Artificial Intelligence-Based Education Data Security Emergency Response and Recovery System and Method
By generating the sensitivity, similarity and correlation intensity evaluation of the educational data matrix, combined with anomaly detection and BP neural network model, the accuracy and recovery speed of the educational data security emergency response are solved, and fast and accurate emergency response and data recovery are achieved.
Patent Information
- Application Number
- CN202411835555.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-13
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2044-12-13
AI Technical Summary
The existing educational data security emergency response methods cannot accurately and timely obtain real-time data situations, generate emergency response plans slowly, and it is difficult to recover. It has not used high-tech technologies such as machine learning to increase labor costs.
By generating an initial educational data matrix, computed sensitivity, similarity and correlation strength for risk assessment, network anomaly detection and risk prediction are used using anomaly detection algorithm and BP neural network model, and data recovery and network security situation assessment are combined with reload technology.
It realizes the accuracy and objectivity of risk assessment of educational data, quickly identify abnormal states, reduce false alarm rates, and improves the feasibility of data recovery speed and emergency response.
Smart Images

Figure CN119294847B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and specifically to an education data security emergency response and recovery system and method based on artificial intelligence. Background Art
[0002] Chinese Patent CN116521303A discloses a dynamic display method and system for an emergency plan based on multi-source data fusion. The method specifically includes obtaining multiple fine-grained emergency plans containing multi-source emergency data controls, where the multi-source emergency data controls include at least one type of multi-source emergency data; then fusing the multiple fine-grained emergency plans containing multi-source emergency data controls through the multi-source emergency data, for receiving response actions that trigger the multiple fine-grained emergency plans containing multi-source emergency data controls; when triggering the multiple fine-grained emergency plans containing multi-source emergency data controls, obtaining real-time multi-source emergency data in the triggered fine-grained emergency plans, and updating the display content of the multi-source emergency data controls in the multiple fine-grained emergency plans containing multi-source emergency data controls according to the real-time multi-source emergency data to achieve the dynamic display of the emergency plan. This invention does not process the data, and the result error is relatively large.
[0003] Traditional education data security emergency response methods cannot accurately, timely and comprehensively obtain the real-time education data situation when an education security accident occurs, nor can they generate emergency response plans in a timely manner, posing a continuous threat to education data; at the same time, the education data recovery method is slow and difficult to recover, and does not use high-tech such as machine learning, increasing the labor cost. Summary of the Invention
[0004] In view of the problems in the related art, the present invention provides an education data security emergency response and recovery system and method based on artificial intelligence to overcome the above-mentioned technical problems existing in the existing related technologies.
[0005] To solve the above technical problems, the present invention is implemented through the following technical solutions:
[0006] The present invention is an education data security emergency response and recovery system and method based on artificial intelligence, including the following steps:
[0007] S1. Obtain education-related data, generate an initial education data matrix, calculate the sensitivity, similarity and association strength of the initial education data in the initial education data matrix respectively, and conduct a risk assessment on the initial education data in the initial education data matrix. By comparing with a risk threshold, a processed education data matrix is obtained;
[0008] S2. Use the anomaly detection algorithm to perform network anomaly detection on the processed educational data in the processed educational data matrix. When in an abnormal state, activate the emergency response plan to obtain the final educational data matrix;
[0009] S3. Obtain a new set of educational data samples, extract sample features, train a BP neural network to obtain a BP neural network model, and output the educational data risk prediction result of the processed educational data matrix to complete risk prediction;
[0010] S4. Based on the educational data risk prediction result, restore the final educational data in the final educational data matrix to obtain a restored educational data matrix, and perform a network security situation assessment on the restored educational data matrix.
[0011] The invention generates an initial educational data matrix by obtaining education-related data, calculates the sensitivity of the initial educational data in the initial educational data matrix, then nodeifies the initial educational data in the initial educational data matrix using the generalization tree principle, obtains the similarity by calculating the node distance, and obtains the association strength based on data uncertainty. A risk assessment is performed on the initial educational data matrix based on sensitivity, similarity, and association strength; this method uses multiple evaluation indicators to facilitate the quantification of risk assessment, and the obtained evaluation results are accurate and objective; secondly, the anomaly detection algorithm is used to perform network anomaly detection on the processed educational data matrix, calculate the anomaly coefficient of network traffic data, and determine whether it is in an abnormal state by comparing with a threshold. In an abnormal state, the educational data is invaded by the network, and the educational data is missing or damaged; this method can predict network traffic through window data, reduce the false alarm rate, and quickly judge the abnormal state; then train a BP neural network to obtain a BP neural network model to realize the risk prediction of educational data. This neural network has a short training time and high prediction accuracy; finally, according to the educational data risk prediction result, the missing or damaged educational data is restored to obtain a restored educational data matrix, and a network security situation assessment is performed to realize early security emergency response; this method uses the overloading technology to speed up the restoration speed, and the early security emergency response can reduce the loss of data intrusion and improve the feasibility of the method.
[0012] Preferably, the S1 includes the following steps:
[0013] S11. Obtain education-related data. The types of the education-related data include classroom teaching activity data, student family information data, faculty information data, etc., to obtain an initial educational data set, and generate an initial educational data matrix A as follows:
[0014]
[0015] where, a mnRepresents the nth initial education data under the mth type of education-related data;
[0016] Select any education-related data from the initial education data matrix to form a first education data set Among them Represents the nth initial education data of the mth type of education-related data; Normalize the first education data set, and convert the normalization result into a sensitivity vector, denoted as the education data sensitivity set Among them Represents the nth education data sensitivity of the mth type of education-related data, calculate the average value of the mth type of education-related data sensitivity, and the calculation formula is as follows:
[0017]
[0018] Among them, Represents the nth education data sensitivity of the mth type of education-related data, Represents the average value of the mth type of education-related data sensitivity,
[0019] According to the average value of the mth type of education-related data sensitivity, calculate the subjective sensitivity of the kth type of education-related data, and convert the subjective sensitivity of the kth type of education-related data into an objective sensitivity, and the calculation formula is as follows:
[0020]
[0021] Among them, Represents the objective sensitivity of the kth type of education-related data, Represents the subjective sensitivity of the kth type of education-related data;
[0022] Successively obtain the objective sensitivities of all education-related data in the initial education data matrix to obtain the education data sensitivity set;
[0023] S12. Select any education-related data from the initial education data matrix to form a second education data set Among them Represents the The nth initial education data of a certain type of education-related data; converting the second education data set into a generalization tree, where the generalization tree nodes are the initial education data. Select generalization tree nodes b1 and b2, and calculate the distance between generalization tree nodes b1 and b2. The calculation formula is as follows:
[0024]
[0025] Among them, d(b1, b2) represents the distance between generalization tree nodes b1 and b2, d′(b1, b2) represents the shortest distance between generalization tree nodes b1 and b2, and dmax represents the longest distance of any node in the generalization tree;
[0026] The similarity α(b1, b2) between generalization tree nodes b1 and b2 = 1 - d(b1, b2). The similarity between generalization tree nodes b1 and b2 is the similarity between the b1th initial education data and the b2th initial education data in the second education data set. Then the calculation formula for the similarity of the b1th initial education data is as follows:
[0027]
[0028] Among them, represents the similarity of the b1th initial education data, and b2 = 1, 2, 3,..., n;
[0029] Successively obtain the similarities of all education-related data in the initial education data matrix to obtain an education data similarity set;
[0030] S13. Select any education-related data in the initial education data matrix to form a third education data set Among them represents the nth initial education data of a certain type of education-related data. According to the probabilities of the initial education data in the third education data set, obtain the uncertainty of the initial education data. Calculate the gain of the initial education data. Then the association strength calculation formula is as follows:
[0031]
[0032] Among them, β(b3, b4) represents the association strength of initial education data b3 to initial education data b4, c″(b3, b4) represents the gain of initial education data b3 and initial education data b4, c″′(b3) represents the uncertainty of initial education data b3, and c″′(b4) represents the uncertainty of initial education data b4;
[0033] Calculate the correlation strength of all education-related data in the initial education data matrix in sequence. Set the correlation strength threshold as ω. When the correlation strength of the initial education data is less than the correlation strength threshold, set the correlation strength of the initial education data to 0; otherwise, retain the correlation strength of the initial education data to obtain the education data correlation strength set.
[0034] S14. Assign weights to the education data sensitivity set, education data similarity set, and education data correlation strength set, calculate the risk score of the initial education data in the initial education data matrix, and then calculate the average value of the risk scores of the initial education data under education-related data, denoted as the education data risk index; set the risk threshold as ξ, and select the education-related data corresponding to the education data risk index greater than the risk threshold to obtain the processed education data matrix A1 as follows:
[0035]
[0036] where, a m′n represents the nth processed education data under the m'-th type of education-related data.
[0037] The present invention calculates the sensitivity, similarity, and correlation strength of the initial education data in the initial education data matrix, uses multiple evaluation indicators, facilitates the quantitative processing of risk evaluation, and conducts risk evaluation on the initial education data matrix based on sensitivity, similarity, and correlation strength, and the obtained evaluation results are accurate and objective.
[0038] Preferably, S2 includes the following steps:
[0039] S21. Use an anomaly detection algorithm to perform network anomaly detection on the processed education data in the processed education data matrix to obtain the processed education data in an abnormal state. The specific steps are as follows:
[0040] S211. Set the network traffic window size as δ, collect network traffic at time t to obtain the initial network traffic sequence C = {e t+1 , e t+2 , e t+3 ,..., e t+δ}, where e t+δ represents the network traffic data collected at time t + δ; perform mean processing on the network traffic data in the initial network traffic sequence to obtain the network traffic sequence;
[0041] S212. Set the noise interference term of the network traffic sequence as χ t+g , the (t + g - 1)-th network traffic data in the network traffic sequence is e' t+g-1 , and the (t + g - 2)-th network traffic data in the network traffic sequence is e' t+g-2, if ε1 and ε2 represent traffic parameters, then the (t + g)-th network traffic data e' in the network traffic sequence t+g The calculation formula is as follows:
[0042] e' t+g = ε1·e' t+g-1 + ε2·e' t+g-2 + χ t+g ;
[0043] S213. Obtain the (t + g + 1)-th network traffic data e' in the network traffic sequence based on the (t + g)-th network traffic data in the network traffic sequence t+g+1 , set the anomaly parameter as ε, then the calculation formula for the anomaly coefficient D(t + g + 1) of the (t + g + 1)-th network traffic data in the network traffic sequence is as follows:
[0044]
[0045] Divide the network traffic sequence into a first network traffic sequence and a second network traffic sequence according to positive and negative values, calculate the network traffic means in the first network traffic sequence and the second network traffic sequence, denoted as d1 and d2 respectively, then calculate the network traffic standard deviations in the first network traffic sequence and the second network traffic sequence, denoted as d3 and d4 respectively, and set represents a random number and then the anomaly threshold range is When the anomaly coefficient is within the anomaly threshold range, the network traffic data corresponding to the anomaly coefficient is normal, otherwise the network traffic data corresponding to the anomaly coefficient is abnormal;
[0046] S214. When the network traffic data is abnormal, the processed educational data in the processed educational data matrix at this time is in an abnormal state;
[0047] S22. For the processed educational data in an abnormal state, identify the events that cause the abnormal state, evaluate the severity and scope of influence of the events that cause the abnormal state, set the severity threshold and the scope of influence threshold, and when the severity of the events that cause the abnormal state is greater than the severity threshold and the scope of influence of the events that cause the abnormal state is greater than the scope of influence threshold, at this time, activate the emergency response plan, isolate the processed educational data, obtain the final educational data, and generate the final educational data matrix.
[0048] The present invention performs network anomaly detection on the processed educational data matrix by using an anomaly detection algorithm, and judges whether it is abnormal by comparing with a threshold, which can quickly judge whether the educational data is invaded by the network. This method can predict network traffic through window data, reduce the false alarm rate, and obtain the situation of missing or damaged educational data.
[0049] Preferably, S3 includes the following steps:
[0050] S31. Initialize the BP (Back Propagation) neural network, determine the number of input layer nodes, the number of hidden layer nodes, and the number of output layer nodes according to the input sample data set. The sample data set is input into the input layer, set the learning rate and activation function, calculate the output result of the hidden layer through the connection weights between the input layer and the hidden layer, and output the prediction result in the output layer according to the connection weights based on the output result of the hidden layer;
[0051] S32. Re-obtain new education data. After the new education data passes through risk assessment, a new education data sample set is obtained. Use the new education data sample set to train the BP neural network to obtain a BP neural network model. The specific steps are as follows:
[0052] S321. Select the features of the new education data sample set to obtain a sample feature set. Set the number of input nodes of the BP neural network to φ1, where the number of input nodes is the number of features of the sample feature set, the number of output nodes is 2, adopt the Adam optimizer, the activation function is the Softmax function, and the learning rate is Set the maximum number of iterations to γ; divide the sample feature set into a sample feature training set and a sample feature validation set, input the sample feature training set into the BP neural network, and stop the iteration when the current number of iterations reaches the maximum number of iterations to obtain a trained BP neural network;
[0053] S322. Input the sample feature validation set into the trained BP neural network, set the accuracy threshold to ψ, and stop the iteration to obtain a BP neural network model when the output result accuracy is less than the accuracy threshold; otherwise, adjust the weights until the output result accuracy is less than the accuracy threshold;
[0054] S33. Binarize the processed education data in the processed education data matrix to obtain a binarized data set, input the binarized data set into the BP neural network model. When the BP neural network model outputs 1, there is a risk warning for the processed education data in the processed education data matrix at this time. When the BP neural network model outputs 0, there is no risk warning for the processed education data in the processed education data matrix at this time, and the risk prediction of the education data is completed;
[0055] The invention extracts sample data features, trains a BP neural network to obtain a BP neural network model, identifies whether there is a risk warning for education data, and realizes the risk prediction of education data. The neural network has a short training time and high prediction accuracy.
[0056] Preferably, S4 includes the following steps:
[0057] S41. Store the initial education data in the initial education data matrix in the education database. Based on the education data risk prediction result, use the overloading strategy to restore the final education data in the final education data matrix. The specific steps are as follows:
[0058] S411. Detect that the network is abnormal. At this time, send a transmission data signal application to the education database. After receiving the transmission data signal, the education database selects the data pages with missing or damaged final education data in the final education data matrix and adds them to the transmission queue;
[0059] S412. Prioritize scheduling the data pages of the final education data in the final education data matrix in the transmission queue until the transmission is complete, obtain the restored education data, generate the restored education data matrix, and realize the restoration of education data;
[0060] S42. Conduct a network security situation assessment on the restored education data matrix to obtain a network security situation value, and perform a security emergency response in advance according to the network security situation value. The specific steps are as follows:
[0061] S421. Obtain the network traffic data during the abnormal network process to obtain the network traffic data set C1 = {e1, e2, e3,..., e i}, where e i represents the i-th network traffic data. Perform binary classification processing on the network traffic data set, set the abnormal network traffic data to 1, and the normal network traffic data to 0. Then the attack probability calculation formula is as follows:
[0062]
[0063] Among them, E represents the attack probability, represents the binary classification processing result of the i1-th network traffic data, i1 = 1, 2, 3,..., i;
[0064] S422. During the network attack, set the influence value of the j-th type of network attack on network confidentiality as k j ′, the influence value of the j-th type of network attack on network integrity as k j ″, the influence value of the j-th type of network attack on network availability as k j ″′, and λ1, λ2, and λ3 respectively represent the weights of network confidentiality, network integrity, and network availability. Then the network attack influence coefficient calculation formula is as follows:
[0065]
[0066] Among them, F j represents the network attack influence coefficient of the j-th type of network attack;
[0067] Set the number of types of network attacks as q, and the number of attacks of the j-th type of network attack as l j , and the total amount of network attacks is G. Then the calculation formula of the network security situation value H is as follows;
[0068]
[0069] Set the situation threshold as ζ. When the network security situation value is greater than the situation threshold, there is a risk in the restored education data matrix at this time, and a security emergency response is carried out in advance; otherwise, there is no risk in the restored education data matrix, and the network security situation assessment is completed.
[0070] According to the prediction result of education data risk, this invention restores the missing or damaged education data, and uses the overloading technology to speed up the restoration speed; and conducts network security situation assessment to achieve a security emergency response in advance and improve the feasibility of the method.
[0071] This invention also discloses a system for the security emergency response and restoration method of education data based on artificial intelligence, which specifically includes: an initial education data risk assessment module, an education data security emergency response module, an education data risk prediction module, and an education data restoration and network security situation assessment module;
[0072] The initial education data risk assessment module is used to conduct risk assessment based on the sensitivity, similarity, and association strength of the initial education data;
[0073] The education data security emergency response module is used to conduct network anomaly detection on the education data and activate the emergency response plan;
[0074] The education data risk prediction module is used to predict the education data risk using a BP neural network model;
[0075] The education data restoration and network security situation assessment module is used to restore the missing or damaged education data and conduct network security situation assessment.
[0076] This invention has the following beneficial effects:
[0077] 1. By calculating the sensitivity, similarity, and association strength of the initial education data in the initial education data matrix, this invention uses multiple evaluation indicators, which is convenient for quantifying the risk evaluation and conducting risk evaluation, and the obtained evaluation results are accurate and objective.
[0078] 2. By using the anomaly detection algorithm to conduct network anomaly detection on the processed education data matrix, this invention can quickly judge whether the education data is invaded by the network, predict the network traffic through window data, reduce the false alarm rate, and obtain the situation of missing or damaged education data.
[0079] 3. The invention extracts the characteristics of sample data, trains a BP neural network to obtain a BP neural network model, identifies whether there is a risk warning in educational data, and realizes the risk prediction of educational data. The neural network has a short training time and high prediction accuracy.
[0080] 4. The invention restores the missing or damaged educational data according to the risk prediction result of educational data, and uses the overloading technology to speed up the restoration speed; and conducts network security situation assessment to realize early security emergency response and improve the feasibility of the method.
[0081] Of course, any product implementing the present invention does not necessarily need to achieve all the above advantages simultaneously. Brief Description of the Drawings
[0082] In order to more clearly illustrate the technical solutions of the embodiments of the invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0083] Figure 1 It is a schematic flowchart of the educational data security emergency response and restoration of the educational data security emergency response and restoration system based on artificial intelligence provided by the present invention. Detailed Embodiments
[0084] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0085] In the description of the present invention, it should be understood that the terms "open hole", "upper", "lower", "top", "middle", "inner", etc. indicating the orientation or position relationship are only for the convenience of describing the invention and simplifying the description, rather than indicating or implying that the components or elements referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation to the invention.
[0086] Embodiment 1
[0087] Please refer to Figure 1 , the present invention is an educational data security emergency response and restoration method based on artificial intelligence, including the following steps:
[0088] S1. Obtain education-related data, generate an initial education data matrix, calculate the sensitivity, similarity, and association strength of the initial education data in the initial education data matrix respectively, and conduct a risk assessment on the initial education data in the initial education data matrix. By comparing with a risk threshold, obtain a processed education data matrix;
[0089] S1 includes the following steps:
[0090] S11. Obtain education-related data. The types of the education-related data include classroom teaching activity data, student family information data, faculty information data, etc., to obtain an initial education data set, and generate an initial education data matrix A as follows:
[0091]
[0092] where a mn represents the nth initial education data under the mth type of education-related data;
[0093] Select any education-related data in the initial education data matrix to form a first education data set where represents the nth initial education data of the th type of education-related data; Normalize the first education data set, and convert the normalization result into a sensitivity vector, denoted as the education data sensitivity set where represents the nth education data sensitivity of the th type of education-related data, calculate the average value of the education data sensitivity of the th type of education-related data, and the calculation formula is as follows:
[0094]
[0095] where, represents the th education data sensitivity of the th type of education-related data, represents the average value of the education data sensitivity of the th type of education-related data,
[0096] According to the average value of the education data sensitivity of the th type of education-related data, calculate the subjective sensitivity of the th type of education-related data, and convert the subjective sensitivity of the th type of education-related data into objective sensitivity, and the calculation formula is as follows:
[0097]
[0098] where, represents the objective sensitivity of the kinds of education-related data, represents the subjective sensitivity of the kinds of education-related data;
[0099] Successively obtain the objective sensitivities of all education-related data in the initial education data matrix to obtain an education data sensitivity set;
[0100] S12. Select any education-related data in the initial education data matrix to form a second education data set where represents the n-th initial education data of the k-th kind of education-related data; convert the second education data set into a generalization tree, where the generalization tree nodes are the initial education data. Select generalization tree node b1 and generalization tree node b2, and calculate the distance between generalization tree node b1 and generalization tree node b2. The calculation formula is as follows:
[0101]
[0102] where d(b1, b2) represents the distance between generalization tree node b1 and generalization tree node b2, d′(b1, b2) represents the shortest distance between generalization tree node b1 and generalization tree node b2, and dmax represents the longest distance of any node in the generalization tree;
[0103] The similarity α(b1, b2) between generalization tree node b1 and generalization tree node b2 = 1 - d(b1, b2). The similarity between generalization tree node b1 and generalization tree node b2 is the similarity between the b1-th initial education data and the b2-th initial education data in the second education data set. Then the similarity calculation formula for the b1-th initial education data is as follows:
[0104]
[0105] where represents the similarity of the b1-th initial education data, and b2 = 1, 2, 3,..., n;
[0106] Successively obtain the similarities of all education-related data in the initial education data matrix to obtain an education data similarity set;
[0107] S13. Select any education-related data in the initial education data matrix to form a third education data set where represents the The nth initial educational data of educational - related data, according to the probability of the initial educational data in the third educational data set, obtain the uncertainty of the initial educational data, and calculate the gain of the initial educational data. Then the formula for the association strength is as follows:
[0108]
[0109] Among them, β(b3,b4) represents the association strength of the initial educational data b3 with respect to the initial educational data b4, c″(b3,b4) represents the gain of the initial educational data b3 and the initial educational data b4, c″′(b3) represents the uncertainty of the initial educational data b3, and c″′(b4) represents the uncertainty of the initial educational data b4;
[0110] Calculate the association strength of all educational - related data in the initial educational data matrix in sequence. Set the association strength threshold as ω. When the association strength of the initial educational data is less than the association strength threshold, set the association strength of the initial educational data to 0; otherwise, retain the association strength of the initial educational data to obtain the educational data association strength set;
[0111] S14. Assign weights to the educational data sensitivity set, the educational data similarity set, and the educational data association strength set, calculate the risk score of the initial educational data in the initial educational data matrix, and then calculate the average value of the risk scores of the initial educational data under educational - related data, denoted as the educational data risk index; set the risk threshold as ξ, and select the educational - related data corresponding to the educational data risk index greater than the risk threshold to obtain the processed educational data matrix A1 as follows:
[0112]
[0113] where, a m′n represents the nth processed educational data under the m′th educational - related data;
[0114] S2. Use an anomaly detection algorithm to perform network anomaly detection on the processed educational data in the processed educational data matrix. When in an abnormal state, activate the emergency response plan to obtain the final educational data matrix;
[0115] The S2 includes the following steps:
[0116] S21. Use an anomaly detection algorithm to perform network anomaly detection on the processed educational data in the processed educational data matrix to obtain the processed educational data in the abnormal state. The specific steps are as follows:
[0117] S211. Set the network traffic window size as δ, collect the network traffic at time t to obtain the initial network traffic sequence C = {e t+1, e t+2 , e t+3 ,..., e t+δ} where e t+δ represents the network traffic data collected at time t + δ; perform mean processing on the network traffic data in the initial network traffic sequence to obtain a network traffic sequence;
[0118] S212. Set the noise interference term of the network traffic sequence as χ t+g , the (t + g - 1)-th network traffic data in the network traffic sequence is e' t+g-1 , the (t + g - 2)-th network traffic data in the network traffic sequence is e' t+g-2 , ε1 and ε2 represent traffic parameters, then the (t + g)-th network traffic data e' in the network traffic sequence t+g has the following calculation formula:
[0119] e' t+g = ε1·e' t+g-1 + ε2·e' t+g-2 + χ t+g ;
[0120] S213. Obtain the (t + g + 1)-th network traffic data e' in the network traffic sequence based on the (t + g)-th network traffic data in the network traffic sequence. Set the anomaly parameter as ε, then the calculation formula for the anomaly coefficient D(t + g + 1) of the (t + g + 1)-th network traffic data in the network traffic sequence is as follows: t+g+1 Divide the network traffic sequence into a first network traffic sequence and a second network traffic sequence according to positive and negative values, calculate the network traffic means in the first network traffic sequence and the second network traffic sequence, denoted as d1 and d2 respectively, then calculate the network traffic standard deviations in the first network traffic sequence and the second network traffic sequence, denoted as d3 and d4 respectively. Set
[0121]
[0122] as a random number and Then the anomaly threshold range is When the anomaly coefficient is within the anomaly threshold range, the network traffic data corresponding to the anomaly coefficient is normal; otherwise, the network traffic data corresponding to the anomaly coefficient is abnormal; When the network traffic data is abnormal, the processed educational data in the processed educational data matrix is in an abnormal state at this time;
[0123] S214. When the network traffic data is abnormal, the processed educational data in the processed educational data matrix is in an abnormal state at this time;
[0124] S22. For the processed educational data in an abnormal state, identify the events that caused the abnormal state, evaluate the severity and scope of influence of the events that caused the abnormal state, set the severity threshold and the scope of influence threshold. When the severity of the event that caused the abnormal state is greater than the severity threshold and the scope of influence of the event that caused the abnormal state is greater than the scope of influence threshold, at this time, activate the emergency response plan, isolate the processed educational data to obtain the final educational data, and generate the final educational data matrix;
[0125] S3. Obtain a new set of educational data samples, extract sample features, train a BP neural network to obtain a BP neural network model, and output the educational data risk prediction result of the processed educational data matrix to complete the risk prediction;
[0126] S3 includes the following steps:
[0127] S31. Initialize the BP neural network, determine the number of input layer nodes, the number of hidden layer nodes, and the number of output layer nodes according to the input sample data set. The sample data set is input into the input layer, set the learning rate and activation function, calculate the output result of the hidden layer through the connection weights between the input layer and the hidden layer, and output the prediction result in the output layer according to the connection weights;
[0128] S32. Re-obtain new educational data. After the new educational data passes through risk assessment, a new set of educational data samples is obtained, and the BP neural network is trained using the new set of educational data samples to obtain a BP neural network model. The specific steps are as follows:
[0129] S321. Select the features of the new set of educational data samples to obtain a sample feature set. Set the number of input nodes of the BP neural network to φ1, where the number of input nodes is the number of features of the sample feature set, the number of output nodes is 2, use the Adam optimizer, the activation function is the Softmax function, and the learning rate is Set the maximum number of iterations to γ; divide the sample feature set into a sample feature training set and a sample feature validation set, input the sample feature training set into the BP neural network, and stop the iteration when the current number of iterations reaches the maximum number of iterations to obtain the trained BP neural network;
[0130] S322. Input the sample feature validation set into the trained BP neural network, set the accuracy threshold to ψ. When the accuracy of the output result is less than the accuracy threshold, stop the iteration to obtain the BP neural network model; otherwise, adjust the weights until the accuracy of the output result is less than the accuracy threshold;
[0131] S33. Binarize the processed educational data in the processed educational data matrix to obtain a binarized data set, and input the binarized data set into the BP neural network model. When the BP neural network model outputs 1, there is a risk warning for the processed educational data in the processed educational data matrix at this time. When the BP neural network model outputs 0, there is no risk warning for the processed educational data in the processed educational data matrix at this time, and the educational data risk prediction is completed;
[0132] S4. Based on the educational data risk prediction result, restore the final educational data in the final educational data matrix to obtain a restored educational data matrix, and perform a network security situation assessment on the restored educational data matrix;
[0133] S4 includes the following steps:
[0134] S41. Store the initial educational data in the initial educational data matrix in the educational database. Based on the educational data risk prediction result, use the reload strategy to restore the final educational data in the final educational data matrix. The specific steps are as follows:
[0135] S411. When it is detected that the network is abnormal, a transmission data signal application is sent to the educational database at this time; after receiving the transmission data signal, the educational database selects the data pages in the final educational data matrix where the final educational data is missing or damaged and adds them to the transmission queue;
[0136] S412. Prioritize the scheduling of the data pages of the final educational data in the final educational data matrix in the transmission queue until the transmission is complete, obtain the restored educational data, generate a restored educational data matrix, and realize the restoration of educational data;
[0137] S42. Perform a network security situation assessment on the restored educational data matrix to obtain a network security situation value, and perform a security emergency response in advance according to the network security situation value. The specific steps are as follows:
[0138] S421. Obtain the network traffic data during the abnormal network process to obtain a network traffic data set C1 = {e1, e2, e3,..., e i}, where e i represents the i-th network traffic data. Perform a binary classification process on the network traffic data set, set the abnormal network traffic data to 1, and set the normal network traffic data to 0. Then the attack probability calculation formula is as follows:
[0139]
[0140] where E represents the attack probability, Indicates the binary classification processing result of the i1-th network traffic data, where i1 = 1, 2, 3,..., i;
[0141] S422. During a network attack, set the impact value of the j-th type of network attack on network confidentiality to k j ′, the impact value of the j-th type of network attack on network integrity to k j ″, and the impact value of the j-th type of network attack on network availability to k j ″′. Let λ1, λ2, and λ3 represent the weights of network confidentiality, network integrity, and network availability respectively. Then the calculation formula for the network attack impact coefficient is as follows:
[0142]
[0143] where F j represents the network attack impact coefficient of the j-th type of network attack;
[0144] S423. Set the number of network attack types to q, the number of attacks of the j-th type of network attack to l j , and the total amount of network attacks to G. Then the calculation formula for the network security situation value H is as follows;
[0145]
[0146] Set the situation threshold to ζ. When the network security situation value is greater than the situation threshold, there is a risk in the restored education data matrix at this time, and a security emergency response is carried out in advance; otherwise, there is no risk in the restored education data matrix, and the network security situation assessment is completed.
[0147] Embodiment 2
[0148] The present invention also discloses a system for an education data security emergency response and recovery method based on artificial intelligence, specifically including: an initial education data risk assessment module, an education data security emergency response module, an education data risk prediction module, and an education data recovery and network security situation assessment module;
[0149] The initial education data risk assessment module is used to perform risk assessment based on the sensitivity, similarity, and association strength of the initial education data;
[0150] The education data security emergency response module is used to perform network anomaly detection on the education data and activate the emergency response plan;
[0151] The education data risk prediction module is used to predict the education data risk using a BP neural network model;
[0152] The education data recovery and network security situation assessment module is used to recover missing or damaged education data and perform network security situation assessment.
[0153] In the description of this specification, the descriptions referring to the terms "one embodiment", "example", "specific example", etc. mean that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.
[0154] The preferred embodiments of the invention disclosed above are only used to help explain the invention. The preferred embodiments do not exhaust all the details, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification in order to better explain the principle and practical application of the invention, so that those skilled in the art can well understand and utilize the invention.
Claims
1. An artificial intelligence-based education data security emergency response and recovery method, characterized in that, It includes the following steps: S1. Obtain education-related data, generate an initial education data matrix, calculate the sensitivity, similarity, and correlation strength of the initial education data in the initial education data matrix respectively, and conduct a risk assessment on the initial education data in the initial education data matrix. By comparing with the risk threshold, obtain the processed education data matrix; S2. Use an anomaly detection algorithm to conduct network anomaly detection on the processed education data in the processed education data matrix. When in an abnormal state, activate the emergency response plan to obtain the final education data matrix; Perform mean processing on the network traffic data in the initial network traffic sequence to obtain a network traffic sequence; predict the network traffic according to the network traffic sequence to obtain the (t + g)-th network traffic data in the network traffic sequence; obtain the anomaly coefficient of the network traffic according to the (t + g)-th network traffic data in the network traffic sequence, set a network traffic threshold, and compare whether the network traffic is in an abnormal state; When the network traffic data is abnormal, at this time, the processed education data in the processed education data matrix is in an abnormal state, and the processed education data in the abnormal state is obtained; S3. Obtain a new set of education data samples, extract sample features, train a BP neural network to obtain a BP neural network model, and output the education data risk prediction result of the processed education data matrix to complete the risk prediction; S4. Based on the education data risk prediction result, restore the final education data in the final education data matrix to obtain a restored education data matrix, and conduct a network security situation assessment on the restored education data matrix; The S4 includes the following steps: S41. Store the initial education data in the initial education data matrix in an education database, and based on the education data risk prediction result, use a reload strategy to restore the final education data in the final education data matrix; S42. Conduct a network security situation assessment on the restored education data matrix to obtain a network security situation value, and conduct a security emergency response in advance according to the network security situation value.
2. The method for emergency response and recovery of educational data security based on artificial intelligence according to claim 1, wherein The S1 includes the following steps: S11. Obtain education-related data, generate an initial education data matrix, and calculate the objective sensitivity of the initial education data in the initial education data matrix to obtain a set of education data sensitivities; S12. Convert the initial education data matrix into a generalization tree, where the generalization tree nodes are the initial education data, and calculate the similarity of the generalization tree nodes to obtain a set of education data similarities; S13. Calculate the uncertainty of the initial education data in the initial education data matrix, and calculate the correlation strength of the initial education data according to the uncertainty of the initial education data to obtain a set of education data correlation strengths; S14. Assign weights to the set of education data sensitivities, the set of education data similarities, and the set of education data correlation strengths, calculate the risk score of the initial education data in the initial education data matrix, set the risk threshold as ξ, conduct a risk assessment on the initial education data in the initial education data matrix, and obtain the processed education data matrix.
3. The method for emergency response and recovery of educational data security based on artificial intelligence according to claim 2, wherein, The S2 includes the following steps: S21. Use an anomaly detection algorithm to perform network anomaly detection on the processed educational data in the processed educational data matrix to obtain the processed educational data in an abnormal state; S22. According to the processed educational data in the abnormal state, identify the events causing the abnormal state, evaluate the severity and scope of influence of the events causing the abnormal state, activate the emergency response plan, isolate the processed educational data to obtain the final educational data, and generate the final educational data matrix.
4. The method for emergency response and recovery of educational data security based on artificial intelligence according to claim 3, characterized in that Set a network traffic window, collect network traffic, and obtain an initial network traffic sequence.
5. The method for emergency response and recovery of educational data security based on artificial intelligence according to claim 4, wherein, The S3 includes the following steps: S31. Initialize the BP neural network, determine the number of input layer nodes, the number of hidden layer nodes, and the number of output layer nodes according to the input sample data set. The sample data set is input into the input layer. Set the learning rate and activation function, calculate the output result of the hidden layer through the connection weights between the input layer and the hidden layer, and output the prediction result in the output layer according to the connection weights based on the output result of the hidden layer; S32. Re-obtain new educational data. After the new educational data passes through risk assessment, obtain a new educational data sample set, and use the new educational data sample set to train the BP neural network to obtain a BP neural network model; S33. Binarize the processed educational data in the processed educational data matrix to obtain a binarized data set. Input the binarized data set into the BP neural network model. When the BP neural network model outputs 1, there is a risk warning for the processed educational data in the processed educational data matrix at this time. When the BP neural network model outputs 0, there is no risk warning for the processed educational data in the processed educational data matrix at this time, and complete the risk prediction of the educational data.
6. The method for emergency response and recovery of educational data security based on artificial intelligence according to claim 5, wherein The S32 includes the following steps: S321. Select the features of the new educational data sample set to obtain a sample feature set. Set the number of input nodes of the BP neural network to φ1, where the number of input nodes is the number of features in the sample feature set, the number of output nodes to 2, use the Adam optimizer, the activation function to be the Softmax function, and the learning rate to be Set the maximum number of iterations to γ; divide the sample feature set into a sample feature training set and a sample feature validation set, input the sample feature training set into the BP neural network, and stop the iteration when the current number of iterations reaches the maximum number of iterations to obtain a trained BP neural network; S322. Input the sample feature verification set into the trained BP neural network. Set the accuracy threshold as ψ. When the output result accuracy is less than the accuracy threshold, stop the iteration to obtain the BP neural network model; otherwise, adjust the weights until the output result accuracy is less than the accuracy threshold.
7. The method for emergency response and recovery of educational data security based on artificial intelligence according to claim 1, characterized in that, The steps for restoring the final educational data in the final educational data matrix using the reload strategy include the following: When it is detected that the network is abnormal, the educational data is missing or damaged. At this time, the educational database uses the reload strategy to preferentially schedule the missing or damaged data pages to obtain the restored educational data, generate the restored educational data matrix, and achieve the restoration of the educational data.
8. A system for implementing the artificial intelligence-based education data security emergency response and recovery method according to any one of claims 1-7, characterized in that, Specifically include: Initial educational data risk assessment module, educational data security emergency response module, educational data risk prediction module, and educational data recovery and network security situation assessment module; The initial educational data risk assessment module is used to perform risk assessment based on the sensitivity, similarity, and association strength of the initial educational data; The educational data security emergency response module is used to perform network anomaly detection on the educational data and activate the emergency response plan; The educational data risk prediction module is used to predict the educational data risk using the BP neural network model; The education data recovery and network security situation assessment module is used to recover missing or damaged education data and conduct network security situation assessment.
Citation Information
Patent Citations
Emergency plan dynamic display method and system based on multi-source data fusion
CN116521303A
PCA-based BP neural network detection system, method and application for information security
CN113128615A