Network data security management system based on artificial intelligence

By adopting a traffic monitoring method based on artificial intelligence in the network data security management system, the problem of DDoS attack detection lag in the existing technology is solved, and refined monitoring and real-time identification of network traffic is realized, and the response efficiency to potential attacks is improved.

CN120050081AInactive Publication Date: 2025-05-27邝俊维
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510188853.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-05-27
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The prior art has lag in detecting denial of service attacks (DDoS), resulting in the security of network data being affected when an attack occurs.

Method used

Using an artificial intelligence-based network data security management system, by dividing network traffic data into multiple short time periods, generating coordinate points and calculating theoretical center of gravity, combining the fitting curve to monitor network traffic in real time, identifying abnormal deviation values ​​to warn of potential attacks.

Benefits of technology

It realizes refined sampling and real-time monitoring of network traffic fluctuations, can identify DDoS attacks more timely, reduce misjudgments caused by normal business fluctuations, and improve monitoring and response efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050081A_ABST
    Figure CN120050081A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to the technical field of data security, and particularly discloses a network data security management system based on artificial intelligence, and the system comprises an acquisition module which collects network traffic, draws a curve of the network traffic changing with time, and obtains traffic data; the analysis module is used for determining a reference point, determining the theoretical gravity center of the reference point and calculating the density of coordinate points; adjusting the first radius, recording the density of the coordinate points, determining the target density, and determining the theoretical gravity center of the target point; standard points are generated, and a fitting curve is obtained; the judgment module is used for collecting real-time flow data; obtaining a prediction point and calculating a deviation value; and judging whether the server is abnormal or not. According to the embodiment of the invention, abnormal conditions can be found earlier, and the corresponding processing efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data security, and particularly to an artificial intelligence-based network data security management system. Background Art

[0002] Network data security refers to the comprehensive work of protecting the data stored, transmitted, and processed in the network from unauthorized access, tampering, leakage, or destruction through various technical, management, and institutional means. With the popularization of the Internet and the acceleration of digital transformation, the importance of network data security has become increasingly prominent.

[0003] Denial-of-service attack (DDoS) is a very common and serious means of attacking network data security. Attackers send a large number of junk requests to servers or network devices, making it impossible for normal users to access the target system, thereby indirectly causing the unavailability or even loss of data. In the prior art, most defense measures rely on real-time monitoring of network traffic to determine whether a denial-of-service attack has occurred. For example, when the monitored traffic exceeds a preset threshold, the corresponding handling process will be initiated. However, since this monitoring and response mechanism is usually triggered after the attack traffic surges, there is a certain lag, and at this time, the security of network data has often been affected to varying degrees. Summary of the Invention

[0004] The purpose of this application is to provide an artificial intelligence-based network data security management system to solve the following technical problems:

[0005] In the prior art, most defense measures rely on real-time monitoring of network traffic to determine whether a denial-of-service attack has occurred. For example, when the monitored traffic exceeds a preset threshold, the corresponding handling process will be initiated. However, since this monitoring and response mechanism is usually triggered after the attack traffic surges, there is a certain lag, and at this time, the security of network data has often been affected to varying degrees.

[0006] The purpose of this application can be achieved through the following technical solutions:

[0007] This application proposes an artificial intelligence-based network data security management system, including:

[0008] Collection module: Divide a preset first time period into several time periods of the same length, the length of the time period is a preset length, collect network traffic within the time period, draw a curve g(t) of the network traffic changing with time, where t represents time, and obtain traffic data based on the curve g(t). The traffic data includes the average network traffic A1 and the maximum network traffic A2;

[0009] Analysis module: Generate coordinate points (A1, A2), use the coordinate points corresponding to m first time periods as reference points, where m is a preset quantity, obtain the theoretical center of gravity CCK (AL1, AL2) of the reference points, AL1 and AL2 respectively represent the mean value of the average network traffic A1 corresponding to the reference points and the mean value of the maximum network traffic A2 corresponding to the reference points. Taking the theoretical center of gravity (AL1, AL2) as the center, calculate the coordinate point density within a preset first radius;

[0010] Increase the first radius at a preset radius interval, and record the corresponding coordinate point density each time the first radius is increased. Take the coordinate point density greater than or equal to the preset density threshold as the pending density, take the pending density with the largest corresponding first radius as the target density, take the reference point corresponding to the target density as the target point, and obtain the theoretical center of gravity CMB (AM1, AM2) of the target point, where AM1 and AM2 respectively represent the mean value of the average network traffic A1 corresponding to the target point and the mean value of the maximum network traffic A2 corresponding to the target point;

[0011] Generate standard points (Ti, AM1i, AM2i), where the time point Ti represents the time corresponding to the midpoint of the first time period i, and AM1i and AM2i respectively represent the theoretical center of gravity of the target point corresponding to the first time period i. Fit the standard points to obtain the fitting curve f(t);

[0012] Judgment module: Real-time collect network traffic within a preset monitoring time period, defined as real-time traffic, obtain the traffic data of the real-time traffic and use it as real-time traffic data; Determine the point on the fitting curve corresponding to the time of the real-time traffic, take it as the prediction point, and obtain the average network traffic AB1 and the maximum network traffic AB2 corresponding to the prediction point; Calculate the deviation value P = |AB1 - AS1| + |AB2 - AS2|, where AS1 and AS2 respectively represent the average network traffic and the maximum network traffic in the real-time traffic data;

[0013] Calculate the average deviation value, and take the deviation value whose difference from the average deviation value is greater than the preset value and greater than the average deviation value as the abnormal deviation value, and send a message to prompt the user that there is an abnormality in the server corresponding to the abnormal deviation value.

[0014] As a further solution of this application: In the acquisition module, the process of obtaining the traffic data specifically includes:

[0015] Calculate the average network traffic [t1, t2] represents the domain of the curve g(t);

[0016] Calculate the maximum network traffic A2 = max(g(t)).

[0017] As a further solution of the present application: in the analysis module, the coordinate point density K = N / (πr²), where N represents the number of coordinate points within the first radius.

[0018] As a further solution of the present application: in the judgment module, when the real-time traffic is greater than or equal to the preset network traffic security threshold, a warning message is sent to prompt the user that there is an abnormality in the corresponding server.

[0019] As a further solution of the present application: the analysis module further includes the following steps:

[0020] When the distance between the reference point and the theoretical centroid CCK is greater than or equal to the preset distance threshold, remove the reference point and re-determine the new theoretical centroid CCK.

[0021] As a further solution of the present application: in the acquisition module, when there is network traffic greater than or equal to the network traffic security threshold within the first time period a, remove the first time period a and determine a new first time period to replace the first time period a.

[0022] As a further solution of the present application: the acquisition module further includes the following steps:

[0023] When the curve g(t) is monotonically increasing, do not perform the subsequent steps, determine that there is an abnormality in the corresponding server, and send a warning message for prompt;

[0024] When the curve g(t) is monotonically decreasing, do not perform the subsequent steps, and determine that there is no abnormality in the corresponding server.

[0025] As a further solution of the present application: in the judgment module, when the average deviation exceeds the preset average deviation value, all servers greater than the preset deviation value threshold are regarded as abnormal servers, and the user is prompted to handle them.

[0026] The beneficial effects of the present application at least include:

[0027] By dividing a relatively long time period into multiple short time periods of the same length, the system can record the network traffic conditions within each short time period with a finer granularity, which can more accurately depict the fluctuation trajectory of the network traffic at different moments. It should be noted that if only a relatively large time window is used, it is very likely that the instantaneous peak traffic or short-term surge will be buried in the average value of a longer period. After splitting the long time period, it is possible to capture relatively instantaneous abnormal increases or decreases. For attack methods such as DDoS attacks, which are often characterized by suddenness and concentration, this refined sampling can enable the system to maintain a more sensitive sense of smell for suspicious behaviors. Subsequently, based on the average traffic and maximum traffic collected within m first short time periods, corresponding coordinate points are generated respectively. These coordinate points can intuitively reflect the traffic distribution on a two-dimensional plane. Next, the system will obtain a theoretical centroid based on these coordinate points, using this as the approximate central position of the "normal" traffic during this period, and examine the density of these coordinate points within a certain range. Then, through the iteration and optimization of the first radius, a batch of coordinates with the largest radius that still meet the requirements in terms of density are selected as target points, and a new theoretical centroid is calculated from them. This progressive screening method can enable the system to have a more stable and accurate description of the "normal" traffic, filtering out overly scattered outliers on the one hand, and taking into account the large-scale fluctuations that may occur in normal operations on the other hand. Then, by matching the theoretical centroids of these target points corresponding to each time period with the specific time, the system can obtain a series of standard points, and then fit these standard points to generate a curve that changes with time. This curve can be regarded as a description of the evolution trend of the "normal" traffic, giving the system a rough reference for the traffic expectation value at different time points. Finally, by continuously collecting the instant network traffic and calculating the deviation between these new data and the reference information obtained previously, a deviation value is obtained. If the deviation value of the server shows a deviation from the average state, it may be caused by a targeted attack.

[0028] It can be understood that if the average traffic or maximum traffic of a certain server is inconsistent with the overall trend, it often means that it may be impacted by abnormal traffic, rather than simply relying on a pre-set fixed threshold to determine whether there is abnormal traffic. This can not only more timely identify possible DDoS attacks, but also effectively reduce misjudgments caused by normal business fluctuations. By cross-referencing among multiple servers, the traffic anomalies of individual or a small number of servers can be accurately located, so that rapid response measures can be taken when any sudden and concentrated traffic deviation is discovered, improving the efficiency of monitoring and response. Brief Description of the Drawings

[0029] The present application will be further described below in conjunction with the drawings.

[0030] Figure 1It is a schematic flow diagram of the network data security management system based on artificial intelligence in this application. Specific implementation manners

[0031] To more fully understand the technical content of this application, the following will further introduce and explain this application in combination with the accompanying drawings and specific embodiments; it should be noted that the orientation or positional relationship indicated by terms such as "upper", "lower", "front", "rear", "inner", "outer", etc. is not the orientation or positional relationship shown in the accompanying drawings. It is only for the convenience of describing this application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, so it cannot be understood as a limitation to this application. In addition, descriptions such as "first", "second", etc. are used to distinguish different components, etc., do not represent a sequence, and do not limit that "first" and "second" are of different types.

[0032] The following will clearly and completely describe the technical solutions in the embodiments of this application in combination with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments; based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of this application.

[0033] Embodiment

[0034] Please refer to Figure 1 As shown, the embodiment of this application provides a network data security management system based on artificial intelligence, including:

[0035] Collection module: Divide a preset first time period into several time periods with the same length. The length of the time period is a preset length. Collect network traffic within the time period, draw a curve g(t) of the network traffic changing with time, where t represents time, and obtain traffic data based on the curve g(t). The traffic data includes the average network traffic A1 and the maximum network traffic A2;

[0036] Analysis module: Generate coordinate points (A1, A2), use the coordinate points corresponding to m first time periods as reference points, where m is a preset quantity, obtain the theoretical centroid CCK(AL1, AL2) of the reference points, where AL1 and AL2 respectively represent the mean value of the average network traffic A1 corresponding to the reference points and the mean value of the maximum network traffic A2 corresponding to the reference points, and calculate the coordinate point density within a preset first radius with the theoretical centroid (AL1, AL2) as the center;

[0037] Increase the first radius at preset radius intervals. After each increase of the first radius, record the corresponding coordinate point density. Take the coordinate point density greater than or equal to the preset density threshold as the pending density, take the pending density with the largest corresponding first radius as the target density, take the reference point corresponding to the target density as the target point, and obtain the theoretical centroid CMB(AM1, AM2) of the target point, where AM1 and AM2 respectively represent the mean of the average network traffic A1 corresponding to the target point and the mean of the maximum network traffic A2 corresponding to the target point;

[0038] Generate standard points (Ti, AM1i, AM2i), where the time point Ti represents the time corresponding to the midpoint of the first time period i, and AM1i and AM2i respectively represent the theoretical centroids of the target points corresponding to the first time period i. Fit the standard points to obtain the fitting curve f(t);

[0039] Judgment module: Real-time collect network traffic within a preset monitoring period, defined as real-time traffic, obtain the traffic data of the real-time traffic and use it as real-time traffic data; Determine the point on the fitting curve corresponding to the time of the real-time traffic, take it as the prediction point, and obtain the average network traffic AB1 and the maximum network traffic AB2 corresponding to the prediction point; Calculate the deviation value P = |AB1 - AS1| + |AB2 - AS2|, where AS1 and AS2 respectively represent the average network traffic and the maximum network traffic in the real-time traffic data;

[0040] Calculate the average deviation value, take the deviation value whose difference from the average deviation value is greater than the preset value and greater than the average deviation value as the abnormal deviation value, and send a message to prompt the user that there is an abnormality in the server corresponding to the abnormal deviation value.

[0041] It should be noted that by dividing a long time period into multiple short time periods of the same length, the system can record the network traffic situation in each short time period with a finer granularity, so that the fluctuation trajectory of the network traffic at different moments can be depicted more accurately; It is worth noting that if only a large time window is used, it is very likely to bury the instantaneous peak traffic or short-term surge in the average value of a long period. After splitting the long period, the relatively instantaneous abnormal increase or decrease can be captured. For attack means such as DDoS attacks that are often characterized by suddenness and concentration, this refined sampling can make the system more sensitive to suspicious behaviors.

[0042] After that, according to the average flow rate and the maximum flow rate collected from the m first long and short inner linings, corresponding coordinate points are generated respectively. These coordinate points can visually reflect the flow distribution on a two-dimensional plane. Next, the system will obtain a theoretical centroid based on these coordinate points, which is used as the approximate central position of the "normal" flow during this period, and the density of these coordinate points is examined within a certain range. Then, through the iteration and optimization of the first radius, a batch of coordinates with the largest radius that still meet the requirements are selected as target points, and a new theoretical centroid is calculated from them. This progressive screening method can enable the system to have a more stable and accurate description of the "normal" flow. Based on this, on the one hand, outliers that are too scattered are filtered out, and on the other hand, large-scale fluctuations that may occur in normal operations can also be taken into account.

[0043] Then, the theoretical centroids of these target points corresponding to each time period are matched with the specific time. The system can obtain a series of standard points, and then fit these standard points to generate a curve that changes with time. This curve can be regarded as a description of the evolution trend of the "normal" flow, giving the system a rough reference for the flow expectation value at different time points. Finally, by continuously collecting the instant network flow and calculating the deviation value from the reference information obtained previously, if the deviation value of the server shows a deviation from the average state, it may be caused by a targeted attack.

[0044] It can be understood that if the average flow rate or the maximum flow rate of a certain server is inconsistent with the overall trend, it often means that it may be impacted by abnormal traffic, rather than simply relying on a pre-set fixed threshold to determine whether there is abnormal traffic. This can not only identify possible DDoS attacks more timely but also effectively reduce misjudgments caused by normal business fluctuations. By cross-referencing among multiple servers, the traffic anomalies of individual or a small number of servers can be accurately located, so that rapid response measures can be taken when any sudden and concentrated traffic deviation is found, improving the efficiency of monitoring and response.

[0045] In another preferred embodiment of the present application, in the acquisition module, the process of obtaining the traffic data specifically includes:

[0046] Calculate the average network flow rate [t1, t2] represents the domain of the curve g(t);

[0047] Calculate the maximum network flow rate A2 = max(g(t)).

[0048] It should be noted that in this preferred embodiment, by first obtaining the average network traffic during the time period [t1, t2] of the curve g(t), which can better reflect the "normal" level of the overall business during this time period, and then obtaining the maximum network traffic A2 = max(g(t)), the possible peak values within the time period can be effectively captured.

[0049] In another preferred embodiment of the present application, in the analysis module, the coordinate point density K = N / (πr2), where N represents the number of coordinate points within the first radius.

[0050] It can be understood that when drawing a circle with the theoretical centroid as the center and r as the radius, it is necessary to first know how many coordinate points (i.e., N) fall within this circle, and then divide N by the area of the circle (πr 2 ), to obtain a density value of "the number of coordinate points per unit area". The advantage of doing this is that it can intuitively quantify whether the distribution of coordinate points in the target area is dense. If the density is low within a certain radius range, it means that the traffic distribution during these time periods is relatively dispersed and not sufficient to represent the "stable" normal state; if the density is high within a certain radius range, it means that these points are mostly clustered together, which can reflect more concentrated and reliable traffic characteristics.

[0051] In another preferred embodiment of the present application, in the judgment module, when the real-time traffic is greater than or equal to the preset network traffic security threshold, a warning message is sent to prompt the user that the corresponding server is abnormal.

[0052] It can be understood that in actual situations, there may be a sudden increase in traffic in extreme cases. The system can remind the operation and maintenance personnel in the shortest time, without waiting for a more complex analysis process to draw a conclusion; its purpose is to provide a fast alarm channel for possible large-scale or sudden attacks (such as a large number of malicious requests increasing suddenly in a short time), to prevent the instantaneous exhaustion of network resources.

[0053] In another preferred embodiment of the present application, the analysis module further includes the following steps:

[0054] When the distance between the reference point and the theoretical centroid CCK is greater than or equal to the preset distance threshold, remove this reference point and re-determine the new theoretical centroid CCK.

[0055] It should be noted that by removing the reference point when the distance between the reference point and the theoretical center of gravity CCK exceeds the preset distance threshold and recalculating the new theoretical center of gravity, it is possible to effectively eliminate points that are too discrete or deviate significantly, preventing these "extreme" reference points from causing too large a deviation in the overall theoretical center of gravity; the new theoretical center of gravity can more accurately represent the "normal" traffic distribution corresponding to most reference points, making the subsequent analysis and determination links more stable and robust; the purpose is to avoid interference from a few abnormal points (which may be noise values or temporary extreme fluctuations) to the global judgment.

[0056] In another preferred embodiment of the present application, in the acquisition module, when there is network traffic greater than or equal to the network traffic security threshold within the first time period a, the first time period a is removed, and a new first time period is determined to replace the first time period a.

[0057] It should be noted that in this preferred embodiment, when the network traffic within a certain first time period has reached or exceeded the network traffic security threshold preset by the system, this time period will be directly discarded and replaced with a new time period. This can exclude extreme high traffic peaks or instantaneous anomalies from the overall traffic analysis reference range, avoiding subsequent "benchmark" distortion caused by large-scale malicious traffic or sudden business peaks during a certain period; by discarding these time periods known to have extreme situations, the reference values and theoretical centers of gravity obtained by the system will be more in line with the true business operation level in most time periods, so that when judging and comparing whether there are anomalies in the traffic of other time periods, it can more sensitively and accurately identify suspicious traffic and reduce the false alarm probability, and can more safely capture real abnormal bursts for DDoS detection.

[0058] In another preferred embodiment of the present application, the acquisition module further includes the following steps:

[0059] When the curve g(t) is monotonically increasing, the subsequent steps are not executed, it is determined that the corresponding server is abnormal, and a warning message is sent for prompt;

[0060] When the curve g(t) is monotonically decreasing, the subsequent steps are not executed, and it is determined that the corresponding server is normal.

[0061] It is worth noting that if g(t) shows a monotonically increasing trend, it means that the traffic during this period has been continuously increasing, and it is very likely to be caused by a large traffic attack. Therefore, it is directly determined that the corresponding server is abnormal and a warning message is sent; if g(t) shows a monotonically decreasing trend, it means that the traffic as a whole gradually decreases during this period, which usually conforms to the situation where normal business declines after the peak. Therefore, it is determined that the corresponding server is not abnormal; when the increasing or decreasing trend of the traffic is very obvious and relatively stable, a preliminary judgment can be made without investing more analysis steps, quickly identifying potential attack or non-attack situations, so as to improve the efficiency and timeliness of the entire detection process.

[0062] In another preferred embodiment of the present application, in the analysis module,

[0063] In the judgment module, when the average deviation exceeds the preset average deviation value, all servers greater than the preset deviation value threshold are regarded as abnormal servers, and the user is prompted to handle them.

[0064] The technical solutions provided by the embodiments of the present application have been introduced in detail above. Specific examples are used in this article to elaborate on the principles and implementation manners of the embodiments of the present application. The descriptions of the above embodiments are only applicable to help understand the principles of the embodiments of the present application; at the same time, for those of ordinary skill in the art, based on the embodiments of the present application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present application.

Claims

1. A network data security management system based on artificial intelligence, characterized in that: include: Collection module: divide the preset first time period into a number of time periods of the same length, the length of the time period is the preset length, collect network traffic within the time period, draw a curve g(t) showing the change of network traffic over time, t represents time, and obtain traffic data based on the curve g(t), the traffic data includes average network traffic A1 and maximum network traffic A2; Analysis module: Generate coordinate points (A1, A2), take m coordinate points corresponding to the first time period as reference points, where m is a preset number, obtain the theoretical center of gravity CCK (AL1, AL2) of the reference points, AL1 and AL2 respectively represent the mean of the average network flow A1 corresponding to the reference point and the mean of the maximum network flow A2 corresponding to the reference point, and calculate the density of coordinate points within a preset first radius with the theoretical center of gravity (AL1, AL2) as the center; Increase the first radius at a preset radius interval, and after each increase of the first radius, record the corresponding coordinate point density, take the coordinate point density greater than or equal to the preset density threshold as the pending density, take the corresponding first radius with the largest pending density as the target density, take the reference point corresponding to the target density as the target point, and obtain the theoretical center of gravity CMB (AM1, AM2) of the target point, AM1 and AM2 respectively represent the mean of the average network flow A1 corresponding to the target point and the mean of the maximum network flow A2 corresponding to the target point; Generate standard points (Ti, AM1i, AM2i), where time point Ti represents the time corresponding to the midpoint of the first time period i, and AM1i and AM2i represent the theoretical center of gravity of the target point corresponding to the first time period i, respectively. Fit the standard points to obtain a fitting curve f(t); Judgment module: collect network traffic in real time within a preset monitoring period, define it as real-time traffic, obtain traffic data of the real-time traffic, and use it as real-time traffic data; Determine the point on the fitting curve at the time corresponding to the real-time traffic, use it as the prediction point, and obtain the average network traffic AB1 and the maximum network traffic AB2 corresponding to the prediction point; calculate the deviation value P = |AB1-AS1|+|AB2-AS2|, AS1 and AS2 respectively represent the average network traffic and the maximum network traffic in the real-time traffic data; The average deviation value is calculated, and the deviation value whose difference with the average deviation value is greater than a preset value and greater than the average deviation value is taken as an abnormal deviation value, and information is sent to the user to prompt that the server corresponding to the abnormal deviation value has an abnormality.

2. The network data security management system based on artificial intelligence according to claim 1 is characterized in that: In the acquisition module, the process of obtaining the flow data specifically includes: Calculate average network traffic [t1, t2] represents the domain of the curve g(t); Calculate the maximum network flow A2 = max(g(t)).

3. The network data security management system based on artificial intelligence according to claim 1 is characterized in that: In the analysis module, the coordinate point density K=N / (πr2), where N represents the number of coordinate points within the first radius.

4. The network data security management system based on artificial intelligence according to claim 1 is characterized in that: In the judgment module, when the real-time traffic is greater than or equal to a preset network traffic security threshold, an early warning message is sent to prompt the user that the corresponding server has an abnormality.

5. The network data security management system based on artificial intelligence according to claim 1 is characterized in that: The analysis module further comprises the following steps: When the distance between the reference point and the theoretical center of gravity CCK is greater than or equal to a preset distance threshold, the reference point is removed and a new theoretical center of gravity CCK is determined again.

6. The network data security management system based on artificial intelligence according to claim 4 is characterized in that: In the acquisition module, when there is network traffic greater than or equal to the network traffic security threshold in the first time period a, the first time period a is removed, and a new first time period is determined to replace the first time period a.

7. The network data security management system based on artificial intelligence according to claim 1 is characterized in that: The acquisition module further includes the following steps: When the curve g(t) increases monotonically, the subsequent steps are not executed, it is determined that the corresponding server is abnormal, and an early warning message is sent to prompt; When the curve g(t) decreases monotonically, the subsequent steps are not executed, and it is determined that there is no abnormality in the corresponding server.

8. The network data security management system based on artificial intelligence according to claim 1 is characterized in that: In the judgment module, when the average deviation exceeds a preset average deviation value, all servers with deviation values ​​greater than a preset threshold are regarded as abnormal servers, and the user is prompted to handle the problem.

Citation Information

Cited By

  • Data intelligent optimization system and method based on artificial intelligence

    CN120880914A