Artificial Intelligence-Based Network Intrusion Detection and Defense Method, System, and Medium
By building an intrusion behavior detection map and a global threat view, combined with artificial intelligence technology, optimized detection strategies and defense strategies are generated, the efficiency and adaptability of existing network intrusion detection systems in complex network attacks is solved, and efficient and accurate network threat prevention and repair are achieved.
Patent Information
- Application Number
- CN202510379449.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-03-28
AI Technical Summary
When facing complex and changing network attacks, existing network intrusion detection systems have low detection efficiency, high false alarm rate, poor adaptability, and lack the ability to predict and respond quickly to new attacks, resulting in poor defense effects.
By integrating a variety of artificial intelligence technologies, an intrusion behavior detection map is built, invasion characteristic information is extracted and attacks is simulated, optimization detection strategies are generated, and defense policies and repair instructions are generated in combination with the global threat view and policy library to achieve accurate identification, rapid response and comprehensive defense of network threats.
It significantly improves the intelligence level and response efficiency of network intrusion detection, can accurately extract intrusion characteristics, dynamically adjust detection strategies, grasp network threat situations in real time, and provide an integrated solution from detection to repair, suitable for large-scale network environments.
Smart Images

Figure CN119892520B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of artificial intelligence and big data technologies. Specifically, it relates to a network intrusion detection and prevention method, system, and medium based on artificial intelligence. Background Art
[0002] Network security issues are becoming increasingly severe, and network intrusion incidents occur frequently, posing a serious threat to security. Traditional network intrusion detection systems rely on rule matching and feature recognition technologies. When facing complex and ever-changing network attacks, they have problems such as low detection efficiency, high false alarm rate, and poor adaptability. In addition, traditional defense mechanisms lack the ability to predict new attacks and respond quickly, resulting in poor defense effects.
[0003] In recent years, artificial intelligence technologies have provided new ideas for network intrusion detection. Through technologies such as machine learning and deep learning, network traffic, user behavior, and system logs can be analyzed more efficiently to identify potential intrusion behaviors. However, existing artificial intelligence-based detection systems have limitations, such as insufficient ability to identify unknown attacks, inaccurate feature extraction, and limited adaptability to large-scale network environments.
[0004] Therefore, developing a network intrusion detection and prevention method and system based on artificial intelligence that can detect and defend against various intrusion behaviors in real time and accurately and has the ability of self-learning and optimization has become an important research direction in the current network security field. This application aims to solve the deficiencies of the existing technology and improve the network security protection level. Summary of the Invention
[0005] The purpose of this application is to provide a network intrusion detection and prevention method, system, and medium based on artificial intelligence. By integrating a variety of artificial intelligence technologies, the intelligent level and response efficiency of network intrusion detection are significantly improved. The method first collects network traffic data, user behavior data, and system log data within a preset time period through an intrusion detection and prevention system to construct an intrusion behavior detection map; then, extracts intrusion feature information from the map, uses a preset adversarial network model to perform simulated attacks, and obtains simulated attack results; then, generates an optimized detection strategy according to the simulated attack results and applies it to the intrusion behavior detection map to achieve detection optimization. In addition, monitoring information is obtained from multiple edge nodes, traffic anomaly data is extracted and a global threat view is generated; finally, according to the global threat view, defense strategies and repair instructions are obtained through a preset policy library and repair instruction library respectively to achieve comprehensive network intrusion prevention and repair.
[0006] The first aspect of this application provides a network intrusion detection and prevention method based on artificial intelligence, including the following steps:
[0007] Obtain network traffic data, user behavior data, and system log data for a preset time period according to the intrusion detection and prevention system, and construct an intrusion behavior detection graph;
[0008] Extract intrusion feature information according to the intrusion behavior detection graph, perform a simulated attack through a preset adversarial network model, and obtain a simulated attack result;
[0009] Generate an optimized detection strategy according to the simulated attack result and input it into the intrusion behavior detection graph for detection optimization;
[0010] Obtain monitoring information of multiple edge nodes according to the intrusion detection and prevention system, extract traffic anomaly data for marking, and generate a global threat view;
[0011] Obtain a defense strategy through a preset policy library according to the global threat view, and obtain a repair instruction through a preset repair instruction library.
[0012] Among them, in the network intrusion detection and prevention method based on artificial intelligence described in this application, the obtaining network traffic data, user behavior data, and system log data for a preset time period according to the intrusion detection and prevention system and constructing an intrusion behavior detection graph is specifically as follows:
[0013] Obtain network traffic data, user behavior data, and system log data for a preset time period according to the intrusion detection and prevention system, and construct an intrusion behavior detection graph;
[0014] The network traffic data includes packet header information, packet payload content, and traffic statistics information;
[0015] The user behavior data includes user login information, operation record information, and permission change record information;
[0016] The system log data includes system event logs, security event logs, and system error logs.
[0017] Among them, in the network intrusion detection and prevention method based on artificial intelligence described in this application, the extracting intrusion feature information according to the intrusion behavior detection graph, performing a simulated attack through a preset adversarial network model, and obtaining a simulated attack result is specifically as follows:
[0018] Extract intrusion feature information according to the intrusion behavior detection graph, and the intrusion feature information includes network traffic patterns, user behavior anomaly indicators, and system log anomaly information;
[0019] Perform a simulated attack through a preset adversarial network model according to the network traffic patterns, user behavior anomaly indicators, and system log anomaly information, and obtain a simulated attack result;
[0020] The simulated attack results include detection success rate, network attack type, and detection response time.
[0021] Among them, in the network intrusion detection and prevention method based on artificial intelligence described in this application, the generating an optimized detection strategy according to the simulated attack results and inputting the optimized detection strategy into the intrusion behavior detection map for detection optimization is specifically as follows:
[0022] Generate an optimized detection strategy according to the simulated attack results, and the optimized detection strategy includes detection threshold adjustment information, detection rule change information, and feature extraction improvement information;
[0023] Input the detection threshold adjustment information, detection rule change information, and feature extraction improvement information into the intrusion behavior detection map for detection optimization.
[0024] Among them, in the network intrusion detection and prevention method based on artificial intelligence described in this application, the obtaining multiple edge node monitoring information according to the intrusion detection and prevention system, extracting traffic anomaly data for marking and generating a global threat view is specifically as follows:
[0025] Obtain multiple edge node monitoring information according to the intrusion detection and prevention system;
[0026] Extract traffic anomaly data according to the multiple edge node monitoring information, and the traffic anomaly data includes data transmission volume mutation information, heterogeneous port access information, and unknown protocol usage information;
[0027] Mark the data transmission volume mutation information, heterogeneous port access information, and unknown protocol usage information and generate a global threat view;
[0028] The global threat view includes a dynamic traffic map, an attack frequency chart, and a threat area distribution map.
[0029] Among them, in the network intrusion detection and prevention method based on artificial intelligence described in this application, the obtaining a defense strategy according to the global threat view through a preset policy library is specifically as follows:
[0030] Extract threat type information, attack source information, attack intention information, and attack impact information according to the global threat view;
[0031] Obtain a defense strategy according to the threat type information, attack source information, attack intention information, and attack impact information through a preset policy library;
[0032] The defense strategy includes access restriction, vulnerability management information, network log analysis, and emergency response information.
[0033] Among them, in the network intrusion detection and prevention method based on artificial intelligence described in this application, the obtaining of the repair instruction is specifically as follows:
[0034] Extract damaged system information, system vulnerability distribution information, attack impact range information, and historical repair record information according to the global threat view;
[0035] Obtain a repair instruction through a preset repair instruction library according to the damaged system information, system vulnerability distribution information, attack impact range information, and historical repair record information;
[0036] The repair instruction includes damaged system isolation information, vulnerability repair information, data recovery information, and security reinforcement information.
[0037] The second aspect of this application provides a network intrusion detection and prevention system based on artificial intelligence. The system includes: a memory and a processor. The memory includes a program of the network intrusion detection and prevention method based on artificial intelligence. When the program of the network intrusion detection and prevention method based on artificial intelligence is executed by the processor, the following steps are implemented:
[0038] Obtain network traffic data, user behavior data, and system log data for a preset time period according to the intrusion detection and prevention system and construct an intrusion behavior detection graph;
[0039] Extract intrusion feature information according to the intrusion behavior detection graph, perform a simulated attack through a preset adversarial network model, and obtain a simulated attack result;
[0040] Generate an optimized detection strategy according to the simulated attack result and input it into the intrusion behavior detection graph for detection optimization;
[0041] Obtain monitoring information of multiple edge nodes according to the intrusion detection and prevention system, extract traffic anomaly data for marking, and generate a global threat view;
[0042] Obtain a defense strategy through a preset strategy library according to the global threat view, and obtain a repair instruction through a preset repair instruction library.
[0043] Among them, in the network intrusion detection and prevention system based on artificial intelligence described in this application, the obtaining of network traffic data, user behavior data, and system log data for a preset time period according to the intrusion detection and prevention system and constructing an intrusion behavior detection graph is specifically as follows:
[0044] Obtain network traffic data, user behavior data, and system log data for a preset time period according to the intrusion detection and prevention system and construct an intrusion behavior detection graph;
[0045] The network traffic data includes packet header information, packet payload content, and traffic statistics information;
[0046] The user behavior data includes user login information, operation record information, and privilege change record information;
[0047] The system log data includes system event logs, security event logs, and system error logs.
[0048] The third aspect of this application also provides a computer-readable storage medium, which includes a program for the network intrusion detection and prevention method based on artificial intelligence. When the program for the network intrusion detection and prevention method based on artificial intelligence is executed by a processor, the steps of the network intrusion detection and prevention method based on artificial intelligence as described above are implemented.
[0049] As can be seen from the above, the network intrusion detection and prevention method, system, and medium provided by the embodiments of this application significantly improve the intelligent level and response efficiency of network intrusion detection by integrating various artificial intelligence technologies. This method first collects network traffic data, user behavior data, and system log data within a preset time period through an intrusion detection and prevention system to construct an intrusion behavior detection map; then, extracts intrusion feature information from the map, uses a preset adversarial network model to perform simulated attacks, and obtains simulated attack results; then, generates an optimized detection strategy based on the simulated attack results and applies it to the intrusion behavior detection map to achieve detection optimization. In addition, monitoring information is obtained from multiple edge nodes, traffic anomaly data is extracted and a global threat view is generated; finally, according to the global threat view, a defense strategy and a repair instruction are obtained through a preset policy library and a repair instruction library respectively to achieve comprehensive network intrusion prevention and repair. The core advantages of this application are: accurately extracting intrusion features through artificial intelligence technology to improve detection efficiency and accuracy; dynamically adjusting the detection strategy based on the simulated attack results to enhance the system's adaptability to new attacks; mastering the network threat situation in real time through the global threat view to achieve rapid response; combining the defense strategy and the repair instruction to provide an integrated solution from detection to repair. This application is applicable to large-scale network environments, can effectively cope with complex and changeable network attacks, and provides strong technical support for network security.
[0050] Other features and advantages of this application will be described in the subsequent specification, and some of them will become obvious from the specification or be understood by implementing the embodiments of this application. The objectives and other advantages of this application can be achieved and obtained through the specification and the drawings. Brief Description of the Drawings
[0051] To more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the accompanying drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0052] Figure 1 Flowchart of the network intrusion detection and prevention method based on artificial intelligence provided by the embodiments of the present application;
[0053] Figure 2 Flowchart of obtaining simulated attack results of the network intrusion detection and prevention method based on artificial intelligence provided by the embodiments of the present application;
[0054] Figure 3 Flowchart of detecting and optimizing the network intrusion detection and prevention method based on artificial intelligence provided by the embodiments of the present application;
[0055] Figure 4 Flowchart of generating a global threat view of the network intrusion detection and prevention method based on artificial intelligence provided by the embodiments of the present application. Detailed implementation manners
[0056] The following will clearly and completely describe the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all embodiments. The components of the embodiments of the present application usually described and shown in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the claimed present application, but only represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.
[0057] It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, terms such as "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance. It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions.
[0058] Please refer to Figure 1 , which is the flowchart of the network intrusion detection and prevention method based on artificial intelligence in this application. This method is used in terminal devices, such as computers, mobile phone terminals, etc. This method includes the following steps:
[0059] S101. Obtain network traffic data, user behavior data, and system log data for a preset time period according to the intrusion detection and prevention system, and construct an intrusion behavior detection graph;
[0060] S102. Extract intrusion feature information according to the intrusion behavior detection graph, perform a simulated attack through a preset adversarial network model, and obtain a simulated attack result;
[0061] S103. Generate an optimized detection strategy according to the simulated attack result and input it into the intrusion behavior detection graph for detection optimization;
[0062] S104. Obtain monitoring information of multiple edge nodes according to the intrusion detection and prevention system, extract traffic anomaly data for marking, and generate a global threat view;
[0063] S105. Obtain a defense strategy through a preset policy library according to the global threat view, and obtain a repair instruction through a preset repair instruction library.
[0064] Among them, first, by obtaining network traffic data, user behavior data, and system log data within a preset time period, an intrusion behavior detection graph is constructed to comprehensively reflect potential threats in the network. Then, intrusion feature information is extracted from the intrusion behavior detection graph, and a preset adversarial network model is used to perform a simulated attack to generate a simulated attack result for evaluating the effectiveness of the current detection strategy. Subsequently, an optimized detection strategy is generated according to the simulated attack result and fed back into the intrusion behavior detection graph to achieve dynamic optimization of the detection ability. In addition, monitoring information is obtained from multiple edge nodes, traffic anomaly data is extracted and marked to generate a global threat view to comprehensively grasp the security situation in the network. Finally, according to the global threat view, combined with a preset policy library and a repair instruction library, a defense strategy and a repair instruction are generated respectively, so as to achieve a rapid response and repair to network threats. This process improves the accuracy and efficiency of intrusion detection and prevention through data-driven and intelligent analysis.
[0065] According to the embodiments of the present application, obtaining network traffic data, user behavior data, and system log data for a preset time period according to an intrusion detection and prevention system and constructing an intrusion behavior detection graph specifically includes: obtaining network traffic data, user behavior data, and system log data for a preset time period according to the intrusion detection and prevention system and constructing an intrusion behavior detection graph; the network traffic data includes packet header information, packet payload content, and traffic statistics information; the user behavior data includes user login information, operation record information, and permission change record information; the system log data includes system event logs, security event logs, and system error logs.
[0066] Among them, the core of the above technology of the present application lies in constructing an intrusion behavior detection graph by comprehensively collecting and analyzing network traffic data, user behavior data, and system log data to achieve accurate identification and defense of network threats. Specifically, the network traffic data includes packet header information, packet payload content, and traffic statistics information, which is used to monitor abnormal behaviors in network communication; the user behavior data includes user login information, operation record information, and permission change record information, which is used to analyze the potential risks of user activities; the system log data includes system event logs, security event logs, and system error logs, which are used to identify security events and abnormal states at the system level. By integrating these multi-dimensional data, a dynamic intrusion behavior detection graph can be constructed, thereby achieving comprehensive perception and correlation analysis of complex intrusion behaviors. The innovation of this technical solution lies in improving the accuracy and efficiency of intrusion detection through multi-source data fusion and intelligent analysis, while providing data-driven decision support for network security defense. This solution can be applied to the field of network security and has high practical value and market prospects.
[0067] Please refer to Figure 2 , which is a flowchart of obtaining simulation attack results for the network intrusion detection and prevention method based on artificial intelligence in some embodiments of the present application. According to the embodiments of the present application, extracting intrusion feature information according to the intrusion behavior detection graph, performing a simulation attack through a preset adversarial network model and obtaining a simulation attack result specifically includes: S201, extracting intrusion feature information according to the intrusion behavior detection graph, where the intrusion feature information includes network traffic patterns, user behavior anomaly indicators, and system log anomaly information; S202, performing a simulation attack through the preset adversarial network model according to the network traffic patterns, user behavior anomaly indicators, and system log anomaly information and obtaining a simulation attack result; S203, the simulation attack result includes a detection success rate, a network attack type, and a detection response time.
[0068] Among them, the core of the above technology of this application lies in extracting intrusion feature information and using an adversarial network model to conduct simulated attacks to evaluate and optimize the performance of the intrusion detection system. Specifically, the system first extracts intrusion feature information from the intrusion behavior detection map. The intrusion feature information includes network traffic patterns (such as abnormal traffic features), user behavior anomaly indicators (such as abnormal login or operation behaviors), and system log anomaly information (such as security events or error logs). These feature information provide a data basis for subsequent simulated attacks. Then, through a preset adversarial network model, based on the network traffic pattern, user behavior anomaly indicator, and system log anomaly information, a simulated attack is conducted to generate a simulated attack result. The simulated attack result includes the detection success rate (i.e., the system's ability to identify attacks), the type of network attack (such as DDoS attack, malware attack, etc.), and the detection response time (i.e., the time from when the system discovers an attack to when it responds). The innovation of this technical solution lies in that through simulated attack tests, the performance of the intrusion detection system can be comprehensively evaluated and data support can be provided for system optimization. This solution can be applied to the fields of network security testing and defense, and has high practical value and market prospects.
[0069] Please refer to Figure 3 , which is a flowchart for detecting and optimizing the artificial intelligence-based network intrusion detection and defense method in some embodiments of this application. According to the embodiments of this application, an optimized detection strategy is generated based on the simulated attack result and input into the intrusion behavior detection map for detection optimization. Specifically: S301, generating an optimized detection strategy based on the simulated attack result. The optimized detection strategy includes detection threshold adjustment information, detection rule change information, and feature extraction improvement information; S302, inputting the detection threshold adjustment information, detection rule change information, and feature extraction improvement information into the intrusion behavior detection map for detection optimization.
[0070] Among them, an optimized detection strategy is generated by analyzing the simulated attack result, and the intrusion behavior detection map is dynamically adjusted to improve the detection accuracy and response efficiency of the system. Specifically, the system generates an optimized detection strategy based on the simulated attack result (including the detection success rate, the type of network attack, and the detection response time). The optimized detection strategy includes detection threshold adjustment information (such as adjusting the determination threshold of abnormal traffic), detection rule change information (such as updating or adding detection rules), and feature extraction improvement information (such as optimizing the feature extraction algorithm or adding new feature dimensions). Subsequently, the detection threshold adjustment information, detection rule change information, and feature extraction improvement information are input into the intrusion behavior detection map to achieve dynamic optimization of the intrusion behavior detection map. The innovation of this technical solution lies in that through the feedback mechanism of the simulated attack result, the detection strategy can be intelligently adjusted, thereby continuously improving the detection ability and adaptability of the system.
[0071] Exemplarily, Figure 4It is a flowchart for generating a global threat view of an AI-based network intrusion detection and prevention method in some embodiments of the present application. According to the embodiments of the present application, obtaining monitoring information of multiple edge nodes by the intrusion detection and prevention system, extracting traffic anomaly data for marking and generating a global threat view specifically includes: S401, obtaining monitoring information of multiple edge nodes by the intrusion detection and prevention system; S402, extracting traffic anomaly data according to the monitoring information of multiple edge nodes, where the traffic anomaly data includes data transmission volume mutation information, heterogeneous port access information, and unknown protocol usage information; S403, marking the data transmission volume mutation information, heterogeneous port access information, and unknown protocol usage information and generating a global threat view; S404, the global threat view includes a dynamic traffic map, an attack frequency chart, and a threat area distribution map.
[0072] Among them, by collecting and analyzing the monitoring information of multiple edge nodes, traffic anomaly data is extracted and a global threat view is generated to achieve a comprehensive perception and visual display of network threats. Specifically, first, obtain the monitoring information of multiple edge nodes by the intrusion detection and prevention system, including data such as network traffic, port access records, and protocol usage. Then, extract traffic anomaly data from the monitoring information of multiple edge nodes. The traffic anomaly data includes data transmission volume mutation information (such as a sudden increase or decrease in traffic), heterogeneous port access information (such as access behavior to non-common ports), and unknown protocol usage information (such as the use of non-standard protocols). Subsequently, mark the data transmission volume mutation information, heterogeneous port access information, and unknown protocol usage information and generate a global threat view. The global threat view includes a dynamic traffic map (real-time display of network traffic changes), an attack frequency chart (statistics of the frequency and trend of attack events), and a threat area distribution map (identifying the geographical location or network area of the threat source). The innovation of this technical solution lies in the distributed monitoring of edge nodes and the generation of a global threat view, which can achieve real-time perception, accurate positioning, and visual analysis of network threats, thereby providing comprehensive decision-making support for network security defense.
[0073] According to the embodiments of the present application, obtaining a defense strategy through a preset policy library according to the global threat view specifically includes: extracting threat type information, attack source information, attack intention information, and attack-affected information according to the global threat view; obtaining a defense strategy through the preset policy library according to the threat type information, attack source information, attack intention information, and attack-affected information; the defense strategy includes access restrictions, vulnerability management information, network log analysis, and emergency response information.
[0074] Among them, by analyzing the threat information in the global threat view and combining with a preset policy library, targeted defense policies are generated to achieve rapid response and effective defense against network threats. Specifically, first, threat type information (such as DDoS attacks, malware attacks, etc.), attack source information (such as the IP address or geographical location of the attacker), attack intention information (such as data theft, system destruction, etc.), and attack impact information (such as the affected systems or services) are extracted from the global threat view. Then, according to the threat type information, attack source information, attack intention information, and attack impact information, corresponding defense policies are matched and generated through the preset policy library. The defense policies include access restrictions (such as blocking the attack source IP or restricting access to specific ports), vulnerability management information (such as fixing known vulnerabilities or updating patches), network log analysis (such as deeply analyzing logs to trace the attack path), and emergency response information (such as starting an emergency plan or isolating the infected system). The innovation of this technical solution lies in that through the in-depth analysis of the global threat view and the intelligent matching of the policy library, accurate defense policies can be quickly generated, thereby improving the efficiency and effectiveness of network security defense.
[0075] According to the embodiment of the present application, obtaining the repair instruction specifically includes: extracting damaged system information, system vulnerability distribution information, attack impact range information, and historical repair record information according to the global threat view; obtaining the repair instruction through a preset repair instruction library according to the damaged system information, system vulnerability distribution information, attack impact range information, and historical repair record information; the repair instruction includes damaged system isolation information, vulnerability repair information, data recovery information, and security reinforcement information.
[0076] Among them, by analyzing the damaged information and vulnerability distribution in the global threat view and combining with a preset repair instruction library, targeted repair instructions are generated to achieve rapid repair and security reinforcement of the damaged system. Specifically, first, damaged system information (such as the servers or terminal devices affected by the attack), system vulnerability distribution information (such as known or unknown vulnerabilities existing in the system), attack impact range information (such as the network area or business function affected by the attack), and historical repair record information (such as the records and effects of previous repair operations) are extracted from the global threat view. Then, according to the damaged system information, system vulnerability distribution information, attack impact range information, and historical repair record information, corresponding repair instructions are matched and generated through the preset repair instruction library. The repair instruction includes damaged system isolation information (such as isolating the attacked system from the network to prevent further spread), vulnerability repair information (such as patching vulnerabilities or updating patches), data recovery information (such as recovering damaged data from backups), and security reinforcement information (such as strengthening system configuration or deploying additional security protection measures). The innovation of this technical solution lies in that through the in-depth analysis of the global threat view and the intelligent matching of the repair instruction library, accurate repair instructions can be quickly generated, thereby improving the efficiency and security of system repair.
[0077] According to an embodiment of the present application, it further includes: obtaining detection optimization information for a preset time period, and extracting detection rate data, false alarm rate data, missed alarm rate data, and response time; processing the detection rate data, false alarm rate data, missed alarm rate data, and response time through a preset optimization success rate evaluation model to obtain an optimization success rate index; comparing the optimization success rate index with a preset success rate index threshold; if the optimization success rate index is greater than or equal to the preset success rate index threshold, sending an optimization success message; if the optimization success rate index is less than the preset success rate index threshold, sending an optimization failure message; the calculation formula of the preset optimization success rate evaluation model is:
[0078] 。
[0079] Among them, is the optimization success rate index, are the detection rate data, false alarm rate data, missed alarm rate data, and response time respectively, is a preset feature coefficient (the feature coefficient is obtained by querying a preset optimization detection database).
[0080] Among them, in order to evaluate the optimization effect of the detection strategy, it is first necessary to obtain the detection optimization information within a preset time period, including data such as the detection rate, false alarm rate, missed alarm rate, and response time. These data will be input into a preset optimization success rate evaluation model, and through model processing, an optimization success rate index will be generated. This index comprehensively reflects the performance improvement of the detection system. Next, the optimization success rate index will be compared with a preset success rate index threshold: if the optimization success rate index is greater than or equal to the threshold, it means that the optimization has achieved the expected goal, and the system will send an optimization success message; if the optimization success rate index is less than the threshold, it means that the optimization has not achieved the expected goal, and the system will send an optimization failure message. This process can intuitively judge the optimization effect of the detection strategy through automated evaluation and quantitative indicators, and provide clear feedback for subsequent improvements, so as to continuously improve the accuracy and efficiency of the detection system.
[0081] The present application also discloses an artificial intelligence-based network intrusion detection and prevention system, including a memory and a processor. The memory includes an artificial intelligence-based network intrusion detection and prevention method program. When the artificial intelligence-based network intrusion detection and prevention method program is executed by the processor, the following steps are implemented: obtaining network traffic data, user behavior data, and system log data for a preset time period according to the intrusion detection and prevention system, and constructing an intrusion behavior detection graph; extracting intrusion feature information from the intrusion behavior detection graph, performing a simulated attack through a preset adversarial network model, and obtaining a simulated attack result; generating an optimized detection strategy according to the simulated attack result and inputting it into the intrusion behavior detection graph for detection optimization; obtaining monitoring information of multiple edge nodes according to the intrusion detection and prevention system, extracting traffic anomaly data for marking, and generating a global threat view; obtaining a defense strategy through a preset policy library according to the global threat view, and obtaining a repair instruction through a preset repair instruction library.
[0082] Among them, first, by obtaining network traffic data, user behavior data, and system log data within a preset time period, an intrusion behavior detection graph is constructed to comprehensively reflect potential threats in the network. Then, intrusion feature information is extracted from the intrusion behavior detection graph, and a preset adversarial network model is used to perform a simulated attack to generate a simulated attack result for evaluating the effectiveness of the current detection strategy. Subsequently, an optimized detection strategy is generated according to the simulated attack result and fed back into the intrusion behavior detection graph to achieve dynamic optimization of the detection ability. In addition, monitoring information is obtained from multiple edge nodes, traffic anomaly data is extracted and marked to generate a global threat view to comprehensively grasp the security situation in the network. Finally, according to the global threat view, combined with a preset policy library and a repair instruction library, a defense strategy and a repair instruction are respectively generated, so as to achieve a rapid response and repair to network threats. This process improves the accuracy and efficiency of intrusion detection and prevention through data-driven and intelligent analysis.
[0083] According to an embodiment of the present application, obtaining network traffic data, user behavior data, and system log data for a preset time period according to the intrusion detection and prevention system and constructing an intrusion behavior detection graph specifically includes: obtaining network traffic data, user behavior data, and system log data for a preset time period according to the intrusion detection and prevention system and constructing an intrusion behavior detection graph; the network traffic data includes packet header information, packet payload content, and traffic statistics information; the user behavior data includes user login information, operation record information, and permission change record information; the system log data includes system event logs, security event logs, and system error logs.
[0084] Among them, the core of the above technology of this application lies in constructing an intrusion behavior detection map by comprehensively collecting and analyzing network traffic data, user behavior data, and system log data to achieve accurate identification and defense of network threats. Specifically, the network traffic data includes packet header information, packet payload content, and traffic statistics information, which are used to monitor abnormal behaviors in network communications; the user behavior data includes user login information, operation record information, and permission change record information, which are used to analyze potential risks of user activities; the system log data includes system event logs, security event logs, and system error logs, which are used to identify security events and abnormal states at the system level. By integrating these multi-dimensional data, a dynamic intrusion behavior detection map can be constructed, thereby achieving comprehensive perception and correlation analysis of complex intrusion behaviors. The innovation of this technical solution lies in improving the accuracy and efficiency of intrusion detection through multi-source data fusion and intelligent analysis, and at the same time providing data-driven decision support for network security defense. This solution can be applied to the field of network security and has high practical value and market prospects.
[0085] According to an embodiment of the present application, extracting intrusion feature information according to the intrusion behavior detection map, and performing a simulated attack through a preset adversarial network model to obtain a simulated attack result, specifically:
[0086] Extract intrusion feature information according to the intrusion behavior detection map, where the intrusion feature information includes network traffic patterns, user behavior anomaly indicators, and system log anomaly information;
[0087] Perform a simulated attack through a preset adversarial network model according to the network traffic patterns, user behavior anomaly indicators, and system log anomaly information, and obtain a simulated attack result;
[0088] The simulated attack result includes the detection success rate, network attack type, and detection response time.
[0089] Among them, the core of the above technology of this application lies in extracting intrusion feature information and using an adversarial network model to conduct simulated attacks to evaluate and optimize the performance of the intrusion detection system. Specifically, the system first extracts intrusion feature information from the intrusion behavior detection map. This intrusion feature information includes network traffic patterns (such as abnormal traffic characteristics), user behavior anomaly metrics (such as abnormal login or operation behaviors), and system log anomaly information (such as security events or error logs). These feature information provide a data basis for subsequent simulated attacks. Then, through a preset adversarial network model, based on this network traffic pattern, user behavior anomaly metrics, and system log anomaly information, a simulated attack is conducted to generate a simulated attack result. The simulated attack result includes the detection success rate (i.e., the system's ability to identify attacks), the type of network attack (such as DDoS attack, malware attack, etc.), and the detection response time (i.e., the time from when the system discovers an attack to when it responds). The innovation of this technical solution lies in that through simulated attack tests, the performance of the intrusion detection system can be comprehensively evaluated and data support can be provided for system optimization. This solution can be applied to the fields of network security testing and defense, and has high practical value and market prospects.
[0090] According to an embodiment of this application, an optimized detection strategy is generated based on the simulated attack result and input into the intrusion behavior detection map for detection optimization. Specifically:
[0091] An optimized detection strategy is generated based on the simulated attack result. The optimized detection strategy includes detection threshold adjustment information, detection rule change information, and feature extraction improvement information;
[0092] The detection threshold adjustment information, detection rule change information, and feature extraction improvement information are input into the intrusion behavior detection map for detection optimization.
[0093] Among them, an optimized detection strategy is generated by analyzing the simulated attack result, and the intrusion behavior detection map is dynamically adjusted to improve the detection accuracy and response efficiency of the system. Specifically, the system generates an optimized detection strategy based on the simulated attack result (including the detection success rate, the type of network attack, and the detection response time). The optimized detection strategy includes detection threshold adjustment information (such as adjusting the determination threshold of abnormal traffic), detection rule change information (such as updating or adding detection rules), and feature extraction improvement information (such as optimizing the feature extraction algorithm or adding new feature dimensions). Subsequently, the detection threshold adjustment information, detection rule change information, and feature extraction improvement information are input into the intrusion behavior detection map to achieve dynamic optimization of the intrusion behavior detection map. The innovation of this technical solution lies in that through the feedback mechanism of the simulated attack result, the detection strategy can be intelligently adjusted, thereby continuously improving the detection ability and adaptability of the system.
[0094] According to an embodiment of the present application, multiple edge node monitoring information is obtained according to an intrusion detection and prevention system, and traffic anomaly data is extracted, marked, and a global threat view is generated. Specifically:
[0095] Obtain multiple edge node monitoring information according to the intrusion detection and prevention system;
[0096] Extract traffic anomaly data according to the multiple edge node monitoring information. The traffic anomaly data includes data transmission volume mutation information, heterogeneous port access information, and unknown protocol usage information;
[0097] Mark the data transmission volume mutation information, heterogeneous port access information, and unknown protocol usage information and generate a global threat view;
[0098] The global threat view includes a dynamic traffic map, an attack frequency chart, and a threat area distribution map.
[0099] Among them, by collecting and analyzing the monitoring information of multiple edge nodes, traffic anomaly data is extracted and a global threat view is generated to achieve comprehensive perception and visual display of network threats. Specifically, first, obtain the monitoring information of multiple edge nodes according to the intrusion detection and prevention system, including data such as network traffic, port access records, and protocol usage. Then, extract traffic anomaly data from the multiple edge node monitoring information. The traffic anomaly data includes data transmission volume mutation information (such as a sudden increase or decrease in traffic), heterogeneous port access information (such as access behavior to unusual ports), and unknown protocol usage information (such as the use of non-standard protocols). Subsequently, mark the data transmission volume mutation information, heterogeneous port access information, and unknown protocol usage information and generate a global threat view. The global threat view includes a dynamic traffic map (real-time display of network traffic changes), an attack frequency chart (statistics of the frequency and trend of attack events), and a threat area distribution map (identifying the geographical location or network area of the threat source). The innovation of this technical solution lies in the ability to achieve real-time perception, accurate positioning, and visual analysis of network threats through distributed monitoring of edge nodes and the generation of a global threat view, thereby providing comprehensive decision-making support for network security defense.
[0100] According to an embodiment of the present application, obtaining a defense strategy according to the global threat view through a preset policy library is specifically as follows: Extract threat type information, attack source information, attack intention information, and attack-affected information according to the global threat view; Obtain a defense strategy according to the threat type information, attack source information, attack intention information, and attack-affected information through the preset policy library; The defense strategy includes access restrictions, vulnerability management information, network log analysis, and emergency response information.
[0101] Among them, by analyzing the threat information in the global threat view and combining with a preset policy library, targeted defense policies are generated to achieve rapid response and effective defense against network threats. Specifically, first, threat type information (such as DDoS attacks, malware attacks, etc.), attack source information (such as the attacker's IP address or geographical location), attack intention information (such as data theft, system destruction, etc.), and attack impact information (such as the affected systems or services) are extracted from the global threat view. Then, according to the threat type information, attack source information, attack intention information, and attack impact information, corresponding defense policies are matched and generated through the preset policy library. The defense policies include access restrictions (such as blocking the attack source IP or restricting access to specific ports), vulnerability management information (such as fixing known vulnerabilities or updating patches), network log analysis (such as deeply analyzing logs to trace the attack path), and emergency response information (such as starting an emergency plan or isolating the infected system). The innovation of this technical solution lies in that through in-depth analysis of the global threat view and intelligent matching of the policy library, accurate defense policies can be quickly generated, thereby improving the efficiency and effectiveness of network security defense.
[0102] According to the embodiment of the present application, the obtaining of the repair instruction is specifically as follows: extracting damaged system information, system vulnerability distribution information, attack impact range information, and historical repair record information from the global threat view; obtaining a repair instruction through a preset repair instruction library according to the damaged system information, system vulnerability distribution information, attack impact range information, and historical repair record information; the repair instruction includes damaged system isolation information, vulnerability repair information, data recovery information, and security reinforcement information.
[0103] Among them, by analyzing the damaged information and vulnerability distribution in the global threat view and combining with a preset repair instruction library, targeted repair instructions are generated to achieve rapid repair and security reinforcement of the damaged system. Specifically, first, damaged system information (such as the servers or terminal devices affected by the attack), system vulnerability distribution information (such as known or unknown vulnerabilities existing in the system), attack impact range information (such as the network area or business function affected by the attack), and historical repair record information (such as the records and effects of previous repair operations) are extracted from the global threat view. Then, according to the damaged system information, system vulnerability distribution information, attack impact range information, and historical repair record information, corresponding repair instructions are matched and generated through the preset repair instruction library. The repair instruction includes damaged system isolation information (such as isolating the attacked system from the network to prevent further spread), vulnerability repair information (such as patching vulnerabilities or updating patches), data recovery information (such as recovering damaged data from backups), and security reinforcement information (such as strengthening system configuration or deploying additional security protection measures). The innovation of this technical solution lies in that through in-depth analysis of the global threat view and intelligent matching of the repair instruction library, accurate repair instructions can be quickly generated, thereby improving the efficiency and security of system repair.
[0104] According to an embodiment of the present application, it further includes:
[0105] Obtain detection optimization information for a preset time period, and extract detection rate data, false alarm rate data, missed alarm rate data, and response time;
[0106] Process the detection rate data, false alarm rate data, missed alarm rate data, and response time through a preset optimization success rate evaluation model to obtain an optimization success rate index;
[0107] Compare the optimization success rate index with a preset success rate index threshold;
[0108] If the optimization success rate index is greater than or equal to the preset success rate index threshold, send an optimization success message;
[0109] If the optimization success rate index is less than the preset success rate index threshold, send an optimization failure message;
[0110] The calculation formula of the preset optimization success rate evaluation model is:
[0111] .
[0112] Wherein, is the optimization success rate index, are the detection rate data, false alarm rate data, missed alarm rate data, and response time respectively, is a preset feature coefficient (the feature coefficient is obtained by querying a preset optimization detection database).
[0113] Wherein, in order to evaluate the optimization effect of the detection strategy, it is first necessary to obtain detection optimization information within a preset time period, including data such as detection rate, false alarm rate, missed alarm rate, and response time. These data will be input into a preset optimization success rate evaluation model, and through model processing, an optimization success rate index is generated. This index comprehensively reflects the performance improvement of the detection system. Next, the optimization success rate index is compared with a preset success rate index threshold: if the optimization success rate index is greater than or equal to the threshold, it means that the optimization meets the expected goal, and the system will send an optimization success message; if the optimization success rate index is less than the threshold, it means that the optimization does not meet the expected goal, and the system will send an optimization failure message. This process can intuitively judge the optimization effect of the detection strategy through automated evaluation and quantitative indicators, and provide clear feedback for subsequent improvements, thereby continuously improving the accuracy and efficiency of the detection system.
[0114] The third aspect of the present application provides a computer-readable storage medium, which includes a program for a network intrusion detection and prevention method based on artificial intelligence. When the program for the network intrusion detection and prevention method based on artificial intelligence is executed by a processor, the steps of the foregoing method are implemented.
[0115] The network intrusion detection and prevention method, system and medium based on artificial intelligence disclosed in this application obtain network traffic data, user behavior data and system log data within a preset time period through an intrusion detection and prevention system, and construct an intrusion behavior detection map to comprehensively reflect potential threats in the network. Intrusion feature information is extracted from the intrusion behavior detection map, and the intrusion feature information includes network traffic patterns, user behavior anomaly indicators and system log anomaly information, and a preset adversarial network model is used to perform a simulated attack to generate a simulated attack result (such as detection success rate, network attack type and detection response time), and then an optimized detection strategy (including detection threshold adjustment information, detection rule change information and feature extraction improvement information) is generated according to the simulated attack result and input into the intrusion behavior detection map for detection optimization to improve the detection accuracy and response efficiency of the system. At the same time, by obtaining the monitoring information of multiple edge nodes, traffic anomaly data (such as data transmission volume mutation information, heterogeneous port access information and unknown protocol usage information) is extracted, and a global threat view (including a dynamic traffic map, an attack frequency chart and a threat area distribution map) is generated to achieve comprehensive perception and visual analysis of network threats. Based on the global threat view, a defense strategy (such as access restriction, vulnerability management information, network log analysis and emergency response information) is generated through a preset policy library, and a repair instruction (such as damaged system isolation information, vulnerability repair information, data recovery information and security reinforcement information) is generated through a preset repair instruction library, so as to achieve a rapid response and effective defense against network threats. The innovation of this technical solution lies in realizing the full-chain intelligent network security protection from data collection, threat detection, policy optimization to defense repair through multi-source data fusion, simulated attack testing, global threat view generation and intelligent policy matching.
[0116] In several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined, or can be integrated into another system, or some features can be ignored, or not executed. In addition, the coupling, direct coupling or communication connection between the components shown or discussed with each other can be through some interfaces, and the indirect coupling or communication connection of devices or units can be electrical, mechanical or other forms.
[0117] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units; they may be located in one place or distributed to multiple network units; some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0118] In addition, each functional unit in the embodiments of the present application may all be integrated into one processing unit, or each unit may be separately used as one unit, or two or more units may be integrated into one unit; the above-mentioned integrated unit may be implemented in the form of hardware, or in the form of a combination of hardware and software functional units.
[0119] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a readable storage medium. When the program is executed, it performs the steps including the above method embodiments; and the foregoing storage medium includes: various media such as removable storage devices, read-only memories, random access memories, magnetic disks, or optical disks that can store program codes.
[0120] Alternatively, if the above-mentioned integrated unit of the present application is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a readable storage medium. Based on such an understanding, the technical solution of the embodiments of the present application essentially or the part that contributes to the prior art can be embodied in the form of a software product. The software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in the various embodiments of the present application. And the foregoing storage medium includes: various media such as removable storage devices, ROM, RAM, magnetic disks, or optical disks that can store program codes.
Claims
1. An artificial intelligence-based network intrusion detection and prevention method, characterized in that Including the following steps: Obtain network traffic data, user behavior data, and system log data for a preset time period according to the intrusion detection and prevention system, and construct an intrusion behavior detection map; Extract intrusion feature information according to the intrusion behavior detection map, perform a simulated attack through a preset adversarial network model, and obtain a simulated attack result; Generate an optimized detection strategy according to the simulated attack result and input it into the intrusion behavior detection map for detection optimization; Obtain monitoring information of multiple edge nodes according to the intrusion detection and prevention system, extract traffic anomaly data for marking, and generate a global threat view; Obtain a defense strategy through a preset policy library according to the global threat view, and obtain a repair instruction through a preset repair instruction library; Obtain detection optimization information for a preset time period, and extract detection rate data, false alarm rate data, missed alarm rate data, and response time; Process the detection rate data, false alarm rate data, missed alarm rate data, and response time through a preset optimization success rate evaluation model to obtain an optimization success rate index; compare the optimization success rate index with a preset success rate index threshold; If the optimization success rate index is greater than or equal to the preset success rate index threshold, send an optimization success message; if the optimization success rate index is less than the preset success rate index threshold, send an optimization failure message; Among them, the generating an optimized detection strategy according to the simulated attack result and inputting it into the intrusion behavior detection map for detection optimization is specifically: Generate an optimized detection strategy according to the simulated attack result, and the optimized detection strategy includes detection threshold adjustment information, detection rule change information, and feature extraction improvement information; Input the detection threshold adjustment information, detection rule change information, and feature extraction improvement information into the intrusion behavior detection map for detection optimization; The obtaining monitoring information of multiple edge nodes according to the intrusion detection and prevention system, extracting traffic anomaly data for marking, and generating a global threat view is specifically: Obtain monitoring information of multiple edge nodes according to the intrusion detection and prevention system; Extract traffic anomaly data according to the monitoring information of the multiple edge nodes, and the traffic anomaly data includes data transmission volume mutation information, heterogeneous port access information, and unknown protocol usage information; Mark the data transmission volume mutation information, heterogeneous port access information, and unknown protocol usage information and generate a global threat view; The global threat view includes a dynamic traffic map, an attack frequency chart, and a threat area distribution map.
2. The network intrusion detection and prevention method based on artificial intelligence according to claim 1, wherein, The obtaining network traffic data, user behavior data, and system log data for a preset time period according to the intrusion detection and prevention system, and constructing an intrusion behavior detection map is specifically: Obtain network traffic data, user behavior data, and system log data for a preset time period according to the intrusion detection and prevention system, and construct an intrusion behavior detection map; The network traffic data includes packet header information, packet payload content, and traffic statistics information; The user behavior data includes user login information, operation record information, and permission change record information; The system log data includes system event logs, security event logs, and system error logs.
3. The network intrusion detection and prevention method based on artificial intelligence according to claim 2, characterized in that, Extracting intrusion feature information according to the intrusion behavior detection graph, and performing a simulated attack through a preset adversarial network model to obtain a simulated attack result, specifically: Extracting intrusion feature information according to the intrusion behavior detection graph, where the intrusion feature information includes network traffic patterns, user behavior anomaly metrics, and system log anomaly information; Performing a simulated attack through a preset adversarial network model according to the network traffic patterns, user behavior anomaly metrics, and system log anomaly information, and obtaining a simulated attack result; The simulated attack result includes the detection success rate, network attack type, and detection response time.
4. The network intrusion detection and prevention method based on artificial intelligence according to claim 1, wherein, Obtaining a defense strategy according to the global threat view through a preset policy library, specifically: Extracting threat type information, attack source information, attack intention information, and attacked impact information according to the global threat view; Obtaining a defense strategy through a preset policy library according to the threat type information, attack source information, attack intention information, and attacked impact information; The defense strategy includes access restrictions, vulnerability management information, network log analysis, and emergency response information.
5. The network intrusion detection and prevention method based on artificial intelligence according to claim 4, characterized in that, Obtaining a repair instruction, specifically: Extracting damaged system information, system vulnerability distribution information, attack impact range information, and historical repair record information according to the global threat view; Obtaining a repair instruction through a preset repair instruction library according to the damaged system information, system vulnerability distribution information, attack impact range information, and historical repair record information; The repair instruction includes damaged system isolation information, vulnerability repair information, data recovery information, and security reinforcement information.
6. An artificial intelligence-based network intrusion detection and prevention system, characterized in that, Including a memory and a processor, where the memory includes a program for the network intrusion detection and defense method based on artificial intelligence. When the program for the network intrusion detection and defense method based on artificial intelligence is executed by the processor, the following steps are implemented: Obtaining network traffic data, user behavior data, and system log data for a preset time period according to the intrusion detection and defense system, and constructing an intrusion behavior detection graph; Extracting intrusion feature information according to the intrusion behavior detection graph, and performing a simulated attack through a preset adversarial network model to obtain a simulated attack result; Generating an optimized detection strategy according to the simulated attack result and inputting it into the intrusion behavior detection graph for detection optimization; Obtaining monitoring information of multiple edge nodes according to the intrusion detection and defense system, extracting traffic anomaly data for marking, and generating a global threat view; Obtaining a defense strategy according to the global threat view through a preset policy library, and obtaining a repair instruction through a preset repair instruction library; Obtaining detection optimization information for a preset time period, and extracting detection rate data, false alarm rate data, missed alarm rate data, and response time; Processing according to the detection rate data, false alarm rate data, missed alarm rate data, and response time through a preset optimization success rate evaluation model to obtain an optimization success rate index; comparing the optimization success rate index with a preset success rate index threshold; If the optimization success rate index is greater than or equal to the preset success rate index threshold, sending an optimization success message; if the optimization success rate index is less than the preset success rate index threshold, sending an optimization failure message; Among them, generating an optimized detection strategy according to the simulated attack result and inputting it into the intrusion behavior detection map for detection optimization specifically includes: Generating an optimized detection strategy according to the simulated attack result, where the optimized detection strategy includes detection threshold adjustment information, detection rule change information, and feature extraction improvement information; Inputting the detection threshold adjustment information, detection rule change information, and feature extraction improvement information into the intrusion behavior detection map for detection optimization; Obtaining monitoring information of multiple edge nodes according to the intrusion detection and prevention system, extracting traffic anomaly data for marking and generating a global threat view, specifically including: Obtaining monitoring information of multiple edge nodes according to the intrusion detection and prevention system; Extracting traffic anomaly data according to the monitoring information of the multiple edge nodes, where the traffic anomaly data includes sudden change information of data transmission volume, heterogeneous port access information, and unknown protocol usage information; Marking the sudden change information of data transmission volume, heterogeneous port access information, and unknown protocol usage information and generating a global threat view; The global threat view includes a dynamic traffic map, an attack frequency chart, and a threat area distribution map.
7. The network intrusion detection and prevention system based on artificial intelligence according to claim 6, characterized in that, Obtaining network traffic data, user behavior data, and system log data in a preset time period according to the intrusion detection and prevention system and constructing an intrusion behavior detection map, specifically including: Obtaining network traffic data, user behavior data, and system log data in a preset time period according to the intrusion detection and prevention system and constructing an intrusion behavior detection map; The network traffic data includes packet header information, packet payload content, and traffic statistics information; The user behavior data includes user login information, operation record information, and permission change record information; The system log data includes system event logs, security event logs, and system error logs.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a network intrusion detection and prevention method, system, and medium program based on artificial intelligence. When the network intrusion detection and prevention method, system, and medium program based on artificial intelligence are executed by a processor, the steps of the network intrusion detection and prevention method based on artificial intelligence according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Network intrusion detection and response system using deep learning algorithm
CN118646563A
Network attack and defense decision support method and system based on artificial intelligence
CN119155099A