Network security analysis method and system based on privatized generative artificial intelligence
Through the network security analysis method based on privatized generative artificial intelligence, a structured feature library and generation of adversarial samples are built, combined with heterogeneous neural networks and transfer learning technology, the data island and static feature engineering problems of the traditional network security defense system are solved, and efficient identification and response to dynamic attack behavior is achieved.
Patent Information
- Application Number
- CN202510250189.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-04
- Publication Date
- 2025-05-27
AI Technical Summary
Traditional network security defense systems have problems with data silos, static feature engineering and defense strategy lag, making it difficult to effectively identify and deal with dynamic attack behavior.
A network security analysis method based on privatized generative artificial intelligence is adopted to capture network traffic, user behavior logs and security events, build a structured feature library, train a generative adversarial network to generate high-fidelity adversarial samples, and generate dynamic risk vectors through a heterogeneous neural network detection engine, combining transfer learning and game theory optimization mechanisms to generate dynamic cache strategies and defense measures.
It realizes efficient identification and response to dynamic attack behavior, improves cache hit rate and attack detection accuracy, reduces misjudgment rate, and supports rapid cross-scene adaptation.
Smart Images

Figure CN120050109A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to a network security analysis method and system based on privatized generative artificial intelligence. Background Art
[0002] With the acceleration of digital transformation, network security faces dual challenges of new attack means (such as zero-day vulnerabilities, APT attacks) and massive heterogeneous data (network traffic, user behavior, security events). The traditional defense system is based on rule matching and static feature engineering, and has three major limitations: First, the data island problem makes it difficult to integrate multi-source information (such as traffic patterns and user intentions), resulting in insufficient threat detection coverage; Second, static feature engineering cannot adapt to dynamic attack behaviors, and is prone to missed detections and misjudgments; Third, the lag of defense strategies is reflected in the disconnection between cache resource allocation and risk perception, and it is difficult to cope with sudden traffic anomalies and long-term trend risks.
[0003] In recent years, although progress has been made in adversarial sample enhancement based on generative artificial intelligence and complex feature learning techniques of heterogeneous neural networks, there is still a lack of refined modeling of the dynamic boundaries of business scenarios, and the closed-loop coordination of attack detection, resource scheduling, and automated response has not been achieved. Summary of the Invention
[0004] In view of the above existing problems, the present invention is proposed.
[0005] Therefore, the present invention provides a network security analysis method based on privatized generative artificial intelligence to solve the problems of static feature engineering and lagging defense strategies.
[0006] To solve the above technical problems, the present invention provides the following technical solutions:
[0007] In a first aspect, the present invention provides a network security analysis method based on privatized generative artificial intelligence, which includes capturing network traffic, user behavior logs, and security events, constructing a mixed data set through abnormal traffic marking, log repair, and feature standardization to form a structured feature library; based on the structured feature library, training a generative adversarial network to generate high-fidelity adversarial samples and injecting them into the structured feature library through dynamic weight factors; based on the adjusted structured feature library, constructing a heterogeneous neural network detection engine to generate dynamic risk vectors by fusing temporal correlation, semantic features, and regional boundary information; using transfer learning technology to predict the probability of users' future resource access, and combining with the dynamic risk vectors to generate a dynamic cache policy; capturing attack events in the dynamic cache policy through a comprehensive detection strategy, triggering an automated response mechanism optimized based on game theory, and generating defense measures.
[0008] As a preferred solution of the network security analysis method based on privatized generative artificial intelligence of the present invention, wherein:
[0009] The formation of the structured feature library includes the following steps:
[0010] Hierarchically extract the data of abnormal traffic marking, log repair, and feature standardization, and construct an attack pattern knowledge graph;
[0011] Define the regional boundaries of the security area, risk transition area, and attack area based on business logic;
[0012] Merge the constructed attack pattern knowledge graph with the defined regional boundaries to form a structured feature library.
[0013] As a preferred solution of the network security analysis method based on privatized generative artificial intelligence according to the present invention, wherein:
[0014] The generation of high-fidelity adversarial samples includes the following steps:
[0015] Extract the regional boundaries of the security area, risk transition area, and attack area from the structured feature library;
[0016] Use the regional feature embedding technology to convert the regional boundaries into a continuous vector space representation, and generate regional boundary embedding vectors;
[0017] Load the attack pattern feature vectors from the attack pattern knowledge graph;
[0018] Perform dual-branch attention fusion of the regional boundary embedding vectors and the attack pattern feature vectors on the behavior prediction branch and the protocol generation branch to generate multi-modal high-fidelity adversarial samples.
[0019] As a preferred solution of the network security analysis method based on privatized generative artificial intelligence according to the present invention, wherein:
[0020] The construction of the heterogeneous neural network detection engine, which fuses temporal correlation, semantic features, and regional boundary information to generate dynamic risk vectors, includes the following steps:
[0021] Extract temporal features, semantic features, and regional boundary features from the adjusted structured feature library;
[0022] Based on the temporal features, construct an undirected graph structure, and perform two-layer jump graph walks through the neighbor aggregation mechanism of the improved GraphSAGE network to capture the traffic temporal patterns in the temporal graph blocks, and output temporal correlation feature vectors;
[0023] Adopt a dynamic routing capsule network to automatically select the optimal feature subspace for semantic features, and capture the context semantics of the attack payload and the strength of the attack intention through the digital capsule layer, and output high-order semantic feature vectors;
[0024] Construct a three-layer attention gating mechanism, input the regional boundary features into the gating attention mechanism, dynamically adjust the weight distribution of temporal and semantic features, and establish a constraint relationship between features through regional similarity calculation;
[0025] Based on the constraint relationship between features, weighted fuse the adjusted weights with the temporal correlation feature vector, the high-order semantic feature vector, and the regional boundary features to output the final risk vector.
[0026] As a preferred solution of the network security analysis method based on privatized generative artificial intelligence described in the present invention, wherein:
[0027] The use of transfer learning technology to predict the future resource access probability of users includes the following steps,
[0028] Extract the request data in the user behavior log in the structured feature library, aggregate the data by user ID, and generate a user behavior sequence;
[0029] Slice the user behavior sequence into windows of a fixed length, and intercept the last behavior as the prediction target;
[0030] Load the pre-trained BERT-base model in the financial transaction scenario, replace the last layer of the pre-trained BERT-base model with a custom output layer to obtain a fine-tuned BERT-base model;
[0031] Input the intercepted last behavior into the fine-tuned BERT-base model to predict the future resource access probability distribution of the user.
[0032] As a preferred solution of the network security analysis method based on privatized generative artificial intelligence described in the present invention, wherein:
[0033] The generation of a dynamic caching policy by combining dynamic risk vectors includes the following steps,
[0034] Combine the dynamic risk vector with the predicted future resource access probability distribution of the user to generate a joint feature;
[0035] Based on the joint feature, construct a state transition matrix, calculate the transition probability, and generate a hot resource access probability curve optimized based on a Markov chain;
[0036] Use double failure detection based on long-term trend anomalies and burst traffic anomalies to correct the hot resource access probability curve;
[0037] Based on the correction result, calculate the comprehensive score of resource access probability and failure risk, and generate a dynamic caching policy.
[0038] As a preferred solution of the network security analysis method based on privatized generative artificial intelligence according to the present invention, wherein:
[0039] The attack events in the dynamic caching policy are captured through the comprehensive detection strategy, triggering an automated response mechanism optimized based on game theory, and generating defense measures, including the following steps:
[0040] Map the risk scores in the dynamic caching policy and the resource scheduling rules to a multi-dimensional decision space;
[0041] Through multi-dimensional decision space scanning, identify the areas deviating from the normal policy and mark them as potential attack events;
[0042] Fuse the region boundary embedding vectors with the risk scores to form an attack type - impact degree matrix;
[0043] Based on the attack type - impact degree matrix, trigger the solution of the optimal strategy combination by the Nash equilibrium optimized based on game theory to generate defense measures.
[0044] In a second aspect, the present invention provides a network security analysis system based on privatized generative artificial intelligence, including a data integration module that captures network traffic, user behavior logs, and security events, constructs a mixed data set through abnormal traffic marking, log repair, and feature standardization, and forms a structured feature library; an adversarial training module that, based on the structured feature library, trains a generative adversarial network, generates high-fidelity adversarial samples, and injects them into the structured feature library through dynamic weight factors; a vector generation module that, based on the adjusted structured feature library, constructs a heterogeneous neural network detection engine, and fuses temporal correlation, semantic features, and region boundary information to generate dynamic risk vectors; a caching policy module that uses transfer learning technology to predict the probability of future resource access by users, and combines with the dynamic risk vectors to generate a dynamic caching policy; a defense measure module that captures attack events in the dynamic caching policy through a comprehensive detection strategy, triggers an automated response mechanism optimized based on game theory, and generates defense measures.
[0045] In a third aspect, the present invention provides a computer device, including a memory and a processor, where the memory stores a computer program, and wherein: when the computer program is executed by the processor, any step of the network security analysis method based on privatized generative artificial intelligence as described in the first aspect of the present invention is implemented.
[0046] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and wherein: when the computer program is executed by the processor, any step of the network security analysis method based on privatized generative artificial intelligence as described in the first aspect of the present invention is implemented.
[0047] The beneficial effects of the present invention are as follows: Through the generative adversarial network and the improved GraphSAGE algorithm, heterogeneous feature fusion of network traffic time series patterns, user semantic intentions, and dynamic labels of regional boundaries is carried out to construct high-fidelity adversarial samples and dynamic risk vectors. Compared with traditional methods, it can effectively identify hidden attacks in encrypted traffic; Based on Markov chains and dual failure detection, the access probability curve of hot resources is dynamically corrected, and the optimal defense strategy combination is solved by combining game theory Nash equilibrium, which improves the cache hit rate and reduces the false positive rate of high-risk attacks at the same time; Through the correlation analysis of the attack pattern knowledge graph and regional boundary embedding, a closed-loop linkage of attack detection, strategy generation, and response mechanism is realized; The transfer learning framework supports fast adaptation across scenarios. Fine-tuning the BERT model can meet business requirements with a small number of labeled samples. The dynamic adjustment of regional boundaries based on the fuzzy C-means algorithm shortens the response time to new attack types. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0049] Figure 1 It is a flowchart of the network security analysis method based on privatized generative artificial intelligence in Embodiment 1.
[0050] Figure 2 It is a module diagram of the network security analysis system based on privatized generative artificial intelligence in Embodiment 1. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0051] To make the above objects, features, and advantages of the present invention more obvious and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings of the specification.
[0052] Many specific details are set forth in the following description to facilitate a thorough understanding of the present invention, but the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar generalizations without departing from the spirit of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0053] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that can be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it an individual or alternative embodiment that is mutually exclusive with other embodiments.
[0054] Embodiment 1, refer toFigure 1 and Figure 2 This is the first embodiment of the present invention, which provides a network security analysis method based on privatized generative artificial intelligence, including the following steps:
[0055] S1. Capture network traffic, user behavior logs, and security events, and construct a hybrid dataset through abnormal traffic marking, log repair, and feature standardization to form a structured feature library.
[0056] S1.1. Hierarchically extract the data of abnormal traffic marking, log repair, and feature standardization to construct an attack pattern knowledge graph.
[0057] Further explanation, the capture of network traffic is grabbed through a network packet capture tool, and information such as source IP, destination IP, port, protocol type, packet size, and timestamp needs to be recorded.
[0058] The collection of user behavior logs is collected through a log collection tool, and information such as user ID, operation type, operation time, and operation object needs to be recorded.
[0059] Real-time collect security event logs through a security information and event management mechanism, and information such as event type, event time, event source, and event target needs to be recorded.
[0060] The hierarchical extraction is divided into an abnormal traffic layer, a log repair layer, and a feature standardization layer.
[0061] Abnormal traffic layer: Detect outlier requests (such as a sudden increase in burst traffic > 500%) through Isolation Forest and mark them as potential attack samples.
[0062] Log repair layer: Fill in the missing fields using linear interpolation to ensure the continuity of the behavior sequence.
[0063] Feature standardization layer: Standardize numerical features (such as packet size) to [0,1], and encode categorical features (such as protocol type) as binary vectors.
[0064] The construction of the attack pattern knowledge graph is to define nodes and edges. Define attack types, attack vectors, and affected resources as nodes, and define attack frequency (weight) and relevance (such as SQL injection often accompanying XSS attacks) as edges.
[0065] S1.2. Define the regional boundaries of the security area, risk transition area, and attack area based on business logic.
[0066] Further explanation, the regional division driven by business logic:
[0067] Security area: High-frequency legitimate access resources (such as the login page, access frequency > 100 times / hour).
[0068] Risk transition zone: Temporarily access unknown resources (such as when a new user downloads for the first time, with an access frequency of 1 - 10 times per hour).
[0069] Attack area: Includes known attack patterns (such as SQL injection) or abnormal behaviors (such as a single IP accessing 10 different resources continuously).
[0070] S1.3. Merge the constructed attack pattern knowledge graph with the defined regional boundaries to form a structured feature library.
[0071] The generation of the structured feature library is to merge the edge weights (such as attack frequency) in the attack pattern knowledge graph with the regional labels into the feature library.
[0072] S2. Based on the structured feature library, train and generate an adversarial network, generate high-fidelity adversarial samples and inject them into the structured feature library through dynamic weight factors.
[0073] S2.1. Extract the regional boundaries of the security area, risk transition zone, and attack area from the structured database.
[0074] Further explanation, the regional boundaries include regional labels, feature vectors, and boundary definitions.
[0075] It should be noted that extracting the regional boundary data, clarifying the scope and characteristics of each region, provides a basis for subsequent generation of adversarial samples, and provides clear guidance for the training and sample generation of the adversarial network.
[0076] S2.2. Use regional feature embedding technology to convert the regional boundaries into a continuous vector space representation, generating regional boundary embedding vectors.
[0077] Further explanation, regional feature embedding technologies include Word2Vec, BERT, and custom neural networks, etc.
[0078] It should be noted that converting the discrete regional boundaries into a continuous vector space representation facilitates processing by the adversarial network, and the embedding vectors can retain the semantic information of the regional boundaries, providing context support for generating adversarial samples.
[0079] S2.3. Load the attack pattern feature vectors from the attack pattern knowledge graph.
[0080] Further explanation, use the Neo4j query language to traverse the attack pattern knowledge graph, extract node features (such as attack type "SQL injection", attack vector "exploit code") and edge features (such as attack frequency, associated resources), perform random walks on the nodes in the knowledge graph (window size = 5, number of walks = 10), and generate attack pattern feature vectors.
[0081] S2.4. Perform dual-branch attention fusion of the region boundary embedding vector and the attack pattern feature vector for the behavior prediction branch and the protocol generation branch to generate high-fidelity adversarial samples in multiple modalities.
[0082] The generation of the region boundary embedding vector is through the mapping of the fuzzy C-means clustering results. Samples in the mixed dataset are assigned to the safe zone, the risk transition zone, and the attack zone, and the region labels are semantically encoded to generate a 512-dimensional region boundary embedding vector.
[0083] The behavior prediction branch takes the user behavior sequence as input and predicts the next resource access type (classification task) through the LSTM network.
[0084] The protocol generation branch takes the original traffic payload as input and generates forged protocols that conform to the RFC standard (such as tampering with the Host field) through the Transformer model.
[0085] The high-fidelity adversarial samples are obtained by inputting the fused features into the generator network through adversarial training (Adversarial Training) and outputting high-fidelity adversarial samples (such as HTTP requests with malicious payloads injected).
[0086] It should be noted that the behavior prediction branch captures the user's intention (such as adding to the shopping cart → paying), and the protocol generation branch simulates the real traffic characteristics (such as the TLS handshake version) to generate adversarial samples with both behavioral rationality and protocol compliance.
[0087] S3. Based on the adjusted structured feature library, construct a heterogeneous neural network detection engine, and fuse temporal correlation, semantic features, and region boundary information to generate a dynamic risk vector.
[0088] S3.1. Extract temporal features, semantic features, and region boundary features from the adjusted structured feature library.
[0089] Temporal feature extraction is to extract time series features (such as the interval time between consecutive user resource accesses, operation frequency) from the user behavior logs, and use a sliding window (window size = 10) to generate temporal segments.
[0090] For example: User A accesses resources B → C → D in sequence within 1 hour, and the temporal features can be encoded as [0.2, 0.5, 0.8] (representing the normalized values of the access intervals).
[0091] Semantic feature extraction is based on the pre-trained BERT model to semantically encode the user request content (such as URL path, HTTP method) to generate a 768-dimensional semantic embedding vector.
[0092] Region boundary feature extraction is to obtain the region label probabilities (such as safe = 0.7, attack = 0.3) from the fuzzy C-means clustering results and compress them into 256-dimensional vectors through a fully connected layer.
[0093] S3.2. Construct an undirected graph structure based on temporal features, perform two-layer jump graph walks through the neighbor aggregation mechanism of the improved GraphSAGE network, capture the traffic temporal patterns in the temporal graph blocks, and output the temporal correlation feature vectors.
[0094] The undirected graph construction is to use the resource ID as the node and the user access temporal relationship as the edge (the weight is the access frequency) to construct an undirected graph structure.
[0095] For example: the access sequence of user A→B→C is transformed into edges (A,B), (B,C), and the weights are both 1.
[0096] Preferably, the improved GraphSAGE algorithm is based on the traditional GraphSAGE algorithm, introduces a node attention mechanism, dynamically adjusts the weights of neighbor nodes, can improve the accuracy of threat detection, calculates the importance weights of neighbor nodes using the node attention mechanism, highlights the role of key nodes, and captures the node relationships from different perspectives through the node attention mechanism to enhance the feature extraction ability.
[0097] S3.3. Use a dynamic routing capsule network to automatically select the optimal feature subspace for semantic features, capture the context semantics of the attack payload and the strength of the attack intention through the digital capsule layer, and output high-order semantic feature vectors; based on the constraint relationship between features, perform weighted fusion of the adjusted weights with the temporal correlation feature vectors, high-order semantic feature vectors, and region boundary features, and output the final risk vector.
[0098] Preferably, the hierarchical structure of the capsule network can capture long-range dependencies and context semantics better than CNN / RNN (such as the "login→transfer→payment" attack chain).
[0099] S3.4. Construct a three-layer attention gating mechanism, input the region boundary features into the gating attention mechanism, dynamically adjust the weight distribution of the temporal and semantic features, and establish the constraint relationship between features through the regional similarity calculation.
[0100] Three-layer attention gating mechanism:
[0101] The first layer: Use the regional boundary similarity as the weight to adjust the contribution degree of the temporal features (such as enhancing the temporal correlation if the similarity is high).
[0102] The second layer: The high-order semantic features output the attack intention intensity through the capsule network and dynamically suppress irrelevant features (such as false alarms with low confidence).
[0103] The third layer: Integrate the weights of temporal and semantic features to generate a constraint relationship matrix (such as an attention mask).
[0104] It should be noted that by dynamically selecting the optimal subspace, the semantic understanding ability in complex attack scenarios (such as hybrid attacks) is significantly improved. The regional similarity constraint is introduced to avoid over-reliance on local features (such as misjudging isolated high-frequency access as an attack).
[0105] S4. Use transfer learning technology to predict the probability of a user's future resource access, and combine it with a dynamic risk vector to generate a dynamic caching policy.
[0106] S4.1. Using transfer learning technology to predict the probability of a user's future resource access includes the following steps:
[0107] Extract the request data from the user behavior logs in the structured feature library, aggregate the data by user ID to generate a user behavior sequence; divide the user behavior sequence into windows of a fixed length and intercept the last behavior as the prediction target; load the pre-trained BERT-base model in the financial transaction scenario, replace the last layer of the pre-trained BERT-base model with a custom output layer to obtain a fine-tuned BERT-base model; input the intercepted last behavior into the fine-tuned BERT-base model to predict the probability distribution of the user's future resource access.
[0108] Further explanation, data aggregation refers to extracting request data (such as resource ID, access timestamp) from the structured feature library by user ID, and filtering invalid requests (such as the interval between repeated accesses to the same resource < 5 seconds).
[0109] For example: The historical behavior sequence of user A is [resource 1, resource 2, resource 3, resource 4].
[0110] For the pre-trained BERT-base model, its number of layers = 12, the hidden layer dimension = 768, freeze the parameters of the first 10 layers to retain domain knowledge, replace the last layer with a classifier, and the output dimension is equal to the total number of resources.
[0111] S4.2. Combining the dynamic risk vector to generate a dynamic caching policy includes the following steps:
[0112] Combine the dynamic risk vector with the predicted probability distribution of the user's future resource access to generate joint features; based on the joint features, construct a state transition matrix, calculate the transition probability, and generate a hot resource access probability curve optimized based on the Markov chain; use double failure detection based on long-term trend anomalies and burst traffic anomalies to correct the hot resource access probability curve; based on the correction results, calculate the comprehensive score of resource access probability and failure risk to generate a dynamic caching policy.
[0113] Furthermore, to generate the combined features, first, the user's future resource access probability distribution (768 - dimensional) and the dynamic risk vector (512 - dimensional) are normalized to the [0, 1] interval through Min - Max normalization, and then the contribution degrees of the two features are adjusted through attention weight assignment. For example, the time - series prediction weight = 0.6, and the risk weight = 0.4.
[0114] To construct the state - transition matrix, state definition is carried out first. The user behavior is discretized into finite states (such as "browse", "download", "pay"), and then the state - transition matrix is constructed.
[0115] Calculating the transition probability is to identify the long - tail states (such as low - frequency resources) in the Markov chain through the PageRank algorithm, retain the top 20% of the high - frequency states to reduce the computational complexity, and introduce a dynamic risk factor to adjust the transition probability to obtain the optimized transition probability.
[0116] Preferably, a Markov chain is a prediction model based on state - transition probabilities. Assuming that the future state only depends on the current state, modeling user behavior through a Markov chain can effectively predict the user's future requests. Modeling user behavior using a Markov chain and combining matrix ranking techniques can optimize the computational efficiency.
[0117] Long - term trend anomaly detection is to fit the historical access sequence using the Holt - Winters exponential smoothing method. If the deviation between the predicted value and the actual value exceeds 3σ, it is marked as a long - term anomaly.
[0118] Sudden traffic anomaly detection is to detect outliers through an isolation forest. If the proportion of abnormal traffic exceeds 15%, the traffic cleaning mechanism is triggered (such as throttling by 50%).
[0119] S5. Capture attack events in the dynamic caching policy through a comprehensive detection strategy, trigger an automated response mechanism optimized based on game theory, and generate defense measures.
[0120] Map the risk scores in the dynamic caching policy and the resource scheduling rules to a multi - dimensional decision space; through scanning the multi - dimensional decision space, identify the regions deviating from the normal policy and mark them as potential attack events; fuse the region boundary embedding vectors and the risk scores to form an attack type - impact degree matrix; based on the attack type - impact degree matrix, trigger the solution of the Nash equilibrium optimized based on game theory to obtain the optimal policy combination and generate defense measures.
[0121] Furthermore, to construct the multi - dimensional decision space, three dimensions are defined first, and then each resource node in the dynamic caching policy is converted into a three - dimensional coordinate point.
[0122] Multi-dimensional space scanning uses Isolation Forest to detect outliers in the multi-dimensional decision space. By setting the LOF score threshold, points exceeding the score threshold are marked as potential attack events.
[0123] The defense strategy selection based on Nash equilibrium is achieved by constructing a resource scheduling matrix, including strategy options and payoff matrix; using Nash equilibrium solution and the Shapley value algorithm to calculate the optimal strategy combination for each party, ensuring that the defender cannot unilaterally improve the payoff, dynamically adjusting the payoff matrix according to the attack type weight (such as increasing the traffic limiting weight for high-risk attacks), and associating the attack events that trigger the strategy with the knowledge graph nodes.
[0124] This embodiment also provides a network security analysis system based on privatized generative artificial intelligence, including: a data integration module that captures network traffic, user behavior logs, and security events, constructs a hybrid data set through abnormal traffic marking, log repair, and feature standardization, and forms a structured feature library; an adversarial training module that, based on the structured feature library, trains a generative adversarial network, generates high-fidelity adversarial samples and injects them into the structured feature library through a dynamic weight factor; a vector generation module that, based on the adjusted structured feature library, constructs a heterogeneous neural network detection engine, and generates a dynamic risk vector by fusing temporal correlation, semantic features, and regional boundary information; a cache strategy module that uses transfer learning technology to predict the probability of future resource access by users, and combines with the dynamic risk vector to generate a dynamic cache strategy; a defense measure module that captures attack events in the dynamic cache strategy through a comprehensive detection strategy, triggers an automated response mechanism optimized based on game theory, and generates defense measures.
[0125] This embodiment also provides a computer device applicable to the case of the network security analysis method based on privatized generative artificial intelligence, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the network security analysis method based on privatized generative artificial intelligence as proposed in the above embodiment.
[0126] The computer device can be a terminal, which includes a processor, a memory, a communication interface, a display screen, and an input device connected via a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be implemented through WIFI, carrier networks, NFC (Near Field Communication), or other technologies. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads provided on the outer shell of the computer device, or an external keyboard, touchpad, or mouse, etc.
[0127] This embodiment also provides a storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the network security analysis method for realizing privatized generative artificial intelligence as proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disc.
[0128] In summary, the present invention, through the generative adversarial network and the improved GraphSAGE algorithm, fuses heterogeneous features of network traffic time series patterns, user semantic intentions, and regional boundary dynamic labels to construct high-fidelity adversarial samples and dynamic risk vectors. Compared with traditional methods, it can effectively identify hidden attacks in encrypted traffic; based on the Markov chain, the response time for the dual new attack types is shortened.
[0129] It should be noted that re-failure detection is carried out, the access probability curve of hot resources is dynamically corrected, and the optimal defense strategy combination is solved by combining the Nash equilibrium of game theory to improve the cache hit rate and at the same time reduce the misjudgment rate of high-risk attacks; through the correlation analysis of the attack pattern knowledge graph and regional boundary embedding, the closed-loop linkage of attack detection, strategy generation and response mechanism is realized; the transfer learning framework supports fast adaptation across scenarios, and the fine-tuned BERT model can meet the business requirements through a small number of labeled samples. Based on the dynamic regional boundary adjustment of the fuzzy C-means algorithm, yes, the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.
Claims
1. A network security analysis method based on privatized generative artificial intelligence, characterized by: include, Capture network traffic, user behavior logs, and security events, build a hybrid data set through abnormal traffic marking, log repair, and feature standardization to form a structured feature library; Based on the structured feature library, the generative adversarial network is trained to generate high-fidelity adversarial samples and inject them into the structured feature library through dynamic weight factors; Based on the adjusted structured feature library, a heterogeneous neural network detection engine is built to generate a dynamic risk vector by integrating temporal association, semantic features and regional boundary information; Use transfer learning technology to predict the user's future resource access probability and generate dynamic caching strategies based on dynamic risk vectors; Through comprehensive detection strategies, attack events in dynamic cache strategies are captured, triggering an automated response mechanism based on game theory optimization to generate defense measures.
2. The network security analysis method based on privatized generative artificial intelligence according to claim 1, characterized in that: The forming of the structured feature library comprises the following steps: The data of abnormal traffic marking, log repair and feature standardization are extracted in layers to build an attack pattern knowledge graph; Define the regional boundaries of the security zone, risk transition zone, and attack zone based on business logic; The constructed attack pattern knowledge graph is merged with the defined region boundaries to form a structured feature library.
3. The network security analysis method based on privatized generative artificial intelligence according to claim 1, characterized in that: The generation of high-fidelity adversarial samples includes the following steps: Extracting the regional boundaries of the safe area, risk transition area and attack area from the structured feature library; Use regional feature embedding technology to convert the region boundary into a continuous vector space representation and generate a region boundary embedding vector; Load the attack pattern feature vector from the attack pattern knowledge graph; The region boundary embedding vector and the attack pattern feature vector are fused through dual-branch attention of the behavior prediction branch and the protocol generation branch to generate multi-modal high-fidelity adversarial samples.
4. The network security analysis method based on privatized generative artificial intelligence according to claim 1, characterized in that: The construction of a heterogeneous neural network detection engine and the generation of a dynamic risk vector by fusing temporal association, semantic features and regional boundary information include the following steps: Extracting temporal features, semantic features and regional boundary features from the adjusted structured feature library; An undirected graph structure is constructed based on the timing features, and a two-layer jump graph walk is performed through the neighbor aggregation mechanism of the improved GraphSAGE network to capture the traffic timing pattern in the timing graph block and output the timing correlation feature vector; A dynamic routing capsule network is used to automatically select the optimal feature subspace for semantic features, and the digital capsule layer is used to capture the contextual semantics of the attack payload and the strength of the attack intent, and output a high-order semantic feature vector. Construct a three-layer attention gating mechanism, input the regional boundary features into the gated attention mechanism, dynamically adjust the weight distribution of temporal and semantic features, and establish the constraint relationship between features through regional similarity calculation; Based on the constraint relationship between features, the adjusted weights are weightedly fused with the time-series correlation feature vector, high-order semantic feature vector and regional boundary features to output the final risk vector.
5. The network security analysis method based on privatized generative artificial intelligence according to claim 1, characterized in that: The method of using transfer learning technology to predict the user's future resource access probability includes the following steps: Extract request data from user behavior logs in the structured feature library, aggregate data by user ID, and generate user behavior sequences; Divide the user behavior sequence into windows of fixed length and take the last behavior as the prediction target; Load the BERT-base model that has been pre-trained in the financial transaction scenario, replace the last layer of the pre-trained BERT-base model with a custom output layer, and obtain the fine-tuned BERT-base model; The last intercepted behavior is input into the fine-tuned BERT-base model to predict the user's future resource access probability distribution.
6. The network security analysis method based on privatized generative artificial intelligence according to claim 1, characterized in that: The generation of a dynamic cache strategy in combination with a dynamic risk vector includes the following steps: Combine the dynamic risk vector with the predicted user's future resource access probability distribution to generate joint features; Based on the joint features, the state transition matrix is constructed, the transition probability is calculated, and the hotspot resource access probability curve based on Markov chain optimization is generated; Use dual failure detection based on long-term trend anomalies and burst traffic anomalies to correct the access probability curve of hotspot resources; Based on the correction results, the comprehensive score of resource access probability and failure risk is calculated to generate a dynamic cache strategy.
7. The network security analysis method based on privatized generative artificial intelligence according to claim 1, characterized in that: The method of capturing attack events in the dynamic cache strategy through a comprehensive detection strategy, triggering an automated response mechanism based on game theory optimization, and generating defense measures includes the following steps: Mapping the risk scores and resource scheduling rules in the dynamic cache strategy into a multi-dimensional decision space; By scanning the multi-dimensional decision space, we can identify areas that deviate from normal strategies and mark them as potential attack events. The region boundary embedding vector is fused with the risk score to form an attack type-impact degree matrix; Based on the attack type-impact degree matrix, the Nash equilibrium based on game theory optimization is triggered to solve the optimal strategy combination and generate defense measures.
8. A network security analysis system based on privatized generative artificial intelligence, based on the network security analysis method based on privatized generative artificial intelligence according to any one of claims 1 to 7, characterized in that: include, The data integration module captures network traffic, user behavior logs, and security events, and constructs a hybrid data set through abnormal traffic marking, log repair, and feature standardization to form a structured feature library; The adversarial training module trains the generative adversarial network based on the structured feature library, generates high-fidelity adversarial samples and injects them into the structured feature library through dynamic weight factors; The vector generation module builds a heterogeneous neural network detection engine based on the adjusted structured feature library, and generates a dynamic risk vector by integrating temporal association, semantic features and regional boundary information; The cache strategy module uses transfer learning technology to predict the user's future resource access probability and generates a dynamic cache strategy based on the dynamic risk vector; The defense measures module captures attack events in the dynamic cache strategy through a comprehensive detection strategy, triggers an automated response mechanism based on game theory optimization, and generates defense measures.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the network security analysis method based on privatized generative artificial intelligence described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the network security analysis method based on privatized generative artificial intelligence described in any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Network security threat detection method and system based on artificial intelligence
CN121000521A
An artificial intelligence-based network security threat detection method and system
CN121000521B
Intelligent scene perception method and system based on time sequence scene classification model
CN121455347A