Computer information security processing method and system based on big data
Through computer information security processing methods and systems based on big data, deep learning and real-time behavioral analysis technology are used to identify and respond to network attacks, and a dynamic risk assessment model is established for adaptive updates, which solves the problem of traditional information security protection methods being unable to do so in the face of complex network attacks, and achieves efficient security incident response and protection.
Patent Information
- Application Number
- CN202411799683.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-09
- Publication Date
- 2025-05-13
AI Technical Summary
Traditional information security protection methods seem unscrupulous when facing complex and changing risks of cyber attacks and data leakage, and it is difficult to effectively identify and deal with cyber attacks with strong concealment, long duration and great destructive power.
Using computer information security processing methods and systems based on big data, data is collected and cleaned through a distributed data acquisition architecture, deep learning threat feature extraction model is used to automatically learn and extract potential attack patterns and behavioral characteristics, combine time series analysis and real-time behavior analysis technology to identify abnormal behaviors, establish a dynamic risk assessment model to adaptively update based on real-time threat situations, and generate and execute corresponding defense measures.
It significantly improves the response speed and processing efficiency of security incidents, enhances the protection capability of computer information security, improves the response efficiency of security incidents, and provides strong guarantees for information security in big data environments.
Smart Images

Figure CN119989353A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer information security, and in particular to a computer information security processing method and system based on big data. Background Art
[0002] With the rapid development of big data technology, the storage, processing and analysis of massive data have become an indispensable part of all industries. However, this surge in data volume has also brought unprecedented challenges to computer information security. Traditional information security protection methods, such as firewalls, intrusion detection systems (IDS) and antivirus software, are unable to cope with complex and changing network attacks and data leakage risks.
[0003] Cyber attackers continue to use new technical means and vulnerabilities to launch various forms of attacks, such as distributed denial of service (DDoS) attacks and advanced persistent threats (APTs). These attacks are often highly concealed, long-lasting, and highly destructive. At the same time, the risk of data leakage is becoming increasingly severe. The illegal acquisition and abuse of sensitive data may lead to serious economic losses and reputation damage. For this reason, a computer information security processing method and system based on big data is proposed. Summary of the invention
[0004] The purpose of the present invention is to provide a computer information security processing method and system based on big data to solve the problems raised in the above background technology.
[0005] To achieve the above-mentioned object of the invention, one aspect of the present invention provides a computer information security processing method based on big data, comprising the following steps:
[0006] Step S1, using a distributed data acquisition architecture to collect data generated during computer operation, and perform data cleaning and standardization processing;
[0007] Step S2, a threat feature extraction model based on deep learning, which automatically learns and extracts potential attack patterns and behavior features by training a large amount of historical security event data;
[0008] Step S3: Implement continuous monitoring of user and system behaviors, and identify suspicious behaviors such as abnormal logins and data access by combining time series analysis technology;
[0009] Step S4, establishing a dynamic risk assessment model, based on an adaptive learning mechanism, and updating the risk assessment model according to newly emerging threat cases;
[0010] Step S5, generating and executing corresponding defense measures by isolating infected devices, blocking malicious traffic, automatically repairing vulnerabilities and triggering alarm notifications.
[0011] Furthermore, in step S1, an intelligent data capture algorithm is used to automatically adjust the acquisition frequency and depth according to preset data acquisition rules to optimize resource usage and reduce data redundancy.
[0012] Furthermore, the data cleaning and standardization processing includes removing invalid data, duplicate data, and unifying data formats to provide a high-quality, standardized data foundation for subsequent analysis.
[0013] Furthermore, the real-time behavior analysis of the system in step S3 includes the following steps:
[0014] Step S301, dividing the obtained data into multiple groups, which should have similar characteristics;
[0015] Step S302, setting one or more performance or quality indicators for each group, and determining a reasonable range or threshold of these indicators;
[0016] Step S303: Use real-time monitoring tools or algorithms to track the performance indicators of each group; when the indicators of a group exceed the set reasonable range or threshold, an alarm is triggered. Once a problem is confirmed in a group, use automated tools or scripts to isolate the group from the system and extract key features related to the problem from the problem group;
[0017] Step S304, compare the extracted features with other groups by comparing feature values, calculating similarities or applying machine learning algorithms to detect whether there are similar problems or patterns, use machine learning or statistical methods to identify potential problems that may exist in other groups, automatically detect abnormal data points that do not conform to normal patterns, evaluate the results of comparison and analysis to determine which groups may have problems, determine the severity and priority of the problems, and develop solutions and implement necessary repair measures for the problems found.
[0018] Furthermore, the real-time behavior analysis of the system in step S3 includes user behavior prediction, which uses machine learning algorithms to predict the user's future behavior and collects user historical behavior data, including login time, access content and operation frequency; uses a time series prediction model to train the model; uses the trained model to predict the user's future behavior, including the pages that may be visited and the operations performed; and takes corresponding security measures in advance based on the prediction results and combined with the risk assessment model.
[0019] Furthermore, step S4 also includes risk propagation analysis, analyzing the propagation path and speed of risks between different systems, devices or users; including the following steps:
[0020] Step S401, collecting association information between systems, devices and users, including network connections, data sharing, and access rights;
[0021] Step S402, constructing a risk propagation network model to represent the potential propagation path of risk among systems, devices and users;
[0022] Step S403, using graph theory and network analysis methods, calculate the speed of risk spread and the scope of influence in the network;
[0023] Step S404, identifying key nodes and weak links, and formulating targeted risk control strategies;
[0024] Step S405, updating the risk propagation network model in real time to reflect changes in the associated information between systems, devices and users, and ensuring the accuracy and timeliness of risk assessment.
[0025] Furthermore, data lifecycle management is carried out to monitor the entire life cycle of data, from data generation, storage, processing to destruction, to ensure data compliance, integrity and security. Functions include data classification, data backup, data archiving and data destruction to achieve comprehensive management and control of data.
[0026] Furthermore, in the data collection mechanism, step S1 compresses the collected data and transmits it through encryption technology, thereby reducing network bandwidth usage and enhancing the security of data transmission while ensuring data integrity.
[0027] Furthermore, in the data collection mechanism, data is processed through data desensitization and data masking technologies to protect the privacy of data content.
[0028] Another aspect of the present invention provides a computer information security processing system based on big data, including a data acquisition and preprocessing module, an intelligent threat identification module, a real-time behavior analysis and prediction module, a dynamic risk assessment module, and an intelligent response and defense module, wherein:
[0029] The data acquisition and preprocessing module uses a distributed data acquisition architecture to collect data generated during computer operation, and performs data cleaning and standardization processing;
[0030] The intelligent threat identification module is based on a deep learning threat feature extraction model. By training a large amount of historical security event data, it automatically learns and extracts potential attack patterns and behavior features.
[0031] The real-time behavior analysis and prediction module implements continuous monitoring of user and system behaviors, and combines time series analysis technology to identify abnormal logins and suspicious data access behaviors;
[0032] The dynamic risk assessment module establishes a dynamic risk assessment model and updates the risk assessment model based on the emerging threat cases based on the adaptive learning mechanism;
[0033] The intelligent response and defense module generates and executes corresponding defense measures by isolating infected devices, blocking malicious traffic, automatically repairing vulnerabilities and triggering alarm notifications.
[0034] Compared with the prior art, the present system and method have the following advantages:
[0035] 1. The present invention realizes efficient data collection and cleaning by setting up distributed data collection and intelligent data crawling, providing a solid foundation for information security. It adopts an intelligent threat identification engine and a real-time behavior analysis system, combined with deep learning and machine learning technology, which can accurately identify potential threats and abnormal behaviors, significantly improve the response speed of security incidents, and use a dynamic risk assessment model to adaptively update according to real-time threat situations to ensure the timeliness and accuracy of risk assessment. Finally, by automatically generating and executing defense measures, it effectively blocks attacks and reduces losses. It not only enhances the protection capability of computer information security, but also improves the efficiency of responding to security incidents, providing a strong guarantee for information security in a big data environment.
[0036] 2. The present invention achieves refined management of data by formulating rule grouping, setting performance indicators and threshold monitoring. Once a problem is found, the problem group can be quickly isolated and key features can be extracted. The machine learning algorithm can be used to compare other groups to quickly identify potential problems, effectively improving the response speed and processing efficiency of security incidents, reducing the possibility of security risk spread, and ensuring the stable operation of the system.
[0037] 3. The present invention uses a user behavior prediction module in a real-time behavior analysis system in combination with a risk assessment model to predict future user behavior and take security measures in advance, such as restricting access rights or triggering alarms, thereby achieving predictive management of security risks. At the same time, the risk propagation analysis module in the dynamic risk assessment model analyzes the risk propagation path and speed, identifies key nodes, and formulates risk control strategies, thereby effectively reducing the actual impact of security risks and enhancing the system's security protection capabilities.
[0038] 4. The present invention ensures that every step from data generation to destruction meets security compliance requirements by introducing a data lifecycle management module. Through comprehensive management of data classification, backup, archiving, and destruction, not only data privacy is protected, but also data integrity and security are improved. In addition, the data compression, encrypted transmission, and real-time data analysis functions in the data acquisition mechanism further enhance the security of data transmission and resource utilization efficiency, providing a solid guarantee for information security in a big data environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 The figure is a flow chart of the computer information security processing method based on big data.
[0040] Figure 2 This is a schematic diagram of the working principle of the computer information security processing method based on big data.
[0041] Figure 3 The figure is a specific illustration of the computer information security processing method based on big data.
[0042] Figure 4 This is a structural diagram of the computer information security processing system based on big data. DETAILED DESCRIPTION
[0043] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0044] like Figure 1 , Figure 2 The flowchart of the method of the present invention and the schematic diagram of the working principle are shown. The embodiment of the present invention provides a computer information security processing method based on big data, and the specific steps are as follows:
[0045] Step S1, adopts a distributed data collection architecture to collect data in real time and efficiently from multiple data sources such as network traffic monitoring equipment, system log servers, user behavior recording systems, etc.; by deploying multiple data collection nodes to work in parallel, ensure the comprehensiveness and real-time nature of the data; at the same time, introduce an intelligent data capture algorithm to automatically adjust the collection frequency and depth according to preset rules, optimize resource utilization and reduce data redundancy; implement data cleaning and standardization processing, including removing invalid data, duplicate data, and unifying data formats (such as timestamp format, data type conversion, etc.), to provide a high-quality, standardized data foundation for subsequent analysis.
[0046] In the data collection mechanism, the collected data is compressed and transmitted through encryption technology, which ensures data integrity while reducing network bandwidth usage and enhancing the security of data transmission. The data is processed through data desensitization and data masking technology to protect the privacy of data content. This improves collection efficiency, avoids the risk of leakage of sensitive information, and increases security.
[0047] Step S2, based on deep learning threat feature extraction model, automatically learns and extracts potential attack patterns and behavior features by training historical security event data, and develops anomaly detection algorithms using statistics and machine learning techniques to identify abnormal activities that deviate from normal behavior patterns. This engine can analyze data in real time and discover potential security threats.
[0048] In step S3, the system implements continuous monitoring of user and system behaviors, and combines time series analysis techniques such as ARIMA (AutoRegressive Integrated Moving Average Model) and LSTM (Long Short-Term Memory) to accurately identify suspicious behaviors such as abnormal logins and data access. At the same time, context-aware technology is introduced to comprehensively consider user historical behaviors and current environmental information (such as geographic location, device type, etc.), significantly improving the accuracy and context relevance of behavior recognition.
[0049] The real-time behavior analysis of the system in step S3 includes the following steps:
[0050] Step S301, dividing the obtained data into multiple groups, which should have similar characteristics.
[0051] Step S302: set one or more performance or quality indicators for each group, and determine a reasonable range or threshold of these indicators.
[0052] Step S303, use real-time monitoring tools or algorithms to track the performance indicators of each group; when the indicators of a group exceed the set reasonable range or threshold, an alarm is triggered. Once it is confirmed that a group has a problem, use automated tools or scripts to isolate the group from the system and extract key features related to the problem from the problem group.
[0053] Step S304, compare the extracted features with other groups by comparing feature values, calculating similarities or applying machine learning algorithms to detect whether there are similar problems or patterns, use machine learning or statistical methods to identify potential problems that may exist in other groups, automatically detect abnormal data points that do not conform to normal patterns, evaluate the results of comparison and analysis to determine which groups may have problems, determine the severity and priority of the problems, and develop solutions and implement necessary repair measures for the problems found.
[0054] In order to improve security, we use machine learning algorithms to predict users' future behavior and make full use of the powerful capabilities of machine learning algorithms to predict users' future behavior. Collect historical user behavior data, including login time, access content, and operation frequency; use time series prediction models for model training; use the trained model to predict users' future behavior, including possible pages visited and operations performed; take corresponding security measures in advance based on the prediction results and combined with the risk assessment model.
[0055] Step S4, establish a dynamic risk assessment model, based on the adaptive learning mechanism, update the risk assessment model according to the emerging threat cases. The dynamic risk assessment model is the core component of the computer information security processing method. It is responsible for real-time assessment of the information security risks faced by the system and provides decision support for intelligent response.
[0056] The dynamic risk assessment model establishes a multi-dimensional risk assessment framework including attack type, impact scope and system vulnerability factors. Through this framework, the model can comprehensively and accurately assess the information security risk level faced by the system. At the same time, based on the adaptive learning mechanism, the model can be continuously updated according to emerging threat cases to ensure the timeliness and accuracy of the assessment system.
[0057] To further improve the accuracy and foresight of risk assessment, risk propagation analysis is performed on the system to analyze the path and speed of risk propagation between different systems, devices or users, including the following steps:
[0058] Step S401, collecting association information between systems, devices and users, including network connections, data sharing, and access rights.
[0059] Step S402: construct a risk propagation network model to represent the potential propagation path of risk among the system, equipment and users.
[0060] Step S403, using graph theory and network analysis methods, calculate the speed of risk spread and the scope of influence in the network;
[0061] Step S404, identify key nodes and weak links, formulate targeted risk control strategies, and enhance the foresight of risk assessment.
[0062] Step S405: Update the risk propagation network model in real time to reflect changes in the associated information between systems, devices and users, and ensure the accuracy and timeliness of risk assessment. Formulate risk control strategies based on the analysis results to effectively curb the spread of risks; update the risk propagation model in real time to adapt to the new threat environment and maintain assessment accuracy.
[0063] The dynamic risk assessment model identifies risk factors related to information security through a multi-dimensional risk assessment framework, including attack types (such as DDoS attacks, SQL injections, malware, etc.), impact scope (such as the number of affected systems, the number of users, data sensitivity, etc.) and system vulnerabilities (such as unpatched vulnerabilities, weak password policies, etc.) risk quantification.
[0064] For each identified risk factor, a quantitative method is used to assess its potential impact and probability of occurrence. The impact is determined by assessing the severity of consequences such as data loss, system downtime, and business interruption; the probability of occurrence can be estimated by analyzing historical data, threat intelligence, and current security situation.
[0065] Based on the risk quantification results and combined with the preset risk level classification standards (such as low risk, medium risk, high risk, extremely high risk, etc.), each risk factor is assigned to the corresponding risk level; the risk level is determined by the product or weighted sum of the impact degree and the probability of occurrence, reflecting the overall severity of the risk.
[0066] Organize the risk assessment results into a report, including the identified risk factors, quantitative results, risk levels and corresponding risk treatment recommendations.
[0067] Step S5, based on the risk assessment results, automatically generates and executes corresponding defense measures, such as isolating infected devices, blocking malicious traffic, automatically repairing vulnerabilities and triggering alarm notifications; at the same time, combined with the results of the real-time behavior analysis system, early warning and intervention of potential threats are carried out to ensure the safe operation of the system.
[0068] The data life cycle is monitored throughout the entire process, from data generation, storage, processing to destruction, to ensure data compliance, integrity and security; specifically, it includes data classification, data backup, data archiving and data destruction functions. Through the data classification function, data of different categories and sensitivity levels can be clearly distinguished, which is convenient for implementing targeted protection measures; the data backup function effectively prevents data loss and ensures data recoverability; the data archiving function helps to preserve important data for a long time while reducing the occupation of active storage space; and the data destruction function ensures that discarded data is safely processed to prevent sensitive information leakage. This not only improves the efficiency of data management, but also significantly enhances the security and compliance of the system.
[0069] The process also includes real-time data analysis, which is used to analyze the current data flow and data type, and dynamically adjust the data collection strategy to increase the collection frequency during peak hours and reduce the collection during off-peak hours, thereby balancing resource consumption and data acquisition efficiency. This function achieves a balance between resource consumption and data acquisition efficiency; this dynamic adjustment not only helps to optimize the data collection process and reduce unnecessary resource waste, but also ensures that sufficient data support is obtained at critical moments, improving the flexibility and adaptability of the system, enabling it to better cope with the ever-changing threat environment.
[0070] like Figure 3The figure shows a specific description of the present invention. The computer information security processing method based on big data of the present invention collects multi-source data such as network traffic, system logs, user behavior, etc. in real time and efficiently through a distributed data acquisition architecture. After intelligent data capture, cleaning and standardization processing, it is input into the deep learning intelligent threat identification engine to automatically extract attack patterns and behavior characteristics, and analyze potential security threats in real time; at the same time, the real-time behavior analysis system combines time series analysis and context perception technology to accurately identify abnormal behaviors, and automatically detects abnormal data points and evaluates problem priorities through group monitoring and machine learning algorithm comparative analysis; the user behavior prediction module uses machine learning to predict future behaviors, and the dynamic risk assessment model constructs a multi-dimensional risk assessment framework, integrates the risk propagation analysis module, evaluates information security risks in real time, accurately quantifies risk factors, and generates risk level reports; finally, based on the risk assessment and behavior analysis results, intelligent response and defense strategies are automatically generated and executed to ensure the safe operation of the system.
[0071] Another embodiment of the present invention is a system for computer information security processing based on big data, such as Figure 4 The system structure diagram is shown, including data acquisition and preprocessing module, intelligent threat identification module, real-time behavior analysis and prediction module, dynamic risk assessment module, intelligent response and defense module, among which:
[0072] The data collection and preprocessing module adopts a distributed architecture to collect computer operation data from multiple data sources in real time and intelligently adjust the collection frequency and depth; the data is cleaned and standardized to provide a high-quality foundation for subsequent analysis.
[0073] The intelligent threat identification module uses deep learning and machine learning technologies to automatically learn attack patterns, identify abnormal behaviors, and detect potential threats.
[0074] The real-time behavior analysis and prediction module monitors user and system behaviors in real time, combines time series analysis and context-aware technology to improve the accuracy of behavior recognition, and predicts future user behaviors to take security measures in advance.
[0075] The dynamic risk assessment module establishes a multi-dimensional risk assessment framework, dynamically evaluates information security risk levels, analyzes risk propagation paths and speeds, and formulates risk control strategies.
[0076] The intelligent response and defense module automatically generates and executes defense measures based on risk assessment results, by isolating infected devices, blocking malicious traffic, automatically repairing vulnerabilities and triggering alarm notifications.
[0077] The system also includes a data lifecycle management module, which is used to monitor the data lifecycle and ensure data compliance, integrity and security, including data classification, backup, archiving and destruction functions. It also includes an optimization module to analyze data flow and type, dynamically adjust the collection strategy, and balance resource consumption and data acquisition efficiency.
[0078] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A computer information security processing method based on big data, characterized in that: The following steps are involved: Step S1, using a distributed data acquisition architecture to collect data generated during computer operation, and perform data cleaning and standardization processing; Step S2, a threat feature extraction model based on deep learning, which automatically learns and extracts potential attack patterns and behavior features by training a large amount of historical security event data; Step S3: Implement continuous monitoring of user and system behaviors, and identify suspicious behaviors such as abnormal logins and data access by combining time series analysis technology; Step S4, establishing a dynamic risk assessment model, based on an adaptive learning mechanism, and updating the risk assessment model according to newly emerging threat cases; Step S5, generating and executing corresponding defense measures by isolating infected devices, blocking malicious traffic, automatically repairing vulnerabilities and triggering alarm notifications.
2. The computer information security processing method based on big data according to claim 1 is characterized in that: In step S1, an intelligent data capture algorithm is used to automatically adjust the acquisition frequency and depth according to preset data acquisition rules to optimize resource utilization and reduce data redundancy.
3. The computer information security processing method based on big data according to claim 1 is characterized in that: The data cleaning and standardization processing includes removing invalid data, duplicate data, and unifying data formats to provide a high-quality, standardized data foundation for subsequent analysis.
4. The computer information security processing method based on big data according to claim 1 is characterized in that: The real-time behavior analysis of the system in step S3 includes the following steps: Step S301, dividing the obtained data into multiple groups, which should have similar characteristics; Step S302, setting one or more performance or quality indicators for each group, and determining a reasonable range or threshold of these indicators; Step S303: Use real-time monitoring tools or algorithms to track the performance indicators of each group; when the indicators of a group exceed the set reasonable range or threshold, an alarm is triggered. Once a problem is confirmed in a group, use automated tools or scripts to isolate the group from the system and extract key features related to the problem from the problem group; Step S304, compare the extracted features with other groups by comparing feature values, calculating similarities or applying machine learning algorithms to detect whether there are similar problems or patterns, use machine learning or statistical methods to identify potential problems that may exist in other groups, automatically detect abnormal data points that do not conform to normal patterns, evaluate the results of comparison and analysis to determine which groups may have problems, determine the severity and priority of the problems, and develop solutions and implement necessary repair measures for the problems found.
5. The computer information security processing method based on big data according to claim 1 is characterized in that: In step S3, the real-time behavior analysis of the system includes user behavior prediction, which uses machine learning algorithms to predict the user's future behavior and collects user historical behavior data, including login time, access content and operation frequency; uses a time series prediction model for model training; uses the trained model to predict the user's future behavior, including the pages that may be visited and the operations performed; and takes corresponding security measures in advance based on the prediction results and combined with the risk assessment model.
6. The computer information security processing method based on big data according to claim 1 is characterized in that: Step S4 also includes risk propagation analysis, analyzing the propagation path and speed of risks between different systems, devices or users; including the following steps: Step S401, collecting association information between systems, devices and users, including network connections, data sharing, and access rights; Step S402, constructing a risk propagation network model to represent the potential propagation path of risk among systems, devices and users; Step S403, using graph theory and network analysis methods, calculate the speed of risk spread and the scope of influence in the network; Step S404, identifying key nodes and weak links, and formulating targeted risk control strategies; Step S405, updating the risk propagation network model in real time to reflect changes in the associated information between systems, devices and users, and ensuring the accuracy and timeliness of risk assessment.
7. The computer information security processing method based on big data according to claim 1 is characterized in that: Carry out data life cycle management and monitor the entire life cycle of data, from data generation, storage, processing to destruction, to ensure data compliance, integrity and security. Functions include data classification, data backup, data archiving and data destruction to achieve comprehensive management and control of data.
8. The computer information security processing method based on big data according to claim 1 is characterized in that: In the data collection mechanism, step S1 compresses the collected data and transmits it through encryption technology, which reduces network bandwidth usage and enhances the security of data transmission while ensuring data integrity.
9. The computer information security processing method based on big data according to claim 1 is characterized in that: In the data collection mechanism, data is processed through data desensitization and data masking technologies to protect the privacy of data content.
10. A computer information security processing system based on big data, characterized in that: It includes data collection and preprocessing module, intelligent threat identification module, real-time behavior analysis and prediction module, dynamic risk assessment module, intelligent response and defense module, among which: The data acquisition and preprocessing module uses a distributed data acquisition architecture to collect data generated during computer operation, and performs data cleaning and standardization processing; The intelligent threat identification module is based on a deep learning threat feature extraction model. By training a large amount of historical security event data, it automatically learns and extracts potential attack patterns and behavior features. The real-time behavior analysis and prediction module implements continuous monitoring of user and system behaviors, and combines time series analysis technology to identify abnormal logins and suspicious data access behaviors; The dynamic risk assessment module establishes a dynamic risk assessment model and updates the risk assessment model based on the emerging threat cases based on the adaptive learning mechanism; The intelligent response and defense module generates and executes corresponding defense measures by isolating infected devices, blocking malicious traffic, automatically repairing vulnerabilities and triggering alarm notifications.
Citation Information
Cited By
Railway information infrastructure safety management and control system based on data processing
CN120434067A
A railway information infrastructure security management and control system based on data processing
CN120434067B