Intelligent traceability analysis system based on AI network security

By designing an AI-based intelligent traceability analysis system for network security, using deep learning to analyze historical network security events, summarizing and extracting effective traceability methods and strategies, the problem that network attack traceability systems in the existing technology cannot use AI for learning and optimization, and more efficient and targeted network defense is achieved.

CN119996062APending Publication Date: 2025-05-13GUANGDONG POWER GRID CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510379483.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing cyber attack traceability system can only play back the attack path and cannot use AI for learning and optimization, resulting in insufficient targeted and effective defense.

Method used

An intelligent network security traceability analysis system based on AI was designed, including data collection, AI learning, core processing and interactive display modules. Through deep learning, historical network security events are analyzed, and effective traceability methods and strategies are summarized and extracted.

Benefits of technology

It improves the pertinence and effectiveness of network defense, and monitors and optimizes system performance in real time through capability index and evaluation index, and promptly warns and adjusts defense strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996062A_ABST
    Figure CN119996062A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent traceability analysis system based on AI network security, and belongs to the technical field of network security. Comprising a data acquisition unit, a data storage and management unit, an AI learning unit, a network transmission unit, a core processing unit, a threshold setting unit, an instruction execution unit and an interactive display unit. And the data acquisition unit is used for acquiring various data required by the network security intelligent traceability analysis system. During analysis processing, the number of attacks, the number of times of attacks responded, the number of times of successfully withstanding attacks, the response duration of each attack, the data volume of each attack and the duration of processing and analyzing data of each attack can be acquired; and the data are analyzed and processed to obtain the capability index of the network security intelligent traceability analysis system, so that the capability of the network security intelligent traceability analysis system for processing network attack traceability analysis is judged according to the capability index of the network security intelligent traceability analysis system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to an AI-based network security intelligent tracing and analysis system. Background Art

[0002] Cyber ​​attacks are attacks on systems and resources by exploiting vulnerabilities and security flaws in network information systems. The threats faced by network information systems come from many aspects and will change over time. From a macro perspective, these threats can be divided into man-made threats and natural threats. Natural threats come from various natural disasters, harsh site environments, electromagnetic interference, and natural aging of network equipment. These threats are purposeless, but they will damage network communication systems and endanger communication security. Man-made threats are man-made attacks on network information systems, which achieve the purpose of destruction, deception, and theft of data information in an unauthorized manner by finding system weaknesses. Compared with the two, well-designed man-made attack threats are difficult to guard against, have many types, and are large in number. Existing network attack traceability mostly only replays the attack path and knows where the attacker came from. It fails to optimize the learning of attack cases based on AI to improve the pertinence and effectiveness of defense. Summary of the invention

[0003] Purpose of the invention: The purpose of the present invention is to provide an AI-based network security intelligent tracing and analysis system; it can solve the problem that the existing network attack tracing can only replay the attack path and know where the attacker comes from, but cannot optimize the learning of attack cases based on AI to improve the pertinence and effectiveness of defense.

[0004] Technical solution: To solve the above technical problems, according to one aspect of the present invention, more specifically, an AI network security intelligent tracing analysis system includes: a data collection unit, a data storage unit, an AI learning unit, a network transmission unit, a core processing unit, a threshold setting unit, an instruction execution unit, and an interactive display unit; Data collection unit: used to collect various data required by the network security intelligent tracing analysis system; Data storage unit: used to store and manage various data required by the network security intelligent tracing analysis system collected by the data collection unit; AI learning unit: used to obtain historical cybersecurity incident cases stored in the data storage unit, and after deep learning of the acquired historical cybersecurity incidents, summarize and extract effective tracing methods and strategies, and receive corresponding instructions issued by the core processing unit; Network transmission unit: used to transmit various data required by the network security intelligent source tracing analysis system collected by the data collection unit to the data storage unit, the core processing unit and the interactive display unit, and to transmit various data required by the network security intelligent source tracing analysis system stored in the data storage unit to the AI ​​learning unit, the core processing unit and the interactive display unit, and to transmit the report generated by the core processing unit to the interactive display unit; Core processing unit: used to receive various data transmissions required by the network security intelligent source tracing analysis system collected by the data collection unit and various data required by the network security intelligent source tracing analysis system stored by the data storage unit, analyze and process the above received data, generate corresponding reports according to the analysis and processing results, and issue corresponding instructions according to the analysis and processing results and the thresholds of the corresponding results; Threshold setting unit: used to set the corresponding threshold of the analysis and processing result of the core processing unit; Instruction execution unit: used to execute corresponding warning reminder operations according to the instructions issued by the core processing unit; Interactive display unit: used to receive the various data required by the network security intelligent tracing and analysis system collected by the data collection unit, the various data required by the network security intelligent tracing and analysis system stored by the data storage unit, and the report generated by the core processing unit, and display the above received information, and select the information to be viewed according to the required operations.

[0005] Furthermore, the data collection unit includes: an attack collection module, a duration collection module, a day collection module, and a number collection module; Attack collection module: used to collect various relevant data of network security incident cases of attacks required by the network security intelligent tracing analysis system; Duration collection module: used to collect various duration data required by the network security intelligent tracing analysis system; Days collection module: used to collect various data on days required by the network security intelligent tracing analysis system; Frequency collection module: used to collect various frequency data required by the network security intelligent tracing and analysis system.

[0006] Furthermore, the AI ​​learning unit includes: a case acquisition module, a deep learning module, and a summary and refinement module; Case acquisition module: used to acquire historical network security incident cases stored in the data storage unit; Deep learning module: used to conduct deep learning on historical cybersecurity incident cases acquired by the case acquisition module, and to re-perform deep learning after receiving corresponding instructions issued by the core processing unit to summarize and refine new tracing methods and strategies; Summary and refinement module: used to summarize and refine effective tracing methods and strategies based on the results of deep learning module after deep learning.

[0007] Furthermore, the core processing unit includes: a data receiving module, an analysis and processing module, a report generating module and an instruction issuing module; Data receiving module: used for receiving various data transmissions required by the network security intelligent source tracing analysis system collected by the data collection unit and various data required by the network security intelligent source tracing analysis system stored by the data storage unit; Analysis and processing module: used to analyze and process the data received by the data receiving module to obtain analysis and processing results; Report generation module: used to generate corresponding reports according to the analysis and processing results of the analysis and processing module; Instruction issuing module: used to issue corresponding instructions according to the analysis and processing results and the threshold of the corresponding results.

[0008] Furthermore, the interactive display module includes: a data receiving module, a data display module and an operation selection module; Data receiving module: used to receive various data required by the network security intelligent tracing and analysis system collected by the data collection unit, various data required by the network security intelligent tracing and analysis system stored by the data storage unit, and reports generated by the core processing unit; Data display module: used to display the data received by the data receiving module; Operation selection module: used to select the information to be viewed according to the required operations.

[0009] Furthermore, when performing analysis and processing, the analysis and processing module can obtain the number of attacks suffered, the number of attacks responded to, the number of attacks successfully resisted, the response time for each attack, the amount of data each time an attack occurs, and the time for processing and analyzing data each time an attack occurs, and analyze and process the above data to obtain the capability index of the network security intelligent source tracing analysis system, thereby determining the capability of the network security intelligent source tracing analysis system to handle network attack source tracing analysis based on the capability index of the network security intelligent source tracing analysis system. The higher the capability index of the network security intelligent source tracing analysis system, the higher the capability of the network security intelligent source tracing analysis system to handle network attack source tracing analysis; vice versa.

[0010] Furthermore, when performing analysis and processing, the analysis and processing module can obtain an evaluation index of the summary and refining method and strategy by analyzing and processing the number of attacks suffered, the number of attacks responded to, the number of false alarms, the number of missed reports, and the duration of each response to the attack after the summary and refining method and strategy are summarized and refined. Thus, according to the evaluation index of the summary and refining method and strategy, the pros and cons of the summary and refining method and strategy can be determined. The larger the evaluation index of the summary and refining method and strategy, the better the summary and refining method and strategy, and vice versa.

[0011] Furthermore, when the capability index of the network security intelligent source tracing analysis system does not exceed the set capability index of the network security intelligent source tracing analysis system, the instruction issuing module issues an instruction to issue a capability warning for the network security intelligent source tracing analysis system, so as to warn relevant personnel and promptly improve the performance of the network security intelligent source tracing analysis system; when the evaluation index of the summarized and refined methods and strategies does not exceed the set threshold of the evaluation index of the summarized and refined methods and strategies, an instruction is issued to abandon the current methods and strategies, re-perform deep learning, and summarize and refine new methods and strategies.

[0012] Beneficial effect: When performing analysis and processing, the system can obtain the number of attacks suffered, the number of attacks responded to, the number of attacks successfully resisted, the response time for each attack, the amount of data each time an attack occurs, and the time for processing and analyzing data each time an attack occurs, and analyze and process the above data to obtain the capability index of the network security intelligent source tracing analysis system, thereby determining the capability of the network security intelligent source tracing analysis system to handle network attack source tracing analysis based on the capability index of the network security intelligent source tracing analysis system. The higher the capability index of the network security intelligent source tracing analysis system, the higher the capability of the network security intelligent source tracing analysis system to handle network attack source tracing analysis; vice versa. At the same time, when analyzing and processing, the number of attacks suffered, the number of attacks responded, the number of false positive attacks, the number of missed positive attacks, and the duration of each attack response after the summary and extraction method and strategy are analyzed and processed to obtain the evaluation index of the summary and extraction method and strategy, so as to judge the pros and cons of the summary and extraction method and strategy according to the evaluation index of the summary and extraction method and strategy. The larger the evaluation index of the summary and extraction method and strategy, the better the summary and extraction method and strategy, and vice versa. The worse the summary and extraction method and strategy. And when the capability index of the network security intelligent tracing and analysis system does not exceed the set capability index of the network security intelligent tracing and analysis system, an instruction for capability warning of the network security intelligent tracing and analysis system is issued to warn relevant personnel and timely improve the performance of the network security intelligent tracing and analysis system; when the evaluation index of the summary and extraction method and strategy does not exceed the set threshold of the evaluation index of the summary and extraction method and strategy, an instruction is issued to abandon the current method and strategy, re-perform deep learning and summarize and extract new methods and strategies. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 It is a schematic diagram of the system principle. DETAILED DESCRIPTION

[0014] In order to make the technical solution of the present invention clearer, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments. Example

[0015] First, the attack collection module, duration collection module, day collection module and frequency collection module of the data collection are used to collect various relevant data of the network security incident cases suffered by the network security intelligent tracing analysis system, various data on duration required by the network security intelligent tracing analysis system, various data on days required by the network security intelligent tracing analysis system and various data on frequency required by the network security intelligent tracing analysis system. The data required by the network security intelligent tracing analysis system collected by the data collection unit is stored and managed through the data storage unit.

[0016] Then, the case acquisition module of the AI ​​learning unit acquires historical network security incident cases stored in the data storage unit, and performs deep learning on the historical network security incident cases acquired by the case acquisition module through the deep learning module. At the same time, after receiving the corresponding instructions issued by the core processing unit, it re-performs deep learning to summarize and refine new tracing methods and strategies. At the same time, the summary and refinement module summarizes and refines effective tracing methods and strategies according to the results of deep learning by the deep learning module.

[0017] Thirdly, the threshold setting unit sets the corresponding threshold of the analysis and processing result of the core processing unit, and the data receiving module of the core processing unit receives the various data transmissions required by the network security intelligent source tracing analysis system collected by the data collection unit and the various data required by the network security intelligent source tracing analysis system stored by the data storage unit. The analysis and processing module analyzes and processes the various data received by the data receiving module to obtain the analysis and processing result, and the report generation module generates a corresponding report according to the analysis and processing result of the analysis and processing module, and the instruction issuing module issues the corresponding instruction according to the analysis and processing result and the threshold of the corresponding result. The instruction execution unit executes the corresponding warning reminder operation according to the instruction issued by the core processing unit.

[0018] When performing analysis and processing, the analysis and processing module can obtain the number of attacks suffered, the number of attacks responded to, the number of attacks successfully resisted, the response time for each attack, the amount of data each time an attack occurs, and the time for processing and analyzing data each time an attack occurs, and analyze and process the above data to obtain the capability index of the network security intelligent source tracing analysis system, thereby determining the capability of the network security intelligent source tracing analysis system to handle network attack source tracing analysis based on the capability index of the network security intelligent source tracing analysis system. The higher the capability index of the network security intelligent source tracing analysis system, the higher the capability of the network security intelligent source tracing analysis system to handle network attack source tracing analysis; vice versa.

[0019] When performing analysis and processing, the analysis and processing module can obtain an evaluation index of the summary and refining method and strategy by analyzing and processing the number of attacks suffered, the number of attacks responded to, the number of false alarms, the number of missed attacks, and the duration of each response to the attack after the summary and refining method and strategy are summarized and refined. Thus, the advantages and disadvantages of the summary and refining method and strategy can be judged according to the evaluation index of the summary and refining method and strategy. The larger the evaluation index of the summary and refining method and strategy, the better the summary and refining method and strategy, and vice versa.

[0020] When the capability index of the network security intelligent source tracing analysis system does not exceed the set capability index of the network security intelligent source tracing analysis system, the instruction issuing module issues an instruction to issue a capability warning for the network security intelligent source tracing analysis system to warn relevant personnel and promptly improve the performance of the network security intelligent source tracing analysis system; when the evaluation index of the summary and refinement method and strategy does not exceed the set threshold of the evaluation index of the summary and refinement method and strategy, an instruction is issued to abandon the current method and strategy, re-perform deep learning and summarize and refine new methods and strategies.

[0021] Finally, the interactive display module and the data receiving module receive the various data required by the network security intelligent tracing and analysis system collected by the data collection unit, the various data required by the network security intelligent tracing and analysis system stored by the data storage unit, and the report generated by the core processing unit, and display the various data received by the data receiving module through the data display module, and can select the data to be viewed through the operation selection module as needed.

[0022] The above-mentioned embodiments only express several implementation methods of the present invention, and the description thereof is relatively specific and detailed, but it cannot be understood as limiting the scope of the patent of the present invention. It should be pointed out that, for ordinary technicians in this field, several variations and improvements can be made without departing from the concept of the present invention, which all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the attached claims.

Claims

1. Based on AI network security intelligent tracing analysis system, it is characterized by: include: Data collection unit, data storage unit, AI learning unit, network transmission unit, core processing unit, threshold setting unit, instruction execution unit and interactive display unit; Data collection unit: used to collect various data required by the network security intelligent tracing analysis system; Data storage unit: used to store and manage various data required by the network security intelligent tracing analysis system collected by the data collection unit; AI learning unit: used to obtain historical cybersecurity incident cases stored in the data storage unit, and after deep learning of the acquired historical cybersecurity incidents, summarize and extract effective tracing methods and strategies, and receive corresponding instructions issued by the core processing unit; Network transmission unit: used to transmit various data required by the network security intelligent source tracing analysis system collected by the data collection unit to the data storage unit, the core processing unit and the interactive display unit, and to transmit various data required by the network security intelligent source tracing analysis system stored in the data storage unit to the AI ​​learning unit, the core processing unit and the interactive display unit, and to transmit the report generated by the core processing unit to the interactive display unit; Core processing unit: used to receive various data transmissions required by the network security intelligent source tracing analysis system collected by the data collection unit and various data required by the network security intelligent source tracing analysis system stored by the data storage unit, analyze and process the above received data, generate corresponding reports according to the analysis and processing results, and issue corresponding instructions according to the analysis and processing results and the thresholds of the corresponding results; Threshold setting unit: used to set the corresponding threshold of the analysis and processing result of the core processing unit; Instruction execution unit: used to execute corresponding warning reminder operations according to the instructions issued by the core processing unit; Interactive display unit: used to receive the various data required by the network security intelligent tracing and analysis system collected by the data collection unit, the various data required by the network security intelligent tracing and analysis system stored by the data storage unit, and the report generated by the core processing unit, and display the above received information, and select the information to be viewed according to the required operations.

2. The AI ​​network security intelligent tracing analysis system according to claim 1 is characterized by: The data collection unit includes an attack collection module, a duration collection module, a day collection module and a number collection module; Attack collection module: used to collect various relevant data of network security incident cases of attacks required by the network security intelligent tracing analysis system; Duration collection module: used to collect various duration data required by the network security intelligent tracing analysis system; Days collection module: used to collect various data on days required by the network security intelligent tracing analysis system; Frequency collection module: used to collect various frequency data required by the network security intelligent tracing and analysis system.

3. The AI ​​network security intelligent tracing analysis system according to claim 1 is characterized by: The AI ​​learning unit includes: a case acquisition module, a deep learning module, and a summary and refinement module; Case acquisition module: used to acquire historical network security incident cases stored in the data storage unit; Deep learning module: used to conduct deep learning on historical cybersecurity incident cases acquired by the case acquisition module, and to re-perform deep learning after receiving corresponding instructions issued by the core processing unit to summarize and refine new tracing methods and strategies; Summary and refinement module: used to summarize and refine effective tracing methods and strategies based on the results of deep learning module after deep learning.

4. The AI ​​network security intelligent tracing analysis system according to claim 1 is characterized by: The core processing unit includes: a data receiving module, an analysis and processing module, a report generating module and an instruction issuing module; Data receiving module: used for receiving various data transmissions required by the network security intelligent source tracing analysis system collected by the data collection unit and various data required by the network security intelligent source tracing analysis system stored by the data storage unit; Analysis and processing module: used to analyze and process the data received by the data receiving module to obtain analysis and processing results; Report generation module: used to generate corresponding reports according to the analysis and processing results of the analysis and processing module; Instruction issuing module: used to issue corresponding instructions according to the analysis and processing results and the threshold of the corresponding results.

5. The AI ​​network security intelligent tracing analysis system according to claim 1 is characterized by: The interactive display module includes: a data receiving module, a data display module and an operation selection module; Data receiving module: used to receive various data required by the network security intelligent tracing and analysis system collected by the data collection unit, various data required by the network security intelligent tracing and analysis system stored by the data storage unit, and reports generated by the core processing unit; Data display module: used to display the data received by the data receiving module; Operation selection module: used to select the information to be viewed according to the required operations.

6. The AI ​​network security intelligent tracing analysis system according to claim 1 is characterized by: When performing analysis and processing, the analysis and processing module can obtain the number of attacks suffered, the number of attacks responded to, the number of attacks successfully resisted, the response time for each attack, the amount of data each time an attack occurs, and the time for processing and analyzing data each time an attack occurs, and analyze and process the above data to obtain the capability index of the network security intelligent source tracing analysis system, thereby determining the capability of the network security intelligent source tracing analysis system to handle network attack source tracing analysis based on the capability index of the network security intelligent source tracing analysis system. The higher the capability index of the network security intelligent source tracing analysis system, the higher the capability of the network security intelligent source tracing analysis system to handle network attack source tracing analysis; vice versa.

7. The AI ​​network security intelligent tracing analysis system according to claim 1 is characterized by: When performing analysis and processing, the analysis and processing module can obtain an evaluation index of the summary and refinement method and strategy by analyzing and processing the number of attacks suffered, the number of attacks responded to, the number of false alarms, the number of missed attacks, and the duration of each response to the attack after the summary and refinement method and strategy are summarized and refined. Therefore, according to the evaluation index of the summary and refinement method and strategy, the pros and cons of the summary and refinement method and strategy can be determined. The larger the evaluation index of the summary and refinement method and strategy, the better the summary and refinement method and strategy, and vice versa.

8. The AI ​​network security intelligent tracing analysis system according to claim 1 is characterized by: When the capability index of the network security intelligent source tracing analysis system does not exceed the set capability index of the network security intelligent source tracing analysis system, the instruction issuing module issues an instruction to issue a capability warning for the network security intelligent source tracing analysis system, so as to warn relevant personnel and promptly improve the performance of the network security intelligent source tracing analysis system; when the evaluation index of the summarized and refined methods and strategies does not exceed the set threshold of the evaluation index of the summarized and refined methods and strategies, the instruction issuing module issues an instruction to abandon the current methods and strategies, re-perform deep learning, and summarize and refine new methods and strategies.