An unmanned inspection and intelligent fault judgment method

By constructing a security threat model and multi-layered protection architecture for unmanned inspection systems, and utilizing deep learning and encryption technologies to identify potential threats, the security issues of unmanned inspection systems are solved, achieving data transmission security and system stability.

CN119728211BActive Publication Date: 2026-02-27THREE GORGES ZHUJIANG POWER GENERATION CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411842354.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-13
Publication Date
2026-02-27
Estimated Expiration
2044-12-13

AI Technical Summary

Technical Problem

Unmanned inspection systems face high risks of cyberattacks and unauthorized access, difficulty in ensuring data transmission and storage security, and an imperfect overall security protection system.

Method used

A security threat model for the unmanned inspection system is constructed, and deep learning and decision tree algorithms are used to identify potential threats. Data protection is carried out by combining security protocols and encryption technologies, deploying a multi-layered security protection architecture, and conducting anomaly detection and regular security assessments.

Benefits of technology

It effectively reduces the possibility of cyberattacks, ensures system stability, guarantees data confidentiality and integrity, enhances overall security protection capabilities, and reduces security vulnerabilities and maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728211B_ABST
    Figure CN119728211B_ABST
Patent Text Reader

Abstract

A kind of unmanned inspection and intelligent fault judgment method, potential risks are identified and strategies are developed by constructing security threat model through deep learning, security analysis modeling based on contrast technology is used to detect system state anomalies.In data transmission, confidentiality and integrity are guaranteed by integrating various security measures, and a multi-level protection architecture is designed to provide comprehensive defense from network boundaries, host terminals to application systems.With the help of abnormal detection monitoring index data, correlation analysis of abnormality and risk is carried out to provide basis for decision-making.Safety evaluation and penetration testing are carried out regularly to repair vulnerabilities and optimize reinforcement.The present application covers threat modeling, security analysis, data protection, protection architecture building, anomaly detection and evaluation and reinforcement, etc., effectively improves the security and reliability of unmanned inspection system, resists network attacks and illegal access, and guarantees the stable operation of the system.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of fault judgment, and particularly relates to an unmanned inspection and intelligent fault judgment method. BACKGROUND

[0002] In the unmanned inspection system, safety is the primary consideration. By introducing the unmanned inspection system security mechanism, network attacks and illegal access can be resisted. The comparative technology can identify normal and abnormal states in security analysis, helping to detect and respond to threats. In practical applications, detailed security architecture design needs to be combined with security protocols, encryption technology and access control strategies. This includes defining threat models, security policies and specific technical measures. For example, deep learning-based anomaly detection technology and data encryption can be used to monitor the data transmission of the unmanned inspection system, and potential security risks can be prevented by identifying behaviors that deviate from the expected pattern.

[0003] The openness and interconnectivity of the unmanned inspection system make it vulnerable to network attacks, including malicious hacking, data theft, malicious software implantation, and illegal access risks are rising. The confidentiality and integrity of data during transmission and storage are difficult to guarantee, and once the data is leaked or tampered with, it may lead to serious consequences such as production failure, privacy invasion, economic loss, etc. In addition, existing security protection measures often lack systematicness and depth, and are difficult to cope with complex and variable security threat environments, and are particularly vulnerable when faced with new attack methods.

[0004] In summary, the technical problems to be solved by the present application are: the unmanned inspection system faces high network attack and illegal access risk, data transmission and storage security is difficult to guarantee, and the overall security protection system is imperfect. SUMMARY

[0005] The technical problem to be solved by the present application is to provide an unmanned inspection and intelligent fault judgment method. In terms of security threat prevention, a precise security threat model is constructed through a deep learning algorithm, which can identify potential network attacks and illegal access risks in advance, and formulate targeted strategies combined with decision tree algorithms to effectively reduce the likelihood of being attacked. The security analysis method based on comparative technology can monitor the system running state in real time, discover abnormalities in time and trigger the response mechanism, and ensure the stability of system operation.

[0006] To solve the above technical problems, the technical solution adopted by the present application is:

[0007] An unmanned inspection and intelligent fault judgment method, the steps are:

[0008] S1, according to the business characteristics of the unmanned inspection system, a security threat model of the unmanned inspection system is constructed, potential network attacks and illegal access risks are determined, and security strategies and technical measures are formulated; S2, a security analysis method based on comparison technology is adopted, the running state of the unmanned inspection system is modeled through a deep learning algorithm, and the feature patterns of the normal state and the abnormal state are obtained, if the running state of the unmanned inspection system deviates from the normal mode, it is judged that there is a potential security threat, and a real-time response mechanism is triggered; S3, during the data transmission process of the unmanned inspection system, security protocols, encryption technology and access control strategies are comprehensively used to encrypt and protect the transmission data and control the authority, prevent data from being illegally intercepted and tampered, and ensure the confidentiality and integrity of data transmission; S4, for the unmanned inspection scene, a multi-level security protection architecture is designed, security protection measures are deployed at different levels including network boundary, host terminal and application unmanned inspection system, and through the construction of a depth defense system, the security protection capability of the unmanned inspection system is comprehensively improved; S5, abnormal detection method is used to continuously monitor various index data in the running process of the unmanned inspection system, and through comparison analysis with the pre-established normal mode, abnormal behaviors deviating from the expected threshold are found in time, and potential security risks are judged, which provides basis for subsequent security decision; S6, the security evaluation and penetration test of the unmanned inspection system are carried out regularly, the security vulnerabilities and weak links in the unmanned inspection system are fully investigated, and the problems found are repaired and reinforced in time, so as to continuously improve the overall security of the unmanned inspection system and the ability to resist external attacks.

[0009] Preferably, the sub-step of S1 is:

[0010] S1.1, according to the business characteristics of the unmanned inspection system, a deep learning algorithm is used to analyze the historical running data of the unmanned inspection system, a security threat model of the unmanned inspection system is constructed, and potential network attacks and illegal access risks are identified;

[0011] S1.2, for the identified security threats, a decision tree algorithm is adopted, and the pre-set security strategy knowledge base is combined to automatically infer the corresponding security protection measures;

[0012] S1.3, the real-time running data of the unmanned inspection system is obtained, and through comparison and analysis with the security threat model, it is judged whether the unmanned inspection system exists network attack and illegal access risk in real time, if it exists, the corresponding security protection measures are triggered;

[0013] S1.4, according to the new security threats identified in the running process of the unmanned inspection system, through reinforcement learning algorithm, the existing security threat model and security strategy knowledge base are continuously optimized and improved, and the security protection capability of the unmanned inspection system is improved;

[0014] S1.5, according to the characteristics of unmanned inspection business scenarios, a distributed security protection mechanism based on blockchain is deployed to encrypt and store and verify the key business data of the unmanned inspection system, ensuring the confidentiality and integrity of the data;

[0015] S1.6, a zero trust architecture is adopted to strictly authenticate and authorize the identity of all users and devices in the unmanned inspection system, minimizing potential internal threats, thereby further strengthening the overall security of the unmanned inspection system;

[0016] S1.7, continuously monitor the safe operation state of the unmanned inspection system, and through visualization technology, real-time present the security threat situation of the unmanned inspection system, provide intuitive decision support for security management personnel, and continuously optimize the security protection level of the unmanned inspection system.

[0017] Preferably, the sub-steps of S2 are:

[0018] S2.1, according to the deep learning algorithm, feature extraction and representation learning are performed on the unmanned inspection system operation state data, and a feature model of the unmanned inspection system state is constructed;

[0019] S2.2, an unsupervised learning method is adopted, and clustering algorithm is used to cluster the feature of the unmanned inspection system state, to obtain a feature cluster representing normal mode and a feature cluster representing abnormal mode;

[0020] S2.3, during the operation of the unmanned inspection system, real-time acquisition of the state data of the unmanned inspection system is performed, feature vectors are extracted, and similarity calculation is performed with the feature cluster of the normal mode;

[0021] S2.4, if the feature vector deviates from the feature cluster of the normal mode by more than a preset threshold, it is determined that the unmanned inspection system is in an abnormal state, and there is a potential security threat;

[0022] S2.5, according to the severity of the abnormal state and the threat level, dynamically adjust the strategy and strength of the real-time response mechanism;

[0023] S2.6, through active defense measures, block and isolate abnormal behavior, reduce the impact range of security threats, and ensure the safe and stable operation of the unmanned inspection system;

[0024] S2.7, continuously optimize the deep learning model, through incremental learning and online learning, continuously improve the accuracy of anomaly detection and the efficiency of real-time response.

[0025] Preferably, the sub-steps of S3 are:

[0026] S3.1, According to the sensitivity of the data and the transmission environment, a secure transmission channel is established through a security protocol, and the transmission process is encrypted for protection; the security protocol is SSL or TLS;

[0027] S3.2, Symmetric encryption and asymmetric encryption are combined to encrypt the transmission data;

[0028] S3.3, Through a secure key management mechanism, the confidentiality and integrity of the encryption key are ensured;

[0029] S3.4, Before transmitting the data, the data is digitally signed to ensure the integrity of the data;

[0030] S3.5, The receiver verifies the digital signature to determine whether the data has been tampered with;

[0031] S3.6, Role-based access control policy is used to manage the permissions of different users and unmanned inspection systems;

[0032] S3.7, Through identity authentication and authorization mechanism, the access and operation of illegal users to data are limited;

[0033] S3.8, In the transmission process, a secure routing protocol and network isolation technology are used to prevent data from being illegally intercepted and eavesdropped during transmission;

[0034] S3.9, A perfect log audit and monitoring mechanism is established to monitor the data transmission process in real time and detect abnormal behavior;

[0035] S3.10, Through machine learning algorithm, potential security threats are identified and warned;

[0036] S3.11, The security protocol, encryption algorithm and access control policy are evaluated and updated regularly to ensure their adaptability to the changing security situation and technological development;

[0037] S3.12, Through continuous security reinforcement and optimization, the overall security of data transmission is improved.

[0038] Preferably, the sub-steps of S4 are:

[0039] S4.1, A firewall and intrusion detection system are deployed at the network boundary to monitor and filter the data traffic entering and leaving the network in real time. If malicious traffic or attack behavior is found, it will be immediately blocked and an alarm information will be sent out, and relevant logs will be recorded for subsequent analysis and tracking;

[0040] S4.2, Install antivirus software and host intrusion detection system on the host terminal, monitor files, processes and registry on the terminal in real time, determine whether there are malicious programs such as viruses and trojans through signature matching and behavior analysis technology, and if detected, isolate or delete immediately and report alarm information;

[0041] S4.3, For application of unmanned inspection system, use Web application firewall to deeply detect access traffic, identify and block common web attacks such as SQL injection and cross-site scripting through rule engine and machine learning algorithm, and authenticate and authorize user identity to avoid illegal access and unauthorized operation;

[0042] S4.4, Establish a security management platform to centrally manage security devices and unmanned inspection systems at various levels, ensure the consistency and effectiveness of various protection measures through unified policy configuration and management, and correlate various security events to discover potential security threats in time;

[0043] S4.5, Conduct regular security assessment and penetration testing to comprehensively assess the security status of the unmanned inspection system, find weak links and vulnerabilities in the unmanned inspection system through simulated attacks, and propose targeted improvement measures to continuously improve the security protection capability of the unmanned inspection system;

[0044] S4.6, Strengthen safety awareness education and training to improve the safety awareness and skills of relevant personnel, and master basic safety operation specifications and emergency disposal methods through regular safety propaganda and training;

[0045] S4.7, Establish and improve safety management system and process, clearly define the safety responsibilities and operation procedures of each post, standardize personnel behavior through institutionalized and processized management, reduce human error and internal threats, and provide institutional guarantee for the safe operation of the unmanned inspection system.

[0046] Preferably, the sub-step of S5 is:

[0047] S5.1, Obtain various index data in the running process of the unmanned inspection system, establish a corresponding time series data model for each index, and form a normal mode of index data;

[0048] S5.2, Cluster analysis of index data is performed using clustering algorithm, and the normal value range of each index is determined according to the clustering result to obtain the expected threshold;

[0049] S5.3, Continuously obtain real-time data of various indexes in the running process of the unmanned inspection system, compare the real-time data with the expected threshold, and if the real-time data deviates from the expected threshold, it is judged as abnormal behavior;

[0050] S5.4, For the detected abnormal behavior, a correlation rule mining algorithm is used to analyze the correlation between the abnormal behavior and the security risk, and the potential security risk that the abnormal behavior may cause is obtained;

[0051] S5.5, According to the severity of the abnormal behavior and the size of the potential security risk, a decision tree algorithm is used to generate corresponding security decision rules, which provide basis for subsequent security decision;

[0052] S5.6, During the operation of the unmanned inspection system, continuous abnormal detection and security risk analysis are carried out, and the expected threshold and security decision rules are dynamically adjusted according to the analysis results, so as to improve the accuracy of abnormal detection and the effectiveness of security decision;

[0053] S5.7, The results of abnormal detection and security decision are fed back to the administrator of the unmanned inspection system in real time, which helps the administrator to take corresponding security prevention measures in time, reduces the security risk, and ensures the safe and stable operation of the unmanned inspection system.

[0054] Preferably, the sub-steps of S6 are:

[0055] S6.1, According to the architecture and business characteristics of the unmanned inspection system, a comprehensive security assessment and penetration test plan is formulated, the scope, method and frequency of the assessment are clarified, and the assessment work is ensured to be unmanned and systematic and continuous;

[0056] S6.2, The combination of automatic vulnerability scanning tools and manual penetration testing is used to comprehensively identify the security vulnerabilities and weak links in the unmanned inspection system, and the vulnerabilities are classified and rated according to their severity and impact;

[0057] S6.3, For the identified security vulnerabilities and weak links, detailed repair and reinforcement schemes are formulated in time, the priority, responsible person and completion time limit of repair are clarified, and the vulnerabilities can be repaired in time and effectively;

[0058] S6.4, After the completion of the vulnerability repair, regression testing and verification testing are used to verify the effectiveness of the repair measures, and the repaired unmanned inspection system is reinforced to improve the overall security performance of the unmanned inspection system;

[0059] S6.5, A security vulnerability management database is established to record all the identified security vulnerabilities and weak links, as well as the corresponding repair and reinforcement measures, and regular statistical analysis is carried out to master the changing trend of the security status of the unmanned inspection system;

[0060] S6.6, analyze and mine the security vulnerability data through a machine learning algorithm to identify common problems and weak links in the unmanned inspection system and provide decision support for subsequent security reinforcement; the machine learning algorithm includes support vector machines, decision trees and random forests;

[0061] S6.7, based on the analysis results of the machine learning, continuously optimize and improve the methods and strategies of security assessment and penetration testing to improve the pertinence and effectiveness of the assessment and continuously improve the overall security performance and the ability to resist external attacks of the unmanned inspection system.

[0062] An unmanned inspection and intelligent fault judgment system, comprising:

[0063] A threat modeling and strategy generation module for constructing a security threat model of the unmanned inspection system, determining potential network attacks and illegal access risks, and formulating security strategies and technical measures according to the business characteristics of the unmanned inspection system;

[0064] A deep learning security analysis module for modeling the running state of the unmanned inspection system through a deep learning algorithm using a security analysis method based on a comparison technique to obtain the feature patterns of the normal state and the abnormal state, and if the running state of the unmanned inspection system deviates from the normal mode, it is judged that there is a potential security threat, triggering a real-time response mechanism;

[0065] A data security guarantee module for comprehensively using security protocols, encryption technology and access control strategies to encrypt and protect the transmission data and control the access rights during the data transmission process of the unmanned inspection system to prevent the data from being illegally intercepted and tampered with and to ensure the confidentiality and integrity of the data transmission;

[0066] A multi-level security protection deployment module for designing a multi-level security protection architecture for the unmanned inspection scene, deploying security protection measures at different levels including network boundaries, host terminals and application unmanned inspection systems, and building a defense-in-depth system to comprehensively improve the security protection capability of the unmanned inspection system;

[0067] An anomaly detection and risk judgment module for continuously monitoring various index data in the running process of the unmanned inspection system using an anomaly detection method, comparing and analyzing with the pre-established normal mode to timely find abnormal behaviors deviating from the expected threshold and judge potential security risks to provide a basis for subsequent security decisions;

[0068] A security assessment and reinforcement module is used to periodically carry out security assessment and penetration testing of the unmanned inspection system, comprehensively check the security loopholes and weak links in the unmanned inspection system, take timely repair and reinforcement measures against the problems found, and continuously improve the overall security of the unmanned inspection system and the ability to resist external attacks.

[0069] A computer device comprises:

[0070] One or more processors;

[0071] The processor is used to store one or more programs;

[0072] When the one or more programs are executed by the one or more processors, the unmanned inspection and intelligent fault judgment method is realized.

[0073] A computer readable storage medium has a computer program stored thereon, and the computer program is executed to realize the unmanned inspection and intelligent fault judgment method.

[0074] The present application can achieve the following beneficial effects:

[0075] 1. The present application builds a multi-level security protection architecture against potential network attacks and illegal access risks in the unmanned inspection scene. The normal and abnormal state feature patterns are obtained by modeling the running state of the unmanned inspection system through a deep learning algorithm. In the data transmission process, security protocols, encryption technology and access control strategies are comprehensively used to ensure the confidentiality and integrity of data transmission. The present application uses anomaly detection technology to continuously monitor the running indicators of the unmanned inspection system, compares and analyzes with the pre-established normal mode, and timely discovers the abnormal behavior deviating from the expected threshold. At the same time, regular security assessment and penetration testing are carried out to comprehensively check security loopholes and weak links, and timely repair and reinforcement measures are taken. The present application improves the security protection capability of the unmanned inspection system in all directions through the construction of the in-depth defense system, and effectively copes with the security threats in complex environment.

[0076] 2. The present application builds an accurate security threat model through a deep learning algorithm, which can identify potential network attacks and illegal access risks in advance, and formulates targeted strategies combined with decision tree algorithm to effectively reduce the possibility of being attacked. The security analysis method based on comparison technology can monitor the system running state in real time, timely discover abnormalities and trigger response mechanism, and guarantee the system running stability.

[0077] 3. The present application uses a multi-level security protection architecture to protect from network boundary, host terminal to application system in all directions, builds an in-depth defense system, greatly improves the overall security protection capability, and reduces security loopholes and weak links.

[0078] 4、The application accurately judges potential security risks and provides decision-making basis, facilitating timely preventive measures. Regular security assessment and penetration testing can timely discover and repair vulnerabilities, and machine learning-based analysis optimization can continuously improve system security and resistance to external attacks, enabling the system to maintain good adaptability and reliability in complex and changing security environments, reducing operation and maintenance costs and security incident losses. BRIEF DESCRIPTION OF DRAWINGS

[0079] The application will be further described below in conjunction with the drawings and examples:

[0080] Fig. 1 A flowchart of an unmanned inspection and intelligent fault judgment method of the application.

[0081] Fig. 2 A schematic diagram of an unmanned inspection and intelligent fault judgment method of the application.

[0082] Fig. 3 Another schematic diagram of an unmanned inspection and intelligent fault judgment method of the application. DETAILED DESCRIPTION

[0083] The preferred scheme is as shown in a kind of unmanned inspection and intelligent fault judgment method, step: Figs. 1 to 3

[0084] S1, according to the business characteristics of unmanned inspection system, constructs the security threat model of unmanned inspection system, determines potential network attack and illegal access risk, formulates security strategy and technical measures;

[0085] S1.1, according to the business characteristics of unmanned inspection system, adopts deep learning algorithm, analyzes the historical operation data of unmanned inspection system, constructs the security threat model of unmanned inspection system, and identifies potential network attack and illegal access risk;

[0086] Deep learning algorithm can adopt convolutional neural network (CNN) or recurrent neural network (RNN) etc. For example, if the unmanned inspection system involves a large amount of image data (such as monitoring images of the inspection area), CNN can be used to analyze abnormal patterns in the image, such as unauthorized personnel entering the image area. For system log data with time series, RNN can better capture the correlation between data, thereby identifying potential risks. Taking a power inspection system as an example, the historical operation data includes time series data such as device power fluctuation and temperature change. By analyzing these data with RNN, it may be found that some abnormal power and temperature change combination patterns indicate potential device failure risks or network attack risks of malicious tampering with power data.

[0087] ​S1.2 For the identified security threats, a decision tree algorithm is used in conjunction with a pre-set security policy knowledge base to automatically deduce targeted security protection measures.

[0088] Decision tree algorithms operate based on a pre-defined security policy knowledge base. For example, the knowledge base contains protection policies for different types of network attacks (such as DDoS attacks and malware intrusions). When a security threat is identified as a suspected DDoS attack (judged by characteristics such as a sudden increase in network traffic and dispersed sources), the decision tree algorithm automatically infers corresponding security protection measures based on the policy branches for DDoS attacks in the knowledge base, such as increasing network bandwidth limits or enabling traffic scrubbing services.

[0089] S1.3 Obtain real-time operational data of the unmanned inspection system, and through comparison and analysis with the security threat model, determine in real time whether the unmanned inspection system is at risk of network attacks and unauthorized access. If so, trigger corresponding security protection measures.

[0090] Real-time operational data may include network packet information, device operating status parameters, etc. When comparing with security threat models, for example, for network packets, information such as source address, destination address, and port number will be checked to see if they match the model characteristics corresponding to normal business processes. If it is found that a certain source address sends requests to a large number of different destination addresses in a short period of time, and this behavior is inconsistent with the network communication characteristics under normal business patterns (the connection frequency and target distribution of normal network communication source addresses in the security threat model have certain patterns), then it may be judged that there is a network attack risk, thereby triggering security protection measures such as blocking access from that source address.

[0091] S1.4 Based on the new security threats identified during the operation of the unmanned inspection system, the existing security threat model and security strategy knowledge base are continuously optimized and improved through reinforcement learning algorithms to enhance the security protection capabilities of the unmanned inspection system.

[0092] During the operation of an unmanned inspection system, suppose a new type of command tampering attack targeting a specific model of inspection equipment emerges. The reinforcement learning algorithm will adjust the parameters related to command legitimacy judgment in the security threat model based on this emerging attack data (such as the characteristics of tampered commands, abnormal equipment responses, etc.). Simultaneously, it will update the security policy knowledge base, adding protection strategies against this new attack, such as upgrading the encryption method for command transmission to this model of equipment and adding command verification steps, thereby enhancing the system's ability to protect against this new threat.

[0093] S1.5. In view of the characteristics of unmanned inspection business scenarios, deploy a distributed security protection mechanism based on blockchain to encrypt and verify the key business data of the unmanned inspection system to ensure the confidentiality and integrity of the data.

[0094] For example, in an unmanned inspection system, for critical inspection data such as detection result data of important equipment, the distributed security mechanism of blockchain is used to encrypt and store the data using the encryption hash function of blockchain. Each data block contains the hash value of the previous data block, forming a chain structure. When data is transmitted or stored, the receiving party or storage node can verify the hash value to ensure that the data has not been tampered with. For example, in an unmanned inspection system for oil pipelines, critical detection data such as pipeline pressure and flow rate are transmitted and stored between different monitoring points and data centers. Blockchain technology ensures the integrity and confidentiality of these data, preventing malicious modification or theft during transmission.

[0095] S1.6, adopt zero trust architecture, strictly authenticate and authorize the identity of all users and devices in the unmanned inspection system, minimize potential internal threats, and further strengthen the overall security of the unmanned inspection system;

[0096] Under the zero trust architecture, users (such as system administrators, data analysts, etc.) and devices (such as inspection robots, data collection terminals, etc.) in the unmanned inspection system need to be strictly authenticated and authorized every time they access system resources. For example, when an administrator logs in to the system, in addition to the usual username and password verification, dynamic verification code verification, biometric identification (such as fingerprint identification or facial recognition), etc. multi-factor authentication may be required. When a device accesses the system, it needs to verify the unique identification (such as device serial number) and pre-configured access key information of the device. Only users and devices that have passed authentication and authorization can access corresponding system resources, so that even in an internal network environment, illegal users or compromised devices can be prevented from performing malicious operations, minimizing internal threats.

[0097] S1.7, continuously monitor the safe operation state of the unmanned inspection system, use visualization technology to present the security threat situation of the unmanned inspection system in real time, provide intuitive decision support for security management personnel, and continuously optimize the security protection level of the unmanned inspection system.

[0098] Through visualization technology, the security threat situation can be displayed, for example, in the form of a dashboard. The network security status of the unmanned inspection system (such as the number of attacks, type distribution), the device security status (such as device failure rate, number of abnormal devices), and other information can be presented in the form of charts. Security managers can visually see the changing trend of the overall security level of the system. If it is found that the number of network attacks suddenly increases in a certain period of time and is concentrated in a specific type (such as SQL injection attacks), the manager can adjust the security policy in a timely manner according to this information, such as strengthening the restrictions on database access, updating firewall rules, etc., to optimize the security protection level of the system.

[0099] S2.1. According to the deep learning algorithm, the feature extraction and representation learning of the unmanned inspection system running state data are performed, and the feature model of the unmanned inspection system state is constructed.

[0100] In the feature extraction and representation learning of the deep learning algorithm, for example, for the device running state data in the unmanned inspection system (such as the speed, temperature, and vibration frequency of the motor), the complex relationships and feature representations between these data can be automatically learned by a multi-layer neural network. Taking an unmanned device inspection system in a factory as an example, the deep learning model can convert the speed, temperature, and vibration frequency data of the motor in normal operation into a low-dimensional feature vector, which can comprehensively reflect the health status characteristics of the motor, thereby constructing a feature model of the system state.

[0101] S2.2. An unsupervised learning method is adopted, and a clustering algorithm is used to cluster the feature of the unmanned inspection system state, to obtain a feature cluster representing the normal mode and a feature cluster representing the abnormal mode.

[0102] The clustering algorithm of unsupervised learning, such as K-Means clustering algorithm, can cluster the system state features. In the unmanned inspection system, a large number of equipment running state feature data are taken as input, and the K-Means algorithm divides the data into different clusters according to the similarity of the data. For example, the equipment features in the normal running state are clustered into one class (representing the feature cluster of the normal mode), and the abnormal features generated when the equipment fails or is attacked are clustered into another class (representing the feature cluster of the abnormal mode). For example, in an unmanned inspection system of an automatic production line, the temperature, pressure and other feature data of the equipment in normal production form a relatively stable cluster, and when the equipment fails (such as part wear causing increased friction, and then temperature rise and abnormal pressure), the feature data in the abnormal state will form another obviously different cluster.

[0103] S2.3, during the operation of the unmanned inspection system, real-time acquisition of the state data of the unmanned inspection system, extraction of the feature vector, similarity calculation with the feature cluster of the normal mode;

[0104] During the operation of the system, the real-time acquired system state data such as new data collected by the equipment sensor will be extracted as a feature vector. For example, for an unmanned inspection system of a smart building, the real-time acquired elevator running data (such as running speed, floor stay time, load, etc.) is extracted as a feature vector, and similarity calculation is performed with the feature cluster of the normal mode (obtained by clustering a large amount of historical normal running data). The method of calculating the similarity can use the Euclidean distance or other measurement methods to calculate the distance between the feature vector and the center of the normal mode feature cluster. The closer the distance, the higher the similarity.

[0105] S2.4, if the feature vector deviates from the feature cluster of the normal mode by more than a preset threshold, it is determined that the unmanned inspection system is in an abnormal state, and there is a potential security threat;

[0106] The preset threshold can be determined according to the accuracy requirement of the system and the statistical analysis of the historical data. For example, in a traffic monitoring unmanned inspection system, the similarity threshold of the feature vector of the vehicle flow data and the normal mode feature cluster is set to 0.8 (a suitable threshold can be calculated according to a large amount of historical normal flow data). If the calculated similarity is less than 0.8 at a certain time, it means that the vehicle flow pattern is abnormal, and there may be traffic congestion, accidents or malicious interference with traffic signals causing abnormal aggregation of vehicles, etc. At this time, it is determined that the system is in an abnormal state, and there is a potential security threat.

[0107] S2.5, according to the severity of the abnormal state and the threat level, dynamically adjusting the strategy and strength of the real-time response mechanism;

[0108] The severity and threat level of the abnormal state can be determined based on various factors. For example, in an unmanned inspection system of a financial data center, if an abnormal database access is found, if it is only an individual user's login error attempt, the threat level may be low; but if it is a large number of intensive access attempts from unknown external IP addresses, and there is a trend of breaking through the firewall restrictions, the threat level is high. According to different threat levels, the strategy and strength of the real-time response mechanism will be different. For low threat level, it may only record logs and issue a light alarm; while for high threat level, it may immediately cut off all external network connections, start data backup and encryption, and other high-intensity measures.

[0109] S2.6, by actively defending measures, blocking and isolating abnormal behavior, reducing the impact range of security threats, and ensuring the safe and stable operation of the unmanned inspection system;

[0110] Active defense measures can include various forms. For example, in an unmanned inspection system of a network service, once abnormal network traffic (such as suspected DDoS attack traffic) is detected, the active defense system can automatically divert the attack traffic to a special honeypot server, making the attacker mistakenly believe that the attack is successful, while protecting the real server resources, blocking and isolating abnormal behavior, avoiding affecting normal user services, reducing the impact range of security threats, and ensuring the safe and stable operation of the system.

[0111] S2.7, continuously optimize the deep learning model, and improve the accuracy of anomaly detection and the efficiency of real-time response through incremental learning and online learning.

[0112] Incremental learning and online learning are effective ways to optimize deep learning models. For example, in an unmanned inspection system of an e-commerce platform, as the business develops, new promotional activities, new user behavior patterns, etc. will produce new data features. Incremental learning can learn and update the model based on the original deep learning model only for new data, without the need to retrain the entire model, saving computing resources and time. Online learning can adjust model parameters in real time according to new data, such as when a new user login abnormal pattern (such as using new malicious software to bypass login verification) is found, the model can quickly learn and update, improve the accuracy of anomaly detection and the efficiency of real-time response, and better adapt to the dynamic changes in the system operation process.

[0113] S3.1, according to the sensitivity of the data and the transmission environment, a secure transmission channel is established through a security protocol, and the transmission process is encrypted and protected; the security protocol is SSL or TLS;

[0114] The SSL / TLS protocol establishes a secure transmission channel, for example, in a remote medical unmanned inspection system, the patient's medical data (such as physical examination report, image data, etc.) is transmitted from the primary medical site to the data center of the superior hospital. The SSL / TLS protocol establishes an encrypted transmission channel between the client (primary medical site device) and the server (hospital data center server) through the handshake process, and negotiates encryption algorithms, exchanges keys and other information. This channel can prevent data from being stolen or tampered with by hackers during Internet transmission, ensuring the confidentiality and integrity of medical data.

[0115] S3.2, symmetric encryption and asymmetric encryption are combined to encrypt the transmission data;

[0116] The combination of symmetric encryption and asymmetric encryption has multiple application scenarios. For example, in an unmanned file inspection system within an enterprise, for a large number of ordinary file transmissions, symmetric encryption algorithms (such as AES) can be used because of their fast encryption and decryption speed, and the same key is used to encrypt and decrypt the file. For the transmission of important information such as system configuration files or user keys, the symmetric encryption key is first encrypted and transmitted using an asymmetric encryption algorithm (such as RSA), and the receiving party uses the private key to decrypt the symmetric encryption key, and then uses the symmetric encryption key to decrypt the file, which can ensure encryption efficiency and improve security.

[0117] S3.3, through a secure key management mechanism, ensure the confidentiality and integrity of the encryption key;

[0118] A secure key management mechanism can use a key distribution center (KDC). In a distributed unmanned warehouse inspection system, multiple warehouse devices need to transmit data. The KDC is responsible for generating, distributing and managing encryption keys. For example, when a warehouse inventory management device needs to interact with another warehouse inventory device, the KDC generates and distributes appropriate symmetric encryption keys for them based on the device's identity information and permissions, and ensures the confidentiality and integrity of the key during transmission and storage, preventing the key from being leaked and causing data to be decrypted illegally.

[0119] S3.4, before transmitting the data, digitally sign the data to ensure the integrity of the data;

[0120] The process of digital signature is to encrypt the hash value of data using the sender's private key. For example, in an e-government unmanned inspection system, the government-issued document data is digitally signed before transmission. The sender first calculates the hash value of the document data, then encrypts the hash value using its own private key to obtain the digital signature, and sends the digital signature and the document data together. After receiving the data, the receiver first calculates the hash value of the data, and then decrypts the digital signature using the sender's public key to obtain the original hash value. If the two hash values are consistent, it means that the data has not been tampered with, ensuring the integrity of the data.

[0121] S3.5, the receiver judges whether the data is tampered with by verifying the digital signature;

[0122] The process of receiving the digital signature is as above in the example of the e-government unmanned inspection system. The receiver compares the hash value obtained by decrypting the digital signature with the hash value of the data calculated by itself. If they do not match, it means that the data has been tampered with during transmission, and the receiver can refuse to receive the data or take appropriate security measures, such as alerting and recording logs, to trace the source of the tampered data.

[0123] S3.6, based on the role-based access control policy, the permissions of different users and the unmanned inspection system are managed;

[0124] The role-based access control policy has a clear application in the unmanned inspection system. For example, in a large enterprise's unmanned device inspection system, the system administrator role can modify the configuration parameters of all devices and view all inspection data; while the ordinary inspector role can only view the device inspection data of the area he is responsible for and cannot modify the device configuration. By assigning different permissions to different roles, such as read, write, and modify permissions to database tables, the permissions of different users and the system are managed to prevent illegal users from accessing data.

[0125] S3.7, through the identity authentication and authorization mechanism, the access and operation of illegal users to data are limited;

[0126] The identity authentication and authorization mechanism can be combined with multiple technologies. For example, in a financial unmanned transaction inspection system, when the user logs in, the username and password are first verified, then a dynamic verification code (such as an SMS verification code or a time-based one-time password TOTP) may be required, and biometric identification (such as fingerprint recognition or facial recognition) may also be required. Only after passing these multi-factor authentication, the system will authorize the user according to the user's role and permission, allowing the user to perform corresponding transaction operations or data access, limiting the access and operation of illegal users to data.

[0127] S3.8. During transmission, use secure routing protocols and network isolation technologies to prevent data from being illegally intercepted and eavesdropped during transmission;

[0128] Secure routing protocols and network isolation technologies play an important role in unmanned inspection systems. For example, in an unmanned inspection system of an industrial control network, a secure routing protocol such as OSPF is used to set routing policies to isolate and guide network traffic in different areas (such as production area, management area, monitoring area), preventing data from being illegally intercepted and eavesdropped during transmission. For example, device data in the production area can only be transmitted to specific monitoring servers and cannot be accessed by devices or networks in other areas, ensuring the security of the data transmission path.

[0129] S3.9. Establish a perfect log audit and monitoring mechanism to monitor and detect abnormal behavior in real time during data transmission;

[0130] Log audit and monitoring mechanism can record detailed data transmission information. For example, in an Internet service provider's unmanned network inspection system, log records include source address, destination address, transmission time, data volume, and protocol used. By monitoring these log information in real time, abnormal behavior can be found, such as a source address transmitting data to a large number of different destination addresses in a short period of time (which may be a prelude to malicious data leakage or DDoS attack), and timely warning and taking appropriate security measures.

[0131] S3.10. Identify and warn potential security threats through machine learning algorithms;

[0132] Machine learning algorithms have a variety of applications in identifying and warning potential security threats. For example, in an unmanned resource inspection system of a cloud computing platform, a naive Bayes algorithm is used to analyze data transmission logs. By learning a large number of historical normal data and known attack data, a probability model of data transmission behavior is established. When a new data transmission behavior occurs, the probability of being normal or abnormal is calculated according to the model. If a data transmission behavior is determined to be highly abnormal (such as a large amount of data transmission to an unknown external IP address, and the behavior rarely occurs in normal data), a warning is issued to identify and warn potential security threats.

[0133] S3.11. Regularly evaluate and update security protocols, encryption algorithms and access control strategies to ensure their adaptability to changing security situations and technological development;

[0134] It is necessary to regularly evaluate and update security protocols, encryption algorithms, and access control strategies. For example, with the development of quantum computing technology, traditional encryption algorithms such as RSA may face the risk of being cracked. In an unmanned data inspection system of a scientific research institution, it is necessary to regularly evaluate the security of the currently used encryption algorithm, research new encryption algorithms that are resistant to quantum computing attacks (such as quantum key distribution QKD related technologies) and update them. At the same time, with the continuous change of network attack methods, such as new zero-day vulnerability exploitation attacks, it is necessary to update security protocols (such as SSL / TLS protocol vulnerability fixes and version upgrades) and access control strategies (such as permission limit adjustments for new vulnerabilities) in a timely manner to ensure that they adapt to the changing security situation and technological development.

[0135] S3.12, through continuous security reinforcement and optimization, improve the overall security of data transmission.

[0136] Continuous security reinforcement and optimization can include a variety of measures. For example, in an unmanned inspection system of a mobile application, continuously optimize the implementation code of encryption algorithms to reduce resource consumption and time delay in the encryption process and improve data transmission efficiency. At the same time, strengthen the management of access control strategies, such as regularly cleaning up expired user accounts and permissions, and increasing security verification steps for new device access. Through these continuous security reinforcement and optimization measures, the overall security of data transmission is improved.

[0137] S4.1, deploy firewalls and intrusion detection systems at the network boundary to monitor and filter data traffic entering and leaving the network in real time. If malicious traffic or attack behavior is found, it will be immediately blocked and an alarm information will be sent out, and relevant logs will be recorded for subsequent analysis and tracking;

[0138] When deploying a firewall and intrusion detection system at the network boundary, for example in an unattended patrol system of a campus network, the firewall can set rules to allow only specific network ports (such as those used for data transmission of unattended patrol devices) and IP address ranges (such as the IP addresses of legal devices on campus) to enter and exit the network. The intrusion detection system monitors network traffic in real time, using feature-based detection methods (such as detecting specific malicious software traffic characteristics) and anomaly-based detection methods (such as detecting abnormal fluctuations in network traffic, such as sudden increases in traffic or a large number of connection requests from the same source address). When malicious traffic or attacks are detected, such as a large number of port scanning traffic from outside the school, the firewall immediately blocks the traffic and sends an alert message, while recording relevant logs, including attack source address, attack time, attack type, etc. Information for subsequent network security personnel to analyze and track, find the source of the attack and take further preventive measures.

[0139] S4.2, install antivirus software and host intrusion detection system on the host terminal, monitor files, processes and registry on the terminal in real time, determine whether there are viruses and malicious programs such as Trojans through signature matching and behavior analysis technology, if detected, immediately isolate or delete, and report alarm information;

[0140] When installing antivirus software and host intrusion detection system on the host terminal, for example in an unattended patrol system of an enterprise office computer, the antivirus software detects viruses through virus signature library matching. For example, when a new malicious software spreads, its code characteristics match the characteristics of a virus in the virus signature library, the antivirus software immediately isolates or deletes it, and reports an alarm message.

[0141] S4.3, for the application of unattended patrol system, use Web Application Firewall to deeply detect access traffic, identify and block common web attacks such as SQL injection and cross-site scripting through rule engine and machine learning algorithm, and authenticate and authorize user identity to avoid illegal access and unauthorized operation;

[0142] For the application of unmanned inspection system to use Web Application Firewall to detect access traffic deeply, for example, in an unmanned inspection system of an e-commerce platform, the rule engine of the Web Application Firewall can set rules for common attacks such as SQL injection. When the user inputs information containing malicious SQL statements (such as SQL injection statements constructed by special characters in the search box) when searching for goods or placing orders, the rule engine will recognize that it is an SQL injection attack attempt according to the preset rules, and immediately intercept it to prevent the request from further accessing the backend database. At the same time, machine learning algorithms can continuously optimize the detection capabilities of the rule engine by learning from a large amount of normal and abnormal access data, and can identify some new and variant SQL injection attack patterns. In terms of user identity authentication and authorization management, multi-factor authentication is used, such as requiring the user to input a mobile phone verification code or use fingerprint recognition and other biometric authentication when logging in. For different user roles, such as ordinary users, administrators, and merchants, different permissions are set, and ordinary users can only browse goods, place orders, and other operations, while administrators can manage goods, user information, and other operations, to avoid illegal access and unauthorized operations and ensure the security of the application system and the integrity of the data.

[0143] S4.4, Establish a security management platform to centrally manage security devices and unmanned inspection systems at various levels, ensure the consistency and effectiveness of various protection measures through unified policy configuration and management, and conduct correlation analysis on various security events to timely discover potential security threats;

[0144] When establishing a security management platform, for example, in a comprehensive unmanned inspection system of a large enterprise, the security management platform can integrate network boundary firewalls, intrusion detection systems, host terminal antivirus software, host intrusion detection systems, and Web Application Firewall of application systems, and other security device and system information at various levels. Through unified policy configuration and management, such as setting unified password strength requirements and network access restriction policies for the entire company, the consistency and effectiveness of various protection measures are ensured. When the network boundary detects a DDoS attack from the outside, the security management platform can correlate and analyze the performance data of the host terminal (such as whether the host response is slow due to the attack) and the access anomaly of the application system (such as a large number of user login failures or transaction interruptions), timely discover potential security threats, and according to the preset emergency response strategy, coordinate the security devices at various levels to respond, such as starting a backup network line, increasing host resource allocation to resist attacks, etc.

[0145] S4.5, Regularly conduct security assessment and penetration testing to comprehensively assess the security status of the unmanned inspection system, find out the weak links and vulnerabilities in the system through simulated attacks, and propose targeted rectification measures to continuously improve the security protection capability of the unmanned inspection system;

[0146] When conducting regular security assessment and penetration testing, for example in an unmanned inspection system of a financial institution, security assessment can use vulnerability scanning tools to scan the system's network architecture, servers, applications, etc. to check for known security vulnerabilities such as vulnerabilities caused by unpatched operating systems, buffer overflow vulnerabilities in application code, etc. Penetration testing simulates hacker attacks by professional security personnel trying to break through the system's security lines, such as obtaining user account passwords through social engineering methods, and then using the account password to try to elevate privileges to access sensitive data. According to the assessment and test results, find out the weak links and vulnerabilities in the system, such as a logical vulnerability in the transfer function of an online banking system that allows attackers to bypass the transfer amount limit. To address these issues, targeted rectification measures are proposed, such as timely updating operating system and application patches, fixing code logic vulnerabilities, and strengthening user account password management, etc. to continuously improve the security protection capability of the unmanned inspection system and ensure the safe conduct of financial transactions.

[0147] S4.6, Strengthen security awareness education and training to improve the safety awareness and skills of relevant personnel, through regular safety propaganda and training to master basic safety operation specifications and emergency response methods;

[0148] When strengthening security awareness education and training, for example in an unmanned inspection system of a government department, through regular organization of safety training courses, basic safety operation specifications such as how to identify phishing emails (such as whether the email source is suspicious, whether the content contains malicious links or attachments), how to safely use office equipment (such as avoiding logging into sensitive systems in public network environments, regularly updating device passwords) are explained to staff. At the same time, emergency response method training is conducted, such as when an office computer is found to be infected with a virus, it should be immediately disconnected from the network and reported to the security management department, and when the system is unable to work normally due to network attacks, data backup, system recovery, etc. operations should be performed according to the predetermined emergency procedures. Through these trainings, the safety awareness and skills of relevant personnel are improved, enabling them to consciously comply with safety regulations in their daily work, reducing security incidents caused by human negligence, and creating a good atmosphere of whole staff participation and mutual prevention.

[0149] S4.7, Establish a sound safety management system and process, clearly define the safety responsibilities and operating procedures of each post, through institutionalized and process-based management, regulate personnel behavior, reduce human error and internal threats, and provide institutional safeguards for the safe operation of the unmanned inspection system.

[0150] When establishing a sound safety management system and process, for example in an unmanned inspection system in a medical institution, the safety responsibilities of the system administrator are clearly defined, such as regular backup of medical data, monitoring of system operation status, timely installation of security patches, etc.; the operating procedures of ordinary users such as doctors and nurses, such as only authorized terminal devices can access patient medical information, and passwords should not be shared arbitrarily. Through institutionalized and process-based management, regulate personnel behavior, reduce human error and internal threats. For example, if there is no strict institutional constraints, doctors may tell others their account passwords for convenience, thereby increasing the risk of medical data leakage. With a sound system and process, such violations can be monitored and punished, providing institutional safeguards for the safe operation of the unmanned inspection system, ensuring the confidentiality, integrity and availability of patient medical information.

[0151] S5.1, Obtain various index data in the running process of the unmanned inspection system, establish a corresponding time series data model for each index, and form a normal mode of index data;

[0152] Obtain various index data in the running process of the unmanned inspection system, for example, in an intelligent factory unmanned inspection system, the index data may include device temperature, vibration amplitude, running current, production efficiency, product pass rate, etc. For each index, a corresponding time series data model is established, such as for the device temperature index, an autoregressive moving average (ARIMA) model can be used. By analyzing the time series characteristics of historical temperature data, the parameters of the model are determined, and the normal mode of the device temperature index data is constructed. This normal mode can reflect the temperature variation of the device over time under normal operating conditions, such as the stable range of temperature in different production stages, the fluctuation amplitude, etc., providing a basis for subsequent anomaly detection.

[0153] S5.2, Use clustering algorithm to cluster and analyze the index data, determine the normal value range of each index according to the clustering results, and obtain the expected threshold;

[0154] When clustering algorithms are used to analyze index data, for example in an unmanned inspection system for a logistics warehouse, multiple index data of the cargo handling equipment (such as running speed, load weight, energy consumption, etc.) are taken as the objects of clustering analysis. The K-Means clustering algorithm is used to divide the data into different clusters according to their similarity. By clustering a large amount of historical data, the center and range of each cluster are determined, and the normal value range of each index, i.e. the expected threshold, is obtained. For example, under normal circumstances, the running speed of the cargo handling equipment fluctuates within a certain interval, the load weight is within a certain rated range, and the energy consumption is at a relatively stable level. When real-time data deviates from the range determined by clustering, it may mean that the equipment is abnormal or there is a potential safety risk.

[0155] S5.3. Continuously acquire real-time data of each index during the operation of the unmanned inspection system, and compare the real-time data with the expected threshold. If the real-time data deviates from the expected threshold, it is judged as abnormal behavior.

[0156] Continuously acquire real-time data of each index during the operation of the unmanned inspection system, for example in an unmanned inspection system for a power substation, real-time acquisition of transformer oil temperature, oil pressure, winding temperature and other index data, and conversion into feature vectors. Then compare these real-time data feature vectors with the expected threshold. If the real-time data of the transformer oil temperature is higher than the expected threshold, it may indicate that the transformer cooling system has failed or there is an overload operation. At this time, it is judged as abnormal behavior. This comparison process is real-time and continuous, so that any abnormal change in system operation can be captured in time to provide the possibility of rapid response.

[0157] S5.4. For the detected abnormal behavior, use the association rule mining algorithm to analyze the association between the abnormal behavior and the safety risk, and obtain the potential safety risk that the abnormal behavior may cause.

[0158] For the detected abnormal behavior, when using the association rule mining algorithm to analyze the association between the abnormal behavior and the safety risk, for example in an unmanned inspection system for a data center, if the abnormal behavior of the server CPU usage rate is detected, the association rule mining algorithm will analyze the changes of other index data related to it, such as memory usage rate, network traffic, etc. By mining the CPU usage rate anomaly and other index changes in a large amount of historical data, it is found that when the CPU usage rate is abnormally high and the memory usage rate also rises rapidly, and the network traffic fluctuates abnormally, there may be a potential security risk of malicious software intrusion or DDoS attack. In this way, the security threat hidden behind the abnormal behavior can be understood in depth, and the basis for formulating targeted security strategies is provided.

[0159] S5.5, According to the severity of abnormal behavior and the size of potential safety risks, use decision tree algorithm to generate corresponding safety decision rules, provide basis for subsequent safety decision;

[0160] When generating corresponding safety decision rules using decision tree algorithm according to the severity of abnormal behavior and the size of potential safety risks, for example, in an unmanned security inspection system in an airport, if the image recognition accuracy of a security inspection device is detected to be declining, the decision tree algorithm will first evaluate the severity of the abnormal behavior. If it only declines slightly, it may only need to arrange maintenance personnel to check and calibrate during off-peak hours; but if the accuracy drops significantly and affects the normal operation of security inspection, the potential safety risk is greater, the decision tree algorithm may generate safety decision rules such as stopping the device immediately, enabling the backup device, notifying safety experts for emergency treatment, etc., to provide clear and explicit basis for subsequent safety decision, ensuring that the system can respond quickly and effectively when facing abnormal situations.

[0161] S5.6, Continuously conduct abnormal detection and safety risk analysis during the operation of unmanned inspection system, dynamically adjust expected threshold and safety decision rules according to the analysis results, improve the accuracy of abnormal detection and the effectiveness of safety decision;

[0162] Continuously conduct abnormal detection and safety risk analysis during the operation of unmanned inspection system, for example, in an unmanned inspection system of intelligent transportation system, as the traffic flow changes, weather conditions change and road facilities update, the environment and conditions of system operation change continuously. Through continuous abnormal detection and safety risk analysis, dynamically adjust the expected threshold and safety decision rules according to new data and actual operation. For example, in heavy rain, road waterlogging will affect the data accuracy of vehicle sensors, at this time the expected threshold of some indicators related to vehicle driving stability can be appropriately relaxed; at the same time, if a new type of traffic signal interference is found to cause an increase in abnormal behavior of vehicles, timely adjust the safety decision rules, increase the safety inspection frequency of traffic signal detection and vehicle autonomous navigation system, improve the accuracy of abnormal detection and the effectiveness of safety decision, to adapt to various dynamic changes in the operation process of the system, and ensure the safe and stable operation of the entire intelligent transportation system.

[0163] S5.7, Real-time feedback of abnormal detection and safety decision results to the administrator of unmanned inspection system, assist the administrator to take corresponding safety precautions in time, reduce safety risks, and ensure the safe and stable operation of unmanned inspection system.

[0164] The results of anomaly detection and safety decisions are fed back to the administrator of the unmanned inspection system in real time. For example, in an unmanned fire inspection system in a large shopping mall, when an abnormally high smoke concentration is detected in a certain area and analysis indicates a potential fire risk, the system immediately feeds back the anomaly detection results (such as smoke concentration values ​​and the location of the abnormal area) and safety decision suggestions (such as activating the fire extinguishing devices in that area and evacuating nearby personnel) to the administrator in real time. The administrator can quickly verify the situation based on this information and take corresponding safety precautions, such as organizing personnel evacuation and notifying the fire department, to reduce safety risks and ensure the safety of people and property in the mall. This ensures that the unmanned inspection system plays an effective auxiliary role in ensuring safety and achieves collaborative safety management between humans and the system. S6. Regularly conduct security assessments and penetration tests on the unmanned inspection system to comprehensively identify security vulnerabilities and weaknesses. For any problems found, timely repair and reinforcement measures should be taken to continuously improve the overall security and resistance to external attacks of the unmanned inspection system.

[0165] S6.1 Based on the architecture and business characteristics of the unmanned inspection system, formulate a comprehensive security assessment and penetration testing plan, clarify the scope, methods and frequency of the assessment, and ensure the systematic and continuous nature of the assessment work for the unmanned inspection system.

[0166] Develop a comprehensive security assessment and penetration testing plan based on the architecture and business characteristics of the unmanned inspection system. For example, for an unmanned inspection system with a distributed architecture and business involving multi-regional data transmission, the assessment scope should cover network nodes, data storage centers, and various business application modules in all regions. Assessment methods may include using vulnerability scanning tools to perform port scanning and vulnerability detection on network devices and servers, manual analysis of business logic vulnerabilities, and inspection of the system's physical security environment. In terms of frequency, a routine vulnerability scan can be performed monthly, and a comprehensive penetration test can be conducted quarterly to ensure the systematic and continuous nature of the assessment work and to promptly identify potential security issues at different levels and at different times.

[0167] S6.2. Use a combination of automated vulnerability scanning tools and manual penetration testing to comprehensively identify security vulnerabilities and weaknesses in the unmanned inspection system, and classify and rate them according to the severity and scope of impact.

[0168] The combination of automated vulnerability scanning tools and manual penetration testing. Automated vulnerability scanning tools such as Nessus can quickly scan a large number of devices and software in the unmanned inspection system, detect vulnerabilities such as operating system vulnerabilities, known security vulnerabilities of common software (such as buffer overflow vulnerabilities in some open source libraries), etc. Manual penetration testing is more focused on simulating real attack scenarios and digging out business logic vulnerabilities that automated tools cannot find. For example, in an e-commerce unmanned inspection system, manual penetration testers will try to detect business logic vulnerabilities such as order amount tampering and malicious modification of commodity inventory by constructing special order transaction processes, and classify and rate vulnerabilities according to their severity (such as whether they can directly obtain user sensitive information, whether they can cause system paralysis) and impact range (such as affecting a single user or all platform users) to determine the priority of subsequent repair.

[0169] S6.3, For the identified security vulnerabilities and weak links, timely develop detailed repair and reinforcement plans, clearly define the repair priority, responsible person and completion time limit, and ensure that the vulnerabilities can be repaired in a timely and effective manner;

[0170] Develop detailed repair and reinforcement plans for identified security vulnerabilities and weak links. For example, for a high-risk vulnerability found in a network device (such as a vulnerability that allows remote unauthorized access), the repair priority is clearly defined as the highest, the responsible person can be the network administrator, and the vulnerability repair is required to be completed within 24 hours, which can be solved by upgrading the device firmware. For some low-risk vulnerabilities in application systems (such as minor information leakage in interface display), the priority is low, and developers can be assigned to fix the code within a week. Through such clear plan development, vulnerabilities can be repaired in a timely and effective manner, avoiding the use of vulnerabilities by attackers due to long-term existence, and ensuring the safe and stable operation of the unmanned inspection system.

[0171] S6.4, After the completion of vulnerability repair, verify the effectiveness of the repair measures through regression testing and verification testing methods, and perform security reinforcement on the repaired unmanned inspection system to improve the overall security performance of the unmanned inspection system;

[0172] After the vulnerability is fixed, regression testing and verification testing are performed. Regression testing mainly checks whether the operation of fixing the vulnerability has any impact on the original functions of the system. For example, in an industrial control unmanned inspection system, after fixing a data transmission encryption vulnerability, regression testing is performed on the system's data collection, device control, and other functions to ensure that these functions are still running normally. Verification testing focuses on verifying whether the repair measures have truly solved the vulnerability problem. This can be verified by using vulnerability scanning tools again or simulating the attack scenario of the previously discovered vulnerability. For example, after fixing the SQL injection vulnerability, use a specialized SQL injection testing tool to verify. If it is no longer possible to successfully inject, it means that the repair is effective. Then further security hardening is performed on the repaired system, such as optimizing system configuration, increasing access restriction policies, etc., to improve the overall security performance of the system.

[0173] S6.5, Establish a security vulnerability management database to record all identified security vulnerabilities and weak links, as well as corresponding repair and reinforcement measures, and conduct regular statistical analysis to master the changing trend of the security status of the unmanned inspection system;

[0174] Establish a security vulnerability management database. For example, in a financial unmanned inspection system, each time a security vulnerability (such as missing security patches for server operating systems, code vulnerabilities for application programs, etc.) and weak link (such as loose access control for a network segment in the network architecture) is discovered, and the corresponding repair and reinforcement measures (such as the version number of the installed patch, the specific content of the modified network access control policy) are recorded in the database. Regularly analyze the database, such as the frequency of different types of vulnerabilities and the distribution of repair time, to master the changing trend of the security status of the unmanned inspection system, so as to predict possible security problems in advance and develop corresponding prevention strategies, and also facilitate the summary and improvement of the security management work of the system.

[0175] S6.6, Through machine learning algorithms, analyze and mine security vulnerability data to identify common problems and weak links in the unmanned inspection system, and provide decision support for subsequent security reinforcement; machine learning algorithms include support vector machines, decision trees, and random forests;

[0176] Security vulnerability data is analyzed and mined through machine learning algorithms. Taking the support vector machine algorithm as an example, in a comprehensive unmanned inspection system of a large enterprise, various features in the security vulnerability data (such as vulnerability type, location of occurrence, affected business module, etc.) are taken as input to train a support vector machine model. Through model analysis, common problems existing in the system are found, such as finding that network devices of a certain brand often have specific types of vulnerabilities, or that code written by a certain development team is prone to certain types of logical vulnerabilities, etc. Weaknesses provide decision support for subsequent security reinforcement, such as focusing on monitoring and upgrading plans for network devices of that brand, and targeted code specification training for related development teams, etc.

[0177] S6.7, based on the analysis results of machine learning, continuously optimize and improve the methods and strategies of security assessment and penetration testing, improve the pertinence and effectiveness of the assessment, and continuously improve the overall security performance and resistance to external attacks of the unmanned inspection system.

[0178] Based on the analysis results of machine learning, the methods and strategies of security assessment and penetration testing are optimized and improved. For example, if machine learning analysis finds that a new business module in the system has many unknown types of vulnerability risks, then in subsequent security assessment, the proportion of manual deep penetration testing of this module is increased, the scanning strategy of the vulnerability scanning tool is adjusted, and the vulnerability features related to this module are focused on. At the same time, according to the analysis results, the scene library of penetration testing is updated, the simulated attack scenes for newly discovered common problems are increased, the pertinence and effectiveness of the assessment are improved, the overall security performance and resistance to external attacks of the unmanned inspection system are continuously improved, and the security protection system of the system can evolve and improve with the development of the system and the changes of the external security environment.

[0179] An unmanned inspection and intelligent fault judgment system, comprising:

[0180] A threat modeling and strategy generation module for constructing a security threat model of the unmanned inspection system, determining potential network attacks and illegal access risks, and formulating security strategies and technical measures according to the business characteristics of the unmanned inspection system;

[0181] A deep learning security analysis module for modeling the running state of the unmanned inspection system through deep learning algorithms using a security analysis method based on contrast technology, obtaining the feature patterns of normal and abnormal states, and if the running state of the unmanned inspection system deviates from the normal pattern, it is judged that there is a potential security threat, triggering a real-time response mechanism;

[0182] A data security guarantee module is configured to comprehensively use security protocols, encryption technology and access control strategies to encrypt and protect and control the rights of the transmission data in the data transmission process of the unmanned inspection system, prevent the data from being illegally intercepted and tampered with, and ensure the confidentiality and integrity of the data transmission.

[0183] A multi-level security protection deployment module is configured to design a multi-level security protection architecture for the unmanned inspection scene, deploy security protection measures at different levels including network boundaries, host terminals and application unmanned inspection systems, and comprehensively improve the security protection capability of the unmanned inspection system by building a depth defense system.

[0184] An anomaly detection and risk judgment module is configured to continuously monitor various index data in the operation process of the unmanned inspection system by using an anomaly detection method, compare and analyze the data with a pre-established normal mode, timely find abnormal behaviors deviating from the expected threshold, judge potential security risks, and provide a basis for subsequent security decisions.

[0185] A security evaluation and reinforcement module is configured to periodically carry out security evaluation and penetration testing of the unmanned inspection system, comprehensively investigate security vulnerabilities and weak links in the unmanned inspection system, timely take repair and reinforcement measures for the problems found, and continuously improve the overall security of the unmanned inspection system and the ability to resist external attacks.

[0186] A computer device comprises:

[0187] One or more processors;

[0188] The processor is configured to store one or more programs;

[0189] When the one or more programs are executed by the one or more processors, the method for unmanned inspection and intelligent fault judgment is implemented.

[0190] A computer readable storage medium has a computer program stored thereon, and the computer program is executed to implement the method for unmanned inspection and intelligent fault judgment.

[0191] Embodiment 1:

[0192] Step S101, according to the business characteristics of the unmanned inspection system, a security threat model of the unmanned inspection system is constructed, potential network attacks and illegal access risks are determined, and security strategies and technical measures are formulated.

[0193] According to the business characteristics of the unmanned inspection system, a deep learning algorithm is used to analyze the historical operation data of the unmanned inspection system, a security threat model of the unmanned inspection system is constructed, and potential network attacks and illegal access risks are identified. For the identified security threats, a decision tree algorithm is used to automatically infer the targeted security protection measures in combination with the preset security policy knowledge base. Real-time operation data of the unmanned inspection system is obtained, and by comparing and analyzing with the security threat model, it is judged whether there is a network attack and illegal access risk in the unmanned inspection system, and if there is, the corresponding security protection measures are triggered. According to the new security threats identified in the operation process of the unmanned inspection system, through the reinforcement learning algorithm, the existing security threat model and security policy knowledge base are continuously optimized and improved, and the security protection capability of the unmanned inspection system is improved. According to the characteristics of the unmanned inspection business scene, a distributed security protection mechanism based on blockchain is deployed to encrypt and store and verify the key business data of the unmanned inspection system, ensuring the confidentiality and integrity of the data. A zero-trust architecture is used to strictly authenticate and authorize the identity of all users and devices in the unmanned inspection system, minimizing potential internal threats, thereby further strengthening the overall security of the unmanned inspection system. The security running state of the unmanned inspection system is continuously monitored, and through visualization technology, the security threat situation of the unmanned inspection system is presented in real time, providing intuitive decision support for security management personnel, and continuously optimizing the security protection level of the unmanned inspection system.

[0194] In step S102, a security analysis method based on a contrast technology is used to model the operation state of the unmanned inspection system through a deep learning algorithm to obtain the feature patterns of the normal state and the abnormal state. If it is detected that the operation state of the unmanned inspection system deviates from the normal pattern, it is judged that there is a potential security threat, and a real-time response mechanism is triggered.

[0195] According to the deep learning algorithm, the operation state data of the unmanned inspection system is feature extracted and represented, and a feature model of the state of the unmanned inspection system is constructed. An unsupervised learning method is used to cluster the state features of the unmanned inspection system through a clustering algorithm to obtain a feature cluster representing the normal pattern and a feature cluster representing the abnormal pattern. In the operation process of the unmanned inspection system, the state data of the unmanned inspection system is obtained in real time, the feature vector is extracted, and similarity calculation is performed with the feature cluster of the normal pattern. If the feature vector deviates from the feature cluster of the normal pattern by more than a preset threshold, it is determined that the unmanned inspection system is in an abnormal state and there is a potential security threat. According to the severity of the abnormal state and the threat level, the strategy and intensity of the real-time response mechanism are dynamically adjusted. Through active defense measures, abnormal behavior is blocked and isolated, the impact range of security threats is reduced, and the safe and stable operation of the unmanned inspection system is ensured. The deep learning model is continuously optimized through incremental learning and online learning to continuously improve the accuracy of anomaly detection and the efficiency of real-time response.

[0196] In step S103, during the data transmission process of the unmanned inspection system, security protocols, encryption techniques, and access control strategies are comprehensively used to encrypt and protect the transmission data and control the rights, prevent the data from being illegally intercepted and tampered with, and ensure the confidentiality and integrity of the data transmission.

[0197] According to the sensitivity of the data and the transmission environment, appropriate security protocols such as SSL / TLS are selected to establish a secure transmission channel and encrypt the transmission process. Symmetric encryption and asymmetric encryption are combined to encrypt the transmission data. Through a secure key management mechanism, the confidentiality and integrity of the encryption key are ensured. Before transmitting the data, the data is digitally signed to ensure its integrity. The receiving party verifies the digital signature to determine whether the data has been tampered with. Role-based access control policies are used to manage the rights of different users and the unmanned inspection system. Through identity authentication and authorization mechanisms, access and operation of data by illegal users are restricted. During the transmission process, secure routing protocols and network isolation techniques are used to prevent data from being illegally intercepted and eavesdropped during transmission. A complete log audit and monitoring mechanism is established to monitor the data transmission process in real time and detect abnormal behavior. Machine learning algorithms are used to identify and warn potential security threats. Security protocols, encryption algorithms, and access control strategies are regularly evaluated and updated to ensure their adaptability to changing security situations and technological development. Through continuous security reinforcement and optimization, the overall security of data transmission is improved.

[0198] In step S104, a multi-level security protection architecture is designed for the unmanned inspection scene, and security protection measures are deployed at different levels such as network boundaries, host terminals, and application unmanned inspection systems. By building a multi-layer defense system, the security protection capability of the unmanned inspection system is comprehensively improved.

[0199] Firewalls and intrusion detection systems are deployed at the network boundary to monitor and filter data traffic entering and leaving the network in real time. If malicious traffic or attack behavior is detected, it is immediately blocked and an alarm is issued, while relevant logs are recorded for subsequent analysis and tracing. Antivirus software and host intrusion detection systems are installed on host terminals to monitor files, processes, and the registry in real time. Signature matching and behavioral analysis technologies are used to determine the presence of viruses, Trojans, or other malicious programs. If detected, they are immediately isolated or deleted, and alarm information is reported. For the unmanned inspection system, a web application firewall is used to perform deep inspection of access traffic. Through rule engines and machine learning algorithms, common web attacks such as SQL injection and cross-site scripting are identified and blocked. User authentication and authorization management are also implemented to prevent unauthorized access and unauthorized operations. A security management platform is established to centrally manage security devices and unmanned inspection systems at all levels. Through unified policy configuration and management, the consistency and effectiveness of various protective measures are ensured, and correlation analysis of various security events is performed to promptly identify potential security threats. Regularly conduct security assessments and penetration tests to comprehensively evaluate the security status of the unmanned inspection system. Through simulated attacks, identify weaknesses and vulnerabilities in the system and propose targeted corrective measures to continuously improve its security capabilities. Strengthen security awareness education and training to improve the security awareness and skills of relevant personnel. Through regular security publicity and training, ensure they master basic safe operating procedures and emergency response methods, fostering a positive atmosphere of full participation and joint prevention. Establish and improve security management systems and processes, clearly defining the security responsibilities and operating procedures for each position. Through institutionalized and process-oriented management, standardize personnel behavior, reduce human error and internal threats, and provide institutional guarantees for the safe operation of the unmanned inspection system.

[0200] Step S105: Using anomaly detection technology, continuously monitor various indicator data during the operation of the unmanned inspection system. By comparing and analyzing the data with the pre-established normal mode, timely detect abnormal behaviors that deviate from the expected threshold, identify potential safety risks, and provide a basis for subsequent safety decisions.

[0201] The index data in the operation process of the unmanned inspection system is acquired, a corresponding time series data model is established for each index to form a normal mode of the index data, clustering analysis is performed on the index data by using a clustering algorithm, the normal value range of each index is determined according to the clustering result to obtain an expected threshold, real-time data of each index is continuously acquired in the operation process of the unmanned inspection system, the real-time data is compared with the expected threshold, if the real-time data deviates from the expected threshold, it is judged as an abnormal behavior, for the detected abnormal behavior, a correlation rule mining algorithm is used to analyze the correlation between the abnormal behavior and a security risk to obtain a potential security risk possibly caused by the abnormal behavior, according to the severity of the abnormal behavior and the size of the potential security risk, a decision tree algorithm is used to generate a corresponding security decision rule to provide a basis for subsequent security decision, the abnormal detection and security risk analysis are continuously performed in the operation process of the unmanned inspection system, the expected threshold and the security decision rule are dynamically adjusted according to the analysis result to improve the accuracy of the abnormal detection and the effectiveness of the security decision, the result of the abnormal detection and the security decision is fed back to the administrator of the unmanned inspection system in real time to assist the administrator to timely take corresponding security prevention measures, reduce the security risk and guarantee the safe and stable operation of the unmanned inspection system.

[0202] In step S106, the safety evaluation and penetration testing of the unmanned inspection system are carried out regularly, the security vulnerabilities and weak links existing in the unmanned inspection system are comprehensively investigated, the repair and reinforcement measures are taken in a timely manner for the problems found, and the overall safety and the ability to resist external attacks of the unmanned inspection system are continuously improved.

[0203] According to the architecture and business characteristics of the unmanned inspection system, a comprehensive security assessment and penetration testing plan is developed, and the scope, method and frequency of the assessment are clearly defined to ensure the systematicness and continuity of the assessment work. The combination of automated vulnerability scanning tools and manual penetration testing is adopted to comprehensively identify the security vulnerabilities and weak links in the unmanned inspection system, and the vulnerabilities are classified and rated according to their severity and impact. For the identified security vulnerabilities and weak links, detailed repair and reinforcement schemes are developed in a timely manner, and the repair priority, responsible person and completion time limit are clearly defined to ensure that the vulnerabilities can be repaired in a timely and effective manner. After the completion of the vulnerability repair, regression testing and verification testing are used to verify the effectiveness of the repair measures, and the security of the repaired unmanned inspection system is reinforced to improve the overall security performance of the unmanned inspection system. A security vulnerability management database is established to record all identified security vulnerabilities and weak links, as well as the corresponding repair and reinforcement measures, and regular statistical analysis is conducted to master the changing trend of the security status of the unmanned inspection system. Through machine learning algorithms such as support vector machine, decision tree and random forest, the security vulnerability data is analyzed and mined to identify common problems and weak links in the unmanned inspection system, providing decision support for subsequent security reinforcement. Based on the analysis results of machine learning, the methods and strategies of security assessment and penetration testing are continuously optimized and improved to improve the pertinence and effectiveness of the assessment, and the overall security performance and resistance to external attacks of the unmanned inspection system are continuously improved.

[0204] The above embodiments are only preferred technical solutions of the present application, and should not be regarded as limitations of the present application. The protection scope of the present application should be based on the technical solutions recited in the claims, including equivalent replacement solutions of the technical features recited in the claims. That is, equivalent replacement improvements within this scope are also within the protection scope of the present application.

Claims

1. A method for unmanned inspection and intelligent fault judgment, characterized in that Comprise the following steps: S1, according to the business characteristics of unmanned inspection system, build unmanned inspection system security threat model, determine the potential network attack and illegal access risk, formulate security policy and technical measures; S2, using the security analysis method based on contrast technology, through deep learning algorithm, the normal state and the characteristic mode of abnormal state are obtained by modeling the running state of unmanned inspection system, if the running state of unmanned inspection system deviates from the normal mode, it is judged that there is potential security threat, and the real-time response mechanism is triggered; S3, in the process of data transmission of unmanned inspection system, the security protocol, encryption technology and access control strategy are comprehensively used, the transmission data is encrypted and protected and the permission control is carried out, so as to prevent the data from being illegally intercepted and tampered, and ensure the confidentiality and integrity of data transmission; S4, for unmanned inspection scene, design multi-level security protection architecture, deploy security protection measures in different levels including network boundary, host terminal and application unmanned inspection system, and build in-depth defense system to improve the security protection ability of unmanned inspection system; S5, using abnormal detection method, continuously monitor the index data in the running process of unmanned inspection system, compare and analyze with the normal mode established in advance, find out the abnormal behavior deviating from the expected threshold in time, judge the potential security risk, and provide basis for subsequent security decision; S6, carry out security evaluation and penetration test of unmanned inspection system regularly, fully investigate the security vulnerabilities and weak links in unmanned inspection system, take repair and reinforcement measures in time according to the problems found, and continuously improve the overall security and resistance to external attack of unmanned inspection system.

2. The unmanned inspection and intelligent fault judgment method according to claim 1, characterized in that: The sub steps of S1 are: S1.1, according to the business characteristics of unmanned inspection system, using deep learning algorithm, analyze the historical running data of unmanned inspection system, build unmanned inspection system security threat model, and identify potential network attack and illegal access risk; S1.2, for the identified security threat, using decision tree algorithm, combined with the preset security policy knowledge base, automatically infer the corresponding security protection measures; S1.3, get the real-time running data of unmanned inspection system, compare and analyze with the security threat model, judge whether there is network attack and illegal access risk in unmanned inspection system in real time, if there is, trigger the corresponding security protection measures; S1.4, according to the new security threat identified in the running process of unmanned inspection system, through reinforcement learning algorithm, continuously optimize and improve the existing security threat model and security policy knowledge base, and improve the security protection ability of unmanned inspection system; S1.5, according to the characteristics of unmanned inspection business scene, deploy distributed security protection mechanism based on blockchain, encrypt and store the key business data of unmanned inspection system, and verify the data to ensure the confidentiality and integrity of the data; S1.6, using zero trust architecture, strictly authenticate and authorize the identity of all users and devices in unmanned inspection system, minimize the potential internal threat, so as to further strengthen the overall security of unmanned inspection system; S1.7, continuously monitor the safe operation state of the unmanned inspection system, present the security threat situation of the unmanned inspection system in real time through visualization technology, provide intuitive decision support for security management personnel, and continuously optimize the security protection level of the unmanned inspection system.

3. The unmanned inspection and intelligent fault judgment method according to claim 1, characterized in that: The sub-steps of S2 are: S2.1, according to the deep learning algorithm, feature extraction and representation learning are performed on the unmanned inspection system operation state data, and a feature model of the unmanned inspection system state is constructed; S2.2, using unsupervised learning method, clustering algorithm is used to cluster the feature of unmanned inspection system state, and feature cluster representing normal mode and feature cluster representing abnormal mode are obtained; S2.3, in the running process of the unmanned inspection system, the state data of the unmanned inspection system is obtained in real time, the feature vector is extracted, and the similarity calculation is carried out with the feature cluster of normal mode; S2.4, if the feature vector deviates from the feature cluster of normal mode more than the preset threshold, it is judged that the unmanned inspection system is in abnormal state, and there is potential security threat; S2.5, according to the severity of abnormal state and threat level, the strategy and intensity of real-time response mechanism are dynamically adjusted; S2.6, through active defense measures, abnormal behavior is blocked and isolated, the influence range of security threat is reduced, and the safe and stable operation of the unmanned inspection system is ensured; S2.7, continuously optimize the deep learning model, and through incremental learning and online learning, continuously improve the accuracy of anomaly detection and the efficiency of real-time response.

4. The unmanned inspection and intelligent fault judgment method according to claim 1, characterized in that: The sub-steps of S3 are: S3.1, according to the sensitivity of data and transmission environment, a secure transmission channel is established through security protocol, and the transmission process is encrypted for protection; the security protocol is SSL or TLS; S3.2, using the combination of symmetric encryption and asymmetric encryption, the transmission data is encrypted; S3.3, through the safe key management mechanism, the confidentiality and integrity of the encryption key are ensured; S3.4, before transmitting data, the data is digitally signed to ensure the integrity of the data; S3.5, the receiver verifies the digital signature to determine whether the data has been tampered with; S3.6, role-based access control strategy is adopted to manage the permissions of different users and the unmanned inspection system; S3.7, through identity authentication and authorization mechanism, the access and operation of illegal users to data are limited; S3.8, in the transmission process, safe routing protocol and network isolation technology are adopted to prevent data from being illegally intercepted and eavesdropped in the transmission process; S3.9, a perfect log audit and monitoring mechanism is established to monitor and detect abnormal behavior in real time during data transmission process; S3.10, through machine learning algorithm, potential security threats are identified and warned; S3.11, the security protocol, encryption algorithm and access control strategy are evaluated and updated regularly; S3.12, through continuous security reinforcement and optimization, the overall security of data transmission is improved.

5. The unmanned inspection and intelligent fault judgment method according to claim 1, characterized in that: The sub-steps of S4 are: S4.1, Deploy firewalls and intrusion detection systems at network boundaries to monitor and filter data traffic in real time, and if malicious traffic or attack behavior is found, immediately block and send alarm information, and record relevant logs for subsequent analysis and tracking; S4.2, Install antivirus software and host intrusion detection systems on host terminals to monitor files, processes and registries in real time, and use signature matching and behavior analysis techniques to determine whether there are viruses and Trojan malware, and if detected, immediately isolate or delete and report alarm information; S4.3, For application unmanned inspection system, use Web Application Firewall to deeply detect access traffic, identify and block common web attacks such as SQL injection and cross-site scripting through rule engine and machine learning algorithm, and authenticate and authorize user identity to avoid illegal access and unauthorized operation; S4.4, Establish a security management platform to centrally manage security devices and unmanned inspection systems at various levels, ensure consistency and effectiveness of various protection measures through unified policy configuration and management, and correlate and analyze various security events to detect potential security threats in a timely manner; S4.5, Conduct regular security assessment and penetration testing to comprehensively assess the security status of the unmanned inspection system, find weak links and vulnerabilities in the unmanned inspection system through simulated attacks, and propose targeted corrective measures to continuously improve the security protection capability of the unmanned inspection system; S4.6, Strengthen security awareness education and training to improve the safety awareness and skills of relevant personnel, and through regular safety propaganda and training, make them master the basic safety operation specifications and emergency disposal methods; S4.7, Establish and improve safety management systems and processes, clearly define the safety responsibilities and operating procedures of each post, standardize personnel behavior through institutionalized and process-oriented management, reduce human error and internal threats, and provide institutional safeguards for the safe operation of the unmanned inspection system.

6. The unmanned inspection and intelligent fault judgment method according to claim 1, characterized in that: The sub-steps of S5 are: S5.1, Obtain various index data during the operation of the unmanned inspection system, establish a corresponding time series data model for each index, and form a normal pattern of index data; S5.2, Use clustering algorithm to cluster and analyze the index data, determine the normal value range of each index according to the clustering results, and obtain the expected threshold value; S5.3, Continuously obtain real-time data of various indexes during the operation of the unmanned inspection system, compare the real-time data with the expected threshold value, and if the real-time data deviates from the expected threshold value, it is determined as abnormal behavior; S5.4, For the detected abnormal behavior, use association rule mining algorithm to analyze the association between abnormal behavior and security risk, and obtain the potential security risk that may be caused by abnormal behavior; S5.5, According to the severity of the abnormal behavior and the size of the potential security risk, use decision tree algorithm to generate corresponding security decision rules to provide basis for subsequent security decision making; S5.6, continuously conduct anomaly detection and security risk analysis during the operation of the unmanned inspection system, dynamically adjust the expected threshold and security decision rules according to the analysis results, and improve the accuracy of anomaly detection and the effectiveness of security decision; S5.7, real-time feedback the results of anomaly detection and security decision to the administrator of the unmanned inspection system, assist the administrator to take corresponding security prevention measures in time, reduce security risks, and ensure the safe and stable operation of the unmanned inspection system.

7. The unmanned inspection and intelligent fault judgment method according to claim 1, characterized in that: The sub-steps of S6 are: S6.1, according to the architecture and business characteristics of the unmanned inspection system, develop a comprehensive security assessment and penetration testing plan, clearly define the scope, method and frequency of the assessment, and ensure the systematicness and continuity of the assessment work of the unmanned inspection system; S6.2, use a combination of automated vulnerability scanning tools and manual penetration testing to comprehensively identify security vulnerabilities and weak links in the unmanned inspection system, and classify and rate them according to their severity and impact; S6.3, for the identified security vulnerabilities and weak links, develop detailed repair and reinforcement schemes in a timely manner, clearly define the repair priority, responsible person and completion time limit, and ensure that the vulnerabilities can be repaired in a timely and effective manner; S6.4, after the completion of the vulnerability repair, verify the effectiveness of the repair measures through regression testing and validation testing, and reinforce the security of the repaired unmanned inspection system to improve the overall security performance of the unmanned inspection system; S6.5, establish a security vulnerability management database to record all identified security vulnerabilities and weak links, as well as the corresponding repair and reinforcement measures, and conduct statistical analysis regularly to grasp the changing trend of the security status of the unmanned inspection system; S6.6, through machine learning algorithms, analyze and mine security vulnerability data to identify common problems and weak links in the unmanned inspection system, providing decision support for subsequent security reinforcement; Machine learning algorithms include support vector machines, decision trees and random forests; S6.7, based on the analysis results of machine learning, continuously optimize and improve the methods and strategies of security assessment and penetration testing, improve the pertinence and effectiveness of the assessment, and continuously improve the overall security performance and resistance to external attacks of the unmanned inspection system.

8. An unmanned inspection and intelligent fault judgment system, characterized in that: It includes: Threat modeling and strategy generation module, used to construct the security threat model of the unmanned inspection system according to the business characteristics of the unmanned inspection system, determine the potential network attack and illegal access risk, and develop security strategies and technical measures; Deep learning security analysis module, used to adopt security analysis methods based on contrast technology, model the running state of the unmanned inspection system through deep learning algorithms, obtain the feature patterns of normal state and abnormal state, and if the running state of the unmanned inspection system deviates from the normal mode, it is judged that there is a potential security threat, triggering the real-time response mechanism; Data security protection module, used to comprehensively use security protocols, encryption technology and access control strategies during data transmission in the unmanned inspection system, to encrypt and protect the transmission data and control the access rights, prevent data from being illegally intercepted and tampered, and ensure the confidentiality and integrity of data transmission; The multi-level security protection deployment module is used for designing a multi-level security protection architecture for the unmanned inspection scene, deploying security protection measures at different levels including network boundaries, host terminals and application unmanned inspection systems, and improving the security protection capability of the unmanned inspection system in all directions by constructing a defense-in-depth system. The abnormality detection and risk judgment module is used for continuously monitoring various index data in the operation process of the unmanned inspection system by using an abnormality detection method, comparing and analyzing the data with a pre-established normal mode, discovering abnormal behaviors deviating from the expected threshold in a timely manner, judging potential security risks, and providing a basis for subsequent security decisions. The security evaluation and reinforcement module is used for periodically carrying out security evaluation and penetration testing of the unmanned inspection system, comprehensively checking security vulnerabilities and weak links in the unmanned inspection system, taking timely repair and reinforcement measures for the discovered problems, and continuously improving the overall security of the unmanned inspection system and the ability to resist external attacks.

9. A computer device, comprising: The method comprises the following steps: one or more processors; the processor is used to store one or more programs; when the one or more programs are executed by the one or more processors, the method for unmanned inspection and intelligent fault judgment according to any one of claims 1-7 is realized.

10. A computer-readable storage medium, characterized in that: The computer program is stored thereon, and when the computer program is executed, the method for unmanned inspection and intelligent fault judgment according to any one of claims 1-7 is realized.

Citation Information

Patent Citations

  • Video intelligent analysis auxiliary inspection and abnormity warning method

    CN111274880A

  • Industrial control host security event automatic response method based on artificial intelligence

    CN117648689A