Public Data Security Control System and Method Based on Multi-Source Data Fusion
By adopting a public data security control method of multi-source data fusion in the Internet of Things communication, combined with historical early warning record analysis and false alarm coefficient calculation, the problem of false alarm information in the existing technology is solved, and data transmission efficiency is improved.
Patent Information
- Application Number
- CN202510397585.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2045-04-01
AI Technical Summary
When the prior art in IoT communications causes data transmission errors due to noise, interference or equipment failure during transmission, the analysis is lacking in combination with historical early warning information, resulting in imperfect monitoring mechanisms or excessively sensitive to data changes, resulting in false alarm information alarm information, wasting manpower and time, and reducing data transmission efficiency.
The public data security control method based on multi-source data fusion is adopted to obtain several historical warning records, extract and analyze the warning time, and obtain feature records; then obtain multiple feature records for several days in history, set the weight of each day, and calculate the false alarm coefficient of each warning node in each sub-period; finally, based on the sensor value and warning time to detect the detection, the false alarm rate is calculated to determine whether the relevant personnel are prompted.
By combining historical warning records for analysis, the rational judgment of the current warning records to be detected is improved, the prompts of false warning information are reduced, and data transmission efficiency is improved.
Smart Images

Figure CN119922069B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security control, and specifically to a public data security control system and method based on multi-source data fusion. Background Art
[0002] In the Internet of Things communication technology, data will pass through several intermediate nodes and networks during transmission. In order to enable the data to accurately reach the destination address from the source address through several intermediate nodes and networks, it is crucial to ensure the consistency and timeliness of the data during the entire transmission process. However, when the data is transmitted at a certain node, due to reasons such as noise, interference, or equipment failure during the transmission process, the data may be incorrect during transmission. At this time, the error information will be sent to the upstream and downstream in a timely manner through the warning mechanism. However, the existing method does not analyze in combination with historical warning information, and there may be false alarms of warning information due to the imperfect monitoring mechanism or excessive sensitivity to data changes, wasting manpower and time to process these false information, and thus reducing the data transmission efficiency. Summary of the Invention
[0003] The purpose of the present invention is to provide a public data security control system and method based on multi-source data fusion to solve the problems raised in the prior art.
[0004] To achieve the above purpose, the present invention provides the following technical solutions:
[0005] A public data security control method based on multi-source data fusion includes the following steps:
[0006] Step S100: Obtain a number of historical warning records. The warning records are records of data anomalies that occur when the collected sensor values are transmitted from the source address through several nodes to the target address and pass through a certain node during the process; extract and analyze the warning time of each warning record, and then extract characteristic records from them;
[0007] In this solution, the characteristic records are those records whose transmission duration of sensor data at each node stage is relatively more balanced compared with other warning records. The relatively balanced in this solution is calculated based on other warning records and the average duration of all node stages of itself. Using such records for the following analysis will increase the reliability of the calculation results;
[0008] Step S200: Obtain multiple characteristic records within a number of historical days, and set the weight corresponding to each historical day; divide a day into several sub-periods, and obtain the false alarm coefficient corresponding to each warning node in each sub-period according to the warning time and warning node corresponding to each characteristic record;
[0009] Step S300: Obtain the sensor values corresponding to the node positions where warnings occur and the sensor values corresponding to the source addresses in the warning records to be detected, and obtain the first false alarm coefficient corresponding to the warning records to be detected according to the corresponding sensor values and warning times in the feature records;
[0010] Step S400: Obtain the second false alarm coefficient corresponding to the current warning record to be detected according to the false alarm coefficients corresponding to the warning nodes in each sub-period, obtain the false alarm rate of the warning record to be detected according to the first false alarm coefficient, and determine whether to prompt the warning record to be detected to relevant personnel according to the false alarm rate.
[0011] Further, step S100 includes:
[0012] Step S110: Obtain a number of historical warning records. The warning records are records that monitor that the sensor values transmitted to a certain node are abnormal according to a preset warning rule; extract the moments when the sensor values corresponding to the warning records pass through each node from the source address to the target address. Take two adjacent nodes as a node stage, and obtain the stage duration corresponding to each node stage in the warning record according to the moments passing through each node;
[0013] According to the stage duration of a certain node stage n in each warning record, calculate the average value as the average duration D of the node stage n n , and then obtain the reference duration range of stage n as F n =(P1*D n , P2*D n ), where P1 is the first duration coefficient, P2 is the second duration coefficient, 0 < P1 < 1 < P2, and obtain the reference duration range of each node stage;
[0014] Step S120: Obtain the stage duration corresponding to each node stage in a certain warning record R, and obtain the average value of the differences between the stage durations of each node stage in record R and the corresponding average durations; if the stage durations of each node stage in record R are all within the corresponding reference duration ranges, and the variance obtained according to all the average values of the differences is less than a preset variance threshold, then take record R as a feature record, and then obtain all the feature records in the warning records.
[0015] Further, step S200 includes:
[0016] Step S210: Divide a day into Q sub-periods with uniform time, obtain a number of feature records within the historical M days, extract the warning time and warning nodes of each feature record, and record the number of nodes as B; according to the existing judgment method, judge whether each feature record is a false alarm record or a target record with a real warning, obtain the number of false alarm records a1 and the number of target records a2 of the b-th node in the q-th sub-period on the m-th day, and obtain the false alarm degree C = a1 / (a1 + a2);
[0017] Step S220: Sort each day in the order of time from the front to the back according to the number of days in the historical M days, and set the weight corresponding to each day according to the condition that the larger the serial number of the day, the larger the weight, and the sum of the weights of all days is 1;
[0018] According to the false alarm degree and the weight, the false alarm coefficient of the b-th node in the q-th sub-period is obtained as: , where M is the total number of days, W m is the weight corresponding to the m-th day, C is the false alarm degree corresponding to the b-th node in the q-th sub-period on the m-th day, and then the false alarm coefficient corresponding to each node in each sub-period is obtained.
[0019] It should be noted that for temperature values, generally there will be certain changes within a day, that is, under a fixed sub-period within a day, the temperature value usually does not change much. Since temperature will affect device performance and environmental conditions, and then affect false alarm situations, so in this solution, the false alarm coefficient corresponding to each sub-period should be different. And according to different sub-periods within a day, the following second false alarm coefficient is obtained, which is reasonable and can improve the accuracy of the calculation result for calculating the false alarm rate of the to-be-detected warning record.
[0020] Further, step S300 includes:
[0021] Step S310: Extract a number of false alarm records obtained according to the existing judgment method, the sensor value is the temperature value, and the false alarm record is a record of transmitting the temperature value; respectively obtain the sensor values T1 and T2 corresponding to the source address of two adjacent false alarm records, and the warning times t1 and t2 of two adjacent false alarm records, and obtain the characteristic slope K = |(T1 - T2) / (t1 - t2)|, where || is to find the absolute value, and obtain all the characteristic slopes, and take the maximum characteristic slope as K1;
[0022] Step S320: Obtain the sensor value S1 corresponding to the node position where the warning occurs and the sensor value S2 corresponding to the source address in the to-be-detected warning record. If the value S1 is different from the value S2, confirm that the to-be-detected warning record is a record with a real warning;
[0023] If the value S1 is the same as the value S2, obtain the sensor value S3 collected at the source address in the transmission record adjacent to the previous time corresponding to the warning record to be detected, use the warning time of the warning record to be detected as s1, and use the warning time of the transmission record adjacent to the previous time of the warning record to be detected as s2, and obtain the characteristic slope corresponding to the warning record to be detected as: K2 = |(S1 - S3) / (s1 - s2)|, and then obtain the first false alarm coefficient of the warning record to be detected , where e is the natural exponent and h is the adjustment factor coefficient.
[0024] Since the sensor value should be a fixed value during the process from the source address to the target address via multiple nodes, when the values S1 and S2 are different, it indicates that the warning record to be detected is a real warning record and not a false alarm. The characteristic slope represents the change range of temperature over a period of time. Of course, the maximum characteristic slope K1 among them represents the maximum change range of temperature. The greater the characteristic slope of the warning record to be detected, the greater the possibility of false alarm.
[0025] Further, step S400 includes: obtaining the sub-period corresponding to the warning time of the warning record to be detected, and using the false alarm coefficient of the warning node corresponding to the warning record to be detected in the corresponding sub-period as the second false alarm coefficient X2 of the warning record to be detected, and then obtaining the false alarm rate Z = X2*(1 - X1) of the warning record to be detected. If the false alarm rate Z is greater than the preset false alarm rate threshold, the warning record to be detected is promptly prompted to the relevant personnel.
[0026] In this solution, the first false alarm coefficient X1 is obtained based on the characteristic slope and takes values in the range of [0, 1). The smaller X1 is, the closer the current warning record is to the situation obtained from the normal record, and the greater the false alarm rate. The first false alarm coefficient X2 is obtained based on the warning time and takes values in the range of [0, 1]. The larger X2 is, the greater the false alarm rate. Therefore, the false alarm rate Z takes values in the range of [0, 1], and the greater the false alarm rate Z is, the more likely the warning record to be detected is a false alarm, and the warning record to be detected should be promptly prompted to the relevant personnel.
[0027] The public data security control system based on multi-source data fusion includes a characteristic record extraction module, a sub-period analysis module, a first false alarm coefficient calculation module, and a warning record prompt module;
[0028] The characteristic record extraction module: is used to obtain a number of historical warning records. The warning record is a record of data anomaly when the collected sensor value is transmitted from the source address through several nodes to the target address and passes through a certain node among them; extract and analyze the warning time of each warning record, and then extract the characteristic record from it;
[0029] Sub - time - period analysis module: It is used to obtain multiple feature records within several historical days, and set the weight corresponding to each historical day; divide a day into several sub - time - periods, and according to the warning time and warning node corresponding to each feature record, obtain the false - alarm coefficient corresponding to each warning node in each sub - time - period.
[0030] First false - alarm coefficient calculation module: It is used to obtain the sensor value corresponding to the node position where the warning occurs and the sensor value corresponding to the source address in the warning record to be detected, and according to the corresponding sensor value and warning time in the feature record, obtain the first false - alarm coefficient corresponding to the warning record to be detected.
[0031] Warning record prompt module: It is used to obtain the second false - alarm coefficient corresponding to the current warning record to be detected according to the false - alarm coefficient corresponding to each warning node in each sub - time - period, obtain the false - alarm rate of the warning record to be detected according to the first false - alarm coefficient, and judge whether to prompt the warning record to be detected to relevant personnel according to the false - alarm rate.
[0032] Further, the feature record extraction module includes a reference duration range determination unit and a unit;
[0033] Reference duration range determination unit: It is used to obtain several historical warning records, extract the moments when the sensor values corresponding to the warning records pass through each node from the source address to the target address, obtain the stage duration corresponding to each node stage in the warning records, and then obtain the reference duration range of each node stage.
[0034] Feature record extraction: It is used to obtain the stage duration corresponding to each node stage in the warning record, obtain the average value of the difference between the stage duration of each node stage in the record and the corresponding average duration, and obtain all feature records in the warning record according to the reference duration range.
[0035] Further, the first false - alarm coefficient calculation module includes a feature slope determination unit and a first false - alarm coefficient calculation unit;
[0036] Feature slope determination unit: It is used to extract several false - alarm records obtained according to the existing judgment method, respectively obtain the sensor values corresponding to the source address of two adjacent false - alarm records, and the warning times of two adjacent false - alarm records, and obtain the feature slope.
[0037] First false - alarm coefficient calculation unit: It is used to obtain the sensor value corresponding to the node position where the warning occurs in the warning record to be detected, obtain the feature slope corresponding to the warning record to be detected, and then obtain the first false - alarm coefficient of the warning record to be detected.
[0038] Compared with the prior art, the beneficial effects of the present invention are as follows: The present invention provides a public data security control system and method based on multi-source data fusion, including: obtaining a number of historical warning records, extracting and analyzing the warning time of each warning record, and then extracting characteristic records therefrom; obtaining a number of characteristic records within a number of historical days, setting the weight of each day, and obtaining the false alarm coefficient corresponding to each warning node in each sub-period according to the warning time and warning node corresponding to each characteristic record; obtaining a to-be-detected warning record, obtaining the first false alarm coefficient and the second false alarm coefficient corresponding to the to-be-detected warning record, obtaining the false alarm rate of the to-be-detected warning record, and judging whether to prompt the to-be-detected warning record to relevant personnel according to the false alarm rate. By analyzing in combination with historical warning records, the present invention judges the rationality of the current to-be-detected warning record and promptly prompts it to relevant personnel, which helps to improve the data transmission efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 is a schematic flowchart of the public data security control method based on multi-source data fusion of the present invention;
[0040] Figure 2 is a structural diagram of the public data security control system based on multi-source data fusion of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0041] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0042] Embodiment: As Figure 1 shown, the present invention provides a technical solution for a public data security control method based on multi-source data fusion, including the following steps:
[0043] Step S100: Obtain a number of historical warning records. The warning record is a record of data anomaly when the collected sensor value is transmitted from the source address through several nodes to the target address and passes through a certain node among them; extract and analyze the warning time of each warning record, and then extract characteristic records therefrom.
[0044] Step S110: Obtain a number of historical warning records. A warning record is a record that, according to a preset warning rule, detects that the sensor values transmitted to a certain node are abnormal; extract the time when the sensor values corresponding to the warning records pass through each node from the source address to the target address. Take two adjacent nodes as a node stage, and according to the time passing through each node, obtain the stage duration corresponding to each node stage in the warning record.
[0045] Based on the stage duration of a certain node stage n in each warning record, calculate the average value as the average duration D of the node stage n. n , and then obtain the reference duration range F of stage n. n =(P1*D n , P2*D n ), where P1 is the first duration coefficient, P2 is the second duration coefficient, 0 < P1 < 1 < P2, and obtain the reference duration range of each node stage.
[0046] Step S120: Obtain the stage duration corresponding to each node stage in a certain warning record R, and obtain the average value of the differences between the stage duration of each node stage in record R and the corresponding average duration; if the stage duration of each node stage in record R is within the corresponding reference duration range, and the variance obtained from all the average differences is less than the preset variance threshold, then regard record R as a characteristic record, and then obtain all the characteristic records in the warning records.
[0047] In this solution, characteristic records are those records in which the transmission duration of sensor data in each node stage is relatively more balanced compared with other warning records. The relatively balanced in this solution is calculated based on other warning records and the average duration of all node stages of itself. Using such records for the following analysis will increase the reliability of the calculation results.
[0048] Step S200: Obtain multiple characteristic records within a number of historical days, and set the weight corresponding to each historical day; divide a day into several sub-periods, and according to the warning time and warning node corresponding to each characteristic record, obtain the false alarm coefficient corresponding to each warning node in each sub-period.
[0049] Step S210: Divide a day into Q evenly spaced sub-periods, obtain a number of characteristic records within historical M days, and extract the warning time and warning node of each characteristic record. Denote the number of nodes as B; according to the existing judgment method, judge whether each characteristic record is a false alarm record or a target record with a real warning, obtain the number a1 of false alarm records and the number a2 of target records of the b-th node in the q-th sub-period on the m-th day, and obtain the false alarm degree C = a1 / (a1 + a2).
[0050] Step S220: Sort each day in the order of time from the earliest to the latest in the historical M days, and set the weight corresponding to each day according to the condition that the larger the serial number of the day, the larger the weight, and the sum of the weights of all days is 1.
[0051] In this embodiment, the weights of each day are set as follows: Add up all the serial numbers to get the total serial number AL = 1 + 2 + … + M. Then, since the serial number corresponding to the m-th day is m, the weight corresponding to the m-th day is m / AL. Similarly, the weights of each day can be obtained, and the weight of the day with a larger serial number is greater than the weight of the day with a smaller serial number, and the sum of the weights of each day is 1. Since setting the weights of each day, where the weight of the day with a larger serial number is greater than the weight of the day with a smaller serial number, and the sum of the weights of all days is 1, it can be achieved in the prior art, and there are multiple setting methods. Only one of them is introduced in this embodiment, and the specific setting method can be set according to the actual situation.
[0052] According to the false alarm degree and the weight, the false alarm coefficient of the b-th node in the q-th sub-period is obtained as: , where M is the total number of days, W m is the weight corresponding to the m-th day, and C is the false alarm degree corresponding to the q-th sub-period of the b-th node within the m-th day, thereby obtaining the false alarm coefficient corresponding to each node in each sub-period.
[0053] It should be noted that for temperature values, generally, there will be certain changes within a day, that is, under a fixed sub-period within a day, the temperature value usually does not change much. Since temperature can affect device performance and environmental conditions, and thus affect false alarm situations, in this solution, the false alarm coefficient corresponding to each sub-period should be different. According to different sub-periods within a day, the following second false alarm coefficient is obtained, which is reasonable and can improve the accuracy of the calculation result for calculating the false alarm rate of the to-be-detected early warning record.
[0054] Step S300: Obtain the sensor value corresponding to the node position where the warning occurs and the sensor value corresponding to the source address in the to-be-detected early warning record, and obtain the first false alarm coefficient corresponding to the to-be-detected early warning record according to the corresponding sensor value and warning time in the feature record.
[0055] Step S310: Extract several false alarm records obtained according to the existing judgment method, where the sensor value is the temperature value, and the false alarm record is a record of transmitting the temperature value; respectively obtain the sensor values T1 and T2 corresponding to the source address of two adjacent false alarm records, and the warning times t1 and t2 of two adjacent false alarm records, and obtain the characteristic slope K = |(T1 - T2) / (t1 - t2)|, where || is to find the absolute value, and obtain all the characteristic slopes, and take the largest characteristic slope as K1.
[0056] Step S320: Obtain the sensor value S1 corresponding to the node position where the warning occurs and the sensor value S2 corresponding to the source address in the warning record to be detected. If the value S1 is different from the value S2, confirm that the warning record to be detected is a record with a real warning;
[0057] If the value S1 is the same as the value S2, obtain the sensor value S3 collected at the source address in the transmission record adjacent to the previous time corresponding to the warning record to be detected, and use the warning time of the warning record to be detected as s1, and the warning time of the transmission record adjacent to the previous time of the warning record to be detected as s2, and obtain the characteristic slope corresponding to the warning record to be detected as: K2 = |(S1 - S3) / (s1 - s2)|, and then obtain the first false alarm coefficient of the warning record to be detected , where e is the natural exponent and h is the adjustment factor coefficient.
[0058] Since the sensor value should be a fixed value during the process from the source address through multiple nodes to the target address, when the value S1 is different from the value S2, it indicates that the warning record to be detected is a record with a real warning, rather than a false alarm. The characteristic slope represents the change range of temperature over a period of time. Of course, the maximum characteristic slope K1 among them represents the maximum change range of temperature. When the characteristic slope of the warning record to be detected is larger, it indicates that the possibility of false alarm is greater. Since y = 1 - e -x When x takes values x ≥ 0, y takes values in the range [0, 1), and it is a function where y increases as x increases. And when x is smaller, the increase rate of y is larger than when x is larger. In this solution, the first false alarm coefficient is judged based on the characteristic slope K2 and the maximum characteristic slope K1 of the warning record to be detected. When K2 / K1 is smaller, it also indicates that there may be an error, and the larger K2 / K1 is, the greater the possibility of error. Therefore, when K2 / K1 is smaller, the first false alarm coefficient should also be made larger. So here, the function y = 1 - e -x is used for design, and the adjustment factor coefficient h is used as the adjustment factor coefficient of the first false alarm coefficient, and its specific value should be determined according to the actual situation.
[0059] Step S400: Obtain the second false alarm coefficient corresponding to the current warning record to be detected according to the false alarm coefficient corresponding to the warning node in each sub - period, and obtain the false alarm rate of the warning record to be detected according to the first false alarm coefficient, and judge whether to prompt the warning record to be detected to relevant personnel according to the false alarm rate.
[0060] Step S400 includes: obtaining a sub-period corresponding to the warning time of the warning record to be detected, and taking the false alarm coefficient of the warning node corresponding to the warning record to be detected in the corresponding sub-period as the second false alarm coefficient X2 of the warning record to be detected, so as to obtain the false alarm rate Z = X2 * (1 - X1) of the warning record to be detected. If the false alarm rate Z is greater than the preset false alarm rate threshold, the warning record to be detected will be promptly prompted to relevant personnel.
[0061] In this solution, the first false alarm coefficient X1 is obtained according to the characteristic slope and takes values in [0, 1). The smaller X1 is, the closer the current warning record is to the situation obtained from normal records, and the greater the false alarm rate. The first false alarm coefficient X2 is obtained according to the warning time and takes values in [0, 1]. The larger X2 is, the greater the false alarm rate. Therefore, the false alarm rate Z takes values in [0, 1], and the larger the false alarm rate Z is, the more likely the warning record to be detected has a false alarm, and the warning record to be detected should be promptly prompted to relevant personnel. In this embodiment, the false alarm rate threshold is 0.6, and the specific value should be determined according to the actual situation.
[0062] The present invention also provides a public data security control system based on multi-source data fusion, including a feature record extraction module, a sub-period analysis module, a first false alarm coefficient calculation module, and a warning record prompt module;
[0063] Feature record extraction module: used to obtain a number of historical warning records. The warning record is a record of data anomaly when the collected sensor values are transmitted from the source address through several nodes to the target address and pass through a certain node among them; extract and analyze the warning time of each warning record, and then extract the feature record from it;
[0064] Sub-period analysis module: used to obtain a number of feature records within several historical days and set the weight corresponding to each historical day; divide a day into several sub-periods, and obtain the false alarm coefficient corresponding to each warning node in each sub-period according to the warning time and warning node corresponding to each feature record;
[0065] First false alarm coefficient calculation module: used to obtain the sensor value corresponding to the node position where the warning occurs and the sensor value corresponding to the source address in the warning record to be detected, and obtain the first false alarm coefficient corresponding to the warning record to be detected according to the corresponding sensor value and warning time in the feature record;
[0066] Warning record prompt module: used to obtain the second false alarm coefficient corresponding to the current warning record to be detected according to the false alarm coefficient corresponding to each warning node in each sub-period, obtain the false alarm rate of the warning record to be detected according to the first false alarm coefficient, and judge whether to prompt the warning record to be detected to relevant personnel according to the false alarm rate.
[0067] It is obvious to those skilled in the art that the present invention is not limited to the details of the above-described exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be embraced within the present invention. Any reference signs in the claims should not be construed as limiting the claims involved.
Claims
1. A public data security management and control method based on multi-source data fusion, characterized in that: The following steps are involved: Step S100: Acquire several historical warning records, wherein the warning records are records of abnormal data when the collected sensor values are transmitted from the source address through several nodes to the target address, and when passing through a certain node; extract and analyze the warning time of each warning record, and then extract feature records therefrom; Step S200: Acquire multiple feature records within several days of history, and set the weight corresponding to each day of history; divide a day into several sub-periods, and obtain the false alarm coefficient corresponding to each warning node in each sub-period according to the warning time and warning node corresponding to each feature record; Step S300: obtaining the sensor value corresponding to the node position where the warning occurs and the sensor value corresponding to the source address in the warning record to be detected, and obtaining the first false alarm coefficient corresponding to the warning record to be detected according to the corresponding sensor value and warning time in the feature record; Step S400: obtaining a second false alarm coefficient corresponding to the current warning record to be detected according to the false alarm coefficient corresponding to the warning node in each sub-period; And according to the first false alarm coefficient and the second false alarm coefficient, the false alarm rate of the warning record to be detected is obtained, and according to the false alarm rate, it is determined whether to prompt the warning record to be detected to relevant personnel.
2. The public data security management and control method based on multi-source data fusion according to claim 1 is characterized in that: Step S100 includes: Step S110: Obtain several historical warning records, wherein the warning records are records of abnormal sensor values transmitted to a certain node according to preset warning rules; extract the time when the sensor value corresponding to the warning record passes through each node from the source address to the target address, and regard two adjacent nodes as a node stage. According to the time when each node is passed, the stage duration corresponding to each node stage in the warning record is obtained; Based on the stage duration of a certain node stage n in each warning record, calculate the average value as the average duration D of the certain node stage n n , and then obtain the reference duration range of stage n as F n =(P1*D n , P2*D n ), where P1 is the first duration coefficient, P2 is the second duration coefficient, 0 < P1 < 1 < P2, and obtain the reference duration range of each node stage; Step S120: Obtain the stage duration corresponding to each node stage in a certain warning record R, and obtain the average value of the difference between the stage duration of each node stage in the record R and the corresponding average duration; if the stage duration of each node stage in the record R is within the corresponding benchmark duration range, and the variance obtained based on the average value of all differences is less than a preset variance threshold, then the record R is used as a feature record, and then all feature records in the warning record are obtained.
3. The public data security management and control method based on multi-source data fusion according to claim 1 is characterized in that: Step S200 includes: Step S210: Divide a day into Q sub-periods with uniform time, obtain several feature records within the historical M days, and extract the warning time and warning node of each feature record, and record the number of nodes as B; according to the existing judgment method, judge whether each feature record is a false alarm record or a target record for real warning, obtain the number of false alarm records a1 and the number of target records a2 of the b-th node in the q-th sub-period on the m-th day, and obtain the false alarm degree C=a1 / (a1+a2); Step S220: Sort the days in the historical M days in order from the beginning to the end, and set the weight corresponding to each day according to the condition that the larger the serial number of the day, the larger the weight, and the sum of the weights of all days is 1; According to the false alarm degree and weight, the false alarm coefficient of the b-th node in the q-th sub-period is obtained as: , where M is the total number of days, W is m is the weight corresponding to the mth day, C is the false alarm degree corresponding to the qth sub-period of the bth node in the mth day, and then the false alarm coefficient corresponding to each node in each sub-period is obtained.
4. The public data security management and control method based on multi-source data fusion according to claim 3 is characterized in that: Step S300 includes: Step S310: extracting a number of false alarm records obtained according to the existing judgment method, where the sensor value is a temperature value, and the false alarm record is a record of transmitting the temperature value; respectively obtaining the sensor values T1 and T2 corresponding to the source address of two adjacent false alarm records, and the warning times t1 and t2 of the two adjacent false alarm records, and obtaining a characteristic slope K=|(T1-T2) / (t1-t2)|, where || is the absolute value, and obtaining all characteristic slopes, and taking the maximum characteristic slope as K1; Step S320: Obtain the sensor value S1 corresponding to the node position where the warning occurs and the sensor value S2 corresponding to the source address in the warning record to be detected. If the value S1 is different from the value S2, confirm that the warning record to be detected is a record of a real warning. If the value S1 is the same as the value S2, obtain the sensor value S3 collected at the source address in the previous adjacent transmission record corresponding to the warning record to be detected, and use the warning time of the warning record to be detected as s1, and the warning time of the previous adjacent transmission record of the warning record to be detected as s2, and obtain the characteristic slope corresponding to the warning record to be detected: K2=|(S1-S3) / (s1-s2)|, and then obtain the first false alarm coefficient of the warning record to be detected , where e is the natural index and h is the adjustment factor coefficient.
5. The public data security management and control method based on multi-source data fusion according to claim 1 is characterized in that: Step S400 includes: obtaining the sub-period corresponding to the warning time of the warning record to be detected, and using the false alarm coefficient of the warning node corresponding to the warning record to be detected in the corresponding sub-period as the second false alarm coefficient X2 of the warning record to be detected, and then obtaining the false alarm rate Z=X2*(1-X1) of the warning record to be detected. If the false alarm rate Z is greater than the preset false alarm rate threshold, the warning record to be detected will be promptly notified to relevant personnel.
6. A public data security management and control system, used to execute the public data security management and control method based on multi-source data fusion as described in any one of claims 1 to 5, characterized in that: The system includes a feature record extraction module, a sub-period analysis module, a first false alarm coefficient calculation module and an early warning record prompt module; Feature record extraction module: used to obtain several historical warning records, which are records of abnormal data when the collected sensor values are transmitted from the source address to the target address through several nodes; extract and analyze the warning time of each warning record, and then extract feature records from it; Sub-period analysis module: used to obtain multiple feature records within several days of history and set the weight corresponding to each day of history; divide a day into several sub-periods, and obtain the false alarm coefficient corresponding to each warning node in each sub-period according to the warning time and warning node corresponding to each feature record; The first false alarm coefficient calculation module is used to obtain the sensor value corresponding to the node position where the warning occurs and the sensor value corresponding to the source address in the warning record to be detected, and obtain the first false alarm coefficient corresponding to the warning record to be detected according to the corresponding sensor value and warning time in the feature record; Warning record prompt module: used to obtain the second false alarm coefficient corresponding to the current warning record to be detected according to the false alarm coefficient corresponding to the warning node in each sub-period; and to obtain the false alarm rate of the warning record to be detected according to the first false alarm coefficient and the second false alarm coefficient, and to determine whether to prompt the warning record to be detected to relevant personnel based on the false alarm rate.
7. The public data security management and control system according to claim 6, characterized in that: The feature record extraction module includes a reference duration range determination unit and a unit; The reference duration range determination unit is used to obtain a number of historical warning records, extract the time when the sensor value corresponding to the warning record passes through each node from the source address to the target address, obtain the stage duration corresponding to each node stage in the warning record, and then obtain the reference duration range of each node stage; Feature record extraction: used to obtain the stage duration corresponding to each node stage in the early warning record, and obtain the average value of the difference between the stage duration of each node stage in the record and the corresponding average duration, and obtain all feature records in the early warning record based on the benchmark duration range.
8. The public data security management and control system according to claim 6, characterized in that: The first false alarm coefficient calculation module includes a characteristic slope determination unit and a first false alarm coefficient calculation unit; Characteristic slope determination unit: used to extract a number of false alarm records obtained according to the existing judgment method, respectively obtain the sensor values corresponding to the source addresses of two adjacent false alarm records, and the warning time of the two adjacent false alarm records, and obtain the characteristic slope; The first false alarm coefficient calculation unit is used to obtain the sensor value corresponding to the node position where the warning occurs in the warning record to be detected, and obtain the characteristic slope corresponding to the warning record to be detected, and then obtain the first false alarm coefficient of the warning record to be detected.
Citation Information
Patent Citations
Traffic data processing method and device
CN111131290A
Edge node fault analysis method for automatic driving
CN112492025A