Safety inspection methods and related equipment based on distributed experimental devices
By employing a security detection model in the distributed experimental equipment management system for automated initial security checks and approvals, the problem of low efficiency in managing diverse data has been solved, and the operating efficiency and security of the equipment have been improved.
Patent Information
- Application Number
- CN202411913633.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-24
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2044-12-24
AI Technical Summary
The diverse and unstructured data generated by distributed experimental equipment is difficult to manage efficiently. Traditional security inspection methods are inefficient, costly, and cannot meet the needs of secure storage and management.
A security detection model is used to perform automated initial security checks on target objects, and data is pushed to different approval channels for further security checks through routing and sorting. Combined with a distributed experimental equipment management system, automated initial security checks and approvals are achieved.
It improved the operating efficiency and management level of experimental equipment, reduced the workload of safety testing, reduced safety risks caused by delays and human factors, and enhanced the system's concurrent processing capabilities and overall performance.
Smart Images

Figure CN119885194B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of data processing, and in particular relates to a security inspection method and related equipment based on distributed experimental equipment. Background Technology
[0002] To promote the widespread adoption of intelligent applications across various industries and sectors, distributed experimental equipment generates a large amount of data.
[0003] In related technologies, data generated by distributed experimental devices often contains various formats and types, and its structure may change dynamically. Traditional systems may be inefficient in processing such diverse and unstructured data, with limited processing capabilities and slow response times, making it impossible to manage this data and creating difficulties for the management of distributed experimental devices. For example, distributed experimental devices may generate data of various formats and types, such as text, images, videos, and sensor data, which may have different structures and semantics, making it difficult for traditional systems to process and manage them uniformly. To ensure the secure storage and management of this data, security checks are required, but current check methods all require manual setup and evaluation, which is extremely inefficient and costly.
[0004] Therefore, there is an urgent need to design a security inspection scheme based on distributed experimental equipment to solve at least one of the above-mentioned technical problems. Summary of the Invention
[0005] The purpose of this invention is to provide a security inspection method and related equipment based on distributed experimental equipment. This method achieves automated initial security inspection of equipment data through a security detection model. Then, combined with routing and sorting, the equipment data is pushed to different approval channels for further security inspection, which greatly reduces the workload of security inspection, helps to improve the operating efficiency and management level of the equipment, and enhances the security and reliability of distributed experimental equipment.
[0006] The technical solution of the present invention:
[0007] Firstly, this application provides a security inspection method based on distributed experimental equipment, applied to a distributed experimental equipment management and control system. The distributed experimental equipment management and control system is used to operate and manage experimental equipment, which includes different types of equipment. The security inspection method based on distributed experimental equipment includes:
[0008] In response to the receiving instruction for the target object in the distributed experimental equipment management system, the system obtains the review information of the target object and sets the target object to a pending inspection state; the target object includes at least one of the following: experimental equipment files, experimental equipment software, and experimental parameters;
[0009] The information to be reviewed of the target object is input into the security detection model to perform a security review on the target object, thereby obtaining the review result of the target object;
[0010] Based on the review results of the target object, the target object is set to a corresponding candidate inspection status; the candidate inspection status includes a security label corresponding to the target object; the security label is associated with the security status and object type of the target object;
[0011] The information of the target object to be reviewed is pushed to the approval channel that matches the candidate inspection status, and the security approval of the target object is performed.
[0012] Secondly, this application provides a distributed experimental equipment management and control system, which is used to operate and manage experimental equipment, including different types of equipment. The distributed experimental equipment management and control system includes:
[0013] The acquisition unit is configured to, in response to a receiving instruction for a target object in the distributed experimental equipment management system, acquire the review information of the target object and set the target object to a pending inspection state; the target object includes at least one of the following: experimental equipment files, experimental equipment software, and experimental parameters;
[0014] The inspection unit is configured to input the information to be reviewed of the target object into the security detection model, perform a security review on the target object, and obtain the review result of the target object;
[0015] The setting unit is configured to set the target object to a corresponding candidate inspection state based on the inspection result of the target object; the candidate inspection state includes a security label corresponding to the target object; the security label is associated with the security state and object type of the target object;
[0016] The push unit is configured to push the review information of the target object to the approval channel that matches the candidate inspection status, and perform security approval on the target object.
[0017] Thirdly, this application provides an intelligent computing platform, the intelligent computing platform comprising:
[0018] At least one processor, memory, and input / output unit;
[0019] The memory is used to store computer programs, the processor is used to call the computer programs stored in the memory to execute the security inspection method based on the first aspect of the distributed experimental device, and the input / output unit is used to receive user input and display the output information of the computer programs stored in the memory.
[0020] Fourthly, a computer-readable storage medium is provided, comprising instructions that, when executed on a computer, cause the computer to perform the security inspection method of the first aspect based on a distributed experimental device.
[0021] The beneficial effects of this invention are:
[0022] The technical solution provided by this invention can be applied to a distributed experimental equipment management and control system. This system is used to operate and manage experimental equipment, including different types of devices. In this solution, firstly, in response to a receiving instruction from the distributed experimental equipment management and control system regarding a target object, the system acquires the target object's pending review information and sets the target object to a pending inspection state. The target object includes at least one of the following: experimental equipment files, experimental equipment software, and experimental parameters. Next, the pending review information of the target object is input into a security detection model to perform a security review of the target object, thereby obtaining the review result. Then, based on the review result, the target object is set to a corresponding candidate inspection state. Finally, the pending review information of the target object is pushed to the approval channel matching the candidate inspection state, and a security approval for the target object is performed.
[0023] This invention's technical solution can respond to instructions in real time, quickly acquire information to be reviewed, and conduct security reviews. This ensures timely and effective control of experimental equipment, reducing security risks caused by delays. Reviewing target objects through a security detection model allows for a comprehensive review of experimental equipment files, software, and parameters, improving the comprehensiveness and accuracy of the review. Furthermore, associating review results with security tags allows for better management of the security status of experimental equipment. Setting security tags helps administrators or users quickly understand the security of the equipment, facilitating timely implementation of necessary security measures. It can also automatically push information to be reviewed to the matching approval channel and execute security approvals. This reduces the cost of manual intervention, improves approval efficiency, and reduces security vulnerabilities caused by human factors. Through a distributed experimental equipment management system, review tasks can be distributed to different nodes for processing, reducing the load on a single node and improving the system's concurrent processing capacity and overall performance. This application's technical solution achieves automated initial security checks on equipment data through a security detection model, and then combines routing and sorting to push equipment data to different approval channels for further security checks, significantly reducing the workload of security detection, helping to improve equipment operating efficiency and management level, and enhancing the security and reliability of distributed experimental equipment. Attached Figure Description
[0024] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0025] Figure 1 This is a flowchart illustrating a security inspection method based on distributed experimental equipment according to an embodiment of this application;
[0026] Figure 2 This is a schematic diagram of the structure of a distributed experimental equipment management and control system according to an embodiment of this application;
[0027] Figure 3 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application. Detailed Implementation
[0028] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0029] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the application.
[0030] To promote the widespread adoption of intelligent applications across various industries and sectors, distributed experimental equipment generates a large amount of data.
[0031] In related technologies, data generated by distributed experimental devices often contains various formats and types, and its structure may change dynamically. Traditional systems may be inefficient in processing such diverse and unstructured data, with limited processing capabilities and slow response times, making it impossible to manage this data and creating difficulties for the management of distributed experimental devices. For example, distributed experimental devices may generate data of various formats and types, such as text, images, videos, and sensor data, which may have different structures and semantics, making it difficult for traditional systems to process and manage them uniformly. To ensure the secure storage and management of this data, security checks are required, but current check methods all require manual setup and evaluation, which is extremely inefficient and costly.
[0032] Therefore, there is an urgent need to design a security inspection scheme based on distributed experimental equipment to solve at least one of the above-mentioned technical problems.
[0033] This application provides a security inspection method and related equipment based on distributed experimental equipment.
[0034] Specifically, in the security inspection scheme based on distributed experimental equipment, firstly, in response to the receiving instruction for the target object in the distributed experimental equipment management system, the system obtains the review information of the target object and sets the target object to a pending inspection state. The target object includes at least one of the following: experimental equipment files, experimental equipment software, and experimental parameters. Next, the review information of the target object is input into the security detection model to perform a security review of the target object, thereby obtaining the review result. Then, based on the review result, the target object is set to a corresponding candidate inspection state. Finally, the review information of the target object is pushed to the approval channel matching the candidate inspection state, and a security approval for the target object is performed.
[0035] The distributed experimental equipment security inspection scheme can respond to commands in real time, quickly acquire information to be reviewed, and conduct security reviews. This ensures timely and effective control of experimental equipment and reduces security risks caused by delays. Reviewing target objects through a security detection model allows for a comprehensive review of experimental equipment files, software, and parameters, improving the comprehensiveness and accuracy of the review. Furthermore, associating review results with security tags allows for better management of the security status of experimental equipment. Setting security tags helps administrators or users quickly understand the security of the equipment, facilitating timely implementation of necessary security measures. It can also automatically push information to be reviewed to the matching approval channel and execute security approvals. This reduces the cost of manual intervention, improves approval efficiency, and reduces security vulnerabilities caused by human factors. Through the distributed experimental equipment management system, review tasks can be distributed to different nodes for processing, thereby reducing the load on a single node and improving the system's concurrent processing capacity and overall performance.
[0036] In summary, the security inspection scheme based on distributed experimental equipment achieves automated initial security checks on equipment data through a security detection model. Combined with routing and sorting, the equipment data is pushed to different approval channels for further security checks, significantly reducing the workload of security detection and helping to improve equipment operating efficiency and management level, thereby enhancing the security and reliability of distributed experimental equipment. The security inspection scheme based on distributed experimental equipment provided in this application can also be executed by electronic devices, such as servers, server clusters, or cloud servers. These electronic devices can also be terminal devices such as mobile phones, computers, tablets, wearable devices, or dedicated devices (such as dedicated terminal devices with a security inspection system based on distributed experimental equipment). These electronic devices can also carry the chips described in the above embodiments. Alternatively, these electronic devices can also install service programs for executing the security inspection scheme based on distributed experimental equipment.
[0037] In this embodiment, the distributed experimental equipment management and control system is primarily responsible for storing various related data from the advanced computing platform, including input data, calculation results, observation data, and visualization data. This data may originate from different applications and requires unified management and storage for subsequent analysis and processing.
[0038] Figure 1 A schematic diagram of a security inspection method based on distributed experimental equipment provided in this application embodiment is shown below. Figure 1 The method includes the following steps:
[0039] 101. In response to the receiving instruction for the target object in the distributed experimental equipment management system, obtain the review information of the target object and set the target object to the inspection state.
[0040] In this embodiment, the distributed experimental equipment management system is used to operate and manage experimental equipment. This experimental equipment includes different types of devices.
[0041] In this embodiment, the security inspection method based on the distributed test equipment security management system involves a relatively complex system architecture, requiring full consideration of communication, data transmission, and security between the server and client. The following is a brief introduction to the system's technical background and related equipment:
[0042] Alternatively, the distributed testing equipment safety management system is designed based on a client / server architecture. A client / server architecture separates the user interface from the application logic; the user communicates with the server through the client, and the server processes requests and returns results. This architecture is typically used for applications requiring complex logic processing and large amounts of data storage.
[0043] Microservice architecture is an architectural pattern that breaks down an application into a series of small, independently deployed services. Each microservice can be developed, deployed, and scaled independently, communicating through lightweight communication protocols, thereby achieving a highly cohesive and loosely coupled system architecture.
[0044] Qt is a cross-platform C++ application development framework for developing graphical user interface (GUI) applications. It provides a rich set of GUI components and tools, simplifying the development process of cross-platform applications while offering good performance and scalability.
[0045] Distributed testing equipment refers to testing devices deployed at different locations or nodes. These devices can collaborate to complete testing tasks and communicate and exchange data via a network. Distributed testing equipment typically features high flexibility and scalability, allowing for dynamic configuration and deployment as needed.
[0046] The server is the core of the entire system, responsible for implementing various functional modules and processing data. In this system, the server adopts a microservice architecture, containing multiple independent functional modules, such as runtime status monitoring, audit log collection and analysis, ledger management, and resource management. Each functional module can be deployed and extended independently, interacting through a lightweight communication mechanism.
[0047] The client is the interface through which users interact with the system, responsible for receiving user input, displaying information, and sending requests to the server. In this system, the client is developed based on QT and includes functional modules such as user authentication, device management, information management, test parameter management, file management, software management, and remote control. Through communication with the server, the client enables user interaction with the system and performs security checks.
[0048] In summary, the security inspection method based on the distributed test equipment security management system combines C / S architecture, microservice architecture, and QT development technology to achieve real-time management and intelligent control of distributed test equipment, providing strong support for the security, stability, and reliability of test equipment.
[0049] Further optionally, the target object includes at least one of the following: experimental equipment files, experimental equipment software, and experimental parameters. When target objects are involved in an experimental equipment management system, these objects are typically important components of the system that require management and review.
[0050] Specifically, experimental equipment files refer to various files related to experimental equipment, which may include experimental data files, configuration files, log files, etc. These files contain data and configuration information generated during the experiment and are crucial to the accuracy and completeness of the experimental results. Reviewing experimental equipment files ensures the integrity, confidentiality, and reliability of the data, prevents malicious tampering or leakage, and thus safeguards the credibility and security of research findings.
[0051] Experimental equipment software refers to the software programs that run on experimental equipment, including control software, analysis software, and simulation software. Experimental equipment software directly affects the functionality and performance of the equipment. Reviewing experimental equipment software ensures its legality, security, and stability; allows for the timely detection and remediation of potential security vulnerabilities; prevents malicious attacks or unauthorized use; and guarantees the normal operation of the experimental equipment and the reliability of experimental data.
[0052] Experimental parameters refer to the various parameters that need to be set and adjusted during the experiment, such as temperature, pressure, and speed. Experimental parameters directly affect the accuracy and repeatability of experimental results. Reviewing experimental parameters ensures the rationality and safety of parameter settings, prevents experimental failures or unexpected events due to incorrect parameter settings, improves experimental efficiency and success rate, and guarantees the accuracy of experimental data and the credibility of research results.
[0053] In summary, experimental equipment documents, software, and parameters are key targets for management and review within the experimental equipment control system, as their security and stability directly impact the results and outcomes of scientific research experiments. A comprehensive security review of these targets ensures the security and reliability of the experimental equipment control system, providing dependable technical support for scientific research.
[0054] As an optional embodiment, in 101, firstly, a system interface or communication protocol can be pre-configured to receive instructions from users or other systems. This can be achieved through network communication, such as using HTTP requests or message queues. An instruction receiving module is set up in the system to receive and parse the received instructions. This module needs to be able to understand the format and meaning of the instructions and translate them into internal system operations. Once an instruction is received, the system can perform corresponding information acquisition operations based on the target object information in the instruction. Different acquisition methods may be required for different types of target objects, such as experimental equipment files, experimental equipment software, and experimental parameters. For example, for files, the file content can be read directly; for software, the software version and configuration information can be queried; and for parameters, they can be obtained from parameter configuration files or databases. After acquiring the information of the target object to be reviewed, the system marks the target object as pending inspection for subsequent security review operations. This status marking can be implemented by setting corresponding flags in the system database or memory, indicating that the target object needs to be security reviewed.
[0055] In this embodiment, the target object is assumed to be an experimental equipment file. File attributes include: filename, size, creation time, modification time, etc. File content: if file content review is allowed, it may include text content, image data, audio data, etc. File permissions include: read / write permissions, execution permissions, etc.
[0056] Assuming the target is experimental equipment software, the software specifications are as follows: Software Version: The software version number and update history. Software Permissions: The required permissions and access scope of the software. Software Configuration: The software configuration information, such as parameter settings and a list of plugins.
[0057] Assuming the target object is experimental parameters, the experimental setup includes: basic information such as the experiment's name, description, and purpose; parameter configuration, including the parameter settings used in the experiment, such as experimental conditions and variable settings; and experimental data, including existing experimental data or results, which may include experimental records, log information, and data files.
[0058] The above information can be adjusted and expanded according to specific application scenarios and review requirements to ensure a comprehensive review and evaluation of the target.
[0059] In summary, implementing this step requires designing and implementing the system's instruction receiving module, information acquisition module, and status management module. Through sound system design and reasonable functional division, the system can accurately and efficiently respond to instructions, acquire information to be reviewed, and set the target object to a pending inspection state, laying the foundation for subsequent security review operations.
[0060] 102. Input the information to be reviewed of the target object into the security detection model, perform a security review on the target object, and obtain the review result of the target object.
[0061] Specifically, security inspection models should possess the ability to continuously learn and optimize to adapt to constantly changing security threats and environments. For example, continuous model improvement can be achieved by introducing online learning algorithms and adaptive model update strategies, thereby enhancing the effectiveness and accuracy of security inspections.
[0062] As an optional embodiment, the security detection model includes at least the following structure: a feature extraction layer, a group election layer, a random election layer, and an integrated output layer. The feature extraction layer is responsible for extracting key features from the information of the target object to be reviewed. These features can be security-related attributes, parameters, or statistical information used to describe the characteristics and features of the target object. Feature extraction can employ various techniques, such as rule-based feature extraction, statistical feature extraction, or deep learning-based feature extraction, to ensure that the extracted features are representative and discriminative. The group election layer aggregates the outputs of multiple security detection sub-models and uses voting or weighted averaging to make decisions, thereby improving the accuracy and robustness of the review results. The group election layer can include multiple different security detection sub-models, each of which may employ different algorithms or techniques to increase model diversity and coverage. The random election layer introduces randomness by randomly selecting a subset of security detection sub-models for decision-making, thereby increasing model diversity and robustness. Random election can dynamically select different sub-models for decision-making during each review process, thereby reducing the risk of model overfitting and improving the model's generalization ability. The ensemble output layer integrates and combines the outputs of the group election layer and the random election layer to generate the final review result. The ensemble output layer can perform weighted fusion of the outputs of each sub-model, or use voting or other methods to make decisions to obtain the final comprehensive review result.
[0063] Through the above structure, the security detection model can make full use of the information and decisions of multiple sub-models, improve the accuracy and robustness of the review results, and thus more effectively discover potential security problems and risks in the target object.
[0064] Based on the above model structure, in step 102, the step of inputting the information to be reviewed of the target object into the security detection model to perform a security review on the target object and obtain the review result of the target object can be implemented as follows:
[0065] 201. Through the feature extraction layer, extract the features of the target object to be reviewed from the information to be reviewed;
[0066] 202. Through the group election layer, the features to be reviewed are input into the navigation module in the group election layer, and the navigation module routes them to different election nodes, so that each election node processes the features to be reviewed to obtain the approval prediction results of each election node.
[0067] 203. Through a random election layer, the features to be reviewed are selected using a random matching mechanism to conduct a security review, so as to obtain random approval prediction results;
[0068] 204. By integrating the output layer, the approval prediction results of each election node and the random approval prediction results are dynamically integrated to obtain the review results of the target object.
[0069] By introducing multiple review sub-models and random factors through group election and random election layers, the model's diversity and robustness are increased. This reduces the risk of overfitting and improves its generalization ability, thus better adapting to the review of target objects in different types and scenarios. The integrated output layer dynamically integrates the results of each election node and random approval, fully utilizing the decision-making information from different review sub-models to improve the accuracy and credibility of the review results. This allows for a more comprehensive assessment of the security of the target object and provides more reasonable review recommendations. The design combining the navigation module and the random election layer allows for dynamic adjustment of the review process and decision-making strategies based on actual conditions. This better adapts to different review scenarios and needs, improving the system's flexibility and adaptability. Due to the integrated output layer, the review results are based on a comprehensive output of multiple review nodes and random approval results, making the review results more persuasive and interpretable. This helps users better understand the review results and take appropriate actions and measures.
[0070] In summary, based on the proposed model structure, a comprehensive security review of the target object can be achieved, providing more accurate and reliable review results, and providing strong support for subsequent security management and risk control.
[0071] In this embodiment of the application, the integration mechanism used in the dynamic integration process is obtained by dynamic feedback and evaluation based on the integration results in the previous cycle.
[0072] This means that each review cycle utilizes the integration results of the previous cycle to dynamically adjust the integration strategy for the current cycle. The system records the integration output results for each cycle, including the approval prediction results of each election node and the random approval prediction results. These historical results are used as a reference to evaluate the model's performance and effectiveness. Based on the performance of historical results, the system dynamically adjusts parameters during the integration process, such as the weight of each election node and the proportion of random elections. This allows for adjustments to the model's preferences and decision-making strategies based on actual circumstances, improving the quality and stability of the integration results. After each review cycle, the system performs a performance evaluation of the integration output results, such as accuracy, recall, and F1 score. Based on the evaluation results, the system adjusts the integration parameters to optimize the integration process for the next cycle. Based on the performance evaluation results and feedback information, the system updates the integration strategy and parameters to adapt to changes in the target object and model performance. This maintains the model's robustness and adaptability, ensuring stable and efficient review results across different scenarios.
[0073] By employing the methods described above, the system can dynamically adjust parameters and strategies during the integration process based on historical experience and real-time feedback, thereby improving the quality and credibility of review results. This allows for better responses to changes in target objects and security requirements, providing continuous support and optimization for security reviews.
[0074] In this embodiment of the application, the features to be examined include at least: device file features, device software features, and experimental parameter features.
[0075] In this application embodiment, the features to be examined include device file features, device software features, and experimental parameter features. Device file features refer to file-related information on the target device, including but not limited to file type, file size, file permissions, file path, file creation time, and file modification time. This information helps determine whether the device has abnormal files or potential security risks, such as files with abnormal permissions or suspicious file paths. Device software features cover information related to the software or applications installed on the device, including software name, version number, installation path, and running status. By analyzing the software features on the device, it is possible to discover whether there are unauthorized software, known vulnerable software, or abnormal software behavior, etc. Experimental parameter features refer to parameter information generated by the device during the experiment, such as sensor data, experimental records, and experimental results. This parameter information can reflect the device's operating status, changes and anomalies during the experiment, helping to identify potential security risks and problems.
[0076] Based on the above characteristics, the security detection model can comprehensively examine the target object from different perspectives, identify potential security hazards and risks, and provide effective support and decision-making basis for security management and risk control.
[0077] As an optional embodiment, in step 202, the feature to be reviewed is input into the navigation module of the group election layer, and the navigation module routes it to different election nodes, so that each election node processes the feature to be reviewed to obtain the approval prediction result of each election node. This can be achieved through the following steps:
[0078] 301, using the navigation module, perform attribute identification on the target object based on the features to be examined; and
[0079] 302. Based on the attribute recognition results, determine multiple routing paths corresponding to the target object, and route the features to be reviewed to different election nodes according to the multiple routing paths;
[0080] 303. Through each election node, the features to be reviewed are subject to security approval according to their respective adaptive evaluation mechanisms, so as to obtain the approval prediction results of each election node.
[0081] In this embodiment, each election node is equipped with its own adaptive evaluation mechanism. In this optional embodiment, each election node is equipped with its own adaptive evaluation mechanism to dynamically adjust the review process and decision-making strategy according to the actual situation. For example, election nodes can learn from historical review data and adjust their review standards and decision-making rules based on past review results and feedback information. By analyzing historical data, nodes can identify common security issues and patterns, thereby improving the accuracy and efficiency of reviews.
[0082] For example, elected nodes can monitor changes in the features to be reviewed and the dynamics of the environment in real time, and adjust their review strategies accordingly. For instance, if changes to certain features are found to be different from the past, nodes can take stricter review measures to address potential security risks.
[0083] For example, elected nodes can dynamically adjust review thresholds and rules based on the current environment and the characteristics of the target object. For instance, for certain key features or high-risk scenarios, nodes can lower the review approval threshold to improve security, while for low-risk scenarios, they can relax the threshold to reduce false positives.
[0084] For example, elected nodes can perform importance analysis on the features to be reviewed and dynamically adjust their review strategies based on the degree of influence of each feature on the review results. For instance, nodes can place greater emphasis on the review results of features with higher importance, while adjusting the review standards appropriately for less important features.
[0085] For example, election nodes can monitor the performance metrics of their own models, such as accuracy and recall, and adjust review strategies and parameter settings in a timely manner based on changes in these metrics. By continuously monitoring model performance, nodes can promptly identify and optimize problems, improving review effectiveness and stability.
[0086] By combining the above adaptive evaluation mechanisms, each election node can dynamically adjust its review strategies and decision-making rules based on actual circumstances, thereby improving the accuracy, credibility, and adaptability of the review results. This allows for better handling of different review scenarios and changes in target objects, resulting in a more effective security review process.
[0087] It is worth noting that each adaptive evaluation mechanism has specific dynamic evaluation parameters and predictive evaluation methods.
[0088] For example, in historical data learning, dynamic evaluation parameters might include learning rate and historical data weights, while predictive evaluation methods might involve statistical analysis or machine learning algorithms based on historical data, such as decision trees or neural networks. Additionally, dynamic parameters for real-time monitoring and feedback might include monitoring frequency and anomaly detection thresholds, while predictive evaluation methods might involve real-time data stream processing or anomaly detection algorithms, such as isolated forests or cluster analysis. Adaptive threshold setting might involve dynamic parameters such as review pass thresholds and false positive rate control parameters, while predictive evaluation methods might include statistical analysis, ROC curve analysis, or cross-validation. Dynamic parameters for feature importance analysis might involve feature weights and feature selection thresholds, while predictive evaluation methods might include information gain, Gini coefficient, or model weight adjustment. Finally, dynamic parameters for model performance monitoring might include performance indicator thresholds and monitoring periods, while predictive evaluation methods might include indicator trend analysis or anomaly detection algorithms, such as fluctuation detection or trend analysis. In specific implementations, the most appropriate parameters and methods will be selected based on the specific circumstances to ensure the effectiveness and adaptability of the evaluation mechanism. The above are examples of possible dynamic evaluation parameters and predictive evaluation methods; in specific implementations, the most appropriate parameters and methods will be selected based on the specific circumstances. The selection of these parameters and methods can be adjusted and optimized according to actual scenarios and needs to ensure the effectiveness and adaptability of the evaluation mechanism.
[0089] Furthermore, when each election node performs partitioning, it can utilize a deep learning model to learn node partitioning rules to maximize the information gain of the nodes or minimize their impurity. For example, the partitioning rules can be based on the characteristics of the election nodes; in file data, partitioning can be based on features such as file type and size.
[0090] Furthermore, to increase the diversity and generalization ability of the model, randomness can be introduced when splitting the election nodes, for example, by randomly selecting a subset of features for splitting.
[0091] In step 303 above, each election node performs security approval on the features to be reviewed according to its own adaptive evaluation mechanism to obtain the approval prediction results of each election node. This can be achieved through the following steps:
[0092] 3031, through the file analysis node, performs static and dynamic analysis on the characteristics of the received device files to obtain the first predicted approval result.
[0093] In this embodiment of the application, the first predicted approval result is used to indicate whether the experimental equipment file of the target object contains potential security risks.
[0094] 3032, through the software evaluation node, adaptively predicts the version information and permission settings in the received device software features to obtain a second predictive approval result.
[0095] In this embodiment of the application, the second predicted approval result is used to indicate the security of the experimental equipment software of the target object.
[0096] 3033, through the parameter review node, based on the characteristics of the received experimental parameters, performs adaptive verification analysis on the legality and completeness of the parameters to obtain the third prediction approval result.
[0097] In this embodiment of the application, the third prediction approval result is used to indicate whether the experimental equipment parameters of the target object meet the safety requirements.
[0098] By implementing multi-node approval, the security of equipment documents, software, and parameters can be comprehensively considered, thereby improving the comprehensiveness and accuracy of the approval results. Each node reviews specific types of features, allowing for a more focused identification and assessment of potential security risks, thus improving the accuracy and efficiency of the review. Each node employs an adaptive evaluation mechanism, dynamically adjusting review strategies and parameter settings based on real-time conditions. This better adapts to the changes and complexities of different feature types, improving the adaptability and accuracy of the review. The review content covers multiple aspects such as equipment documents, software, and parameters, enabling a comprehensive examination of the target object's security and reducing the likelihood of security vulnerabilities and risks. Each node can quickly generate predictive approval results, providing decision-makers with timely information on equipment security, helping them make more accurate decisions and take necessary security measures promptly.
[0099] In summary, this multi-stage approval process improves the comprehensiveness, accuracy, and efficiency of the approval process, providing a more reliable guarantee for equipment safety.
[0100] In this embodiment, the approval prediction results of each election node have at least one of the following forms: binary form, multivariate form, and fractional form. Further optionally, the first predicted approval result is in binary form, the second predicted approval result is in multivariate form, and the third predicted approval result is in fractional form. The first predicted approval result, expressed in binary form, indicates whether a security risk exists. For example, the result might be "passed" or "failed," indicating whether the document contains potential security risks. The second predicted approval result, expressed in multivariate form, can provide richer information. This form may include multiple categories, each representing a different level of security or risk. For example, the result might include multiple levels such as "safe," "suspicious," and "dangerous." The third predicted approval result, expressed in fractional form, typically refers to the security score of device parameters. This form can provide more refined quantitative information, helping users better understand the security of device parameters. The score is usually within a continuous numerical range, such as 0 to 100, with higher scores indicating higher security.
[0101] In practical applications, optionally, the third predicted approval result is a safety confidence score for the equipment parameters. This means that the result not only provides a safety assessment of the equipment parameters but also the level of confidence in that assessment. The confidence score reflects the reliability of the assessment result, helping users better understand the accuracy and credibility of the assessment result.
[0102] In summary, using different forms of approval forecasts can more comprehensively reflect the equipment security situation and provide users with richer information, which helps to make more accurate decisions and take necessary security measures.
[0103] As an optional embodiment, in 303, after each election node performs security approval on the feature to be reviewed according to its own adaptive evaluation mechanism to obtain the approval prediction results of each election node, the adaptive parameters in each election node can be optimized and adjusted through the parameter adjustment layer to improve the approval prediction performance of each election node.
[0104] Specifically, in the optional embodiment, the above steps, through a parameter adjustment layer, optimize and adjust the adaptive parameters in each election node to improve the approval prediction performance of each election node, which can be achieved in the following way:
[0105] Method 1: For file analysis nodes, static analysis parameters are dynamically adjusted based on the type information, file size information, and file data structure characteristics contained in the device file features to improve the static analysis effect for different types of files; and dynamic analysis parameters are dynamically adjusted based on the real-time operating characteristics of the experimental equipment and the file behavior change characteristics.
[0106] Optimization of static analysis parameters: Based on the device file's type, size, and data structure characteristics, static analysis parameters can be dynamically adjusted. For example, the flexibility and sensitivity of the file parsing algorithm can be adjusted to improve the static analysis results for different file types. For instance, for files of different formats, the parsing algorithm parameters can be adjusted to better identify potential security risks.
[0107] Optimization of dynamic analysis parameters: Based on the real-time operating characteristics of the experimental equipment and the changing features of file behavior, dynamic analysis parameters can be dynamically adjusted. For example, the threshold and sensitivity of the monitoring algorithm can be adjusted to more accurately capture abnormal file behavior. Specifically, the parameters of the monitoring algorithm can be adjusted for the dynamic behavior of different files to improve the detection rate and accuracy of abnormal behavior.
[0108] By optimizing the adaptive parameters of the file analysis node, the approval prediction performance for device file security can be improved, and the static and dynamic analysis effects of different types of files can be enhanced, thereby more effectively identifying and assessing potential security risks.
[0109] Method 2: For software evaluation nodes, adjust the parameters of the version information prediction model according to the software type, release cycle, and update frequency to adapt to the version change characteristics of different software; and adjust the parameters of the permission setting prediction model according to the software's permission structure and security policy to improve the prediction accuracy of different permission settings.
[0110] Regarding the parameters of the version information prediction model: The parameters of the version information prediction model can be adjusted based on the software type, release cycle, and update frequency. For example, the model's learning rate and weights can be adjusted to adapt to the characteristics of different software version changes. For instance, for frequently updated software, the model's learning rate can be adjusted to adapt to the features of new versions more quickly.
[0111] Parameters of the permission setting prediction model can be adjusted based on the software's permission structure and security policies. For example, adjusting the model's feature weights and thresholds can improve the accuracy of predictions for different permission settings. For instance, for software with different permission settings, the model's feature weights can be adjusted to more accurately assess its security.
[0112] By optimizing the adaptive parameters of the software evaluation node, the approval prediction performance for device software security can be improved, and the security under different software versions and permission settings can be predicted more accurately, thereby effectively reducing security risks.
[0113] Method 3: For parameter review nodes, adjust the parameters of the legality verification model according to the type, range, and constraints of the experimental parameters to ensure the accuracy of legality checks on different types of parameters; and adjust the parameters of the integrity verification model according to the changing patterns and historical data of the experimental parameters to adapt to the changing needs of parameter integrity analysis.
[0114] Regarding the parameters of the legality verification model: The parameters of the legality verification model can be adjusted based on the type, range, and constraints of the experimental parameters. For example, the model's rules and constraints can be adjusted to ensure the accuracy of legality checks for different types of parameters. For instance, the model's constraints can be adjusted for different types of parameters to better identify illegal parameter values.
[0115] Regarding the parameters of the integrity verification model: Based on the changing patterns of experimental parameters and historical data, the parameters of the integrity verification model can be adjusted, such as adjusting the model's threshold and sensitivity, to adapt to changes in the needs of parameter integrity analysis. For example, based on the changing patterns of different parameters, the model's threshold can be adjusted to more accurately identify abnormal changes in parameters.
[0116] By optimizing the adaptive parameters of the parameter review node, the approval prediction performance for the safety of experimental equipment parameters can be improved, the legality and integrity of parameters can be verified more accurately, and thus the safety of equipment parameters can be effectively guaranteed.
[0117] In summary, by optimizing and adjusting the adaptive parameters in each election node through these methods, the performance and accuracy of the entire approval system can be improved, thereby more effectively identifying and assessing the security risks of the equipment.
[0118] 103. Based on the review results of the target object, set the target object to the corresponding candidate inspection status.
[0119] In this embodiment, the candidate inspection status includes a security tag corresponding to the target object. Specifically, setting a target object to a corresponding candidate inspection status typically involves marking the object into different states for subsequent review and processing. These candidate inspection states may include security tags for the target object to better identify and track its security status. For example, a security tag is a marker used to identify the current security status or risk level of the target object. These tags may be generated based on review results or other security assessment indicators and reflect the security status of the target object.
[0120] Candidate inspection status is a classification of different states or stages that a target object may be in during the review process. Each status is typically associated with a specific security label to indicate the object's security condition. For example, a target object marked as pending review indicates that it requires a security review. At this stage, the security label may be unknown or pending confirmation, requiring further review to determine the object's security. If the target object is determined to be secure after review, it can be set to a secure status. In this case, the security label may be "secure" or "passed," indicating that the object does not contain any obvious security risks. If the target object is determined to have security risks after review, it can be set to a risky status. In this case, the security label may be "at risk," "warning," or other relevant risk level markers to indicate that the object has potential security issues. In some cases, the security of a target object may be uncertain due to the review process, or an anomaly may occur; in this case, it can be set to an anomalous status. In this case, the security label may be "abnormal" or "unknown," indicating that the object's security requires further investigation or action.
[0121] By setting target objects to different candidate inspection states and attaching corresponding security labels, the security status of objects can be better managed and tracked, and necessary security measures can be taken in a timely manner to deal with potential security risks.
[0122] In this embodiment of the application, the security label is associated with the security status and object type of the target object.
[0123] For different security states, corresponding security labels can be defined to represent the security of an object. For example, for an object in a secure state, the security label could be "secure" or "passed," indicating that the object has been determined to be secure after review. For an object in a risky state, the security label could be "risky," "warning," etc., indicating that the object has potential security issues. Different types of target objects may have different security characteristics and review requirements, so different security labels can be defined according to the object type. For example, for file objects, the security label can reflect the data types they contain, file structure, and potential security risks; for software objects, the security label can reflect their version information, release cycle, and known vulnerabilities. Security labels can be further subdivided and customized for different security states and object types to more accurately describe the security status of the object. For example, different security labels can be defined for different levels of risk, such as "low risk," "medium risk," and "high risk"; specific security labels can be defined for different types of files, such as "suspicious file" and "malicious file."
[0124] By associating with security status and object type, security tags can more comprehensively reflect the security characteristics and review results of the target object, providing more targeted and actionable security information, and helping users to more accurately understand and handle the security issues of the object.
[0125] It is worth noting that the security labels associated with the candidate inspection status can be further expanded to consider more dimensions of information, such as security risk level, threat type, and scope of impact, in order to provide richer security information and decision support.
[0126] 104. Push the information of the target object to be reviewed to the approval channel that matches the candidate inspection status, and perform security approval for the target object.
[0127] In this application, the division of approval channels can be based on factors such as the nature, urgency, complexity, and degree of automation of the approval task. For example, approval channels can be divided into manual approval channels and automated approval channels. Manual approval channels are suitable for complex, high-risk, or approval tasks requiring professional knowledge and judgment. These tasks may involve reviewing a large amount of detail, subjective judgment, or specific domain expertise, making it impossible to rely entirely on automated systems. Manual approval channels are typically handled by professional approvers or approval teams who carefully review the information to be reviewed, conduct a comprehensive evaluation, and make approval decisions based on their professional judgment. Automated approval channels are suitable for relatively simple, low-risk, or approval tasks that can be automatically judged by rules or algorithms. These tasks may include routine, repetitive approval processes that can be automated through pre-defined rules, models, or algorithms. Automated approval channels are typically handled by computer systems or software that can quickly and efficiently process the information to be reviewed and generate approval results according to set rules or algorithms. In practical applications, the division of approval channels can be flexibly adjusted and combined according to specific circumstances. For example, for some complex approval tasks, a manual approval channel can be used for preliminary approval, and then an automated approval channel can be used for quick confirmation or further processing; for some simple approval tasks, they can be processed directly through an automated approval channel, thereby improving approval efficiency and speed.
[0128] In summary, both manual and automated approval channels have their advantages in the approval process. Reasonable division and combination can improve approval efficiency, accuracy, and flexibility, and meet the needs of different approval tasks.
[0129] As an optional embodiment, in step 104, when the information to be reviewed is pushed to an approval channel that matches the candidate inspection status, an intelligent algorithm can be introduced to select the most suitable approval channel. This can make decisions based on factors such as the characteristics of the target object, the review results, and the load of the approval channel, thereby improving approval efficiency and accuracy.
[0130] Alternatively, a real-time review and feedback mechanism can be introduced during the security review and approval process to promptly identify and address potential security threats. This can be achieved through integration with real-time monitoring systems and through rapid response mechanisms to address security incidents in a timely manner.
[0131] Furthermore, during the review process, a visual interface for the security review results can be provided to intuitively display the security status and related information of the target object, helping users better understand the review results and make decisions.
[0132] In this embodiment, the method can be applied to a distributed experimental equipment management system. This system is used to operate and manage experimental equipment, including various types of devices. In this scheme, firstly, in response to a receiving instruction from the distributed experimental equipment management system regarding a target object, the system acquires the target object's review information and sets the target object to a pending inspection state. The target object includes at least one of the following: experimental equipment files, experimental equipment software, or experimental parameters. Next, the review information of the target object is input into a security detection model to perform a security review of the target object, thereby obtaining the review result. Then, based on the review result, the target object is set to a corresponding candidate inspection state. Finally, the review information of the target object is pushed to the approval channel matching the candidate inspection state, and a security approval for the target object is performed.
[0133] In this embodiment, instructions can be responded to in real time, information to be reviewed can be quickly obtained, and security reviews can be conducted. This ensures timely and effective control of experimental equipment and reduces security risks caused by delays. Reviewing target objects through a security detection model also allows for a comprehensive review of experimental equipment files, software, and parameters, thereby improving the comprehensiveness and accuracy of the review. Furthermore, associating review results with security tags allows for better management of the security status of experimental equipment. Setting security tags helps administrators or users quickly understand the security of the equipment, facilitating timely implementation of necessary security measures. It also automatically pushes information to be reviewed to the matching approval channel and executes security approval. This reduces the cost of manual intervention, improves approval efficiency, and reduces security vulnerabilities caused by human factors. Through a distributed experimental equipment management system, review tasks can be distributed to different nodes for processing, thereby reducing the load on a single node and improving the system's concurrent processing capacity and overall performance. In this embodiment, an automated initial security check of equipment data is achieved through a security detection model, and then combined with routing sorting, the equipment data is pushed to different approval channels for further security checks, greatly reducing the workload of security detection, helping to improve equipment operating efficiency and management level, and enhancing the security and reliability of distributed experimental equipment.
[0134] In another embodiment of this application, a distributed experimental equipment management and control system is also provided. This system is used to operate and manage experimental equipment, which includes different types of equipment. (See also...) Figure 3 The distributed experimental equipment management and control system includes the following units:
[0135] The acquisition unit is configured to, in response to a receiving instruction for a target object in the distributed experimental equipment management system, acquire the review information of the target object and set the target object to a pending inspection state; the target object includes at least one of the following: experimental equipment files, experimental equipment software, and experimental parameters;
[0136] The inspection unit is configured to input the information to be reviewed of the target object into the security detection model, perform a security review on the target object, and obtain the review result of the target object;
[0137] The setting unit is configured to set the target object to a corresponding candidate inspection state based on the inspection result of the target object; the candidate inspection state includes a security label corresponding to the target object; the security label is associated with the security state and object type of the target object;
[0138] The push unit is configured to push the review information of the target object to the approval channel that matches the candidate inspection status, and perform security approval on the target object.
[0139] Further optionally, the security detection model includes at least the following structure: a feature extraction layer, a group election layer, a random election layer, and an integrated output layer; the inspection unit, which inputs the information to be reviewed of the target object into the security detection model, performs a security review of the target object to obtain the review result of the target object, is configured as follows:
[0140] The feature extraction layer extracts the features of the target object to be reviewed from the information to be reviewed; the features to be reviewed include at least: device file features, device software features, and experimental parameter features.
[0141] Through the group election layer, the features to be reviewed are input into the navigation module in the group election layer, and the navigation module routes them to different election nodes, so that each election node processes the features to be reviewed to obtain the approval prediction results of each election node.
[0142] Through a random election layer, the features to be reviewed are selected using a random matching mechanism to conduct security reviews, thereby obtaining random approval prediction results.
[0143] By integrating the output layer, the approval prediction results of each election node and the random approval prediction results are dynamically integrated to obtain the review results of the target object.
[0144] The integration mechanism used in the dynamic integration process is based on dynamic feedback and evaluation of the integration results in the previous cycle.
[0145] Further optionally, the inspection unit, through a group election layer, inputs the features to be reviewed into a navigation module within the group election layer, and the navigation module routes the input to different election nodes, allowing each election node to process the features to be reviewed separately, thereby obtaining the approval prediction results of each election node. This is configured as follows:
[0146] The navigation module identifies the attributes of the target object based on the features to be examined; and
[0147] Based on the attribute recognition results, multiple routing paths corresponding to the target object are determined, and the features to be reviewed are routed to different election nodes according to the multiple routing paths;
[0148] Each election node performs security approval on the features to be reviewed according to its own adaptive evaluation mechanism to obtain the approval prediction results of each election node.
[0149] Each election node has its own corresponding adaptive evaluation mechanism; each adaptive evaluation mechanism has specific dynamic evaluation parameters and predictive evaluation methods.
[0150] Further optionally, the inspection unit, through each election node, performs security approval on the feature to be reviewed according to its respective adaptive evaluation mechanism to obtain the approval prediction result of each election node, and is configured as follows:
[0151] The received device file features are statically and dynamically analyzed by the file analysis node to obtain a first predictive approval result; the first predictive approval result is used to indicate whether the experimental device file of the target object contains potential security risks.
[0152] Through the software evaluation node, the version information and permission settings in the received device software features are adaptively predicted to obtain a second prediction approval result; the second prediction approval result is used to indicate the security of the experimental device software of the target object.
[0153] Through the parameter review node, based on the characteristics of the received experimental parameters, an adaptive verification analysis is performed on the legality and completeness of the parameters to obtain a third predictive approval result; the third predictive approval result is used to indicate whether the experimental equipment parameters of the target object meet the safety requirements.
[0154] Alternatively, the approval prediction results of each election node may take at least one of the following forms: binary form, multi-dimensional form, or fractional form.
[0155] Further optionally, the first predicted approval result is in a binary form, the second predicted approval result is in a multivariate form, and the third predicted approval result is in a fractional form; the third predicted approval result is a safety confidence score of the equipment parameters.
[0156] Further optionally, the inspection unit is also configured to: perform security approval on the feature to be reviewed through each election node according to its own adaptive evaluation mechanism, and after obtaining the approval prediction results of each election node, optimize and adjust the adaptive parameters in each election node through the parameter adjustment layer to improve the approval prediction performance of each election node.
[0157] Further optionally, the inspection unit, through a parameter adjustment layer, optimizes and adjusts the adaptive parameters in each election node to improve the approval prediction performance of each election node, and is configured as follows:
[0158] For the file analysis node, static analysis parameters are dynamically adjusted based on the type information, file size information, and file data structure characteristics contained in the device file features to improve the static analysis effect for different types of files; and,
[0159] Based on the real-time operating characteristics of the experimental equipment and the changing features of file behavior, dynamically adjust the dynamic analysis parameters.
[0160] For software evaluation stages, the parameters of the version information prediction model are adjusted based on the software type, release cycle, and update frequency to adapt to the version change characteristics of different software.
[0161] Based on the software's permission structure and security policy, adjust the parameters of the permission setting prediction model to improve the accuracy of predictions for different permission settings.
[0162] For parameter review nodes, the parameters of the legality verification model are adjusted according to the type, range, and constraints of the experimental parameters to ensure the accuracy of legality checks for different types of parameters.
[0163] Based on the changing patterns of experimental parameters and historical data, the parameters of the integrity verification model are adjusted to adapt to the changing needs of parameter integrity analysis.
[0164] In this embodiment, an automated initial security check of device data is achieved through a security detection model. Then, combined with routing and sorting, the device data is pushed to different approval channels for further security checks, which greatly reduces the workload of security detection.
[0165] In another embodiment of this application, an intelligent computing platform is also provided, including: a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;
[0166] Memory, used to store computer programs;
[0167] When a processor executes a program stored in memory, it implements the security inspection method based on a distributed experimental device as described in the method embodiment.
[0168] The communication bus 1140 mentioned in the above electronic device can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus 1140 can be divided into an address bus, a data bus, a control bus, etc.
[0169] This application provides a security check method for constructing a low-power computing unit based on a distributed experimental device.
[0170] For ease of representation, Figure 3 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0171] The communication interface 1120 is used for communication between the above-mentioned electronic device and other devices.
[0172] The memory 1130 may include random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.
[0173] The aforementioned processor 1110 can be a general-purpose processor, including artificial intelligence processors, graphics processing units (GPUs), machine learning units (MLUs), central processing units (CPUs), network processors (NPs), etc.; it can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0174] Accordingly, embodiments of this application also provide a computer-readable storage medium storing a computer program, which, when executed, can implement the steps that can be performed by an electronic device in the above method embodiments.
Claims
1. A security inspection method based on distributed experimental equipment, characterized in that, An application is made in a distributed experimental equipment management and control system, which is used to operate and manage experimental equipment, including different types of equipment; the security inspection method based on distributed experimental equipment includes: In response to the receiving instruction for the target object in the distributed experimental equipment management system, the system obtains the review information of the target object and sets the target object to a pending inspection state; the target object includes at least one of the following: experimental equipment files, experimental equipment software, and experimental parameters; The information to be reviewed of the target object is input into the security detection model to perform a security review on the target object, thereby obtaining the review result of the target object; Based on the review results of the target object, the target object is set to a corresponding candidate inspection status; the candidate inspection status includes a security label corresponding to the target object; the security label is associated with the security status and object type of the target object; The information of the target object to be reviewed is pushed to the approval channel that matches the candidate inspection status, and the security approval of the target object is performed. The security detection model includes a group election layer. Through the group election layer, the features to be reviewed are input into the navigation module in the group election layer, and the navigation module routes them to different election nodes, so that each election node processes the features to be reviewed to obtain the approval prediction results of each election node. The navigation module identifies the attributes of the target object based on the features to be reviewed; and determines multiple routing paths corresponding to the target object based on the attribute recognition results, and routes the features to be reviewed to different election nodes according to the multiple routing paths.
2. The security inspection method based on distributed experimental equipment according to claim 1, characterized in that, The security detection model includes at least the following structures: a feature extraction layer, a random election layer, and an integrated output layer; The step of inputting the information to be reviewed of the target object into the security detection model to perform a security review on the target object and obtain the review result of the target object includes: The feature extraction layer extracts the features of the target object to be reviewed from the information to be reviewed; the features to be reviewed include at least: device file features, device software features, and experimental parameter features. Through a random election layer, the features to be reviewed are selected using a random matching mechanism to conduct security reviews, thereby obtaining random approval prediction results. By integrating the output layer, the approval prediction results of each election node and the random approval prediction results are dynamically integrated to obtain the review results of the target object. The integration mechanism used in the dynamic integration process is based on dynamic feedback and evaluation of the integration results in the previous cycle.
3. The security inspection method based on distributed experimental equipment according to claim 2, characterized in that, The process involves inputting the features to be reviewed into the navigation module within the group election layer, which then routes them to different election nodes. Each election node processes the features to be reviewed to obtain the approval prediction results for each node. This includes: Each election node performs security approval on the features to be reviewed according to its own adaptive evaluation mechanism to obtain the approval prediction results of each election node. Each election node has its own corresponding adaptive evaluation mechanism; each adaptive evaluation mechanism has specific dynamic evaluation parameters and predictive evaluation methods.
4. The security inspection method based on distributed experimental equipment according to claim 3, characterized in that, The process of conducting security approval of the features to be reviewed through each election node according to its own adaptive evaluation mechanism, to obtain the approval prediction results of each election node, includes: The received device file features are statically and dynamically analyzed by the file analysis node to obtain a first predictive approval result; the first predictive approval result is used to indicate whether the experimental device file of the target object contains potential security risks. Through the software evaluation node, the version information and permission settings in the received device software features are adaptively predicted to obtain a second prediction approval result; the second prediction approval result is used to indicate the security of the experimental device software of the target object. Through the parameter review node, based on the characteristics of the received experimental parameters, an adaptive verification analysis is performed on the legality and completeness of the parameters to obtain a third predictive approval result; the third predictive approval result is used to indicate whether the experimental equipment parameters of the target object meet the safety requirements.
5. The security inspection method based on distributed experimental equipment according to claim 4, characterized in that, The approval prediction results for each election node can take at least one of the following forms: binary form, multi-dimensional form, or fractional form.
6. The security inspection method based on distributed experimental equipment according to claim 5, characterized in that, The first predicted approval result is in binary form, the second predicted approval result is in multivariate form, and the third predicted approval result is in fractional form; The third prediction approval result is the safety confidence score of the equipment parameters.
7. The security inspection method based on distributed experimental equipment according to claim 4, characterized in that, After obtaining the approval prediction results of each election node by conducting security approval of the features to be reviewed through their respective adaptive evaluation mechanisms, the process further includes: The parameter adjustment layer optimizes and adjusts the adaptive parameters in each election node to improve the approval prediction performance of each election node.
8. The security inspection method based on distributed experimental equipment according to claim 7, characterized in that, The parameter adjustment layer optimizes and adjusts the adaptive parameters in each election node to improve the approval prediction performance of each election node, including: For the file analysis node, the static analysis parameters are dynamically adjusted based on the type information, file size information, and file data structure characteristics contained in the device file features to improve the static analysis effect on different types of files; and the dynamic analysis parameters are dynamically adjusted based on the real-time operating characteristics of the experimental equipment and the file behavior change characteristics. For software evaluation stages, the parameters of the version information prediction model are adjusted based on the software type, release cycle, and update frequency to adapt to the version change characteristics of different software; and Based on the software's permission structure and security policy, adjust the parameters of the permission setting prediction model to improve the accuracy of predictions for different permission settings. For parameter review nodes, the parameters of the legality verification model are adjusted according to the type, range, and constraints of the experimental parameters to ensure the accuracy of legality checks for different types of parameters. Based on the changing patterns of experimental parameters and historical data, the parameters of the integrity verification model are adjusted to adapt to the changing needs of parameter integrity analysis.
9. A distributed experimental equipment management and control system, applied to the method of claim 1, characterized in that, The distributed experimental equipment management and control system is used to operate and manage experimental equipment, which includes different types of equipment. The distributed experimental equipment management and control system includes: The acquisition unit is configured to, in response to a receiving instruction for a target object in the distributed experimental equipment management system, acquire the review information of the target object and set the target object to a pending inspection state; the target object includes at least one of the following: experimental equipment files, experimental equipment software, and experimental parameters; The inspection unit is configured to input the information to be reviewed of the target object into the security detection model, perform a security review on the target object, and obtain the review result of the target object; The setting unit is configured to set the target object to a corresponding candidate inspection state based on the inspection result of the target object; the candidate inspection state includes a security label corresponding to the target object; the security label is associated with the security state and object type of the target object; The push unit is configured to push the review information of the target object to the approval channel that matches the candidate inspection status, and perform security approval on the target object.
10. An intelligent computing platform, characterized in that, The intelligent computing platform includes: At least one processor, memory, and input / output unit; The memory is used to store computer programs, the processor is used to call the computer programs stored in the memory to execute the security inspection method based on distributed experimental equipment as described in any one of claims 1 to 8, and the input / output unit is used to receive user input and display the output information of the computer programs stored in the memory.
Citation Information
Patent Citations
Method and device for managing blockchain nodes and computer readable medium
CN111291060A
Routing information creation method and device and routing information query method and device
CN115665144A