Low-latency Event Response Method Based on Information Security Monitoring and Early Warning AI Platform

By adopting a low-latency incident response method on the information security monitoring and early warning AI platform, monitoring data is collected and analyzed in real time, forming a priority response chain and conducting correlation tracking, the problem of lagging security incident early warning response in the existing technology is solved, and fast and effective security incident response is achieved.

CN119835090BActive Publication Date: 2025-06-10GUANGDONG SHINELY INFORMATION ENG CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510302013.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-06-10
Estimated Expiration
2045-03-14

AI Technical Summary

Technical Problem

The prior art cannot promptly and effectively respond to security incidents, resulting in delayed reactions, complex information processing, and difficulty in judging priorities.

Method used

The low-latency incident response method based on the information security monitoring and early warning AI platform is adopted, and monitoring data is collected in real time through sensor nodes, information abnormality and spatiotemporal characteristics node value are identified, and information response chains with priority response weights are formed, and information correlation tracking and priority adjustment are carried out.

Benefits of technology

It improves the response speed to security incidents, ensures low latency processing, reduces irrelevant incident interference, can quickly identify potential threats, and enhances the system's emergency response capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119835090B_ABST
    Figure CN119835090B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of information security early warning, and discloses a low-latency event response method based on an information security monitoring and early warning AI platform. The present invention collects various types of monitoring data in real time through sensor nodes, identifies the information anomaly degree and the value of spatio-temporal characteristic nodes of the collected data, processes according to the information encapsulation standard, forms an information response chain with a priority response weight, analyzes the information to be analyzed sequentially through the information analysis layer to obtain early warning feedback characteristics, performs information correlation tracking based on the early warning feedback characteristics, classifies the relevant information into highly correlated information and ordinary correlated information and adjusts the response priority respectively, improves the response speed to security events, ensures low-latency processing, optimizes the response priority through intelligent analysis, effectively reduces the interference of irrelevant events, can quickly identify potential threats in multi-dimensional data, enhances the emergency handling ability of the system, and solves the problem that the prior art cannot give an early warning response to security events in a timely and effective manner.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security early warning, and particularly to a low-latency event response method based on an information security monitoring and early warning AI platform. Background Art

[0002] Network security in modern society is not only limited to preventing traditional network attacks such as viruses, Trojans, and ransomware. More and more physical security issues have also come into the scope of security protection. Especially in systems such as industrial Internet of Things (IIoT), smart grid, and smart building, the monitoring of physical parameters (such as temperature, humidity, gas leakage, vibration, etc.) is often intertwined with network security events. For example, problems such as sensor failures, gas leakage, or equipment anomalies occurring at the physical level may directly trigger network security events. Conversely, network attacks may also cause failures or malfunctions of physical devices. In response to this cross-domain security protection requirement, traditional security monitoring systems often have problems such as lagging response, complex information processing, and difficult priority judgment, and cannot effectively give early warning responses to security events in a timely manner. Summary of the Invention

[0003] The purpose of the present invention is to provide a low-latency event response method based on an information security monitoring and early warning AI platform, aiming to solve the problem that existing technologies cannot effectively give early warning responses to security events in a timely manner.

[0004] The present invention is implemented as follows. In a first aspect, the present invention provides a low-latency event response method based on an information security monitoring and early warning AI platform, including:

[0005] The data acquisition layer is used to perform real-time acquisition of monitoring data on a number of pre-deployed sensor nodes to obtain the monitoring data corresponding to each of the sensor nodes;

[0006] According to the information encapsulation standard, identify the information abnormality degree and evaluate the value of the spatio-temporal characteristic nodes of the monitoring data of each of the sensor nodes, and perform information encapsulation processing on the monitoring data of each of the sensor nodes in each time period according to the obtained abnormality index and node value parameter to obtain an information response chain composed of a number of pieces of information to be analyzed with priority response weights; wherein, the information response chain includes an immediate response chain, a priority response chain, and a normal response chain;

[0007] The information analysis layer is used to perform sequential analysis processing on each of the pieces of information to be analyzed in the information response chain to obtain the early warning feedback characteristics of each of the pieces of information to be analyzed;

[0008] Track information association of the information response chain according to the early warning feedback characteristics of the information to be analyzed, divide the information to be analyzed in the information response chain that has an information association relationship with the information to be analyzed into highly associated information and general associated information, increase the priority response weight of the highly associated information, and determine whether to adjust the priority response weight of the general associated information according to the early warning feedback characteristics of the highly associated information, so as to enable the information analysis layer to sequentially analyze the information response chain.

[0009] The present invention provides a low-latency event response method based on an information security monitoring and early warning AI platform, which has the following beneficial effects:

[0010] The present invention relates to the technical field of information security early warning, and discloses a low-latency event response method based on an information security monitoring and early warning AI platform. The present invention collects various monitoring data in real time through sensor nodes, identifies the information abnormality degree and the value of the spatio-temporal characteristic nodes of the collected data, processes them according to the information encapsulation standard, forms an information response chain with a priority response weight, sequentially analyzes the information to be analyzed through the information analysis layer to obtain early warning feedback characteristics, conducts information association tracking based on the early warning feedback characteristics, divides the relevant information into highly associated information and general associated information, respectively adjusts the response priority, improves the response speed to security events, ensures low-latency processing, optimizes the response priority through intelligent analysis, effectively reduces the interference of irrelevant events, can quickly identify potential threats in multi-dimensional data, enhances the emergency handling ability of the system, and solves the problem that security events cannot be warned and reacted in a timely and effective manner in the prior art. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Figure 1 It is a schematic diagram of the steps of a low-latency event response method based on an information security monitoring and early warning AI platform provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0012] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0013] The implementation of the present invention will be described in detail below with reference to specific embodiments.

[0014] Refer to Figure 1 as shown, which is a preferred embodiment provided by the present invention.

[0015] In a first aspect, the present invention provides a low-latency event response method based on an information security monitoring and early warning AI platform, including:

[0016] S1: The system performs real-time acquisition of monitoring data from a number of pre-deployed sensor nodes through the data acquisition layer to obtain the monitoring data corresponding to each of the sensor nodes;

[0017] S2: According to the information encapsulation standard, identify the information abnormality degree and evaluate the value of the spatio-temporal characteristic nodes for the monitoring data of each of the sensor nodes, and perform information encapsulation processing on the monitoring data of each of the sensor nodes in each time period according to the obtained abnormality degree index and node value parameter to obtain an information response chain composed of a number of to-be-analyzed information with priority response weights; wherein, the information response chain includes an immediate response chain, a priority response chain, and a normal response chain;

[0018] S3: The information analysis layer performs sequential analysis processing on each of the to-be-analyzed information in the information response chain to obtain the warning feedback characteristics of each of the to-be-analyzed information;

[0019] S4: Perform information association tracking on the information response chain according to the warning feedback characteristics of the to-be-analyzed information, and classify the to-be-analyzed information in the information response chain that has an information association relationship with the to-be-analyzed information into highly associated information and normally associated information, increase the priority response weight of the highly associated information, and decide whether to adjust the priority response weight of the normally associated information according to the warning feedback characteristics of the highly associated information for the information analysis layer to perform sequential analysis on the information response chain.

[0020] Specifically, in step S1 of the embodiment provided by the present invention, before data acquisition, the system first needs to analyze the node addresses of each sensor node, and these node addresses may include different dimensional information, for example: network node dimension: referring to the position of the sensor node in the network (such as IP address, network topology position), positioning map dimension: referring to the specific position of the sensor in the physical space (such as GPS coordinates or geographical location), regional function dimension: referring to the functional characteristics of the area where the sensor is located, such as industrial area, office area, transportation hub, etc., traffic association dimension: if it is a sensor node related to traffic, it may involve information such as traffic flow and vehicle speed. The analysis of the node addresses enables the system to more accurately identify the specific position and function of each sensor node, so as to more effectively locate and classify the monitoring data. Through these dimensional information, the function and importance of each sensor can be quickly understood, thus laying a foundation for subsequent data acquisition and response priority allocation.

[0021] More specifically, after analyzing the addresses of the sensor nodes, the system needs to perform data port settings to ensure information connectivity between each sensor node and the data acquisition layer. The purpose of this step is to ensure that the collected data can be seamlessly transmitted to the acquisition system for subsequent processing. By setting the data ports, the system can allocate appropriate data transmission paths (such as TCP / IP protocol, wireless communication, etc.) for each sensor node, ensuring the reliability of data transfer from the sensor nodes to the data acquisition layer, guaranteeing the stability and real-time nature of data transmission, reducing data loss and latency issues, and ensuring that real-time monitoring data can be successfully collected and transmitted. The data port settings can also ensure the parallel acquisition ability between multiple nodes, enabling the synchronous acquisition of data from multiple sensors and improving the overall efficiency of the system.

[0022] More specifically, during the data acquisition process, each piece of collected data is marked with data location characteristics, which describe the source and importance of each piece of data. These mainly include: the sensor node identifier of the data: specifying which specific sensor node collected the data; the timestamp of the data: marking the time of data acquisition for subsequent time period analysis; the geographical or functional location of the data: indicating the geographical location or functional area where the data was collected to help understand the context of the data. The marking of data location characteristics can provide rich background information for subsequent data analysis, enhancing the traceability and understandability of the data. By marking the location characteristics, the system can quickly identify the source and scope of influence of the data, assisting in setting the priorities for subsequent anomaly detection and response chains.

[0023] More specifically, each sensor node transmits the collected monitoring data to the data acquisition layer in real time through its data port. This process ensures the rapid flow of data, enabling subsequent data analysis to be carried out in real time or near real time. Transmitting data in real time guarantees that the system can respond to external environmental changes in a timely manner, providing timely feedback and warnings, and avoiding security risks caused by delays. This technology can support the parallel data acquisition of a large number of sensor nodes without affecting the overall monitoring efficiency due to the acquisition delay of a single node.

[0024] It can be understood that by analyzing the node address information of each sensor node (including dimensions such as network, location, area, etc.), ensuring the accuracy of data collection, setting data ports for each sensor node to achieve information connection with the data collection layer, marking the collected data with location characteristics (such as node identifiers, timestamps, etc.), ensuring the accurate identification of data sources and timeliness, and transmitting the monitoring data to the data collection layer in real time for further processing, the accuracy and reliability of data collection can be improved, real-time data transmission can be ensured, data latency can be reduced, rapid response can be ensured, the background information of data analysis can be strengthened, and the effects of subsequent processing and priority adjustment can be enhanced. This method enables the information security monitoring system to ensure the real-time, accurate, and traceable nature of data in the case of large-scale deployment of sensors, providing basic support for low-latency event response.

[0025] Specifically, in step S2 of the embodiment provided by the present invention, the raw data collected from each sensor node needs to be preliminarily identified. The goal of this step is to determine whether the data is abnormal data or has potential risks of security events through the preliminary analysis of the raw data. First, parse the data format to ensure that the data type conforms to the preset standards, such as timestamps, node identifiers, data values, etc. Apply certain rules or preliminary algorithms, such as threshold determination, data fluctuation analysis, pattern recognition, etc., to identify whether there are abnormalities. Through machine learning models or rule engines, preliminarily determine whether the collected data involves potential security risks, such as network attacks, data leaks, or device failures. Data preliminary identification can quickly screen out potential abnormalities or security threats, provide guidance for subsequent processing, reduce the burden of subsequent data processing, prioritize the processing of abnormal or high-risk data, and improve the system response efficiency.

[0026] More specifically, according to the results of the preliminary identification, the monitoring data of each sensor node is encapsulated according to the information encapsulation standard, and a data structure is provided for the establishment of the subsequent response chain. The information encapsulation standard usually includes data format, priority, time interval, node characteristics, etc. Specify the encapsulation format for the data of each sensor node. For example, the encapsulation standard may require each piece of data to include: node identifier (such as sensor ID or location), timestamp (marking the specific time of data collection), data value (such as temperature, flow rate, event indicator, etc.), abnormality identification (indicating whether the data is abnormal or requires further analysis), and priority weight (determined by the results of the preliminary identification, determining the response priority of the event).

[0027] More specifically, priority weights are assigned to the data based on the preliminary recognition results. The priority may be evaluated according to multiple factors, including: The degree of abnormality of the data: If the data exhibits abnormal characteristics or patterns (such as cyber attack behaviors, sensor failures, etc.), the priority weight is higher. The node value of the data source: Some sensor nodes may be more critical than others (for example, the monitoring data of important servers is more important than that of ordinary devices). Time sensitivity: Some events may require an immediate response (such as real-time security events), so the priority weight may also be determined based on time sensitivity.

[0028] More specifically, the encapsulated data is sorted according to the priority weights and a response chain is formed. According to the priority of the data, the system will allocate it to different response chains, usually including: Immediate response chain: High-priority data that requires an immediate response. Priority response chain: Second-high-priority data that requires a relatively fast response but can be slightly delayed. Normal response chain: Low-priority data that can be processed later when resources are limited.

[0029] More specifically, the information encapsulation process ensures a unified data format, facilitating subsequent analysis, evaluation, and response. By assigning priority weights, the system can flexibly adjust the order of responses and processing strategies, avoid resource waste, and ensure the timely handling of critical events. The construction of the response chain enables the system to dynamically respond to various levels of events and adjust the processing strategy according to the situation, ensuring an efficient and accurate response.

[0030] More specifically, when performing information encapsulation, the system will consider the factor of time period. The monitoring data of some sensor nodes may be time-sensitive. For example, the time period of abnormal network traffic may be directly related to the peak period of security attacks, or the occurrence time of equipment failures may be crucial for decision-making. According to a predetermined time window (such as 1 minute, 5 minutes, 1 hour), the monitoring data is segmented by time period. This is to capture the timeliness of certain events, such as attack behaviors during peak periods or the continuous state of equipment failures. The data within each time period is encapsulated and marked for subsequent event response according to the time dimension. The data encapsulation within the time period enables the system to identify rapid changes in the short term and can more accurately capture potential security threats. Through the division of the time dimension, the system can avoid missing key timeliness information and optimize the timeliness of event response.

[0031] More specifically, based on the encapsulated data, the system divides the data into different response chains and sorts them according to priority. The generation of these response chains is a dynamic process that may be affected by different factors, such as real-time data updates, priority adjustments, etc. It analyzes the changes in the data stream in real time and dynamically adjusts the priority of the data in the response chains. For example, if the data originally in the low-priority response chain suddenly has an abnormal situation, it can be dynamically promoted to a higher-priority response chain. According to the processing load and resource conditions, the system can dynamically allocate resources among multiple response chains to optimize the overall event response efficiency. The dynamic generation and priority adjustment of the response chains can ensure that the system quickly responds to the changing security environment, effectively allocate computing resources and response resources, ensure that high-risk events can be responded to in the shortest time, and at the same time reasonably allocate the processing time of low-risk events to improve the response efficiency of the entire system.

[0032] It can be understood that the monitoring data is initially identified to detect anomalies or security risks in the data. According to the encapsulation standard, each piece of data is encapsulated, recording the data identifier, timestamp, anomaly degree, and priority. The encapsulated data is allocated to different response chains according to priority to form immediate, priority, and normal response chains. The response chains are dynamically adjusted to optimize the priority of the data in real time to ensure that critical events are responded to in a timely manner. Through data encapsulation and priority allocation, the system can efficiently process a large amount of sensor data, reducing the processing burden of irrelevant or low-risk data. The dynamic response chains and priority adjustment ensure the flexibility and efficiency of the system in different situations and environments, improving the timeliness and accuracy of event response. The time-sensitive data encapsulation and the construction of the response chains ensure that the system can quickly adapt to the changing environment and ensure a quick response to potential security threats.

[0033] Specifically, in step S3 of the embodiment provided by the present invention, the information analysis layer first receives the encapsulated information response chain from the data acquisition layer, which contains multiple pieces of information to be analyzed. These pieces of information have been sorted according to priority and may contain characteristics such as timestamps, node identifiers, data types, anomaly degrees, etc. The information analysis layer receives the encapsulated information response chain from the data acquisition layer. Each information node contains the data and its related characteristics, such as time, node identifier, priority, etc. According to factors such as the priority, timestamp, and anomaly degree of the information, it is ensured that the information to be analyzed enters the analysis process in order of priority. Events with high priority will be analyzed first to ensure the system's response to emergencies. The priority sorting ensures that the system can timely process high-risk and high-priority events, reducing the response time of potential threats and improving the overall processing efficiency. During the sorting process, the system can automatically optimize the allocation of resources to ensure that high-priority events are not delayed.

[0034] More specifically, before analyzing the information to be analyzed, the information analysis layer needs to preprocess the received data. The purpose of this step is to clean, denoise, and perform necessary formatting on the original data, enabling the data to enter the next analysis process, removing redundant or invalid data information, and correcting errors or missing values in the data. This can include removing duplicate data, filling in missing values, filtering and denoising, etc., converting data from different sources or formats into a unified standard format to ensure that the data can be effectively analyzed in subsequent processing. For example, converting timestamps to a unified time zone, standardizing data units, etc.

[0035] More specifically, key features are extracted from the information to be analyzed. These features can help the system determine whether there are potential risks. For example, the rate of change of traffic and abnormal traffic peaks are extracted from network traffic monitoring data; the slope of temperature change is extracted from environmental monitoring data, etc. Preprocessing and feature extraction ensure the accuracy of information during analysis, avoiding the influence of invalid or incorrect data on the analysis results. The standardized data enables data from different sources to be processed and compared within a unified analysis framework, improving the data consistency of the overall system.

[0036] More specifically, after preprocessing and feature extraction, the information analysis layer will conduct in-depth analysis on each piece of information to be analyzed to identify potential security risks or abnormal events. This analysis is usually based on a certain model or rule engine. Through rule matching, statistical analysis, or machine learning models, the system can identify potential abnormal patterns in the data. For example, a machine learning model trained based on historical data can help identify abnormal patterns in network traffic, fault patterns of sensor nodes, etc. By analyzing the features, the system evaluates the risk level of each event. For example, a sudden increase in traffic may lead to a bandwidth bottleneck, and abnormal device temperature may lead to device failure. The analysis results can further determine the degree of danger of the event based on the risk score output by the rule or model. Cross-analysis of data from different sources is performed to identify the correlation relationships between multiple data sources. For example, there may be a correlation between environmental data and device monitoring data in a certain area. Analyzing the intersection of these data helps discover potential hazards or faults. Information analysis and risk assessment help the system extract potential security threats from a large amount of data, improving the ability to identify abnormal events. The use of pattern recognition and machine learning models enables the system to discover complex patterns that are difficult to capture by traditional rules, enhancing the intelligent level of security detection. Risk assessment provides data support for subsequent response decisions, effectively avoiding false alarms or missed alarms.

[0037] More specifically, after completing information analysis and risk assessment, the information analysis layer generates early warning feedback features, which are a set of data features describing abnormal events and potential risks, usually including information such as early warning level, event type, urgency, impact scope, recommended response, etc. According to the analysis results, the system assigns an early warning level to each event. For example: high risk (severe threat), medium risk (potential threat), low risk (minor threat). According to the type and characteristics of the event, corresponding early warning feedback content is generated. According to the results of risk assessment, the system generates response recommendations for each early warning. The early warning feedback features enable the system to quickly output clear and accurate early warning information to users or other systems, helping decision-makers take measures quickly. The early warning information can clearly indicate the severity, impact scope and response recommendations of the event, thus guiding subsequent rapid responses, improving the system's automated response ability, reducing manual intervention, and improving the event response efficiency.

[0038] More specifically, after the early warning feedback features are generated, the system may also establish a feedback mechanism to feedback the early warning results to the data collection layer, monitoring platform or user terminal. If the feedback results show that the early warning level does not match the actual situation, the system can optimize the analysis model according to the feedback information, adjust the rules or parameters, and enhance the subsequent recognition and prediction accuracy. The feedback mechanism can improve the intelligence level of the system, continuously optimize the analysis model through self-learning, enhance the adaptive ability of the system. The optimized system can discover new security threat patterns in a shorter time, improving the detection accuracy and response speed of the system.

[0039] It can be understood that receiving and sorting the information to be analyzed by priority, preprocessing and feature extraction of the information to ensure that the data is clear, accurate and standardized, using pattern recognition, risk assessment and correlation analysis methods to analyze each piece of information to be analyzed, identifying potential risks, generating early warning feedback features according to the analysis results, evaluating the early warning level, and providing response recommendations, using the feedback mechanism to optimize the analysis model, improving the adaptive ability of the system, improving the ability to identify anomalies and security risks, especially in complex or irregular event patterns. The generated early warning feedback can help decision-makers quickly judge the risk level of the event and take actions. The automated processing and self-learning mechanism of the system make the response more efficient and accurate, reducing the need for manual intervention.

[0040] Specifically, in step S4 of the embodiment provided by the present invention, information association tracking refers to analyzing the correlation between the information to be analyzed, identifying which information is relevant or dependent, and dynamically adjusting the processing order of the information response chain based on these relationships. The core of this process is to perform correlation analysis on the information to find the key information chain, so as to give priority to responding to those events with higher relevance.

[0041] More specifically, the information analysis layer first receives all the information to be analyzed and their early warning feedback features from the information response chain. These early warning feedback features usually include information such as the risk level of the event, the type of early warning, and the degree of urgency. Through pattern recognition, rule engines, or machine learning algorithms, the system analyzes the correlation between different information nodes. The correlation relationship can be a temporal dependence (for example, a change in the state of a certain device may be a precursor to the failure of another device), or a spatial dependence (for example, the failures of multiple devices in a certain area may be caused by the same failure reason).

[0042] More specifically, based on the results of the correlation analysis, the system can construct an information correlation graph. Each node in the graph represents a piece of information to be analyzed, and the edges between the nodes represent the correlation relationships between these pieces of information. For example, the high-temperature alarm and abnormal current of a certain device may be connected by an edge in the graph, indicating that they may jointly indicate the failure of the device. In the information response chain, the system will identify the dependence relationships between the information based on the correlation graph. These dependence relationships may affect the order of event response. For example, if the occurrence of an event may be a precursor to another event, the system needs to process these related events first.

[0043] It can be understood that through information correlation tracking, the system can more intelligently identify the correlation between information, ensuring a coordinated response to multiple related events. The correlation analysis helps the system identify potential chain reactions in a complex environment, avoiding missed or misjudged situations. Especially when multiple devices, sensors, or systems show abnormalities simultaneously, the correlation tracking can help focus on the key information that is most likely to trigger other risks, improving the accuracy and timeliness of event response and avoiding over-response to isolated events or omission of the handling of related events.

[0044] More specifically, based on the information correlation tracking, the system will adjust the priority response weights of the information to be analyzed in the information response chain. This means that the system dynamically adjusts the response priority according to the correlation relationships, risk levels, and degrees of urgency of each piece of information to be analyzed. Through this adjustment, the system can ensure that the most critical and urgent information is processed first.

[0045] More specifically, each piece of information to be analyzed will first be assigned an initial response weight according to its early warning feedback features (such as risk level, degree of urgency, etc.). Usually, information with a higher risk level, greater degree of urgency, and wider potential impact range will obtain a higher initial weight. After the system identifies the correlation relationships between the information, it will dynamically adjust the response weights of the information to be analyzed according to these correlations. For example, if a high-risk event is associated with multiple other events, the system may increase the response priority of the information related to these events to prevent the spread of potential risks.

[0046] More specifically, for the information to be analyzed with a relatively high degree of relevance, the system can increase their response weights through a weighting strategy. For example, if the failure of a certain device may lead to a decline in the overall performance of the system, the associated information will be given a higher priority. For those events with a lower or no relevance, the system will reduce their response weights, thereby optimizing the allocation of resources. Once some information to be analyzed receives a priority response, the system will track and feedback on it. If the early warning feedback characteristics of this information change (for example, the risk level decreases or the event is resolved), the system will re-evaluate and adjust the weights accordingly, so as to ensure that the system always responds to events in the most effective way.

[0047] It can be understood that by adjusting the priority response weights, the system can dynamically optimize the resource allocation according to the relevance between information, ensure the greatest attention is given to the most critical events, reduce the waste of resources on low-priority events, and the adjustment of priority response weights enhances the flexibility and intelligence of the system. It can automatically optimize the response strategy according to the changes in real-time data, thereby improving the overall response efficiency. This mechanism effectively avoids over-response to irrelevant events, and at the same time ensures that any node in the high-correlation information chain can be processed as early as possible to prevent potential chain reactions.

[0048] More specifically, the information analysis layer conducts sequential analysis according to the information response chain after the adjustment of the priority response weights, ensuring the priority processing of information with higher weights, especially those events with a strong correlation with other information. According to the adjustment results of the priority response weights, the system will re-order each piece of information to be analyzed in the information response chain, and the sorted order ensures that the information with a greater correlation with high-priority events is processed first. The sorted information chain will enter the information analysis layer for processing in sequence. Each piece of information will be further analyzed according to its characteristics and risk assessment until all the information in the entire information chain is processed.

[0049] It can be understood that sequential analysis ensures that the system can process each event in the information response chain in an orderly and efficient manner. Especially for complex situations with multiple intertwined events, the sorting of priorities can minimize delays, and high-priority information is processed in a timely manner, greatly improving the response speed and processing efficiency of the system, ensuring that security events can be detected and responded to in the first place. This step significantly enhances the intelligence of information processing by introducing correlation and weight adjustment, avoiding the rigid response method based solely on the chronological order of event occurrence or fixed priorities.

[0050] Specifically, the steps of this solution receive the information to be analyzed and analyze the early warning feedback features, analyze the correlation between information through pattern recognition and rule engines, construct an information correlation graph, identify the dependency chain between information, calculate the initial response weight according to the early warning feedback features, adjust the priority response weight of the information to be analyzed based on the information correlation, dynamically optimize the weight adjustment strategy according to the feedback of events, sort the information to be analyzed and rearrange the analysis order, and process the information in sequence according to the priority to ensure that the most important events are given priority responses. The system can identify the relationship between multiple events through information correlation tracking, thereby reducing omissions or misjudgments. By dynamically adjusting the priority response weight, it ensures that high-risk and high-priority information can be processed first, optimizes resource allocation, and sequential analysis ensures efficient information flow processing, avoiding over-response to low-priority events or ignoring high-priority events, thus improving the response efficiency and event processing accuracy.

[0051] The present invention provides a low-latency event response method based on an information security monitoring and early warning AI platform, which has the following beneficial effects:

[0052] The present invention relates to the technical field of information security early warning, and discloses a low-latency event response method based on an information security monitoring and early warning AI platform. The present invention collects various monitoring data in real time through sensor nodes, identifies the information anomaly degree and the value of spatio-temporal characteristic nodes of the collected data, processes it according to the information encapsulation standard, forms an information response chain with a priority response weight, analyzes the information to be analyzed in sequence through the information analysis layer to obtain early warning feedback features, performs information correlation tracking based on the early warning feedback features, classifies the relevant information into highly correlated information and ordinary correlated information and adjusts the response priority respectively, improves the response speed to security events, ensures low-latency processing, optimizes the response priority through intelligent analysis, effectively reduces the interference of irrelevant events, can quickly identify potential threats in multi-dimensional data, enhances the emergency handling ability of the system, and solves the problem that the prior art cannot give an early warning response to security events in a timely and effective manner.

[0053] Preferably, the step of collecting monitoring data in real time for a plurality of pre-deployed sensor nodes through the data collection layer to obtain the monitoring data corresponding to each of the sensor nodes includes:

[0054] S11: Analyze the node addresses of a plurality of pre-deployed sensor nodes to obtain the node address information of each of the sensor nodes; wherein, the node address information includes address positioning information of several address analysis dimensions, and the address analysis dimensions include network node dimension, positioning map dimension, regional function dimension, and traffic correlation dimension;

[0055] S12: Set data ports for each of the sensor nodes according to the node address information of each of the sensor nodes, so that each of the sensor nodes is in an information communication state with the data acquisition layer;

[0056] S13: Mark the data collected by each of the sensor nodes with data positioning characteristics through the data ports of each of the sensor nodes, so as to obtain monitoring data with the data positioning characteristics corresponding to the sensor nodes, and transmit the monitoring data to the data acquisition layer through the information communication state between the data ports and the data acquisition layer.

[0057] Specifically, the system will analyze the node addresses of a number of pre-deployed sensor nodes. The purpose of node address analysis is to identify the unique address of each sensor node, ensuring that during the data acquisition process, the data sources of each sensor node can be accurately identified. Based on the node address analysis, the system will generate node address information for each sensor node. This information usually includes positioning data in multiple dimensions to ensure that each sensor node can be accurately located in different dimensions. These dimensions include: Network node dimension: The unique identifier of each sensor node in the network, used to determine the position and communication path of the node in the network architecture; Positioning map dimension: Based on a geographic information system (GIS) or map data, the physical location (such as longitude and latitude) of each sensor node will also be part of the node address; Regional function dimension: The area where the sensor node is located and its functional attributes (for example, whether the monitoring area is an industrial area, a residential area, etc.). This dimension helps analyze the different roles of node data in different regions; Traffic association dimension: The node may be associated with the traffic network (such as intersection monitoring sensors, traffic flow sensors, etc.). This dimension can determine the relationship between the sensor node and the traffic system and the impact of its data on traffic management.

[0058] It can be understood that through node address analysis, the system can ensure that each sensor node has unique identification information, avoiding confusion in data sources. The multi-dimensional address information enables sensor data to be accurately located at different levels and from different angles, improving the accuracy and diversity of monitoring data.

[0059] More specifically, based on the node address information of the sensor nodes, the system configures a data port for each sensor node. This port is the communication channel between the sensor and the data acquisition layer, ensuring the smooth transmission of information. Through the configuration of the data port, the system ensures the establishment of a stable information connection between the sensor nodes and the data acquisition layer. This process usually involves the setting of network protocols and the management of data streams, ensuring that each sensor node can transmit the monitoring data to the data acquisition layer in real time through the set port. The configuration of the data port ensures the effective communication between the sensor nodes and the data acquisition layer, thus laying a foundation for subsequent data acquisition and analysis. Through precise port settings, the system can ensure that the data of each sensor is transmitted accurately without error, reducing the risk of communication errors or data loss.

[0060] More specifically, the data collected by each sensor node is transmitted through its configured data port, and data location characteristic tags are added to the data according to the node address information during the transmission process. These tags include: Geographic location tag: The data is tagged with its geographic location according to the positioning map dimensions (latitude and longitude) of the node, so that the data not only contains measurement values but also can be accompanied by the physical location; Functional attribute tag: Based on the regional function dimension and traffic association dimension, the data is tagged as the monitoring data of a specific functional area or traffic network, helping to better understand the application background of the data in subsequent analysis.

[0061] More specifically, through these tags, the collected monitoring data can be associated with background information such as specific locations, regions, and functions, enhancing the data analysis ability and practical value. The tagged data will be more easily subjected to geographic information analysis, trend analysis, regional performance analysis, etc. The data location characteristic tags make the collected data not just raw measurement data but additional rich context information, enhancing the value and usability of the data. The data location characteristic tags contribute to subsequent data analysis. For example, it can judge the environmental conditions based on the specific location or analyze the impact of traffic flow on certain events.

[0062] More specifically, the marked monitoring data will communicate information with the data acquisition layer through the data ports of each sensor node and be transmitted to the data acquisition layer in real time. As the data aggregation and processing center, the data acquisition layer will receive the data uploaded by all sensor nodes and perform further processing and analysis as needed. Since the sensor nodes may be located in different geographical locations and involve different monitoring dimensions, the data acquisition layer needs to synchronously receive the data streams from different sensors. During the data transmission process, issues such as transmission delay and data consistency need to be considered to ensure that the data can be transmitted to the acquisition layer in a timely and accurate manner. Through the effective connection of the data ports and the real-time transmission of the data, it is ensured that the sensor data can be obtained by the data acquisition layer in a timely manner, meeting the requirements of real-time monitoring. The data transmission and marking mechanism ensures the integrity, accuracy, and traceability of the data, providing a reliable basis for subsequent data processing, analysis, and decision-making.

[0063] It can be understood that the system can accurately locate the sensor nodes through the multi-dimensional node address information, avoiding the confusion of data sources. The setting of the data ports ensures the effective communication between the sensor nodes and the data acquisition layer, realizing the real-time transmission of data. By marking the positioning characteristics of the monitoring data, the data has more application value and enhances the accuracy of data analysis. The whole process ensures the real-time, accurate, and efficient nature of the sensor data, providing a reliable basis for subsequent analysis and decision-making.

[0064] Preferably, the steps of identifying the information abnormality degree and evaluating the node value of the spatio-temporal characteristics of the monitoring data of each of the sensor nodes according to the information encapsulation standard, and performing information encapsulation processing on the monitoring data of each of the sensor nodes in each time period according to the obtained abnormality degree index and node value parameter to obtain an information response chain composed of a number of pieces of information to be analyzed with priority response weights include:

[0065] S21: Identifying the information abnormality degree of the monitoring data of each of the sensor nodes according to the information abnormality degree standard in the information encapsulation standard to obtain the abnormality degree index of each of the monitoring data corresponding to the information abnormality degree standard; wherein, the abnormality degree index is used to describe the possibility of the monitoring data feeding back an information security warning event;

[0066] S22: Evaluating the node value of the data positioning characteristics and the time period to which the data belongs of the monitoring data of each of the sensor nodes according to the node address value standard in the information encapsulation standard to obtain the node value parameter of each of the monitoring data corresponding to the node address value standard;

[0067] S23: Perform information encapsulation processing on each of the monitoring data according to the abnormality index and node value parameter of each of the monitoring data, so as to obtain an information response chain composed of a number of pieces of information to be analyzed with priority response weights.

[0068] Specifically, according to a predetermined information encapsulation standard, the system will perform preliminary identification on the monitoring data of each sensor node. The purpose of the preliminary identification is to analyze and process the raw data from different sensors to ensure that the data can be further processed according to a unified standard. The preliminary identification enables different types of monitoring data (such as temperature, humidity, air pressure, flow rate, etc.) to be processed according to the same encapsulation standard, ensuring the consistency and comparability of the data.

[0069] More specifically, according to the abnormality standard in the information encapsulation standard, the system will perform abnormality identification on the monitoring data of each sensor node. The purpose of the abnormality identification is to evaluate the abnormality degree of each monitoring data in the data feedback and calculate the corresponding abnormality index. The abnormality index is a quantitative indicator used to describe possible abnormal situations in the monitoring data, such as abnormal temperature, excessive pressure, etc. This index reflects the possibility of potential security warning events behind the data. Through the abnormality identification, the system can timely detect abnormal behaviors or potential faults in the sensor node data and generate an abnormality index. This provides a basis for subsequent security warning and abnormality handling. The abnormality index helps to quickly determine whether the monitoring data belongs to an emergency or high-risk data that needs further inspection, thus improving the response efficiency of the system.

[0070] More specifically, in the information encapsulation standard, the system will also evaluate the monitoring data according to the node address value standard. The node value evaluation mainly considers the following two factors: data location characteristics: that is, the geographical location, regional function of the monitoring data, and its specific role in the sensor network. For example, if a sensor is located in a key position (such as the core area of a factory), the importance of its data will be relatively high; the time period to which the data belongs: the time period of data collection will also affect the value of the node. For example, certain specific time periods (such as peak periods, emergency periods) have a greater impact on the overall security and resource scheduling of the system, and the value of the node may be higher.

[0071] More specifically, according to the above evaluation, the system assigns a node value parameter to each monitoring data to reflect its relative importance under a specific time period and geographical location. The node value evaluation helps to identify the monitoring data with high priority at critical moments or in critical positions. This evaluation mechanism provides an important reference for the priority sorting and decision-making of the data. The system can reasonably allocate resources for processing according to the importance of different nodes and the timeliness of the data, thereby optimizing the response ability of the system.

[0072] More specifically, according to the anomaly index and the node value parameter, the system performs information encapsulation processing on each piece of monitoring data. During the encapsulation process, the system assigns different priority response weights to the data based on the anomaly degree and node value of the data. The priority response weight is determined according to the importance and urgency of the monitoring data. For example, data with a high anomaly degree and a high node value will be given a higher priority weight. The encapsulated monitoring data will be sorted by priority to form an information response chain. The data in the information response chain will be sorted according to time sequence, urgency, and importance to ensure that critical data can be processed first.

[0073] It can be understood that the information encapsulation processing ensures that the priorities of the data are reasonably assigned, improves the response ability of the system. Data with a higher priority will be able to receive a more rapid response and processing, avoiding the expansion of potential risk events. The generated information response chain provides clear guidance for subsequent security warnings, event responses, and resource scheduling, helping to optimize the overall operation efficiency and emergency response ability of the system; Anomaly identification enables the system to promptly detect potential abnormal events and generate warning signals. Node value evaluation provides multi-dimensional support for data processing and decision-making, ensuring that important data can be processed first. The information encapsulation processing and the generation of the response chain optimize the order and efficiency of data processing, improve the response speed and accuracy of the system. The entire process improves the system's automated processing ability in various scenarios (such as security monitoring, emergency response, etc.), helping managers to quickly and effectively respond to various emergencies.

[0074] Preferably, the step of performing information encapsulation processing on each of the monitoring data according to the anomaly index and the node value parameter of each of the monitoring data to obtain an information response chain composed of a number of pieces of information to be analyzed with priority response weights includes:

[0075] S231: Perform priority gradient division on each of the monitoring data according to the anomaly index of each of the monitoring data to obtain the response priority gradient to which each of the monitoring data belongs; wherein, the response priority gradient includes an immediate response gradient, a priority response gradient, and a normal response gradient;

[0076] S232: Perform preliminary allocation on each of the monitoring data according to the response priority gradient to which each of the monitoring data belongs to obtain an immediate response data set, a priority response data set, and a normal response data set;

[0077] S233: Analyze the execution order within the gradient of each of the monitoring data according to the node value parameter of each of the monitoring data to obtain the in-gradient priority of each of the monitoring data;

[0078] S234: Arrange the processing order of the monitoring data in the immediate response data set, the priority response data set, and the normal response data set according to the gradient priority of each piece of the monitoring data, so as to obtain an immediate response chain, a priority response chain, and a normal response chain;

[0079] S235: Conduct a relevance analysis on the overall response order of each piece of the monitoring data in the immediate response chain, the priority response chain, and the normal response chain, and convert each piece of the monitoring data according to the analysis result to obtain the information to be analyzed corresponding to each piece of the monitoring data, and combine the immediate response chain, the priority response chain, and the normal response chain composed of the information to be analyzed to obtain the information response chain.

[0080] Specifically, the core of this technical solution lies in performing hierarchical priority response processing on the monitoring data of sensor nodes, and performing information encapsulation and priority sorting on each piece of data according to the anomaly index and node value parameter of the data. Finally, an information response chain is formed. This process aims to ensure that data with different priorities can be efficiently responded to according to their urgency and importance, thereby optimizing the decision-making and processing process of the system.

[0081] More specifically, according to the information encapsulation standard, analyze the anomaly index of each piece of monitoring data. The anomaly index is used to measure the degree of anomaly of the monitoring data, that is, it reflects the possible risks of the data or the severity of warning events. Based on the level of the anomaly index, each piece of monitoring data is divided into different response priority gradients: immediate response gradient: the anomaly index is extremely high, indicating that the data needs to be immediately responded to and processed; priority response gradient: the anomaly is relatively high, and it needs to be prioritized, but does not need to be immediately responded to; normal response gradient: the anomaly is relatively low, and the response can be delayed, belonging to routine processing. By dividing the priority gradients of the monitoring data, it is ensured that the system can classify and process data according to the urgency and importance of the data, avoiding waste of processing resources and unnecessary delays. High-priority data will be quickly processed, reducing the probability of potential risk events and enhancing the system's ability to respond to emergencies.

[0082] More specifically, according to the response priority gradients (immediate response gradient, priority response gradient, normal response gradient) of each piece of monitoring data, conduct a preliminary allocation of all the monitoring data. In this way, the data will be divided into: immediate response data set: containing high-priority data that needs to be immediately responded to; priority response data set: containing data that needs to be prioritized for processing; normal response data set: containing data that can be processed later. Through this allocation mechanism, the system can accurately distinguish data with different levels of urgency, avoid the ineffective use of resources, and can prioritize the processing of high-risk data, enabling more rapid centralized processing of emergency data and reducing resource occupancy.

[0083] More specifically, according to the node value parameters in the information encapsulation standard, priority analysis within the gradient is performed on the monitoring data in each data set. The node value parameters consider factors such as the geographical location and functional importance of the nodes to which the data belongs, further determining the priority of the data within the same response gradient. The data within each set is sorted to determine the execution priority of each data item. Even within the same response priority gradient, through the analysis of the node value parameters, the system can more precisely sort and prioritize the data, further optimizing the response processing flow. When allocating resources to the system, the data with higher priority will be processed first, further improving the processing efficiency.

[0084] More specifically, based on the results of the priority analysis within the gradient, the processing order of the data in the immediate response data set, priority response data set, and normal response data set is arranged: Immediate response chain: Arrange the data in all immediate response data sets in priority order, Priority response chain: Arrange the data in all priority response data sets in priority order, Normal response chain: Arrange the data in all normal response data sets in priority order, ensuring that data processing is carried out according to priority, enabling the most urgent and critical tasks to be solved first and avoiding the occupation of system resources by low-priority tasks.

[0085] More specifically, an overall response order analysis is performed on the data in the immediate response chain, priority response chain, and normal response chain. This analysis is mainly based on the time, geographical, priority, and other correlation relationships between the data, aiming to ensure that the data in multiple response chains can be coordinated and conflicts can be avoided. According to the results of the correlation analysis, information conversion is performed on each monitoring data to transform it into corresponding information to be analyzed. These pieces of information to be analyzed will contribute to further decision-making, early warning, and resource scheduling. Through the overall response order analysis, conflicts and inconsistencies between the data are avoided, ensuring that the system's response process is more coordinated and orderly. The information to be analyzed obtained after information conversion provides more accurate and comprehensive reference data for decision-makers, helping to make more reasonable and efficient response decisions.

[0086] More specifically, the information to be analyzed in the immediate response chain, priority response chain, and normal response chain is combined to finally obtain a complete information response chain. This chain contains all the data that needs to be processed, arranged in priority order, ensuring that the most urgent data is responded to first. Through the combination of the information response chain, the system can uniformly manage various response data, achieve unified scheduling of tasks with different response priorities, and the final information response chain obtained can optimize the resource allocation of the entire system, ensuring that the most urgent data can be processed fastest without wasting system resources on unimportant data.

[0087] It can be understood that through the combination of the anomaly index and node value, the refinement of data priority is ensured, and the system can flexibly respond to situations of different urgencies. Through hierarchical management and priority sorting within the gradient, the system can optimize resource scheduling to ensure that critical tasks are processed first. The organization and sorting of the response chain make data processing orderly and efficient, significantly improving the system response time. The finally generated information response chain provides a clear priority order for the system's decision-making, early warning, and execution, enabling timely response to potential security incidents.

[0088] Preferably, the step of performing a relevance analysis on the overall response order of each of the monitoring data in the immediate response chain, the priority response chain, and the normal response chain, and converting each of the monitoring data according to the analysis result to obtain information to be analyzed corresponding to each of the monitoring data includes:

[0089] S2351: Calculate the ratio of the monitoring data to be responded in the priority response chain and the normal response chain to obtain the workload ratio of the priority response chain and the normal response chain;

[0090] S2352: Analyze the chain conversion relationship between the priority response chain and the normal response chain according to the workload ratio of the priority response chain and the normal response chain to obtain the rotation response rule of the priority response chain and the normal response chain;

[0091] S2353: Allocate the priority response weights to each of the monitoring data in the priority response chain and the normal response chain according to the rotation response rule to obtain the information to be analyzed with priority response weights corresponding to each of the monitoring data;

[0092] S2354: Allocate the priority response weights in the most priority form to the monitoring data in the immediate response chain according to the preset most priority response rule to obtain the information to be analyzed with the priority response weights in the most priority form corresponding to each of the monitoring data; wherein, the information to be analyzed with the priority response weights in the most priority form obtained through the most priority response rule is arranged at the forefront of the information to be analyzed with the priority response weights obtained through the rotation response rule.

[0093] Specifically, calculate the ratio of the monitoring data in the priority response chain and the normal response chain to obtain the workload ratio of the two. This ratio reflects the relationship between the priority response chain and the normal response chain in terms of resource consumption, time consumption, etc. By calculating the workload ratio, the work loads between different chains are quantified, enabling the system to more clearly judge the relative importance and resource occupancy of the priority response chain and the normal response chain during the response process. This ratio provides an important basis for further chain conversion and resource scheduling.

[0094] More specifically, based on the calculated workload ratio, analyze the conversion relationship between the priority response chain and the normal response chain. The purpose of this analysis is to identify how the two can be effectively converted through the rotation response rule under the condition of workload change. The rotation response rule includes: when the workload ratio of the priority response chain is large, it is necessary to transfer part of the data in the normal response chain to the priority response chain to improve its processing efficiency. When the workload of the normal response chain is too large, some priority response data may need to be postponed and converted to normal response processing. Through this analysis, the dynamic adjustment rule of data priority between the two can be determined to ensure the efficient use of resources. The chain conversion analysis makes the conversion between the priority response chain and the normal response chain more flexible and orderly, avoids the overcrowding of a certain chain, and ensures the high efficiency of the overall response. By dynamically adjusting the conversion between the priority response chain and the normal response chain, the resource allocation can be effectively optimized and the processing efficiency can be improved.

[0095] More specifically, according to the rotation response rule, assign priority response weights to the monitoring data in the priority response chain and the normal response chain. Specifically, the data in the priority response chain will be assigned a higher weight, while the data in the normal response chain will be assigned a lower weight to ensure that emergency data is processed first. According to the priority and importance of the data, a higher priority response weight is assigned to the data in the priority response chain. Although the data in the normal response chain has a lower priority, it still needs to be processed according to the weight to ensure that it receives an appropriate response. After the assignment, the information to be analyzed with priority response weights is formed. Through the assignment of priority response weights, the system can accurately adjust the response order of each monitoring data to ensure that key data is processed first and the response efficiency is improved. Through this dynamic assignment method, it can be ensured that the high-priority data in the priority response chain is processed first, while the data in the normal response chain can be processed in a timely manner to avoid processing delays.

[0096] More specifically, according to the preset most-priority response rule, assign priority response weights to the monitoring data in the immediate response chain. The most-priority response rule is based on the urgency, importance of the data, and the magnitude of the impact on the system. The strongest priority response weights are preferentially assigned to the data in the immediate response chain. These data will be given the most-priority form of priority response weights to ensure that these data receive the highest-priority response during the processing. The information to be analyzed with the most-priority form of priority response weights obtained according to the most-priority response rule is arranged at the forefront of the information to be analyzed with priority response weights obtained through the rotation response rule. Through the empowerment of the most-priority response rule for the data in the immediate response chain, it is ensured that the most urgent and critical tasks can be processed in the most-priority order, avoiding delays in the rapid response of the system. The combination of the most-priority response rule and the rotation response rule enables data with different priorities to be responded to in an orderly manner, improving the reaction speed and resource scheduling efficiency of the entire system.

[0097] More specifically, through the above process, three chains are formed: an immediate response chain, which is controlled by the most prioritized response rule, and the most urgent data is processed first; a prioritized response chain, which is adjusted according to the rotation response rule and workload ratio analysis to ensure that data is processed as needed; a normal response chain, which is processed according to normal priorities to ensure that no necessary response is missed. Finally, by comprehensively sorting the data of these three chains, an information response chain with a complete priority system is formed to ensure that different types of data can be accurately and orderly responded to. Through the final sorting and analysis, the data processing of all chains is ensured to be orderly, avoiding priority chaos or resource conflicts. This process ensures that the system can quickly and accurately respond when facing complex monitoring data, greatly improving the system's response ability and processing efficiency.

[0098] It can be understood that through multi-level prioritized response rules and weight allocation, it is ensured that the most urgent and important data can be quickly responded to. The reasonable allocation of chain conversion and prioritized response weights enables the system to still maintain high efficiency in response under limited resources. The combination of the most prioritized response rule and the rotation response rule enables the system to quickly process various types of monitoring data and improve the overall response speed.

[0099] Preferably, the steps of sequentially analyzing and processing each piece of information to be analyzed in the information response chain by the information analysis layer to obtain the early warning feedback characteristics of each piece of information to be analyzed include:

[0100] S31: Sequentially retrieve and process each piece of information to be analyzed in the information response chain to obtain the real-time processing object at the current moment;

[0101] S32: Extract data features and conduct event early warning analysis on the real-time processing object based on a pre-trained information security early warning model to obtain the security risk indices of several information security early warning events corresponding to the real-time processing object;

[0102] S33: Conduct a comprehensive combination of the security risk indices of various information security early warning events corresponding to the real-time processing object to obtain the early warning feedback characteristics of the real-time processing object.

[0103] Specifically, in the information response chain, each piece of information to be analyzed will be retrieved and processed in a predetermined order. This process ensures that the system processes data sequentially according to characteristics such as data priority and timeliness, avoiding delays or losses in data processing. The system extracts the information to be analyzed in order through a certain mechanism (such as timestamps, priorities, event importance, etc.). By retrieving the information to be analyzed, the system can obtain the object to be processed at the current moment in real time, ensuring that the data to be analyzed can be accurately located each time. Sequentially retrieving and processing ensures that data flows smoothly into the processing link in sequence, avoiding disorder, repetition, or omission, ensuring that the system can process the most urgently needed data at the current moment, and improving the timeliness of system response.

[0104] More specifically, a pre-trained information security warning model is used to analyze the real-time processing object and extract data features from it. These features may include: Abnormal behavior patterns: such as abnormal data access, frequent system access, abnormal data transmission, etc.; Attack pattern recognition: By analyzing data streams, access records, etc., potential security threats (such as DDoS attacks, data leaks, etc.) are identified; Historical trend analysis: By retrospectively analyzing historical data, abnormal changes in current data are identified; Event warning analysis: Based on the extracted features, event warning analysis is carried out to determine whether there are potential security risks and give corresponding security risk indices.

[0105] It can be understood that through the pre-trained model, the system can automatically identify potential security risks without manual intervention, improving the monitoring efficiency. Through data feature extraction and event warning analysis, security assessment can be carried out from multiple perspectives (such as behavior patterns, attack patterns, historical trends, etc.), improving the accuracy of early warning. It can analyze possible security events at the current moment based on the real-time processing object in real time and accurately calculate the risk level to provide early warning.

[0106] More specifically, the security risk indices corresponding to different warning events (such as intrusion, sensitive data leakage, equipment failure, etc.) of the real-time processing object are comprehensively processed. The goal of this process is to obtain a comprehensive security risk assessment, that is, the warning feedback feature, through weighting or combination of different event risk indices. Specifically, the comprehensive calculation process can include: Weighted average: According to the severity and impact scope of each security event, different risk indices are weighted and averaged; Maximum value selection method: For multiple concurrent security events, the risk index of the most serious event is selected as the overall assessment; Probability combination: If there is a correlation between warning events (such as data leakage caused by a certain intrusion event), then a comprehensive risk assessment can be obtained through joint probability analysis. The comprehensive warning feedback feature reflects the overall security status faced by the system at the current moment and helps decision-makers to carry out emergency responses.

[0107] It is understandable that by synthesizing the risk indices of different events, the system can provide a comprehensive security risk assessment, avoiding the one-sidedness of single event analysis. The early warning feedback features provide accurate data support for subsequent decisions (such as triggering alarms, initiating emergency responses, etc.), enhancing the scientific nature and efficiency of responses. By combining security risks at different levels (such as network layer, application layer, data layer, etc.), it helps the system to more comprehensively manage and respond to potential security threats.

[0108] More specifically, the final system outputs the early warning feedback features to relevant personnel or systems for the next step of security decision-making and emergency response. The output content can be: Real-time alarm: For sudden high-risk events, an alarm is immediately output to notify security personnel to take actions; Trend analysis report: By tracking the history of risk indices, a security situation report of the system is output to assist in long-term security planning. Through the output of the early warning feedback features, the security team can quickly respond to security events, reducing the impact of potential threats on the system. The trend analysis report helps enterprises comprehensively evaluate the security situation, optimize security strategies, and prevent potential threats in advance.

[0109] Preferably, information correlation tracking is performed on the information response chain according to the early warning feedback features of the information to be analyzed, and the information to be analyzed in the information response chain that has an information correlation relationship with the information to be analyzed is divided into highly correlated information and generally correlated information. The priority response weight of the highly correlated information is adjusted upward, and whether to adjust the priority response weight of the generally correlated information is determined according to the early warning feedback features of the highly correlated information. The steps for the information analysis layer to sequentially analyze the information response chain include:

[0110] S41: Analyze the security thresholds of the early warning feedback features of the information to be analyzed to obtain the security risk levels of various information security early warning events warned by the information to be analyzed, and judge the correlation tracking requirements for the security risk levels of various security early warning events warned by the information to be analyzed to obtain whether the information to be analyzed needs to perform information correlation tracking;

[0111] S42: If the information to be analyzed needs to perform information correlation tracking, analyze the correlation information features of the security risk levels of various information security early warning events warned by the information to be analyzed based on a preset correlation standard to obtain the correlation information features of the information to be analyzed; wherein, the correlation information features include time correlation features and address correlation features;

[0112] S43: Perform correlation tracking processing on the information to be analyzed according to the correlation information features to obtain several pieces of information to be analyzed and information correlation degrees that have a correlation tracking relationship with the information to be analyzed on the information response chain;

[0113] S44: Classify the nature of each piece of information to be analyzed according to the information correlation degree of each piece of information to be analyzed, so as to obtain highly correlated information and generally correlated information;

[0114] S45: Increase the priority response weight of the highly correlated information, so that the highly correlated information has a higher priority response weight;

[0115] S46: Obtain the early warning feedback characteristics of the highly correlated information, and analyze the early warning feedback characteristics of the highly correlated information to obtain the security event verification result of the highly correlated information;

[0116] S47: When the security event verification result shows that the highly correlated information has potential hidden dangers, increase the priority response weight of the generally correlated information.

[0117] Specifically, analyze the early warning feedback characteristics of the information to be analyzed, judge the security risk levels of various information security early warning events corresponding to it, based on a preset threshold, analyze the early warning characteristics (such as the security risk index), obtain the risk level of each event, classify each event according to the risk level, which may include high risk, medium risk, and low risk. Through the analysis of the security threshold, the system can accurately evaluate the risks of different security events, provide data support for subsequent processing steps, improve the accurate identification of security events, and ensure that important security risk events can be discovered in time.

[0118] More specifically, according to the security risk level of the information to be analyzed, judge whether it is necessary to perform associated tracking on this information. Generally, if the risk level of the information to be analyzed is relatively high, the system will initiate associated tracking to evaluate whether this information has potential associations with other information. The system can set the criteria for associated tracking according to the type, nature, or threshold of the event, and can dynamically judge which information needs to be deeply tracked according to the security risk level, avoiding redundant analysis of irrelevant information. By screening the requirements for associated tracking, the processing burden of the system is reduced, making the subsequent steps more efficient.

[0119] More specifically, if the information to be analyzed needs to be tracked for correlation, the system will conduct correlation feature analysis on the security risk level of its warning event based on the preset correlation standards. Time correlation feature: analyze the time attributes of the information to be analyzed, such as the interval and frequency of event occurrence, to evaluate whether there are periodic or sudden security risks. Address correlation feature: analyze whether the IP address, physical location, network nodes, etc. involved in the information are correlated, to help identify cross-regional or cross-device security incidents; through the analysis of multi-dimensional features such as time and address, the system can effectively identify potential related events and improve the accuracy of event tracking. Through in-depth correlation analysis, the system can reveal complex attack patterns (such as cross-regional attacks, time-sensitive attacks, etc.).

[0120] More specifically, based on the characteristics of associated information, the system performs associated tracking on the information to be analyzed, identifies other information to be analyzed that has an associated tracking relationship with the information, and calculates the information association between them. The association between information is calculated based on characteristics such as time association and address association. For example, if two events occur at a similar time and are accessed through the same network path, the association is high. Through effective associated tracking, the system can identify multiple related information and provide a more comprehensive reference for subsequent security decisions. By calculating the information association, the system screens out information with strong correlation and reduces the interference of irrelevant information.

[0121] More specifically, the information is divided according to the information correlation between the information to be analyzed. Usually, the information is divided into two categories according to the degree of correlation: highly correlated information indicates that they may have the same root cause or be part of the same attack chain, and low-correlation information may be just some scattered events or accidental associations. The priority response weight of highly correlated information is adjusted upward to give it a higher priority response weight. This step is to ensure that the system responds to those information with greater risks and higher urgency first. If it is found through verification of highly correlated information that it has potential security risks, the system will increase the priority response weight of ordinary correlated information. Through weight adjustment, the system can optimize resource allocation more intelligently, give priority to high-risk and highly correlated information, reduce the risk of security incidents, and dynamically adjust the response strategy according to the correlation and risk level of the information, so that the system can respond to different types of security threats more flexibly.

[0122] More specifically, the system analyzes the early warning feedback characteristics of highly correlated information to obtain the verification results of security incidents, which may include: verifying potential security risks: for example, analyzing whether the information shows signs of an attack and whether it matches known attack patterns; incident confirmation: if the verification results indicate potential risks in the information, corresponding emergency response measures are initiated to ensure the full verification of security incidents related to the correlated information, avoid false positives and false negatives, and improve the reliability of the entire security protection system. Through the verification mechanism, the system can dynamically determine which information may trigger security incidents on a larger scale, thereby optimizing the response strategy.

[0123] More specifically, when the system confirms that certain information poses a security risk, it immediately initiates emergency response measures. This may include: raising the alarm level and triggering an alarm; automated disposal measures (such as blocking IP addresses, isolating devices, etc.); the system can quickly respond based on the risk level and highly correlated information, reducing the risk of incident spread; through the processing of highly correlated information, the system can accurately take response measures to ensure that security incidents are promptly addressed and handled.

[0124] It can be understood that the system can flexibly adjust the response strategy according to the correlation degree and risk level of the information, improving the processing efficiency and response accuracy, ensuring that critical security incidents are given priority, reducing the spread of potential security threats, and comprehensively enhancing the security protection ability and emergency response efficiency of the system through the correlation tracking and risk verification mechanisms.

[0125] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. A low-latency event response method based on an information security monitoring and early warning AI platform, characterized in that: include: The data collection layer collects monitoring data of several pre-deployed sensor nodes in real time to obtain monitoring data corresponding to each of the sensor nodes; According to the information encapsulation standard, the monitoring data of each sensor node is subjected to information anomaly identification and spatiotemporal characteristic node value evaluation, and the monitoring data of each sensor node in each time period is subjected to information encapsulation processing according to the obtained anomaly index and node value parameter, so as to obtain an information response chain composed of a plurality of information to be analyzed with priority response weights; wherein the information response chain includes an immediate response chain, a priority response chain and a common response chain; The information analysis layer sequentially analyzes and processes each of the information to be analyzed in the information response chain to obtain early warning feedback features of each of the information to be analyzed; The information response chain is tracked for information correlation according to the early warning feedback characteristics of the information to be analyzed, and the information to be analyzed in the information response chain that has an information correlation relationship with the information to be analyzed is divided into highly correlated information and generally correlated information, and the priority response weight of the highly correlated information is adjusted upward, and it is determined whether to adjust the priority response weight of the generally correlated information according to the early warning feedback characteristics of the highly correlated information, so that the information analysis layer can analyze the information response chain in sequence.

2. The low-latency event response method based on the information security monitoring and early warning AI platform according to claim 1 is characterized in that: The steps of collecting monitoring data of several pre-deployed sensor nodes in real time through the data collection layer to obtain monitoring data corresponding to each of the sensor nodes include: Analyzing the node addresses of several pre-deployed sensor nodes to obtain the node address information of each of the sensor nodes; wherein the node address information includes address positioning information of several address analysis dimensions, and the address analysis dimensions include network node dimension, positioning map dimension, regional function dimension, and traffic association dimension; Setting a data port for each of the sensor nodes according to the node address information of each of the sensor nodes, so that each of the sensor nodes is in an information connection state with the data acquisition layer; The data collected by each sensor node is marked with data location characteristics through the data port of each sensor node to obtain monitoring data with the data location characteristics corresponding to the sensor node, and the monitoring data is transmitted to the data acquisition layer through the information connectivity status between the data port and the data acquisition layer.

3. The low-latency event response method based on the information security monitoring and early warning AI platform as claimed in claim 2 is characterized in that: The steps of identifying the degree of abnormality of information and evaluating the value of spatiotemporal characteristic nodes for the monitoring data of each sensor node according to the information encapsulation standard, and encapsulating the monitoring data of each sensor node in each time period according to the obtained abnormality index and node value parameter to obtain an information response chain consisting of a plurality of information to be analyzed with priority response weights include: According to the information anomaly standard in the information encapsulation standard, the monitoring data of each sensor node is identified for information anomaly, so as to obtain an anomaly index corresponding to the information anomaly standard for each monitoring data; wherein the anomaly index is used to describe the possibility of the monitoring data feeding back an information security warning event; According to the node address value standard in the information encapsulation standard, the monitoring data of each sensor node is evaluated for the data location characteristics and the node value of the time period to which the data belongs, so as to obtain the node value parameter of each monitoring data corresponding to the node address value standard; Information encapsulation processing is performed on each of the monitoring data according to the abnormality index and the node value parameter of each of the monitoring data to obtain an information response chain consisting of a number of information to be analyzed with priority response weights.

4. The low-latency event response method based on the information security monitoring and early warning AI platform as claimed in claim 3 is characterized in that: The steps of performing information encapsulation processing on each of the monitoring data according to the abnormality index and the node value parameter of each of the monitoring data to obtain an information response chain consisting of a plurality of information to be analyzed with priority response weights include: According to the abnormality index of each monitoring data, each monitoring data is divided into priority gradients to obtain the response priority gradients to which each monitoring data belongs; wherein the response priority gradients include immediate response gradients, priority response gradients, and ordinary response gradients; Preliminarily allocating each of the monitoring data according to the response priority gradient to which each of the monitoring data belongs, so as to obtain an immediate response data set, a priority response data set and a common response data set; Analyzing the execution order of each monitoring data within the gradient according to the node value parameter of each monitoring data to obtain the priority within the gradient of each monitoring data; Arranging the monitoring data in the immediate response data set, the priority response data set and the common response data set in a processing order according to the intra-gradient priority of each of the monitoring data to obtain an immediate response chain, a priority response chain and a common response chain; Perform a correlation analysis on the overall response order of each monitoring data in the immediate response chain, the priority response chain and the ordinary response chain, and convert each monitoring data according to the analysis result to obtain the information to be analyzed corresponding to each monitoring data, and combine the immediate response chain, the priority response chain and the ordinary response chain composed of the information to be analyzed to obtain the information response chain.

5. The low-latency event response method based on the information security monitoring and early warning AI platform as claimed in claim 4 is characterized in that: The steps of performing a correlation analysis of the overall response order on each of the monitoring data in the immediate response chain, the priority response chain, and the ordinary response chain, and converting each of the monitoring data according to the analysis result to obtain information to be analyzed corresponding to each of the monitoring data include: Calculating the ratio of the monitoring data to be responded to of the priority response chain and the common response chain to obtain the workload ratio of the priority response chain and the common response chain; Analyzing the chain conversion relationship between the priority response chain and the ordinary response chain according to the workload ratio of the priority response chain and the ordinary response chain to obtain a rotation response rule between the priority response chain and the ordinary response chain; Allocating priority response weights to each of the monitoring data in the priority response chain and the common response chain according to the rotation response rule, so as to obtain information to be analyzed with priority response weights corresponding to each of the monitoring data; According to the preset highest priority response rule, the monitoring data of the immediate response chain are allocated the highest priority response weight to obtain the information to be analyzed with the highest priority response weight corresponding to each monitoring data; wherein the information to be analyzed with the highest priority response weight obtained by the highest priority response rule is arranged at the forefront of the information to be analyzed with the priority response weight obtained by the rotation response rule.

6. The low-latency event response method based on the information security monitoring and early warning AI platform according to claim 1 is characterized in that: The step of sequentially analyzing and processing each of the information to be analyzed in the information response chain through the information analysis layer to obtain the early warning feedback characteristics of each of the information to be analyzed includes: The information response chain is sequentially retrieved and processed for each piece of information to be analyzed to obtain a real-time processing object at the current moment; Based on the pre-trained information security early warning model, data feature extraction and event early warning analysis are performed on the real-time processing object to obtain security risk indexes of several information security early warning events corresponding to the real-time processing object; The security risk indexes of the real-time processing object corresponding to various information security warning events are comprehensively combined to obtain the warning feedback characteristics of the real-time processing object.

7. The low-latency event response method based on the information security monitoring and early warning AI platform as claimed in claim 6 is characterized in that: The steps of tracking the information association of the information response chain according to the early warning feedback characteristics of the information to be analyzed, dividing the information to be analyzed in the information response chain that has an information association relationship with the information to be analyzed into highly associated information and generally associated information, adjusting the priority response weight of the highly associated information upward, and determining whether to adjust the priority response weight of the generally associated information according to the early warning feedback characteristics of the highly associated information, so that the information analysis layer can analyze the information response chain in sequence include: Perform security threshold analysis on the warning feedback characteristics of the information to be analyzed to obtain the security risk levels of various information security warning events warned by the information to be analyzed, and determine the associated tracking requirements for the security risk levels of various security warning events warned by the information to be analyzed to determine whether the information to be analyzed needs information associated tracking; If the information to be analyzed needs to be tracked for information association, then the security risk levels of various information security warning events warned by the information to be analyzed are analyzed for associated information features based on preset association standards to obtain associated information features of the information to be analyzed; wherein the associated information features include time association features and address association features; Performing association tracking processing on the information to be analyzed according to the associated information feature, so as to obtain a number of information to be analyzed having an associated tracking relationship with the information to be analyzed and information association degrees on the information response chain; Classify the information properties of each of the information to be analyzed according to the information relevance of each of the information to be analyzed, so as to obtain highly relevant information and generally relevant information; Performing an upward adjustment on the priority response weight of the highly relevant information so that the highly relevant information has a higher priority response weight; Acquire the early warning feedback characteristics of the highly correlated information, and analyze the early warning feedback characteristics of the highly correlated information to obtain the security event verification result of the highly correlated information; When the security event verification result shows that the highly relevant information has potential hidden dangers, the priority response weight of the common relevant information is adjusted upward.

Citation Information

Patent Citations

  • Intelligent monitoring and early warning system and method for highway infrastructure group

    CN118247965A

  • 5G-based smart city intelligent security system and method

    CN118283548A