Computer security system based on artificial intelligence

By introducing artificial intelligence technology into computer security systems, combining modules such as data collection, behavioral analysis and threat intelligence integration, it solves the problem that traditional security systems are difficult to cope with complex security threats, and achieves more efficient security incident detection and response.

CN119989357APending Publication Date: 2025-05-13ZIBO VOCATIONAL INST
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510034121.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-09
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

Traditional computer security systems are difficult to adapt to increasingly complex and changeable security threats, and cannot effectively identify and deal with abnormal behaviors and security threats in real-time data.

Method used

Using an artificial intelligence-based computer security system, the monitoring, analysis and response of computer system operating status and security events is achieved through the coordinated work of modules such as data collection, preprocessing, behavior analysis, threat intelligence integration and decision-making and response.

Benefits of technology

The system can automatically learn and adapt to changing security threats, improve the detection and response effects of security incidents, and provides more accurate and comprehensive security protection by integrating threat intelligence sources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989357A_ABST
    Figure CN119989357A_ABST
Patent Text Reader

Abstract

The invention relates to the field of computer security, in particular to a computer security system based on artificial intelligence, comprising: a data acquisition module for acquiring security-related data in real time to obtain system operation state, user behavior and network traffic information; the data preprocessing module is used for cleaning, denoising and unifying the collected data; the behavior analysis module is used for analyzing and modeling the preprocessed data by using machine learning and deep learning algorithms; the threat intelligence integration module is used for integrating various internal and external threat intelligence sources and providing real-time security intelligence support for the system; and the decision and response module is used for automatically or semi-automatically formulating corresponding security decisions and response measures according to the result of the behavior analysis module and the threat intelligence. According to the invention, monitoring, analysis and response to the operation state and security events of the computer system can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer security, and in particular to a computer security system based on artificial intelligence. Background Art

[0002] With the rapid development of the Internet, computer security issues have become increasingly prominent, and defense against security threats such as network attacks, malicious codes, and security vulnerabilities has become increasingly important.

[0003] Traditional computer security systems mainly rely on rules and pattern matching to detect security incidents, but this approach cannot adapt to increasingly complex and changing security threats.

[0004] Therefore, there is an urgent need for a computer security system that can perform intelligent analysis and modeling based on real-time data. Summary of the invention

[0005] To solve the above problems, the present invention provides a computer security system based on artificial intelligence, which can monitor, analyze and respond to the operating status of the computer system and security incidents. Specifically, through the collaborative work of modules such as data acquisition, preprocessing, behavior analysis, threat intelligence integration, and decision-making and response, it can effectively identify abnormal behaviors and security threats, and take corresponding security decisions and response measures.

[0006] To achieve the above object, the technical solution adopted by the present invention is: A computer security system based on artificial intelligence, comprising: Data collection module, used to collect security-related data in real time to obtain system operation status, user behavior and network traffic information; Data preprocessing module, used to clean, denoise and unify the collected data; Behavior analysis module, which is used to analyze and model the pre-processed data using machine learning and deep learning algorithms; Threat intelligence integration module, which is used to integrate various internal and external threat intelligence sources to provide real-time security intelligence support for the system; The decision-making and response module is used to automatically or semi-automatically formulate corresponding security decisions and response measures based on the results of the behavior analysis module and threat intelligence.

[0007] Furthermore, the security-related data includes network communication data, operating system logs and application logs.

[0008] Furthermore, the step of analyzing and modeling the preprocessed data using machine learning and deep learning algorithms specifically includes: By establishing normal behavior models and abnormal behavior detection models, the system operation status can be monitored and security incidents can be identified.

[0009] Furthermore, the threat intelligence sources include security vulnerability information, malicious code samples and network attack information.

[0010] Furthermore, the step of automatically or semi-automatically formulating corresponding security decisions and response measures based on the results of the behavior analysis module and threat intelligence specifically includes: According to the severity of the security incident and the risk level of the threat, take appropriate control strategies and preventive measures to ensure the security of the system.

[0011] Furthermore, the data acquisition module is sequentially communicatively connected through the data preprocessing module, the behavior analysis module and the decision and response module.

[0012] Furthermore, the decision and response module is communicatively connected to the threat intelligence integration module.

[0013] Furthermore, the execution method of the computer security system based on artificial intelligence includes the following steps: Start the computer security system, initialize each module, and establish security policies and rules; The data acquisition module collects safety-related data in real time; The data preprocessing module cleans, denoises and unifies the collected data to obtain preprocessed data; The behavior analysis module uses machine learning and deep learning algorithms to analyze and model pre-processed data to identify abnormal behaviors and security threats; The threat intelligence integration module integrates various internal and external threat intelligence sources to provide real-time security intelligence support for the system; The decision and response module formulates corresponding security decisions and response measures based on the results of the behavior analysis module and threat intelligence to ensure the security of the system; Periodically update security rules and policies, and optimize and improve the system.

[0014] The beneficial effects of the present invention are: The computer security system based on artificial intelligence of the present invention can realize the monitoring, analysis and response of the operation status of the computer system and security events. The system can effectively identify abnormal behaviors and security threats and take corresponding security decisions and response measures through the collaborative work of modules such as data collection, preprocessing, behavior analysis, threat intelligence integration, and decision-making and response. In other words, the computer security system based on artificial intelligence of the present invention can automatically learn and adapt to the ever-changing security threats, improving the detection and response effects of security events. At the same time, by integrating threat intelligence sources, the latest security intelligence can be obtained in a timely manner, providing more accurate and comprehensive security protection for the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 Schematic diagram of the artificial intelligence-based computer security system of the present invention. DETAILED DESCRIPTION

[0016] See also Figure 1 As shown, the present invention relates to a computer security system based on artificial intelligence, comprising: Data collection module, used to collect security-related data in real time to obtain system operation status, user behavior and network traffic information; Data preprocessing module, used to clean, denoise and unify the collected data; Behavior analysis module, which is used to analyze and model the pre-processed data using machine learning and deep learning algorithms; Threat intelligence integration module, which is used to integrate various internal and external threat intelligence sources to provide real-time security intelligence support for the system; The decision-making and response module is used to automatically or semi-automatically formulate corresponding security decisions and response measures based on the results of the behavior analysis module and threat intelligence.

[0017] In the above scheme, the computer security system based on artificial intelligence of the present invention can realize the monitoring, analysis and response of the operating status of the computer system and security events. The system can effectively identify abnormal behaviors and security threats and take corresponding security decisions and response measures through the collaborative work of modules such as data acquisition, preprocessing, behavior analysis, threat intelligence integration, and decision-making and response. In other words, the computer security system based on artificial intelligence of the present invention can automatically learn and adapt to the ever-changing security threats, improving the detection and response effects of security incidents. At the same time, by integrating threat intelligence sources, the latest security intelligence can be obtained in a timely manner, providing more accurate and comprehensive security protection for the system.

[0018] Furthermore, the security-related data includes network communication data, operating system logs and application logs.

[0019] Furthermore, the step of analyzing and modeling the preprocessed data using machine learning and deep learning algorithms specifically includes: By establishing normal behavior models and abnormal behavior detection models, the system operation status can be monitored and security incidents can be identified.

[0020] Furthermore, the threat intelligence sources include security vulnerability information, malicious code samples and network attack information.

[0021] Furthermore, the step of automatically or semi-automatically formulating corresponding security decisions and response measures based on the results of the behavior analysis module and threat intelligence specifically includes: According to the severity of the security incident and the risk level of the threat, take appropriate control strategies and preventive measures to ensure the security of the system.

[0022] Furthermore, the data acquisition module is communicatively connected via the data preprocessing module, the behavior analysis module and the decision and response module in sequence.

[0023] Furthermore, the decision and response module is communicatively connected to the threat intelligence integration module.

[0024] Furthermore, the execution method of the computer security system based on artificial intelligence includes the following steps: Start the computer security system, initialize each module, and establish security policies and rules; The data acquisition module collects safety-related data in real time; The data preprocessing module cleans, denoises and unifies the collected data to obtain preprocessed data; The behavior analysis module uses machine learning and deep learning algorithms to analyze and model pre-processed data to identify abnormal behaviors and security threats; The threat intelligence integration module integrates various internal and external threat intelligence sources to provide real-time security intelligence support for the system; The decision and response module formulates corresponding security decisions and response measures based on the results of the behavior analysis module and threat intelligence to ensure the security of the system; Periodically update security rules and policies, and optimize and improve the system.

[0025] The following is an analysis and description of the computer security system based on artificial intelligence of the present invention through a specific embodiment, which is as follows: Computer security system based on artificial intelligence, including the following modules: Data collection module: responsible for real-time collection of security-related data, including network communication data, operating system logs, application logs, etc. By collecting this data, information such as system operation status, user behavior, and network traffic can be obtained.

[0026] Data preprocessing module: cleans, denoises and unifies the collected data for subsequent analysis and modeling. Through the processing of this module, the interference noise in the data can be eliminated, and the accuracy and effect of the subsequent algorithm can be improved.

[0027] Behavior analysis module: Use machine learning and deep learning algorithms to analyze and model pre-processed data. By establishing normal behavior models and abnormal behavior detection models, it can monitor the system operation status and identify security events.

[0028] Threat intelligence integration module: Integrates various internal and external threat intelligence sources to provide real-time security intelligence support for the system. These threat intelligence sources include security vulnerability information, malicious code samples, network attack information, etc., which can help the system to understand the latest threat situation in a timely manner.

[0029] Decision and response module: According to the results of the behavior analysis module and threat intelligence, the corresponding security decisions and response measures are automatically or semi-automatically formulated. According to the severity of the security incident and the risk level of the threat, the corresponding control strategy and preventive measures can be taken to ensure the security of the system.

[0030] From the above analysis, it can be seen that the artificial intelligence-based computer security system of the present invention can automatically learn and adapt to the ever-changing security threats, improving the detection and response effects of security incidents. At the same time, by integrating threat intelligence sources, it can obtain the latest security intelligence in a timely manner, providing the system with more accurate and comprehensive security protection.

[0031] In summary, compared with the prior art, the beneficial effects of the present invention are at least as follows: The computer security system based on artificial intelligence of the present invention can realize the monitoring, analysis and response of the operation status of the computer system and security events. The system can effectively identify abnormal behaviors and security threats and take corresponding security decisions and response measures through the collaborative work of modules such as data collection, preprocessing, behavior analysis, threat intelligence integration, and decision-making and response. In other words, the computer security system based on artificial intelligence of the present invention can automatically learn and adapt to the ever-changing security threats, improving the detection and response effects of security events. At the same time, by integrating threat intelligence sources, the latest security intelligence can be obtained in a timely manner, providing more accurate and comprehensive security protection for the system.

[0032] The above implementation modes are merely descriptions of the preferred implementation modes of the present invention, and are not intended to limit the scope of the present invention. Without departing from the design spirit of the present invention, various modifications and improvements made to the technical solutions of the present invention by ordinary engineering and technical personnel in the field shall fall within the protection scope determined by the claims of the present invention.

Claims

1. A computer security system based on artificial intelligence, characterized in that: include: Data collection module, used to collect security-related data in real time to obtain system operation status, user behavior and network traffic information; Data preprocessing module, used to clean, denoise and unify the collected data; Behavior analysis module, which is used to analyze and model the pre-processed data using machine learning and deep learning algorithms; Threat intelligence integration module, which is used to integrate various internal and external threat intelligence sources to provide real-time security intelligence support for the system; The decision-making and response module is used to automatically or semi-automatically formulate corresponding security decisions and response measures based on the results of the behavior analysis module and threat intelligence.

2. The computer security system based on artificial intelligence according to claim 1, characterized in that: The security-related data includes network communication data, operating system logs, and application logs.

3. The computer security system based on artificial intelligence according to claim 1, characterized in that: The step of analyzing and modeling the preprocessed data using machine learning and deep learning algorithms specifically includes: By establishing normal behavior models and abnormal behavior detection models, the system operation status can be monitored and security incidents can be identified.

4. The artificial intelligence-based computer security system according to claim 1, characterized in that: The threat intelligence sources include security vulnerability information, malicious code samples and network attack information.

5. The artificial intelligence-based computer security system according to claim 1, characterized in that: The step of automatically or semi-automatically formulating corresponding security decisions and response measures based on the results of the behavior analysis module and threat intelligence specifically includes: According to the severity of the security incident and the risk level of the threat, take appropriate control strategies and preventive measures to ensure the security of the system.

6. The artificial intelligence-based computer security system according to claim 1, characterized in that: The data acquisition module is sequentially connected in communication with the data preprocessing module, the behavior analysis module and the decision and response module.

7. The artificial intelligence-based computer security system according to claim 6, characterized in that: The decision and response module is communicatively connected to the threat intelligence integration module.

8. The artificial intelligence-based computer security system according to claim 1, characterized in that: The execution method of the computer security system based on artificial intelligence includes the following steps: Start the computer security system, initialize each module, and establish security policies and rules; The data acquisition module collects safety-related data in real time; The data preprocessing module cleans, denoises and unifies the collected data to obtain preprocessed data; The behavior analysis module uses machine learning and deep learning algorithms to analyze and model pre-processed data to identify abnormal behaviors and security threats; The threat intelligence integration module integrates various internal and external threat intelligence sources to provide real-time security intelligence support for the system; The decision and response module formulates corresponding security decisions and response measures based on the results of the behavior analysis module and threat intelligence to ensure the security of the system; Periodically update security rules and policies, and optimize and improve the system.