A method and system for statistical analysis of security incident data
By establishing an integrated device system and utilizing algorithms such as random forests and variational autoencoders to automate the monitoring and control of the network security platform, the system solves the overall coordination problem of the existing platform in event handling and achieves efficient and accurate security event response and risk management.
Patent Information
- Application Number
- CN202411789803.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-06
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-12-06
AI Technical Summary
Existing cybersecurity platforms lack systematic coordination in incident collection, analysis, handling, and reporting, resulting in low processing efficiency and slow response speed.
By establishing an integrated equipment system, and utilizing random forests combined with XGBoost and variational autoencoder algorithms, automated monitoring and control of safety equipment can be achieved. By combining fuzzy logic systems for health status assessment, potential risks can be identified and addressed in a timely manner.
It improved the system's overall coordination and manageability, reduced manual intervention, increased data processing efficiency and accuracy, shortened response time for security incidents, and ensured the system's security and stability.
Smart Images

Figure CN119520155B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, specifically to a method and system for statistical analysis of security incident data. Background Technology
[0002] Verification of cybersecurity platform functionality typically involves phases such as unit testing, integration testing, system testing, and acceptance testing to verify the platform's functional correctness, performance stability, security reliability, and user satisfaction. Based on organizational size, business needs, security goals, and budget, a suitable cybersecurity incident collaborative response platform product should be selected. Following product documentation or vendor guidance, the cybersecurity incident collaborative response platform should be deployed and configured to ensure its integration with existing security devices and systems, and to collect and process relevant cybersecurity data and alerts. Currently, cybersecurity platforms lack a systematic approach to collecting, analyzing, handling, and reporting cybersecurity incidents. Therefore, it is necessary to propose a method and system for statistical analysis of security incident data to address this lack of systematic coordination in cybersecurity platforms. Summary of the Invention
[0003] In view of the above-mentioned problems, the present invention is proposed.
[0004] Therefore, the technical problem solved by this invention is that existing network security platforms lack systematic coordination in event collection, analysis, handling and reporting, resulting in low processing efficiency and slow response speed.
[0005] To solve the above-mentioned technical problems, the present invention provides the following technical solution: a method for statistical analysis of security incident data, comprising:
[0006] Each second object is incorporated into the first object, and the first target check is performed to obtain the first target check data.
[0007] Process the data from the first target inspection to identify the third object;
[0008] The third object is processed for the second objective, and the third object is then regulated based on the processing results.
[0009] As a preferred embodiment of the security processing event data statistics method of the present invention, wherein: each second object is included in the first object, multiple second objects are received, one of the second objects is selected, and a feature function of the second object is formed;
[0010] Return to the previous step and select a second object, until all second objects have been selected;
[0011] Extract the feature values of each second object feature function to form the first object feature function.
[0012] As a preferred embodiment of the security processing event data statistics method of the present invention, the first target check includes performing a first target check on a first object according to a first target;
[0013] By combining the feature values of the first object feature function and each second object feature function, the first target inspection data fed back by the second object feature function is received;
[0014] The first target inspection data includes data reflecting the operating status of the first object and the inspection results of the first target.
[0015] As a preferred embodiment of the security event data statistics method described in this invention, determining the third object includes automatically processing the inspection result data of the first target to obtain the running status of all second objects and generating the third object.
[0016] As a preferred embodiment of the security event data statistics method of the present invention, the second target processing of the third object includes analyzing the second target of the third object and determining the state of the third object.
[0017] As a preferred embodiment of the security event data statistics method described in this invention, the automated processing of the first target inspection result data includes, but is not limited to, using a random forest combined with XGBoost algorithm to process the first target inspection result data, obtain the status of all second objects, and generate a third object.
[0018] As a preferred embodiment of the security event data statistics method described in this invention, the determination of the running state of the third object includes, but is not limited to, using a variational autoencoder algorithm to analyze the second target of the third object and determine the state of the third object.
[0019] A security incident data statistics system, wherein:
[0020] The data processing module incorporates each second object into the first object, performs a first target check, and obtains the first target check data.
[0021] The data inspection module processes the inspection data for the first target and identifies the third object.
[0022] The control module performs second-objective processing on the third object and controls the third object based on the processing results.
[0023] A computer device includes: a memory and a processor; the memory stores a computer program, characterized in that: when the processor executes the computer program, it implements the steps of the method described in any one of the present invention.
[0024] A computer-readable storage medium having a computer program stored thereon, characterized in that: when the computer program is executed by a processor, it implements the steps of the method described in any one of the present invention.
[0025] The beneficial effects of this invention are as follows: The security incident data statistics method provided by this invention establishes an integrated equipment system, unifying the management of various security devices and subsystems, greatly improving the system's overall coordination and manageability. The scheduled operation system and automated process orchestration automate and schedule inspection tasks, significantly reducing manual intervention and improving data processing efficiency and accuracy. Rapid identification of abnormal data and platform testing enable timely location of risky devices, ensuring system security. The collaborative work between the emergency response system and mobile devices enables efficient multi-person collaborative response, shortening response time for security incidents and reducing potential risks. Furthermore, the generated security incident data statistics report provides a comprehensive view of the security situation through a feedback mechanism, supporting management's decision-making optimization. Attached Figure Description
[0026] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0027] Figure 1 This is an overall flowchart of a security event data statistics method provided in the first embodiment of the present invention;
[0028] Figure 2 The system structure diagram is provided for a security event data statistics method according to the second embodiment of the present invention. Detailed Implementation
[0029] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.
[0030] Example 1, referring to Figure 1 As an embodiment of the present invention, a method for statistical analysis of security incident data is provided, comprising:
[0031] S1: Incorporate each second object into the first object, perform the first target check, and obtain the first target check data.
[0032] In one implementation of this application, the first object refers to the main system architecture of the equipment integration system, which is responsible for the overall system management and control and periodically checks each subsystem (i.e., the second object). The second object includes various hardware or software subsystems embedded in the main system to provide functional services. Through real-time data acquisition and analysis of the second object, the first objective check aims to identify potentially risky devices. After processing this data, the system can identify a third object, namely, devices or subsystems with anomalies or potential risks. For the third object, the system performs a second objective processing, namely, implementing security response and fault repair, and generating corresponding event data feedback to the management level for decision-making to ensure the healthy operation and security of the system.
[0033] In an optional embodiment, the first object can also be a smart home control system, responsible for the overall management and control of all devices in the home, such as lighting, thermostats, and security systems, and periodically checking each subsystem (i.e., the second object). The second object includes various home subsystems, such as smart lighting, thermostats, and security monitoring, which connect to the main control system as independent modules and provide specific functional services. Through real-time data collection and analysis of the second object, the first object check can identify potentially risky devices. After data processing, the system can identify a third object, i.e., devices with malfunctions or potential risks, such as thermostat malfunctions or security system failures. For the third object, the system implements second object processing, i.e., performs security response and fault repair, and generates corresponding event data feedback to management to help make decisions, thereby ensuring the healthy operation and security of the smart home system.
[0034] By receiving multiple second objects (such as equipment subsystems), features of each second object are selected and extracted one by one to generate its feature function. Each feature function contains the object's key operating parameters or performance indicators. By iteratively processing all second objects, extracting their feature values, and summarizing them, a comprehensive feature function for the entire system (first object) is finally formed. This process ensures the extraction and integration of information from various subsystems, thereby comprehensively describing the performance and status of the first object and providing foundational data for subsequent risk detection and decision-making.
[0035] The first objective check process includes a health status check of the first object (main system architecture). First, operational data of the first object, such as load, stability, and performance indicators, is collected according to the set first objective. Then, by combining the characteristic values of the first object's characteristic function with those of each second object (subsystem), the status of the entire integrated equipment system is analyzed. Each second object will provide feedback on its operational data, including temperature, current, and load information. This feedback data serves as the data source for the first objective check, helping to assess the overall operational status of the first object. Ultimately, the first objective check data reflects the operational status and check results of the first object, providing a basis for system risk assessment, performance optimization, and fault diagnosis, ensuring the healthy operation of the system and promptly identifying potential problems.
[0036] S2: Process the first target inspection data to identify the third object.
[0037] The system automates the processing of data from the first target inspection. First, it analyzes the data from each second object (subsystem) to automatically calculate the operating status of each subsystem. This operating status data may include parameters such as temperature, current, and load, reflecting the health of each subsystem. Based on this, the system further performs a comprehensive assessment of the status of all subsystems, automatically identifying equipment with abnormal operating conditions or potential faults. Finally, these subsystems identified as having risks or abnormalities are defined as third objects—potentially risky or faulty equipment. This process of identifying third objects helps the system promptly detect and address equipment anomalies, preventing major system-wide failures or safety hazards.
[0038] In one implementation of this application, the automated processing of identified devices with abnormal operating states or potential faults involves preprocessing the first target inspection result data using a combination of random forest and XGBoost algorithms. Next, the random forest algorithm is used to evaluate the importance of each feature, selecting features highly correlated with the device state based on feature importance to improve the training efficiency of subsequent models. Subsequently, the XGBoost algorithm is used to perform classification or regression training on the selected feature data, optimizing the model through an adaptive gradient boosting mechanism to predict the state of each second object (subsystem). Based on the model prediction results, abnormal or potentially faulty second objects are marked, and these objects are grouped into a third object, namely, potentially risky devices. This process efficiently identifies potentially abnormal subsystems within the system, providing a reliable basis for subsequent risk management and safety responses.
[0039] In an optional embodiment, the automated processing of devices identified as having abnormal operating conditions or potential malfunctions can also utilize a Support Vector Machine (SVM) algorithm to collect and clean the initial inspection result data, including device operating status, performance indicators, environmental factors, etc. Next, feature extraction and standardization are performed on the data to ensure its suitability for the SVM model. The standardization process typically involves mean normalization or standard deviation normalization for each feature to eliminate the influence of different units on model training. A classification model is then built using the SVM algorithm. The SVM algorithm distinguishes between normal devices and potentially faulty or abnormal devices by constructing a hyperplane (or multiple hyperplanes) to maximize the margin between categories. During model training, using data already labeled with normal and abnormal states as the training set, the SVM model learns how to differentiate between normal and faulty device states.
[0040] After training, the SVM model can classify newly collected inspection data. If the model determines the state of a device or subsystem as "abnormal," that device is identified as a potential faulty or risky device, thus generating a third object. This third object includes all devices identified as faulty or risky, which will then undergo further risk response and safety procedures.
[0041] Furthermore, by automating and comprehensively evaluating the operational status data of each subsystem, devices with potential faults or risks (i.e., third-party objects) can be identified in a timely manner. This process can efficiently and accurately monitor and analyze the health status of each subsystem, avoiding delays and errors caused by human intervention, thereby improving the stability and security of the system. By automatically identifying potentially risky devices, preventative measures can be taken before faults occur, avoiding overall system failures or major safety hazards, and enhancing the reliability and security of the system.
[0042] S3: Perform second-objective processing on the third object, and regulate the third object based on the processing results.
[0043] Data collection and analysis determine the status of equipment or subsystems, identifying whether they are in a normal, warning, or fault state. Based on the analysis results, corresponding control measures are taken, such as shutting down or suspending functions, adjusting operating parameters, switching redundant systems, or issuing alarms. The controlled equipment requires continuous monitoring to evaluate the effectiveness of the treatment, and control strategies are dynamically adjusted based on feedback data to ensure system safety and stability. The results of all processing and control procedures are fed back into the system to optimize future operation and response strategies.
[0044] In one implementation of this application, the operating state of a third object is determined, and a variational autoencoder (VAE) algorithm is used to analyze the second target of the third object. The VAE performs in-depth analysis of the second target data of the third object. By learning the high-dimensional data distribution of the device under normal operating conditions, the VAE can effectively reconstruct the input data. When the operating data of the third object is abnormal, the reconstruction error of the VAE will increase significantly, indicating potential anomalies or faults.
[0045] By combining reconstruction errors with the temporal characteristics of the data, dynamic weighting coefficients and time windows are introduced to more accurately identify anomalies. The formula is expressed as follows:
[0046]
[0047] in, Let X represent the reconstruction error function, where X represents the input dataset of the device, and t represents the current time point. This indicates at time point t i VAE reconstruction error at time ω ( t i) This represents the time weighting coefficient, where T represents the time window size, and exp... ( -αt ) This represents the exponential decay factor.
[0048] Next, the reconstruction error generated by the VAE is used as input and passed to the fuzzy logic system. The fuzzy logic system uses fuzzy logic theory to divide the device's health status into multiple fuzzy intervals, such as "normal," "warning," and "fault," instead of using hard thresholds. By inputting the reconstruction error of the device's operating data, the fuzzy logic system assesses the device's health status according to preset fuzzy rules.
[0049] The formula for health assessment of a fuzzy logic system is expressed as:
[0050]
[0051] Where H(X) represents the health assessment result of the equipment or system status, μ represents the reconstruction error of the Xth data feature at time t in the VAE model. normal The fuzzy membership function representing the "normal" state, μ warning The fuzzy membership function representing the "warning" status, μ fault A fuzzy membership function representing the "fault" state.
[0052]
[0053] Where, μ normal(x) represents the membership function between the device state and the "normal" state, μ warning (x) represents the membership function between the device status and the "warning" status, μ fault (x) represents the membership function between the device state and the "fault" state, μ fault (x) represents the degree to which the current device state is close to the "fault" state, where x represents the current device state variable. These represent the center values for the "normal", "warning", and "fault" states, respectively; σ normal ,σ warning ′σ fault The standard deviations represent the "normal", "warning", and "fault" states, respectively. It represents the absolute difference between device state x and the corresponding state center value. max(0,·) means that this operation ensures that the value of the membership function is not negative.
[0054] In an optional embodiment, the running state of the third object is determined, and the second objective of the third object is analyzed using a combination of principal component analysis (PCA) and independent component analysis (ICA) algorithms.
[0055] First, operational data from the third object is collected, including key parameters acquired by various sensors (such as temperature, pressure, and current). Next, Principal Component Analysis (PCA) is used to reduce the dimensionality of this multidimensional data, extracting the main feature components, reducing data redundancy, and highlighting the main trends. Subsequently, Independent Component Analysis (ICA) is applied to further decompose the PCA-processed data, identifying independent signal sources, which helps distinguish different fault modes and abnormal signals.
[0056] Algorithms that combine PCA and ICA can effectively extract key features that affect the health status of a third object and separate independent sources of abnormal signals, thereby improving the accuracy and sensitivity of fault diagnosis.
[0057] Then, the feature values extracted by PCA and ICA are used as input and passed to the fuzzy logic system. Instead of using hard thresholds, the fuzzy logic system maps these feature values to multiple fuzzy intervals (such as "healthy," "warning," and "fault") using predefined fuzzy rules. This approach can handle the uncertainty and fuzziness of equipment health status, providing smoother and more consistent health assessment results. For example, when a critical parameter approaches a fault threshold, the fuzzy logic system does not immediately classify it as a "fault," but instead outputs a fuzzy value between "healthy" and "fault," indicating the need for further monitoring or preventative maintenance.
[0058] Furthermore, by monitoring and analyzing the status of equipment or subsystems in real time, their health status can be dynamically identified and timely control measures can be taken to ensure the safety and stability of system operation. By adjusting equipment operating parameters, switching redundant systems, or issuing alarms, potential anomalies or malfunctions can be responded to quickly. Continuous monitoring and feedback data can optimize control strategies, improve the system's adaptability and emergency response efficiency, and ultimately achieve intelligent and automated equipment management and maintenance.
[0059] Example 2, refer to Figure 2 As an embodiment of the present invention, a security event data statistics system is provided, comprising:
[0060] S110, receive inspection script.
[0061] S120, based on the inspection script, forms a time probe for the system protection function.
[0062] S130 allocates time probes based on the characteristic values between the system protection function and each security data function.
[0063] S140, start the inspection script to link with the time probe.
[0064] S150 receives real-time data from various security data functions.
[0065] Specifically, the platform provides a way to connect devices using Python scripts. Users can write their own Python code to integrate or add functions to the integration to connect various products and devices, or enrich the calling functions of already connected products and devices.
[0066] By integrating various devices and their inherent inspection scripts, hundreds of system protection functions and various security data functions can be called without secondary writing. For devices with already integrated instances, the inherent functions of that device can be called directly. Numerous built-in scripts are also designed, which can be called directly during task execution. This saves users the time previously spent sorting out and integrating device functions, truly achieving an "out-of-the-box" effect.
[0067] Through function calls, the platform also supports scheduled scheduling of already launched scripts to achieve purposes such as scheduled inspections. Each scheduled job is displayed in a list format, and provides functions such as "Run Now," "Close Job," "Edit Job," and "View Job," displaying the current job's run time and next run time in a detailed and intuitive way.
[0068] The platform allows users to view basic information about scheduled jobs on the front end, including "Job Basic Information," "Job Records," and "Current Participants in the Job." It also supports viewing the workflow status of each job record. The "Workflow Status Display" shows the inputs and outputs of each job and the results generated by each task, achieving both automation and information transparency.
[0069] This embodiment relates to a scheduled system inspection task. The safety automation orchestration and response platform can script routine inspections and other activities for scheduled operation, saving daily maintenance time. It displays the current and next execution times of the task in detail and intuitively. While achieving automation, it also ensures information transparency and enhances the coordination between safety equipment systems.
[0070] In one embodiment of this application, S200 includes:
[0071] S210, Select a time probe.
[0072] S220, referencing the real-time data corresponding to this time probe.
[0073] S230, based on the inherent functions and built-in scripts of the security device corresponding to the time probe, parses the security level of real-time data.
[0074] S240, return to the step of selecting a time probe, until all time probes have been selected.
[0075] S250 automates the workflow orchestration of real-time data based on its security level.
[0076] Specifically, a graphical script editing interface is designed to support the creation of four different types of task nodes: "Action Execution," "Conditional Branch," "User Hints," and "Script." Users can configure a task node simply by dragging and dropping and selecting.
[0077] By integrating various devices and their inherent scripts, the system enables function calls and parses the security level of real-time data. For devices with already integrated instances, the system can directly call the functions inherent to that device. Numerous built-in scripts are also designed for direct invocation during task execution.
[0078] In one embodiment of this application, S300 includes:
[0079] S310, select a real-time data.
[0080] The S320 uses data filters and converters to decode and clean the real-time data, generating a work order to be analyzed.
[0081] Specifically, the platform supports filtering and transforming the data passed in to the task before passing it to the function for command invocation. This approach reduces the trouble and time wasted due to issues such as incorrect data format and the need to organize data, significantly improving the efficiency of task invocation.
[0082] S330, execute script test for work orders to be analyzed.
[0083] Specifically, during the scriptwriting process using the platform's graphical script editing interface, users can choose to directly input the output of prerequisite tasks, fixed parameters of events, and user-configured script inputs as tasks for task flow. The same script will produce different results for different event inputs.
[0084] S340 determines whether the work order to be analyzed is running normally based on the test results.
[0085] S350, if the work order to be analyzed is running normally, return to the step of selecting a real-time data point until all real-time data points have been selected.
[0086] S360, if the work order to be analyzed is not running normally, the real-time data will be included in the abnormal dataset, and the process will return to selecting a real-time data until all real-time data have been selected.
[0087] Specifically, the platform's script nodes call device-specific functions and use built-in scripts, and each node depends on the output of preceding tasks. During script execution, the script test mode can be entered at any time to simulate input events and check the script's running status in real time, thereby identifying various errors during the automated workflow process.
[0088] In one embodiment of this application, S500 includes:
[0089] S500: Select a real-time data point from the abnormal dataset → S520: Invoke the data filter and converter to clean and decode the data.
[0090] S530: Perform unit tests to evaluate the validity of the data functions → S540: Use random forest to perform a preliminary risk assessment of the device and screen out relevant features.
[0091] S550: Perform XGBoost training based on the selected features to further analyze whether the device has security risks → S560: Determine whether the device has system security risks.
[0092] S570: Affix labels to high-risk devices → S580: Perform integration testing to determine if there are system-level security risks → S590: If the device is not risky, return to select the next device for testing, until all devices are completed.
[0093] Specifically, based on the platform's functional implementation, testing and verification will be conducted, including unit testing, integration testing, system testing, and acceptance testing, to verify the platform's functional correctness, performance stability, security reliability, and user satisfaction. Platform testing and verification will be carried out in the following aspects.
[0094] Choose a suitable cybersecurity incident collaborative response platform product based on your organization's size, business needs, security goals, and budget.
[0095] Deploy and configure the cybersecurity incident collaborative response platform according to product documentation or service provider guidance, ensuring that it can integrate with existing security devices and systems to collect and process cybersecurity data and alerts of concern.
[0096] Define and optimize cybersecurity incident handling processes based on organizational characteristics and business scenarios, including incident classification, prioritization, responsible parties, and response measures. The orchestration and automation capabilities provided by a cybersecurity incident collaborative response platform can be leveraged to transform these processes into executable scripts, which can then be regularly audited and updated.
[0097] To verify the functionality and effectiveness of the collaborative response platform for cybersecurity incidents, some common or specific cybersecurity incidents can be simulated and tested to observe how the platform collects, analyzes, handles, and reports these incidents, and to evaluate the platform's role in improving detection speed, reducing response time, and minimizing human intervention.
[0098] After the simulation and testing are completed, the test results can be collected and analyzed, including indicators such as platform operating status, event handling, and response effectiveness.
[0099] These metrics can be used to evaluate the performance, reliability, and ease of use of a network security incident collaborative response platform, and the platform configuration or process settings can be adjusted based on test feedback.
[0100] The S600 includes:
[0101] S610 (Establish a visual interface for group chat): The visual interface for group chat serves as the foundation for monitoring and collaboration, providing collaborative support for subsequent decision-making.
[0102] S620 (with added data interface): The platform imports real-time data from the device into the analysis system via the data interface. At this point, the VAE algorithm begins to reconstruct and detect anomalies in the device's operational data. By learning the high-dimensional data distribution of the device under normal conditions, the VAE can automatically identify behaviors that are significantly different from the normal operating mode, alerting potential anomalies.
[0103] S630 (Execute Security Data Function, System Protection Function Call): Executes the device's security data function to further analyze the abnormal data identified by VAE in order to determine the health status of the device and provide a basis for subsequent troubleshooting.
[0104] By combining reconstruction errors with the temporal characteristics of the data, and introducing dynamic weighting coefficients and time windows, anomalies can be identified more accurately. The formula for determining the health status of the equipment is expressed as follows:
[0105]
[0106] in, Let X represent the reconstruction error function, where X represents the input dataset of the device, and t represents the current time point. This indicates at time point t i VAE reconstruction error at time ω ( t i) This represents the time weighting coefficient, where T represents the time window size, and exp... ( -αt ) This represents the exponential decay factor.
[0107] S650-S700: Safety Equipment Monitoring and Fault Diagnosis
[0108] In this stage, the VAE's reconstruction error results are incorporated into the fuzzy logic system to achieve a more detailed assessment of the equipment's health status.
[0109] S650 (calling the work order system and inspection script): The platform automatically starts the inspection script based on the results of VAE analysis, conducts in-depth inspection of equipment that may have abnormalities, and collects abnormal data of the equipment.
[0110] S710 (Select tagged safety devices): The devices marked as abnormal are entered into the system and assigned to relevant personnel for handling via the work order system.
[0111] At this point, the reconstruction error generated by the VAE is passed as input to the fuzzy logic system to further assess the health status of the device.
[0112] S710-S720 (Labeling and Inspection): The system uses fuzzy logic to classify the health status of equipment into multiple levels. Through fuzzy logic rules, lower reconstruction errors may be classified as "normal" status, while higher reconstruction errors may be classified as "fault" status.
[0113] The formula for health assessment of a fuzzy logic system is expressed as:
[0114]
[0115] Among them, H (X ) The results of a health assessment indicate the status of the equipment or system. μ represents the reconstruction error of the Xth data feature at time t in the VAE model. normal The fuzzy membership function representing the "normal" state, μ warning The fuzzy membership function representing the "warning" status, μ fault: A fuzzy membership function representing the "fault" state.
[0116]
[0117] Where, μ normal ( x ) The membership function μ represents the device status and the "normal" status. warning ( x represents the membership function between the device status and the "warning" status, μ fault( x ) The membership function μ represents the relationship between the device state and the "fault" state. fault9 x ) This indicates how close the current device state is to a "fault" state, where x represents the current device state variable. These represent the center values for the "normal", "warning", and "fault" states, respectively; σ normal ,σ warning ′σ fault The standard deviations represent the "normal", "warning", and "fault" states, respectively. It represents the absolute difference between device state x and the corresponding state center value. max(0,·) means that this operation ensures that the value of the membership function is not negative.
[0118] S800-S900: Risk Response and Management
[0119] In this phase, based on the output of the VAE and fuzzy logic system, the platform responds to and remediates risks associated with the device:
[0120] S800 (Risk Response) uses the reconfiguration error generated by VAE to determine whether the device is in an abnormal state, and uses a fuzzy logic system to determine the level of the abnormality, such as "early warning" or "fault". If an abnormality is detected, the system will notify the corresponding security device group of the security event and initiate the repair process.
[0121] S900 (Event Display and Handling): The platform displays risk events and their status, enabling collaboration through group chat and a visual interface. All event and handling records are transparently displayed on the platform, allowing users to view the anomaly detection status and repair status of each device.
[0122] Example 3, an embodiment of the present invention, differs from the previous two embodiments in that:
[0123] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0124] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.
[0125] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.
[0126] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0127] Example 4: An experiment was conducted. The experimental environment included a network security platform integrating various security devices such as firewalls, intrusion detection systems (IDS), antivirus gateways, and web application firewalls (WAF). Inspection scripts and function libraries were written using Python to automate the inspection and data collection of each security device.
[0128] First, the system receives inspection scripts from various security devices (S110). These scripts cover functions such as device status query, log acquisition, and performance indicator collection. Based on these inspection scripts, time probes are formed for the system protection functions (S120), with each time probe corresponding to a specific security device and inspection task. By analyzing the characteristic values between the system protection functions and various security data functions, such as device response time, CPU utilization, and memory usage, time probes are rationally allocated (S130) to ensure that critical devices receive more frequent inspections.
[0129] Subsequently, the inspection script was initiated in conjunction with the time probe (S140) to perform scheduled inspections of each security device. The inspection script uses the platform's Python interface to call the inherent functions of each security device, eliminating the need for secondary code writing. The platform also includes several built-in scripts, such as those for anomaly log analysis and traffic anomaly detection, which can be directly invoked during task execution. During the inspection process, real-time data from various security data functions is received (S150), including device operating status, performance indicators, and security event logs.
[0130] To further process the real-time data, a time probe was selected (S210), and its corresponding real-time data was referenced (S220). Based on the inherent functions and built-in scripts of the security device corresponding to the time probe, the security level of the real-time data was parsed (S230), and security events were divided into three levels: "Normal," "Warning," and "Critical." The above steps were repeated until all time probes were processed (S240). According to the security level of the real-time data, an automated workflow orchestration was performed on the real-time data (S250). In the platform's graphical script editing interface, task nodes such as "Action Execution," "Conditional Branch," "User Prompt," and "Script" were created, realizing automated response to security events.
[0131] Next, a real-time data point is selected (S310), and the data is decoded and cleaned using a data filter and converter to form a work order to be analyzed (S320). In the work order system, a script test is performed on the work order to be analyzed (S330), and the test results are used to determine whether the work order is running normally (S340). If it is running normally, the process returns to selecting the next real-time data point until all real-time data has been processed (S350); if it is not running normally, the real-time data is added to the abnormal dataset, and the process continues with the next real-time data point (S360). During the script test, the device's inherent functions and built-in scripts are called, relying on the output of the preceding tasks. The system enters script test mode at any time, simulates input events, checks the script's running status in real time, and identifies and resolves various problems encountered during the automated workflow process.
[0132] To evaluate the effectiveness of the algorithm, a variational autoencoder (VAE) was used for in-depth analysis of the abnormal data. The VAE effectively reconstructs the input data by learning the high-dimensional data distribution of the device under normal operating conditions. When the device's operating data becomes abnormal, the reconstruction error of the VAE increases significantly, indicating potential anomalies or faults. The reconstruction error generated by the VAE is used as input to a fuzzy logic system. The fuzzy logic system uses fuzzy logic theory to divide the device's health status into multiple fuzzy intervals such as "normal," "warning," and "fault." Based on the reconstruction error of the input device operating data, the fuzzy logic system evaluates the device's health status according to preset fuzzy rules. The experimental results are shown in Table 1.
[0133] Table 1 Experimental Results
[0134]
[0135]
[0136] As can be seen from the table data, the method of this invention has significant advantages in detecting equipment anomalies and assessing safety risks. Firstly, key performance indicators such as CPU utilization, memory usage, and response time collected through the inspection script provide an initial reflection of the operating status of each device. For example, devices D and F both have CPU utilization and memory usage exceeding 85%, and their response times are significantly higher than other devices, indicating that they are under significant operating pressure and may have performance bottlenecks.
[0137] Furthermore, VAE was used to perform in-depth analysis of the equipment operation data to calculate the reconstruction error. The reconstruction errors of normally operating equipment (such as equipment A and equipment C) were relatively low, at 0.02 and 0.01 respectively, while the reconstruction errors of abnormal equipment (such as equipment D and equipment F) increased significantly, at 0.25 and 0.30 respectively. This indicates that VAE can effectively capture abnormal changes in the operating status of equipment.
[0138] The reconstruction error of the VAE is input into a fuzzy logic system to assess the health status of the devices. The fuzzy logic assessment results show that devices D and F are classified as "faulty," devices B and G as "warning," and the remaining devices as "normal." Compared to traditional hard threshold judgment methods, the fuzzy logic system can more flexibly handle the uncertainty and fuzziness of data, providing smoother and more continuous health assessment results.
[0139] Based on the results of the fuzzy logic assessment, the safety levels of the equipment were further classified, and corresponding handling measures were formulated. For high-risk equipment D and F, an "emergency repair" measure was implemented, immediately notifying relevant personnel to troubleshoot and repair the fault. For medium-risk equipment B and G, a "parameter adjustment" measure was implemented, appropriately reducing their workload or optimizing their configuration. For low-risk equipment A, C, and E, "monitoring" continued to ensure their stable operation.
[0140] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A method for statistical analysis of security incident data, characterized in that, include: Each second object is incorporated into the first object, and the first target check is performed to obtain the first target check data. Process the data from the first target inspection to identify the third object; The third object is processed for the second objective, and the third object is then regulated based on the processing results; The process of determining the third object includes automatically processing the inspection data of the first target to obtain the running status of all second objects and generating the third object. The automated processing of the first target inspection data includes processing the first target inspection result data using an algorithm combining random forest and XGBoost to obtain the state of all second objects and generate a third object; The second target processing of the third object includes analyzing the second target of the third object and determining the state of the third object; The determination of the state of the third object includes analyzing the second target of the third object using a variational autoencoder algorithm to determine the state of the third object; The analysis of the second target of the third object using the variational autoencoder algorithm includes taking the reconstruction error generated by the variational autoencoder as input and passing it to the fuzzy logic system, and the fuzzy logic system evaluating the health status of the device according to the preset fuzzy rules. The first object is the smart home control system, the second object is the various home subsystems, and the third object is the equipment that has malfunctions or potential risks.
2. The security incident data statistics method as described in claim 1, characterized in that: Each second object is included in the first object. Multiple second objects are received, and one of the second objects is selected to form the feature function of the second object. Return to the previous step and select a second object, until all second objects have been selected; Extract the feature values of each second object feature function to form the first object feature function.
3. The security incident data statistics method as described in claim 2, characterized in that: The first target check includes performing a first target check on the first object based on the first target. By combining the feature values of the first object feature function and each second object feature function, the first target inspection data fed back by the second object feature function is received; The first target inspection data includes data reflecting the operating status of the first object and the inspection results of the first target.
4. A security incident data statistics system employing the method described in any one of claims 1-3, characterized in that: The data processing module incorporates each second object into the first object, performs a first target check, and obtains the first target check data. The data inspection module processes the first target inspection data and determines the third object. The determination of the third object includes automatically processing the first target inspection data to obtain the running status of all second objects and generating the third object. The automatic processing of the first target inspection data includes using a random forest combined with XGBoost algorithm to process the first target inspection result data to obtain the status of all second objects and generate the third object. The control module performs second target processing on a third object and controls the third object based on the processing result. The second target processing on the third object includes analyzing the second target of the third object and determining the state of the third object. The determination of the state of the third object includes analyzing the second target of the third object using a variational autoencoder algorithm and determining the state of the third object. The analysis of the second target of the third object using the variational autoencoder algorithm includes taking the reconstruction error generated by the variational autoencoder as input and passing it to the fuzzy logic system. The fuzzy logic system evaluates the health status of the device according to preset fuzzy rules. The first object is the smart home control system, the second object is the various home subsystems, and the third object is the equipment that has malfunctions or potential risks.
5. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the security processing event data statistics method according to any one of claims 1 to 3.
6. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the security processing event data statistics method according to any one of claims 1 to 3.
Citation Information
Patent Citations
New energy vehicle health assessment method and device based on multi-feature fusion
CN116541790A
Intelligent household electrical appliance fault automatic diagnosis and closed loop system and method based on big data
CN118502398A