A network security threat situation assessment system based on AI technology

Through the analysis and real-time monitoring of historical access data, threat assessment and prediction models are built, the risk of crash of network systems under high access volume is solved, and the stability and user experience of network systems are improved.

CN119696917BActive Publication Date: 2025-08-19SHANDONG ZHONGKEZEDA SOFTWARE TECHNOLOGY SERVICE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411950631.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-08-19
Estimated Expiration
2044-12-27

AI Technical Summary

Technical Problem

The existing technology lacks quantitative analysis of network bandwidth and number of visitors, which leads to the inability of timely warning of network systems during peak access, increasing the risk of system crashes and affecting user experience and enterprise operation costs.

Method used

By analyzing the access data when the system crashes in the historical cycle, obtaining bandwidth crash threshold and efficiency warning values, building a threat evaluation model, monitoring network bandwidth and number of visitors in real time, generating threat signals, and building a prediction model based on the warning area curve, and performing a countdown warning display.

Benefits of technology

Dynamic assessment and early warning of network security threats is realized, the risk of system crashes is reduced, and the stability and user experience of the network system are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119696917B_ABST
    Figure CN119696917B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of network security threats, and in particular to an AI-based network security threat situation assessment system. The system comprises the following steps: analyzing access data during system crashes in a historical period to obtain a bandwidth crash threshold; setting a bandwidth efficiency warning value based on the bandwidth crash threshold; analyzing access data acquired in real time during a monitoring period to generate a threat signal based on the bandwidth efficiency warning value; analyzing a warning area curve based on the threat signal to obtain a linear performance value; determining a change type of the warning area curve based on the linear performance value; and constructing an applicable prediction model based on the change type of the warning area curve. The system can display a countdown warning of the remaining time until the bandwidth efficiency value reaches the bandwidth crash threshold, thereby preventing system failures or performance degradations caused by bandwidth efficiency issues in advance, effectively improving the stability of the entire network system operation, and reducing the risk of system crashes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security threat technology, and in particular to a network security threat situation assessment system based on AI technology. Background Art

[0002] In today's digital age, the stable operation of network systems affects many aspects. For enterprises, system crashes may mean serious consequences such as loss of orders, decreased customer satisfaction, and damaged business reputation. For public service areas, such as government systems and medical information systems, system failures may affect social order and people's normal lives.

[0003] In the past, network management mostly adopted a post-remediation approach, that is, the cause was only found and the fault was repaired after the system had already experienced problems such as freezing and crashing. There was a lack of early and dynamic analysis and early warning mechanisms for network operation conditions. After the network crashed, it would directly lead to an increase in the network security threat index. There was also a lack of quantitative analysis of the relationship between network bandwidth and the number of visitors. Effective measures could not be taken to prevent problems before they occurred, resulting in a damaged user experience and increased enterprise operating costs due to frequent fault repairs.

[0004] To this end, we propose a network security threat system based on AI technology. Summary of the Invention

[0005] The object of the present invention is to provide an integrated and efficient method for oxidatively removing hypophosphorous acid from chemical plating wastewater, so as to solve at least one of the above-mentioned problems of the prior art.

[0006] Threat Assessment Module: Analyzes access data during system crashes in historical periods to obtain a bandwidth crash threshold. Based on the bandwidth crash threshold, a bandwidth efficiency warning value is set. Based on the bandwidth efficiency warning value, during the monitoring period, real-time access data is analyzed to obtain a threat assessment value. If the threat assessment value is greater than the threat assessment threshold, a threat signal is generated.

[0007] Among them, access data includes network bandwidth and number of visitors;

[0008] Linear analysis module: Based on the threat signal, the warning area curve is analyzed to obtain a linear performance value. If the linear performance value is greater than the linear performance threshold, it indicates that the change type of the warning area curve is linear. If the linear performance value is less than or equal to the linear performance threshold, it indicates that the change type of the warning area curve is non-linear.

[0009] Prediction model selection and analysis module: Based on the change type of the warning zone curve, an applicable prediction model is constructed, and based on the prediction model, the predicted bandwidth efficiency value is analyzed;

[0010] Approaching trend analysis module: During the forecast period, the bandwidth efficiency value is continuously monitored in real time. The real-time monitored bandwidth efficiency value is compared and analyzed with the forecasted bandwidth efficiency value at different time points to obtain the approaching trend value. If the approaching trend value is greater than the approaching trend threshold, an approaching trend signal is generated. If the approaching trend value is less than or equal to the approaching trend threshold, a non-approaching trend signal is generated. Based on the approaching trend signal, a countdown warning display is performed.

[0011] Regulation and control analysis module: Based on the non-approaching signal, the non-approaching performance value is analyzed. If the non-approaching performance value is greater than the non-approaching performance threshold, an adjustment signal is generated. Based on the adjustment signal, a countdown warning display is performed.

[0012] Beneficial effects of the present invention:

[0013] 1. The present invention analyzes access data during system crashes in historical periods to obtain a bandwidth crash threshold. Based on the bandwidth crash threshold, a bandwidth efficiency warning value is set. Based on the bandwidth efficiency warning value, during the monitoring period, the real-time acquired network bandwidth and the corresponding number of visitors are analyzed to obtain a threat assessment value. If the threat assessment value is greater than the threat assessment threshold, a threat signal is generated. The present invention dynamically analyzes the network operation status before the system crash and evaluates the possibility of network security threats, which is conducive to optimizing user experience, timely discovering risks, and avoiding system freezes or even crashes due to an increase in the number of visitors.

[0014] 2. Based on the threat signal, the warning area curve is analyzed to obtain a linear performance value. The change type of the warning area curve is determined based on the linear performance value. Based on the change type of the warning area curve, an applicable prediction model is constructed. Based on the prediction model, a predicted bandwidth efficiency value is analyzed and obtained. During the prediction period, the bandwidth efficiency value is continuously monitored in real time, and the real-time monitored bandwidth efficiency value is compared and analyzed with the predicted bandwidth efficiency value at different time nodes to obtain a situation approach value. If the situation approach value is greater than the situation approach threshold, an approach signal is generated. Based on the approach signal, a countdown warning display is performed. Through the analysis, prediction, monitoring and warning process, the present invention can display a countdown warning of the remaining time for the bandwidth efficiency value to reach the bandwidth collapse threshold, thereby preventing system failures or performance degradation caused by bandwidth efficiency problems in advance, effectively improving the stability of the entire network system operation, and reducing the risk of system collapse.

[0015] 3. Based on the non-approach signal, a non-approach performance value is analyzed. If the non-approach performance value is greater than the non-approach performance threshold, an adjustment signal is generated. Based on the adjustment signal, a countdown warning display is performed. When the bandwidth efficiency values at different time nodes do not approach the predicted bandwidth efficiency value, the present invention analyzes whether the degree to which the bandwidth efficiency values at different time nodes do not approach the predicted bandwidth efficiency value is similar. If so, the bandwidth collapse threshold is adjusted based on the overall degree of non-approach and input into the model to accurately predict the remaining time for the bandwidth efficiency value to reach the bandwidth collapse threshold. When the actual bandwidth efficiency value and the predicted bandwidth efficiency value do not approach each other, the bandwidth collapse threshold input is changed to accurately predict the remaining time for the bandwidth efficiency value to reach the bandwidth collapse threshold, which is conducive to stable system operation. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0017] Figure 1 This is a schematic diagram of the structure of a network security threat situation assessment system based on AI technology provided in Example 1 of the present invention;

[0018] Figure 2 This is a schematic diagram of the structure of a network security threat situation assessment device based on AI technology provided by the fourth embodiment of the present invention;

[0019] Figure 3 It is a structural diagram of an electronic device according to an embodiment of the present invention.

[0020] Figure numbers: 3, computer device; 301, processor; 302, memory; 303, computer program. DETAILED DESCRIPTION

[0021] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0022] Example 1

[0023] Figure 1A flowchart of a network security threat situation assessment system based on AI technology is provided for the first embodiment of the present invention. The embodiment of the present invention is applicable to situations where the system crashes due to an increase in the number of visitors. The network security threat situation assessment system based on AI technology can be executed by a network security threat situation assessment method based on AI technology. The network security threat situation assessment system based on AI technology can be implemented by software and hardware. The network security threat situation assessment system based on AI technology can be configured in a network security threat situation assessment device based on AI technology. Optionally, the network security threat situation assessment device based on AI technology can be an electronic device, which can be a notebook, desktop computer, smart tablet, etc., and the embodiment of the present invention does not limit this.

[0024] like Figure 1 As shown, an embodiment of the present invention provides a network security threat situation assessment system based on AI technology, specifically including:

[0025] Threat Assessment Module: Analyzes access data during system crashes in historical periods to obtain a bandwidth crash threshold. Based on the bandwidth crash threshold, a bandwidth efficiency warning value is set. Based on the bandwidth efficiency warning value, during the monitoring period, real-time access data is analyzed to obtain a threat assessment value. If the threat assessment value is greater than the threat assessment threshold, a threat signal is generated.

[0026] Among them, access data includes network bandwidth and number of visitors;

[0027] It should be noted that the bandwidth efficiency warning value is greater than the bandwidth collapse threshold DX 阈 ;

[0028] Obtain the network bandwidth and number of visitors during the system crash period in the historical period;

[0029] It should be noted that in Linux systems, command-line tools such as iftop, nload, and ifstat are used to monitor network bandwidth in real time, and to record and save the information in logs before a system crash. After a system crash, logs should be collected as soon as possible and analyzed to calculate the network bandwidth and number of visitors at the time of the crash.

[0030] The bandwidth crash value is obtained by performing a ratio calculation between the network bandwidth and the number of visitors when the system crashes.

[0031] For example, the system's network bandwidth is 1000 Mbps, which can normally support 5 users performing network activities simultaneously. Suppose that when the network crashes, there are 10 users accessing the network at the same time. The ratio of network bandwidth to number of users is 1000 Mbps / 10 people = 100 Mbps / person, that is, bandwidth crash value = 100 Mbps / person;

[0032] The bandwidth collapse threshold DX is obtained by summing and averaging all bandwidth collapse values when the system crashes in the historical period. 阈 ;

[0033] During the monitoring period, the monitoring period is divided into several monitoring time points, and the network bandwidth and the corresponding number of visitors at the monitoring time points are obtained in real time. The network bandwidth and the corresponding number of visitors at the monitoring time points are ratio-processed to obtain the bandwidth efficiency value;

[0034] Construct a bandwidth efficiency value change curve in a two-dimensional coordinate system, where time is the x-axis and the y-axis is the bandwidth efficiency value;

[0035] Mark the bandwidth efficiency warning value in a two-dimensional coordinate system, draw a straight line parallel to the x-axis through the marked point, and mark it as the bandwidth efficiency warning line;

[0036] Set the bandwidth collapse threshold DX 阈 Mark in the two-dimensional coordinate system, draw a straight line parallel to the x-axis through the marked point, and mark it as the bandwidth collapse line;

[0037] If the bandwidth efficiency value is less than the bandwidth efficiency warning value, no action is taken and real-time monitoring continues;

[0038] If the bandwidth efficiency value is greater than the bandwidth efficiency warning value and less than the bandwidth collapse threshold DX 阈 , then generate analysis signal;

[0039] Based on the analysis signal, the bandwidth efficiency value change curve below the bandwidth efficiency warning line curve segment is marked as the warning zone curve, obtain the bandwidth efficiency value in the warning zone curve, and marked as DX;

[0040] Obtain the duration corresponding to the warning zone curve, perform ratio processing on the duration corresponding to the warning zone curve and the duration corresponding to the monitoring period to obtain the time duration ratio SC;

[0041] The bandwidth efficiency value DX and the time duration ratio SC in the warning area curve are processed by the formula: The threat assessment value YB is calculated, where s1 and s2 are preset proportional coefficients, N represents the total number of bandwidth efficiency values in the warning area curve, s1 is 1.656, and s2 is 1.669;

[0042] It should be noted that the threat assessment value is obtained by processing the over-limit value DP and the time duration ratio SC. The over-limit value DP reflects the deviation of the warning area curve from the bandwidth collapse line. The smaller the deviation, the closer the warning area curve is to the bandwidth collapse line, and the greater the threat to the system. The time duration ratio SC reflects the duration of the warning area curve exceeding the bandwidth efficiency warning line. The longer the duration, the greater the threat to the system.

[0043] Compare the threat assessment value to the threat assessment threshold:

[0044] If the threat assessment value is greater than the threat assessment threshold, it indicates that the possibility of network security threats within the monitoring period is high, and a threat signal is generated;

[0045] If the threat assessment value is less than or equal to the threat assessment threshold, it means that the possibility of network security threat during the monitoring period is low, and a non-threat signal is generated;

[0046] The technical solution of the embodiment of the present invention is mainly as follows: analyzing the access data when the system crashes in the historical period to obtain the bandwidth crash threshold, setting the bandwidth efficiency warning value based on the bandwidth crash threshold, and analyzing the network bandwidth and the corresponding number of visitors in the monitoring period based on the bandwidth efficiency warning value to obtain a threat assessment value. If the threat assessment value is greater than the threat assessment threshold, a threat signal is generated. The present invention dynamically analyzes the network operation status before the system crash and evaluates the possibility of network security threats, which is conducive to optimizing user experience, timely discovering risks, and avoiding system freezes or even crashes due to an increase in the number of visitors.

[0047] Example 2

[0048] like Figure 1 As shown, an embodiment of the present invention provides a network security threat situation assessment system based on AI technology, which specifically includes the following steps:

[0049] Linear analysis module: Based on the threat signal, the warning area curve is analyzed to obtain a linear performance value. If the linear performance value is greater than the linear performance threshold, it indicates that the change type of the warning area curve is linear.

[0050] Obtain the corresponding warning area curve, divide the warning area curve into warning area curve segments of equal horizontal length, obtain the slope values of the warning area curve segments, mark the warning area curve segments with negative slope values as negative slope curve segments, count the number of negative slope curve segments in the warning area curve segments, mark them as the total number of negative slope curve segments, and perform ratio processing on the total number of negative slope curve segments and the total number of warning area curve segments to obtain the negative slope curve segment number ratio FQ;

[0051] Connect the two end points of the warning area curve with a straight line to obtain the change reference line, measure the overlap length between the warning area curve and the change reference line, and perform ratio processing with the length of the change reference line to obtain the situation overlap value BH;

[0052] The negative slope curve segment ratio FQ and the situation overlap value BH are processed and the formula is used: The linear performance value XB is calculated, where a1 and a2 are preset proportional coefficients, a1 is 0.568, and a2 is 0.631;

[0053] Compare the linear performance value to the linear performance threshold:

[0054] If the linear performance value is greater than the linear performance threshold, it means that the change type of the warning area curve is linear;

[0055] If the linear performance value is less than or equal to the linear performance threshold, it means that the curve change type of the warning area is nonlinear;

[0056] Prediction model selection and analysis module: Based on the change type of the warning zone curve, an applicable prediction model is constructed, and based on the prediction model, the predicted bandwidth efficiency value is analyzed;

[0057] All bandwidth efficiency values of the warning zone curve are integrated into a dataset as a training dataset. If the change type of the warning zone curve is linear, a linear regression model is selected as the prediction model based on AI technology. If the change type of the warning zone curve is nonlinear, a random forest network model is selected as the prediction model based on AI technology. The prediction model is trained using the training dataset to obtain a trained prediction model.

[0058] Set the bandwidth collapse threshold DX 阈 Input into the prediction model to obtain the bandwidth efficiency value reaching the bandwidth collapse threshold DX 阈 The time point is marked as the arrival time point, and the difference between the arrival time point and the current time point is processed to obtain the bandwidth efficiency value reaching the bandwidth collapse threshold DX 阈 The remaining time is calculated and the time period corresponding to the remaining time is marked as the prediction period;

[0059] Inputting different time nodes within the prediction period into the prediction model to obtain the predicted bandwidth efficiency values at different time nodes within the prediction period;

[0060] Approaching trend analysis module: During the forecast period, the bandwidth efficiency value is continuously monitored in real time. The real-time monitored bandwidth efficiency value is compared and analyzed with the forecasted bandwidth efficiency value at different time points to obtain the approaching trend value. If the approaching trend value is greater than the approaching trend threshold, an approaching trend signal is generated. If the approaching trend value is less than or equal to the approaching trend threshold, a non-approaching trend signal is generated. Based on the approaching trend signal, a countdown warning display is performed.

[0061] Specifically, within the prediction period, a monitoring period is preset, wherein the time length corresponding to the preset monitoring period is shorter than the time length corresponding to the prediction period;

[0062] Obtain the bandwidth efficiency values monitored in real time at different time points during the preset monitoring period and compare them with the predicted bandwidth efficiency values at different time points. Specifically:

[0063] Based on any time point;

[0064] If the bandwidth efficiency value at a time node is not equal to the predicted bandwidth efficiency value, the time node is marked as a different time node;

[0065] If the bandwidth efficiency value at a time node is not equal to the predicted bandwidth efficiency value, the time node is marked as the same time node;

[0066] Count the total number of time nodes and the number of different time nodes within the preset monitoring period, and perform ratio processing on the number of different time nodes and the total number of time nodes within the preset monitoring period to obtain the situation deviation ratio BT;

[0067] Obtain the bandwidth efficiency values at different time nodes, perform difference processing on them with the predicted bandwidth efficiency values at different time nodes, and take the absolute value of the difference to obtain the bandwidth efficiency value deviations at different time nodes. Ratio processing is performed on the bandwidth efficiency value deviations at different time nodes with the predicted bandwidth efficiency values at different time nodes to obtain the bandwidth efficiency value deviation ratios at different time nodes. Sum and average the bandwidth efficiency value deviation ratios of all different time nodes to obtain the situation deviation degree value BJ.

[0068] The situation deviation ratio BT and the situation deviation degree value BJ are processed by data, and the formula is: The situation approach value TQ is obtained, where m1 and m2 are both preset proportional coefficients, m1 is 1.967, and m2 is 1.905;

[0069] Compare the situational proximity value to the situational proximity threshold:

[0070] If the trend approach value is greater than the trend approach threshold, it means that the bandwidth efficiency value change trend during the monitoring period is close to the predicted bandwidth efficiency value change trend, and a trend approach signal is generated;

[0071] If the trend approach value is less than or equal to the trend approach threshold, it means that the bandwidth efficiency value change trend during the monitoring period is not close to the predicted bandwidth efficiency value change trend, and a non-approach signal is generated;

[0072] Based on the approaching signal, the bandwidth efficiency value reaches the bandwidth collapse threshold DX 阈 The remaining time is counted down and warned;

[0073] The technical solution of the embodiment of the present invention mainly includes: analyzing the warning area curve based on the threat signal to obtain a linear performance value, judging the change type of the warning area curve based on the linear performance value, constructing an applicable prediction model based on the change type of the warning area curve, analyzing and obtaining a predicted bandwidth efficiency value based on the prediction model, continuing to monitor the bandwidth efficiency value in real time during the prediction period, and comparing and analyzing the real-time monitored bandwidth efficiency value with the predicted bandwidth efficiency values at different time nodes to obtain a situation approach value. If the situation approach value is greater than the situation approach threshold, an approach signal is generated, and a countdown warning display is performed based on the approach signal. The present invention can display a countdown warning of the remaining time until the bandwidth efficiency value reaches the bandwidth collapse threshold, thereby preventing system failures or performance degradation caused by bandwidth efficiency problems in advance, effectively improving the stability of the entire network system operation, and reducing the risk of system collapse.

[0074] Example 3

[0075] like Figure 1 As shown, an embodiment of the present invention provides a network security threat situation assessment method based on AI technology, which specifically includes the following steps:

[0076] Control analysis module: Based on the non-approaching signal, the non-approaching performance value is analyzed. If the non-approaching performance value is greater than the non-approaching performance threshold, an adjustment signal is generated. Based on the adjustment signal, a countdown warning display is performed;

[0077] Based on the non-approaching signal, the bandwidth efficiency values of different time nodes monitored in real time during the prediction period are obtained, and the difference between the values and the predicted bandwidth efficiency values is processed to obtain the bandwidth efficiency deviation value;

[0078] Count the number of nodes with positive bandwidth efficiency deviation values and the number of nodes with negative bandwidth efficiency deviation values. If the number of nodes with positive bandwidth efficiency deviation values is greater than the number of nodes with negative bandwidth efficiency deviation values, mark the node with positive bandwidth efficiency deviation values as the target node. If the number of nodes with positive bandwidth efficiency deviation values is less than the number of nodes with negative bandwidth efficiency deviation values, mark the node with negative bandwidth efficiency deviation values as the target node. If the number of nodes with positive bandwidth efficiency deviation values is the same as the number of nodes with negative bandwidth efficiency deviation values, it means that the bandwidth efficiency values at different time points are not close to the predicted bandwidth efficiency value to a certain extent, and the analysis is stopped.

[0079] Count the number of target nodes and compare it with the number of nodes at different times to get the target node number ratio MS;

[0080] Integrate all bandwidth efficiency deviation values into a bandwidth efficiency deviation data group, calculate the variance of the bandwidth efficiency deviation values in the bandwidth efficiency deviation data group, and mark it as FC;

[0081] The target node number ratio MS and the variance FC of the bandwidth efficiency deviation value in the bandwidth efficiency deviation data group are processed by the formula: The non-approaching performance value FB is calculated, where n1 and n2 are both preset proportional coefficients, n1 is 1.913, and n2 is 1.444;

[0082] Compare the non-approaching performance value to the non-approaching performance threshold:

[0083] If the non-convergence performance value is greater than the non-convergence performance threshold, it means that the bandwidth efficiency values at different time nodes are not converging to the predicted bandwidth efficiency value to a similar extent, and an adjustment signal is generated;

[0084] If the non-convergence performance value is less than or equal to the non-convergence performance threshold, it means that the bandwidth efficiency values at different time nodes are not close to the predicted bandwidth efficiency value, and no processing is performed;

[0085] Based on the adjustment signal, the bandwidth efficiency deviation values of all target nodes are summed and averaged to obtain the target bandwidth efficiency difference mean. If the target bandwidth efficiency difference mean is positive, the bandwidth collapse threshold DX is set to 阈 The difference between the target bandwidth efficiency difference and the mean value is processed to obtain the adjusted bandwidth collapse threshold, and the value prediction model is re-entered to re-obtain the remaining time. If the target bandwidth efficiency difference mean value is negative, the bandwidth collapse threshold DX is increased. 阈 Sum the result with the absolute value of the mean of the target bandwidth efficiency difference to obtain the adjusted bandwidth collapse threshold, and re-enter the value prediction model to obtain the remaining time.

[0086] The remaining time obtained will be displayed as a countdown warning;

[0087] The technical solution of an embodiment of the present invention is as follows: based on a non-approach signal, a non-approach performance value is analyzed and obtained; if the non-approach performance value is greater than a non-approach performance threshold, an adjustment signal is generated; and based on the adjustment signal, a countdown warning display is performed. When bandwidth efficiency values at different time nodes do not approach the predicted bandwidth efficiency value, the present invention analyzes whether the degree to which the bandwidth efficiency values at different time nodes do not approach the predicted bandwidth efficiency value is similar. If so, the bandwidth collapse threshold is adjusted based on the overall degree of non-approach and input into the model to accurately predict the remaining time for the bandwidth efficiency value to reach the bandwidth collapse threshold. When the actual bandwidth efficiency value and the predicted bandwidth efficiency value do not approach each other, the bandwidth collapse threshold input is changed to accurately predict the remaining time for the bandwidth efficiency value to reach the bandwidth collapse threshold, which is conducive to stable operation of the system.

[0088] Example 4

[0089] like Figure 2 As shown, an embodiment of the present invention provides a network security threat situation assessment method based on AI technology, which specifically includes the following steps:

[0090] Step 1: Analyze access data during system crashes in historical periods to obtain a bandwidth crash threshold. Based on the bandwidth crash threshold, set a bandwidth efficiency warning value. Based on the bandwidth efficiency warning value, analyze the real-time network bandwidth and the corresponding number of visitors during the monitoring period to obtain a threat assessment value. If the threat assessment value is greater than the threat assessment threshold, a threat signal is generated.

[0091] Among them, access data includes network bandwidth and number of visitors;

[0092] Step 2: Based on the threat signal, analyze the warning area curve to obtain a linear performance value. If the linear performance value is greater than the linear performance threshold, it indicates that the change type of the warning area curve is linear. If the linear performance value is less than or equal to the linear performance threshold, it indicates that the change type of the warning area curve is non-linear.

[0093] Step 3: Based on the change type of the warning zone curve, build an applicable prediction model and analyze the predicted bandwidth efficiency value based on the prediction model;

[0094] Step 4: During the forecast period, continue to monitor the bandwidth efficiency value in real time, and compare and analyze the real-time monitored bandwidth efficiency value with the forecast bandwidth efficiency value at different time points to obtain a trend approach value. If the trend approach value is greater than the trend approach threshold, generate a trend approach signal; if the trend approach value is less than or equal to the trend approach threshold, generate a non-trend approach signal, and display a countdown warning based on the trend approach signal;

[0095] Step 5: Based on the non-approaching signal, a non-approaching performance value is analyzed and obtained. If the non-approaching performance value is greater than the non-approaching performance threshold, an adjustment signal is generated. Based on the adjustment signal, a countdown warning display is performed.

[0096] Example 5

[0097] Reference Figure 3 An embodiment of the present invention further provides a computer device 3, comprising: a memory 302, a processor 301, and a computer program 303 stored in the memory 302. When the computer program 303 is executed on the processor 301, a network security threat situation assessment system based on AI technology as described in any one of the above systems is implemented.

[0098] The computer device 3 may be a desktop computer, a notebook computer, a PDA, a cloud server or other computing devices. The computer device 3 may include, but is not limited to, a processor 301 and a memory 302. Those skilled in the art will understand that Figure 3 This is merely an example of the computer device 3 and does not constitute a limitation on the computer device 3 . The computer device 3 may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the computer device 3 may also include input and output devices, network access devices, etc.

[0099] The processor 301 may be a central processing unit (CPU), or other general-purpose processors, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. A general-purpose processor may be a microprocessor or any conventional processor.

[0100] In some embodiments, the memory 302 may be an internal storage unit of the computer device 3, such as a hard drive or memory of the computer device 3. In other embodiments, the memory 302 may also be an external storage device of the computer device 3, such as a plug-in hard drive, a SmartMediaCard (SMC), a Secure Digital (SD) card, a flash memory card, etc. equipped on the computer device 3. Furthermore, the memory 302 may include both an internal storage unit of the computer device 3 and an external storage device. The memory 302 is used to store an operating system, application programs, a boot loader, data, and other programs, such as the program code of the computer program. The memory 302 may also be used to temporarily store data that has been output or is about to be output.

[0101] Example 6

[0102] An embodiment of the present invention also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, it implements a network security threat situation assessment system based on AI technology as described in any one of the above systems.

[0103] In this embodiment, if the integrated unit is implemented as a software functional unit and sold or used as a standalone product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the process steps in the above-mentioned method embodiments by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When executed by a processor, the computer program can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium can include at least: any entity or device capable of carrying computer program code to a camera / terminal device, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signals, telecommunication signals, and software distribution media. Examples include USB flash drives, removable hard drives, magnetic disks, or optical disks. In some jurisdictions, based on legislation and patent practice, computer-readable media cannot be electric carrier signals or telecommunication signals.

[0104] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.

[0105] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0106] In the embodiments disclosed in this application, it should be understood that the disclosed apparatus / terminal equipment and methods can be implemented in other ways. For example, the apparatus / terminal equipment embodiments described above are merely illustrative. For example, the division of the modules or units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed.

[0107] One point is that the coupling or direct coupling or communication connection between each other shown or discussed may be an indirect coupling or communication connection through some interfaces, devices or units, which may be electrical, mechanical or other forms.

[0108] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0109] The above formulas are all dimensionless and numerical calculations. The formulas are obtained by collecting a large amount of data and performing software simulation to obtain the most recent real situation. The preset parameters in the formulas are set by technicians in this field according to actual conditions.

[0110] The above is a detailed description of an embodiment of the present invention. However, the content described is only a preferred embodiment of the present invention and should not be considered to limit the scope of the present invention. All equivalent changes and improvements made within the scope of the present invention should still fall within the scope of the patent coverage of the present invention.

Claims

1. A network security threat situation assessment system based on AI technology, characterized by: include: Threat Assessment Module: Analyzes access data during system crashes in historical periods to obtain a bandwidth crash threshold. Based on the bandwidth crash threshold, a bandwidth efficiency warning value is set. Based on the bandwidth efficiency warning value, during the monitoring period, real-time access data is analyzed to obtain a threat assessment value. If the threat assessment value is greater than the threat assessment threshold, a threat signal is generated. Among them, access data includes network bandwidth and number of visitors; Linear analysis module: Based on the threat signal, the warning area curve is analyzed to obtain a linear performance value. If the linear performance value is greater than the linear performance threshold, it indicates that the change type of the warning area curve is linear. If the linear performance value is less than or equal to the linear performance threshold, it indicates that the change type of the warning area curve is non-linear. Prediction model selection and analysis module: Based on the change type of the warning zone curve, an applicable prediction model is constructed, and based on the prediction model, the predicted bandwidth efficiency value is analyzed; Approaching trend analysis module: During the forecast period, the bandwidth efficiency value is continuously monitored in real time. The real-time monitored bandwidth efficiency value is compared and analyzed with the forecasted bandwidth efficiency value at different time points to obtain the approaching trend value. If the approaching trend value is greater than the approaching trend threshold, an approaching trend signal is generated. If the approaching trend value is less than or equal to the approaching trend threshold, a non-approaching trend signal is generated. Based on the approaching trend signal, a countdown warning display is performed. Regulation and control analysis module: Based on the non-approaching signal, the non-approaching performance value is analyzed. If the non-approaching performance value is greater than the non-approaching performance threshold, an adjustment signal is generated. Based on the adjustment signal, a countdown warning display is performed.

2. The network security threat situation assessment system based on AI technology according to claim 1 is characterized in that: The threat assessment value is obtained as follows: Obtain the network bandwidth and number of visitors during the system crash period in the historical period; The bandwidth crash value is obtained by comparing the network bandwidth and the number of visitors when the system crashed in the historical period. The bandwidth collapse threshold DX is obtained by summing and averaging all bandwidth collapse values when the system crashes in the historical period. 阈 ; Obtain network bandwidth and number of visitors in real time during the monitoring period, and analyze to obtain bandwidth efficiency value DX and time duration ratio SC; The bandwidth efficiency value DX and the time duration ratio SC in the warning area curve are processed by the formula: The threat assessment value YB is calculated, where s1 and s2 are preset proportional coefficients, and N represents the total number of bandwidth efficiency values in the warning area curve.

3. The network security threat situation assessment system based on AI technology according to claim 2 is characterized in that: The time duration ratio SC is obtained as follows: During the monitoring period, the monitoring period is divided into several monitoring time points, and the network bandwidth and the corresponding number of visitors at the monitoring time points are obtained in real time. The network bandwidth and the corresponding number of visitors at the monitoring time points are ratio-processed to obtain the bandwidth efficiency value; Based on the bandwidth efficiency value, a bandwidth efficiency value change curve is constructed; Based on the bandwidth efficiency warning value, a bandwidth efficiency warning line is constructed; Based on bandwidth collapse threshold DX 阈 , construct bandwidth collapse line; If the bandwidth efficiency value is greater than the bandwidth efficiency warning value and less than the bandwidth collapse threshold, an analysis signal is generated; Based on the analysis signal, the bandwidth efficiency value change curve below the bandwidth efficiency warning line curve segment is marked as the warning zone curve, obtain the bandwidth efficiency value in the warning zone curve, and marked as DX; The duration corresponding to the warning zone curve is obtained, and the duration corresponding to the warning zone curve is ratioed with the duration corresponding to the monitoring period to obtain the time duration ratio SC.

4. The network security threat situation assessment system based on AI technology according to claim 3 is characterized in that: The linear performance value XB is obtained as follows: By analyzing the early warning area curve, we can obtain the negative slope curve segment ratio FQ and the situation overlap value BH; The negative slope curve segment ratio FQ and the situation overlap value BH are processed and the formula is used: The linear performance value XB is calculated, where a1 and a2 are both preset proportional coefficients.

5. The network security threat situation assessment system based on AI technology according to claim 4 is characterized in that: The negative slope curve segment number ratio FQ and the situation overlap value BH are obtained as follows: Obtain the corresponding warning area curve, divide the warning area curve into warning area curve segments of equal horizontal length, obtain the slope values of the warning area curve segments, mark the warning area curve segments with negative slope values as negative slope curve segments, count the number of negative slope curve segments in the warning area curve segments, mark them as the total number of negative slope curve segments, and perform ratio processing on the total number of negative slope curve segments and the total number of warning area curve segments to obtain the negative slope curve segment number ratio FQ; Connect the two end points of the warning area curve with a straight line to obtain the change reference line. Measure the overlap length between the warning area curve and the change reference line, and perform ratio processing with the length of the change reference line to obtain the situation overlap value BH.

6. The network security threat situation assessment system based on AI technology according to claim 3 is characterized in that: The method for obtaining the predicted bandwidth efficiency value is as follows: All bandwidth efficiency values of the warning zone curve are integrated into a data set as a training data set. If the change type of the warning zone curve is linear, a linear regression model is selected as the prediction model. If the change type of the warning zone curve is nonlinear, a random forest network model is selected as the prediction model. The prediction model is trained using the training data set to obtain a trained prediction model. Input the bandwidth collapse threshold into the prediction model to obtain the time point when the bandwidth efficiency value reaches the bandwidth collapse threshold, and mark it as the arrival time point. Perform a difference calculation between the arrival time point and the current time point to obtain the remaining time for the bandwidth efficiency value to reach the bandwidth collapse threshold, and mark the time period corresponding to the remaining time as the prediction period; Different time nodes within the prediction period are input into the prediction model to obtain the predicted bandwidth efficiency values at different time nodes within the prediction period.

7. The network security threat situation assessment system based on AI technology according to claim 1 is characterized in that: The method for obtaining the situation approach value is as follows: During the forecast period, a monitoring period is preset, and the bandwidth efficiency values monitored in real time at different time nodes during the preset monitoring period are analyzed to obtain the situation deviation quantity ratio BT and the situation deviation degree value BJ; The situation deviation ratio BT and the situation deviation degree value BJ are processed by data, and the formula is: The situation approach value TQ is obtained, where m1 and m2 are both preset proportional coefficients.

8. The network security threat situation assessment system based on AI technology according to claim 7 is characterized in that: The situation deviation quantity ratio BT and the situation deviation degree value BJ are obtained as follows: Obtain the bandwidth efficiency values monitored in real time at different time points during the preset monitoring period and compare them with the predicted bandwidth efficiency values at different time points. Specifically: Based on any time point; If the bandwidth efficiency value at a time node is not equal to the predicted bandwidth efficiency value, the time node is marked as a different time node; If the bandwidth efficiency value at a time node is not equal to the predicted bandwidth efficiency value, the time node is marked as the same time node; Count the total number of time nodes and the number of different time nodes within the preset monitoring period, and perform ratio processing on the number of different time nodes and the total number of time nodes within the preset monitoring period to obtain the situation deviation ratio BT; Obtain the bandwidth efficiency values at different time nodes, perform difference processing on them with the predicted bandwidth efficiency values at different time nodes, and take the absolute value of the difference to obtain the bandwidth efficiency value deviations at different time nodes. Ratio processing is performed on the bandwidth efficiency value deviations at different time nodes with the predicted bandwidth efficiency values at different time nodes to obtain the bandwidth efficiency value deviation ratios at different time nodes. Sum and average the bandwidth efficiency value deviation ratios of all different time nodes to obtain the situation deviation degree value BJ.

9. The network security threat situation assessment system based on AI technology according to claim 1 is characterized in that: The non-approaching performance value is obtained as follows: The target node number ratio MS and the variance FC of the bandwidth efficiency deviation value in the bandwidth efficiency deviation data group are processed by the formula: The non-approaching performance value FB is calculated, where n1 and n2 are both preset proportional coefficients; The target node number ratio MS and the variance FC of the bandwidth efficiency deviation value in the bandwidth efficiency deviation data group are obtained as follows: Obtain the bandwidth efficiency values of different time nodes monitored in real time during the forecast period, and perform subtraction processing on them from the forecasted bandwidth efficiency value to obtain the bandwidth efficiency deviation value; Count the number of nodes with positive bandwidth efficiency deviation values and the number of nodes with negative bandwidth efficiency deviation values. If the number of nodes with positive bandwidth efficiency deviation values is greater than the number of nodes with negative bandwidth efficiency deviation values, mark the node with positive bandwidth efficiency deviation values as the target node. If the number of nodes with positive bandwidth efficiency deviation values is less than the number of nodes with negative bandwidth efficiency deviation values, mark the node with negative bandwidth efficiency deviation values as the target node. If the number of nodes with positive bandwidth efficiency deviation values is the same as the number of nodes with negative bandwidth efficiency deviation values, it means that the bandwidth efficiency values at different time points are not close to the predicted bandwidth efficiency value to a certain extent, and the analysis is stopped. Count the number of target nodes and compare it with the number of nodes at different times to get the target node number ratio MS; All bandwidth efficiency deviation values are integrated into a bandwidth efficiency deviation data group, and the variance of the bandwidth efficiency deviation values in the bandwidth efficiency deviation data group is calculated and marked as FC.

10. The network security threat situation assessment system based on AI technology according to claim 9 is characterized in that: The warning display mode based on the control signal is as follows: The bandwidth efficiency deviation values of all target nodes are summed and averaged to obtain the target bandwidth efficiency difference mean. If the target bandwidth efficiency difference mean is positive, the bandwidth collapse threshold DX is set to 阈 The difference between the target bandwidth efficiency difference and the mean value is processed to obtain the adjusted bandwidth collapse threshold, and the value prediction model is re-entered to re-obtain the remaining time. If the target bandwidth efficiency difference mean value is negative, the bandwidth collapse threshold DX is increased. 阈 Sum the result with the absolute value of the mean of the target bandwidth efficiency difference to obtain the adjusted bandwidth collapse threshold, and re-enter the value prediction model to obtain the remaining time. The remaining time obtained is sent to the display system for countdown warning display.

Citation Information

Patent Citations

  • Power station monitoring system network security protection method

    CN119094165A

  • Snapshot phishing detection and threat analysis

    US20240323226A1