrusion warning learning parameter row vectors to obtain a set of intrusion warning entropy degradation maximization simulation values; based on the comparison between each intrusion warning entropy degradation maximization simulation value in the set of intrusion warning entropy degradation maximization simulation values and a preset threshold, the learning parameter matrix is gated and pruned to obtain an intrusion warning learning parameter entropy degradation optimization matrix; the early warning alarm judgment classification feature vector is matrix multiplied with the intrusion warning learning parameter entropy degradation optimization matrix to obtain the sparse optimized early warning alarm judgment classification feature vector.
[0054] The optimization steps are specifically expressed as follows:
[0055] P={p1,p2,...,p i ,...,p n}
[0056]
[0057] w i =mask(D i )
[0058]
[0059] P s ={w1·p1,w2·p2,...,w i ·p i ,...,w n ·p n}
[0060]
[0061] Among them, P is the set of row vectors of intrusion warning learning parameters, {…} is a set operation, p1, p2, p i 、p n are the eigenvalues of the first, second, i-th, and n-th intrusion warning learning parameter row vectors in the set of intrusion warning learning parameter row vectors, respectively. i is the ith intrusion warning entropy degradation maximization simulation value in the set of intrusion warning entropy degradation maximization simulation values, max is the maximum value function, D(v1,p i ) represents the calculation vector v1 and p iThe Euclidean distance between them, v1 is the early warning alarm judgment classification feature vector, p i T is the transposed vector of the row vector of the i-th intrusion warning learning parameter, L is the length of the feature vector, is matrix multiplication, w1, w2, w i 、w n are the first, second, i-th, and n-th learning parameter mask values, respectively. Mask is the mask operation, θ represents the preset threshold, and P s is the entropy degradation optimization matrix of intrusion warning learning parameters, and v1' is the sparse optimization warning alarm judgment classification feature vector.
[0062] In the technical solution of the present application, it is taken into account that in the process of inputting the warning alarm judgment classification feature vector into the learning parameter matrix of the classifier to obtain the classification result of whether to issue a network security warning alarm, there is a mismatch between the structure of the learning parameter matrix itself and the warning alarm judgment classification feature vector, that is, the learning parameter matrix has structural redundancy and information confusion relative to the warning alarm judgment classification feature vector, which may cause feature redundancy or noise in the classification result of whether to issue a network security warning alarm, resulting in model overfitting.
[0063] Based on this, in the technical solution of the present application, the entropy degradation maximization optimization based on the walk pattern simulation is performed on the early warning alarm judgment classification feature vector, which uses the early warning alarm judgment classification feature vector as the walk node, and uses the characteristic distribution between the early warning alarm judgment classification feature vector and each row vector in the learning parameter matrix to simulate the walk pattern, and uses the distance topology between the early warning alarm judgment classification feature vector and each row vector in the learning parameter matrix as the walk map. In this way, the walk result of the specific walk pattern of the walk node on the walk map is used to obtain the intrusion warning entropy degradation maximization simulation value. Furthermore, based on the comparison between each intrusion warning entropy degradation maximization simulation value in the set of the intrusion warning entropy degradation maximization simulation value and the preset threshold, the part of the learning parameter matrix that does not significantly contribute to the input data representation and may even introduce noise or redundant information is screened out. Specifically, based on the comparison result, the learning parameter matrix is gated and pruned to obtain the intrusion warning learning parameter entropy degradation optimization matrix. Finally, the structurally optimized learning parameter matrix is used as a feature modulation unit to perform linear modulation on the early warning alarm judgment classification feature vector to obtain the sparse optimized early warning alarm judgment classification feature vector.
[0064] Furthermore, by learning from a large amount of historical data, the classifier can establish a relationship model between features and attack types, thereby accurately classifying the input sparse optimized early warning alert judgment classification feature vector. The classification results may include multiple categories, such as normal or attack. Using the classification results to determine whether to issue a network security early warning alert is crucial. When the classifier identifies potential attack behavior or abnormal activity, the system can respond promptly and issue an alert. This real-time early warning mechanism helps network security teams quickly identify and address security incidents, thereby minimizing potential losses.
[0065] In summary, the embodiment of the present application first obtains historical intrusion event data, network security data sets and current network situation data, and then uses deep learning technology to perform feature extraction and correlation analysis on the three. Finally, a classifier is used to determine whether to issue a network security early warning alarm, thereby judging potential security threats, issuing early warnings in a timely manner, and making more effective security decisions and response strategies.
[0066] Figure 5 FIG is a block diagram of an artificial intelligence-based automatic network security early warning device according to an embodiment of the present application. Figure 5 As shown, according to an embodiment of the present application, an artificial intelligence-based automatic network security early warning device 100 includes: S110, a network security data acquisition module 110, used to obtain historical intrusion event data, a network security data set and current network situation data; a network security data processing module 120, used to extract network security multimodal information association feature vectors and current network situation text semantic feature vectors from the historical intrusion event data, the network security data set and the current network situation data; a network security early warning alarm judgment module 130, used to judge whether to issue a network security early warning alarm based on the network security multimodal information association feature vectors and the current network situation text semantic feature vectors.
[0067] Here, those skilled in the art will understand that the specific operations of each step in the above-mentioned artificial intelligence-based network security automatic early warning device have been referred to above. Figures 1 to 4 The invention has been introduced in detail in the description of the artificial intelligence-based network security automatic early warning method, and therefore, its repeated description will be omitted.
[0068] As described above, the artificial intelligence-based automatic network security early warning device 100 according to the embodiment of the present application can be implemented in various terminal devices. In one example, the artificial intelligence-based automatic network security early warning device 100 can be integrated into the terminal device as a software module and / or hardware module. For example, the artificial intelligence-based automatic network security early warning device 100 can be a software module in the operating system of the terminal device, or can be an application developed for the terminal device; of course, the artificial intelligence-based automatic network security early warning device 100 can also be one of the many hardware modules of the terminal device.
[0069] Alternatively, in another example, the artificial intelligence-based automatic network security early warning device 100 and the terminal device may also be separate devices, and the artificial intelligence-based automatic network security early warning device 100 may be connected to the terminal device via a wired and / or wireless network and transmit interactive information in accordance with an agreed data format.
[0070] The various methods / implementations described in this specification may be used individually or in combination, and may be switched during execution. Furthermore, the processing steps, sequences, flow charts, and the like of the various methods / implementations described in this specification may be reordered as long as there is no conflict. For example, various step units described in this specification are presented in an exemplary order and are not limited to the specific order presented.
[0071] The phrase "based on" used in this specification does not mean "only based on" unless otherwise specified. In other words, the phrase "based on" means both "only based on" and "at least based on."
[0072] Any reference to a unit using a designation such as "first," "second," etc., in this specification does not necessarily limit the number or order of these units. These designations may be used in this specification as a convenient method of distinguishing two or more units. Thus, a reference to a first unit and a second unit does not mean that only two units may be used or that the first unit must precede the second unit in some manner.
[0073] When the terms "including," "comprising," and their variations are used in this specification or claims, these terms are open ended, just like the term "having." Furthermore, the term "or" used in this specification or claims does not mean exclusive or.
[0074] It will be appreciated by those skilled in the art that various aspects of the present application may be illustrated and described by a number of patentable categories or situations, including any new and useful process, machine, product or combination of substances, or any new and useful improvements thereto. Accordingly, various aspects of the present application may be performed entirely by hardware, entirely by software (including firmware, resident software, microcode, etc.), or by a combination of hardware and software. The above hardware or software may be referred to as "data blocks," "modules," "engines," "units," "components," or "systems." In addition, various aspects of the present application may be represented by a computer product located in one or more computer-readable media, the product including computer-readable program code.
[0075] It will be appreciated by those skilled in the art that various aspects of the present application may be illustrated and described by a number of patentable categories or situations, including any new and useful process, machine, product or combination of substances, or any new and useful improvements thereto. Accordingly, various aspects of the present application may be performed entirely by hardware, entirely by software (including firmware, resident software, microcode, etc.), or by a combination of hardware and software. The above hardware or software may be referred to as "data blocks," "modules," "engines," "units," "components," or "systems." In addition, various aspects of the present application may be represented by a computer product located in one or more computer-readable media, the product including computer-readable program code.
[0076] Unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs. It should also be understood that terms such as those defined in common dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and should not be interpreted in an idealized or highly formal sense, unless explicitly defined as such herein.
[0077] While the present invention has been described in detail above, it will be apparent to those skilled in the art that the present invention is not limited to the embodiments described in this specification. The present invention may be implemented in various modifications and variations without departing from the spirit and scope of the present invention as defined by the claims. Therefore, the description in this specification is for illustrative purposes only and is not intended to limit the present invention in any way.
Claims
1. An artificial intelligence-based network security automatic early warning method, characterized in that: include: Obtain historical intrusion event data, network security datasets, and current network situation data; Extracting a network security multimodal information association feature vector and a current network situation text semantic feature vector from the historical intrusion event data, the network security dataset, and the current network situation data; Determining whether to issue a network security early warning alert based on the network security multimodal information association feature vector and the current network situation text semantic feature vector; The step of determining whether to issue a network security early warning alert based on the network security multimodal information association feature vector and the current network situation text semantic feature vector includes: Fusing the network security multimodal information association feature vector and the current network situation text semantic feature vector to obtain a warning alarm judgment classification feature vector; Performing entropy degradation maximization optimization based on walk pattern simulation on the early warning alarm judgment classification feature vector to obtain a sparse optimized early warning alarm judgment classification feature vector; The sparse optimized early warning alarm judgment classification feature vector is passed through a classifier to obtain a classification result, and the classification result is used to determine whether to issue a network security early warning alarm.
2. The method for automatic network security early warning based on artificial intelligence according to claim 1 is characterized in that: Extracting a network security multimodal information association feature vector and a current network situation text semantic feature vector from the historical intrusion event data, the network security dataset, and the current network situation data includes: Performing feature extraction on the historical intrusion event data to obtain a global feature vector of the historical intrusion event; Performing feature extraction on the network security data set to obtain a network security data text understanding feature vector; Associating the historical intrusion event global feature vector with the network security data text understanding feature vector to obtain the network security multimodal information association feature vector; Feature extraction is performed on the current network situation data to obtain a semantic feature vector of the current network situation text.
3. The method for automatic network security early warning based on artificial intelligence according to claim 2 is characterized in that: Performing feature extraction on the historical intrusion event data to obtain a global feature vector of the historical intrusion event includes: Resampling the historical intrusion event data to obtain historical intrusion event resampled data; The historical intrusion event resampled data is passed through a historical intrusion event resampled data generator based on a generative adversarial network to obtain historical intrusion event balanced text data; The historical invasion event balanced text data is passed through a historical invasion event balanced text context semantic encoder to obtain the historical invasion event global feature vector.
4. The method for automatic network security early warning based on artificial intelligence according to claim 3 is characterized in that: Performing feature extraction on the cybersecurity data set to obtain a cybersecurity data text understanding feature vector includes: Segmenting the cybersecurity dataset and passing it through a cybersecurity data item embedding encoder to obtain a sequence of cybersecurity data item embedding vectors; The sequence of network security data item embedding vectors is passed through a network security data item multi-scale neighborhood feature extraction module to obtain the network security data text understanding feature vector.
5. The method for automatic network security early warning based on artificial intelligence according to claim 4 is characterized in that: Associating the historical intrusion event global feature vector with the network security data text understanding feature vector to obtain the network security multimodal information association feature vector includes: Obtain the global feature vector of historical intrusion events and the feature vector of network security data text understanding in array form; Serializing the historical intrusion event global feature vector and the network security data text understanding feature vector into byte streams respectively, and saving them into files; Use the ObjectInputStream mechanism to read serialized historical intrusion event global feature vectors and serialized network security data text understanding feature vectors from files; After reading the serialized global feature vector of historical intrusion events and the serialized network security data text understanding feature vector, calculating the product of the global feature vector of historical intrusion events and the network security data text understanding feature vector to obtain a network security multimodal information association feature vector; The calculated network security multimodal information correlation feature vector is serialized and saved to a file.
6. The method for automatic network security early warning based on artificial intelligence according to claim 5 is characterized in that: Performing feature extraction on the current network situation data to obtain the current network situation text semantic feature vector includes: Passing the current network situation data through a current network situation data semantic encoder based on a converter to obtain a plurality of current network situation text feature vectors; The multiple current network situation text feature vectors are spliced to obtain the current network situation text semantic feature vector.
7. The method for automatic network security warning based on artificial intelligence according to claim 6 is characterized in that: The early warning alarm judgment classification feature vector is optimized by entropy degradation maximization based on walk pattern simulation to obtain a sparse optimized early warning alarm judgment classification feature vector, including: Extracting each row vector of the learning parameter matrix in the classifier as a set of intrusion warning learning parameter row vectors; Calculating an intrusion warning entropy degradation maximization simulation value between the early warning alarm judgment classification feature vector and each intrusion warning learning parameter row vector in the set of intrusion warning learning parameter row vectors to obtain a set of intrusion warning entropy degradation maximization simulation values; Based on the comparison between each intrusion warning entropy degradation maximization simulation value in the set of intrusion warning entropy degradation maximization simulation values and a preset threshold, the learning parameter matrix is gated and pruned to obtain an intrusion warning learning parameter entropy degradation optimization matrix; The early warning alarm judgment classification feature vector is matrix multiplied by the intrusion warning learning parameter entropy degradation optimization matrix to obtain the sparse optimized early warning alarm judgment classification feature vector.
8. An artificial intelligence-based network security automatic early warning device, characterized in that: include: Network security data acquisition module, used to obtain historical intrusion event data, network security data sets and current network situation data; A network security data processing module is used to extract network security multimodal information association feature vectors and current network situation text semantic feature vectors from the historical intrusion event data, the network security data set and the current network situation data; A network security early warning alarm judgment module is used to judge whether to issue a network security early warning alarm based on the network security multimodal information association feature vector and the current network situation text semantic feature vector; The step of determining whether to issue a network security early warning alert based on the network security multimodal information association feature vector and the current network situation text semantic feature vector includes: Fusing the network security multimodal information association feature vector and the current network situation text semantic feature vector to obtain a warning alarm judgment classification feature vector; Performing entropy degradation maximization optimization based on walk pattern simulation on the early warning alarm judgment classification feature vector to obtain a sparse optimized early warning alarm judgment classification feature vector; The sparse optimized early warning alarm judgment classification feature vector is passed through a classifier to obtain a classification result, and the classification result is used to determine whether to issue a network security early warning alarm.
9. The artificial intelligence-based network security automatic early warning device according to claim 8 is characterized in that: Network security data processing module, including: Performing feature extraction on the historical intrusion event data to obtain a global feature vector of the historical intrusion event; Performing feature extraction on the network security data set to obtain a network security data text understanding feature vector; Associating the historical intrusion event global feature vector with the network security data text understanding feature vector to obtain the network security multimodal information association feature vector; Feature extraction is performed on the current network situation data to obtain a semantic feature vector of the current network situation text.
Citation Information
Patent Citations
Data mining system and method based on computer network security
CN118199988A