Network information traceability analysis system based on multi-source data fusion

Through the multi-source data fusion network information traceability analysis system, users of suspected sources are pre-identified and verified, information dissemination confidence is calculated and traceability maps are generated, which solves the problems of low traceability analysis efficiency and lack of confidence in the existing technology, and achieves efficient and accurate network information traceability analysis.

CN120075074AActive Publication Date: 2025-05-30XIAN KANGNAI NETWORK TECH CO LTD

Patent Information

Application Number
CN202510543892.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-05-30
Estimated Expiration
2045-04-28

AI Technical Summary

Technical Problem

The prior art lacks pre-identification of users of suspected source sources of target information in network information traceability analysis, resulting in reduced information retrieval and analysis efficiency, and lacks a comprehensive analysis of the confidence and level of traceability results, resulting in a lack of quantitative basis for the opacity of key node weights and the propagation confidence.

Method used

A network information traceability analysis system that uses multi-source data fusion, including a multi-source data acquisition module, a potential user identification module, a user traceability verification module and a traceability map generation module. Through multi-source data acquisition, traffic data, operation logs and social media usage records are obtained, suspected users are pre-identified, information dissemination confidence is verified, and traceability maps are generated.

Benefits of technology

Through the dual-threshold dynamic adjustment mechanism, pre-identification and confidence verification narrow the traceability range and improve analysis efficiency; by calculating the traceability credibility index and generating traceability maps, the traceability accuracy and visualization effect are improved, providing a reliable basis for subsequent decision-making.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120075074A_ABST
    Figure CN120075074A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network information traceability, and discloses a multi-source data fusion network information traceability analysis system. According to the method, a dual-threshold dynamic adjustment mechanism is set, analysis of two steps of pre-identification and verification is started for the traceability process, and self-adaptive adjustment is carried out for related identification thresholds of a suspected source user set generation process and an information source user confirmation process, so that the traceability depth is improved, and the traceability error rate is reduced. According to the method, the traceability credibility index of each final source node is calculated and the traceability graph is generated, so that the system analysis efficiency and the visualization effect are improved, and a reliable basis is provided for subsequent decision making. According to the method, a multi-source heterogeneous data deep coupling mechanism is set, information is provided from multiple dimensions, mutual complementary verification is achieved, information integrity is enhanced, parallel processing is achieved, the analysis efficiency is improved, the method can flexibly adapt to a complex and changeable network environment, and then the accuracy, comprehensiveness and efficiency of network information traceability analysis are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network information traceability, and relates to a network information traceability analysis system for multi-source data fusion. Background Art

[0002] Network information traceability refers to tracking the source, propagation path, and related entities of network information through various technical means and methods to determine the initial publisher of the information, key nodes in the propagation process, etc. Network information traceability is of crucial significance for combating cybercrime, maintaining network security, guiding public opinion, and ensuring social stability and normal information dissemination order. Therefore, research on network information traceability analysis is of great significance.

[0003] There are also technical solutions for network information traceability in the prior art. For example, a Chinese invention patent application for a method for tracking and tracing network information with the publication number CN118733765A includes: determining key sections of specific public opinion events, extracting discussion content and posting keywords for each topic, establishing an event corpus, and constructing eigen and derivative object sub-corpora. Constructing and training an LSTM model to classify discussion content. Determining the discussion duration and dividing time periods, and accordingly determining public opinion inflection points, comparing accounts and remarks near the inflection points, and obtaining associated accounts.

[0004] In addition, a Chinese invention patent application for a method and device for tracing mobile network information with the publication number CN104750694A includes storing firewall logs and signaling record data by time, setting a time period and delay information, and obtaining data corresponding to the corresponding duration and the number of time periods before obtaining the delay information. Calculating hash codes for the key field information therein respectively, starting a corresponding number of matching processes to match the hash codes, and generating complete traceability information upon successful matching. This method can improve the matching efficiency of information traceability.

[0005] Although the above two solutions propose some solutions for network information traceability, there are still certain limitations. For example, on the one hand, taking the first comparative document above as an example, the prior art solution lacks pre-identification of suspected source users of the target information during the traceability analysis process, directly extracts keywords based on specific public opinion events, and then conducts relevant account analysis, which increases the scope of information retrieval and analysis and reduces the system analysis efficiency.

[0006] On the other hand, taking the second comparative document above as an example, the prior art solution usually only outputs traceability information results during the output of traceability analysis results, lacking comprehensive analysis and output of the corresponding confidence level or traceability level, which will lead to opaque weights of key nodes, lack of quantitative basis for propagation confidence, and poor visualization interactivity. Summary of the Invention

[0007] In view of this, to solve the problems raised in the above-mentioned background technology, a network information traceability analysis system for multi-source data fusion is proposed.

[0008] The object of the present invention can be achieved by the following technical solutions: A network information traceability analysis system for multi-source data fusion, including: a multi-source data acquisition module, which acquires traffic data, operation logs, and social media usage records corresponding to the target network information of the current user within a preset valid time period based on multi-source data acquisition technology.

[0009] A potential user identification module, which pre-identifies the source of the target network information for the current user based on the traffic data, operation logs, and social media usage records to generate a set of suspected source users. If there are no suspected source users, the current user is directly marked as the final source node.

[0010] A user traceability verification module, which performs information similarity verification on the set of suspected source users to obtain the information dissemination confidence of each suspected source user. When it exceeds the dynamic confidence threshold analyzed according to the node hierarchy, it is marked as the information source user and triggers traceability iterative analysis until the final source nodes of each branch are obtained. Otherwise, the path traceability of this branch is terminated.

[0011] A traceability graph generation module, which establishes a weight transfer function for multi-level traceability paths based on the information dissemination confidence to calculate the traceability credibility index of each final source node, and generates a traceability graph accordingly.

[0012] Compared with the prior art, the beneficial effects of the present invention are as follows: (1) By setting a dual-threshold dynamic adjustment mechanism, the present invention analyzes the pre-identification and confidence verification steps during the traceability process. The pre-identification uses multi-source data to screen out suspected source users, narrowing the traceability scope and improving the analysis efficiency; the confidence verification judges the true source by accurately calculating the information dissemination confidence, improving the traceability accuracy. The combination of the two can adapt to complex network environments, construct a complete traceability chain, and facilitate in-depth analysis.

[0013] (2) By calculating the traceability credibility index of each final source node and generating a traceability graph, the present invention improves the efficiency and visualization effect of system analysis, providing a reliable basis for subsequent decision-making.

[0014] (3) By setting a multi-source heterogeneous data deep coupling mechanism, the present invention provides information from multiple dimensions, mutually complements and verifies, enhances information integrity, improves analysis efficiency through parallel processing, and can flexibly adapt to complex and changeable network environments, thereby improving the accuracy, comprehensiveness, and efficiency of network information traceability analysis. Description of the Drawings

[0015] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for describing the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0016] Figure 1 It is a schematic diagram of the connection of each module of the system of the present invention.

[0017] Figure 2 It is a schematic diagram of the working process of the user traceability verification module corresponding to an embodiment provided by the present invention.

[0018] Figure 3 It is a schematic diagram of the propagation path corresponding to an embodiment provided by the present invention.

[0019] Reference numerals: 1 - the current user corresponding to the target network information, 2 - the final source node. Detailed implementation manners

[0020] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present invention.

[0021] Please refer to Figure 1 As shown, the present invention provides a network information traceability analysis system for multi-source data fusion, including a multi-source data acquisition module, a potential user identification module, a user traceability verification module, and a traceability map generation module. Among them, the multi-source data acquisition module is connected to the potential user identification module, the potential user identification module is connected to the user traceability verification module, and the user traceability verification module is connected to the traceability map generation module.

[0022] The multi-source data acquisition module is used to obtain the traffic data, operation logs, and social media usage records of the current user corresponding to the target network information within a preset effective time period based on multi-source data acquisition technology.

[0023] It should be noted that the present invention enhances the integrity of information by setting a deep coupling mechanism for multi-source heterogeneous data, providing information from multiple dimensions, mutually supplementing and verifying, improving the analysis efficiency through parallel processing, and being able to flexibly adapt to complex and changeable network environments, thereby improving the accuracy, comprehensiveness, and efficiency of network information traceability analysis.

[0024] The potential user identification module is used to pre-identify the source of target network information for the current user based on traffic data, operation logs, and social media usage records to generate a set of suspected source users. If there are no suspected source users, the current user is directly marked as the final source node.

[0025] It should be noted that the potential user identification module plays a key role in the preliminary screening and judgment of information sources in the network information traceability analysis system. The following is a detailed explanation from three aspects: data application, pre-identification process, and final source node determination: 1. Application of multi-source data: Traffic data reflects the data interaction between the current user and other network nodes, covering transmission objects, time, frequency, and data volume, etc., and can mine potential associated users; operation logs record the operation behaviors of users in the system, including logins, browsing, etc., and are used to analyze the information acquisition channels and information dissemination sources; social media usage records include interactive behaviors such as publishing and commenting, and can reveal the information dissemination chain and potential source channels in the social network.

[0026] 2. Pre-identification process: The module first extracts the publishing time of the target network information from the operation logs and social media usage records based on the multi-source data. Then, in combination with the multi-source data, it obtains the start and end times of the data reception operation, calculates the exchange duration, determines the target user, obtains the data volume to construct a reference duration, and compares to obtain the access effectiveness evaluation index. Furthermore, through the time difference between the publishing and receiving end times and the timeliness analysis, the timeliness index is obtained, and the recognition rate threshold is corrected. Finally, it compares the recognition rate with the corrected threshold to judge the operation effectiveness, and includes the target users corresponding to the effective operations to construct a set of suspected source users.

[0027] 3. Final source node determination: If no eligible suspected source users are found through analysis and calculation, it means that there is no other dissemination source in the information acquisition path of the current user. At this time, the current user is directly marked as the final source node. This determination method can accurately identify isolated information publishing behaviors or dissemination starting points, providing a clear starting point for subsequent traceability.

[0028] In a preferred embodiment of the present invention, the specific method for generating the set of suspected source users is as follows: Extract the publishing time of the target network information based on the operation logs and social media usage records of the current user within a preset effective period.

[0029] It should be noted that within the preset effective period: 1. Significance in data collection: In the multi-source data collection module, it limits the time span of data collection. For example, when collecting the traffic data, operation logs, and social media usage records of the current user corresponding to the target network information, it does not obtain all the historical data of the user without limitation, but collects within this preset time period. This can ensure that the collected data is closely related to the information to be traced currently, exclude the interference of stale and irrelevant data, and improve the data processing efficiency and the pertinence of traceability analysis.

[0030] 2. Role in the analysis process: In subsequent processes such as potential user identification and information dissemination confidence calculation, the data collected "within the preset effective period" serves as the basis for analysis. It enables the system to focus on the behavior and data interactions of users within a specific time period, accurately determining the source and dissemination path of information. For example, when calculating the timeliness index of data reception operations, it is based on the time difference between the target network information release time and the end time of data reception operations within this period. Without this clear time period limit, time comparison and timeliness analysis lose accuracy and significance, thereby affecting the reliability of the entire traceability analysis result.

[0031] Obtain the start and end times corresponding to each data reception operation of the current user before the release time of the target network information based on the traffic data, operation logs, and social media usage records of the current user within the preset effective period, and obtain the target users corresponding to each data reception operation based on the traffic data of the current user within the preset effective period.

[0032] It should be explained that the target user mentioned here refers to the source user from whom the current user receives traffic data within the preset effective period.

[0033] It should be noted that the present invention conducts traceability analysis on target network information. Therefore, only the data reception operations of the current user are analyzed, and data sending operations are not considered.

[0034] Obtain the network information data volume corresponding to each data reception operation, and then construct the reference data access duration corresponding to each data reception operation.

[0035] It should be noted that the construction duration of the reference data access duration: Obtain the data volume and actual access duration of several types of the same data, and then calculate the average value of the actual access duration to obtain the reference data access duration of this type of data. The reference access durations of different types of data may vary. During actual construction, those skilled in the art will select according to the actual situation.

[0036] It should be noted that the purpose of constructing the reference data access duration corresponding to each data reception operation: constructing the reference data access duration based on the acquired data volume is to set a reasonable standard to evaluate whether the actual data access duration is normal. Under normal circumstances, different data volumes will have different corresponding access durations. Constructing the reference data access duration is like setting a "ruler" for each data reception operation. Suppose that during a certain data reception operation, the normal access duration required for every 10 MB of data is 30 seconds. Then, when the data volume obtained in a certain data reception operation is 20 MB, the constructed reference data access duration may be 60 seconds. In this way, in subsequent analysis, by comparing the actual data access duration with the reference data access duration, it can be determined whether there is an abnormality in this data reception operation and whether it is a valid data reception operation, thereby helping to screen out suspected source users.

[0037] Compare the data access duration of each data reception operation with the corresponding reference data access duration to obtain the access effectiveness evaluation index corresponding to each data reception operation.

[0038] Preferably, the analysis method of the access effectiveness evaluation index: calculate the ratio of the data access duration of each data reception operation to the corresponding reference data access duration to obtain the access effectiveness evaluation index corresponding to each data reception operation, and the maximum value of the access effectiveness evaluation index is 1.

[0039] Calculate the difference between the release time of the target network information and the end time corresponding to each data reception operation, and then conduct timeliness analysis to obtain the timeliness index of each data reception operation.

[0040] A preferably timeliness index analysis method, assuming that the release time of the target network information is , and the end time of a certain data reception operation is , where represents the number of the data reception operation, , represents the number of data reception operations.

[0041] Use the formula to analyze and obtain the timeliness index of each data reception operation , where is a preset attenuation coefficient, which is adjusted according to the characteristics of information dissemination and domain characteristics. For information with fast dissemination speed and frequent updates (such as entertainment news, sports event information), takes a larger value, and the information timeliness decays rapidly; for relatively stable and slowly updated information (such as some professional academic materials), takes a smaller value. For example, in the scenario of social hot spot information dissemination, through testing and setting of empirical values, . Indicates a preset reference interval duration.

[0042] The value range of the timeliness index is between (0, 1]. The closer it is to 1, the stronger the timeliness, which means that the data reception operation is closer to the information release in time, and the value and reliability of the information are relatively higher; the closer it is to 0, the weaker the timeliness, and the information may have experienced a long time during the dissemination process, and its accuracy and relevance to the source may be affected. When calculating the threshold of the access validity evaluation index subsequently, the timeliness index can be used as an important correction factor, so that the entire traceability analysis system can more accurately judge the validity of the data reception operation, thereby improving the accuracy of network information traceability.

[0043] The preset access validity evaluation index threshold is corrected according to the timeliness index of each data reception operation to obtain the access validity evaluation index threshold corresponding to each data reception operation.

[0044] Preferably, the timeliness index of each data reception operation is multiplied by the corresponding preset access validity evaluation index threshold to obtain the access validity evaluation index threshold corresponding to each data reception operation.

[0045] Compare the access validity evaluation index of each data reception operation with the corresponding access validity evaluation index threshold to determine whether each data reception operation is a valid data reception operation. Record the target users corresponding to each valid data reception operation as suspected source users, and then construct a set of suspected source users.

[0046] Preferably, the specific determination method for whether each data reception operation is a valid data reception operation is as follows: if the access validity evaluation index of a certain data reception operation is greater than or equal to the corresponding access validity evaluation index threshold, identify that data reception operation as a valid data reception operation, otherwise identify the data reception operation as an invalid data reception operation.

[0047] It should be further explained that for the data reception operations determined to be valid, the system records the target users corresponding to these operations. Because these users show high information validity during the data reception process, they are very likely to be important nodes in the information dissemination process, or even the source of the information. The system aggregates the target users corresponding to all these valid data reception operations to construct a set of suspected source users. This set provides key clues and a screening range for subsequent further in-depth traceability analysis, greatly reducing the search space for traceability, and improving the efficiency and accuracy of traceability analysis.

[0048] Please refer to Figure 2As shown, the user traceability verification module is used to perform information similarity verification on the set of suspected source users to obtain the information propagation confidence of each suspected source user. If it exceeds the dynamic confidence threshold analyzed according to the node hierarchy, it will be marked as an information source user and trigger traceability iterative analysis until the final source node of each branch is obtained; otherwise, the path traceability of this branch will be terminated.

[0049] In a preferred embodiment of the present invention, the specific analysis method of the information propagation confidence of each suspected source user is as follows: Calculate the information correlation index of the data reception information corresponding to each suspected source user based on the BERT algorithm.

[0050] It should be explained that the BERT algorithm is a pre-trained language model based on the Transformer architecture. Through masked language model and next sentence prediction for large-scale unsupervised pre-training, it can deeply understand the text semantics and bidirectionally capture the meaning of words in the context. After completing the pre-training, it can be fine-tuned for different natural language processing tasks and is widely used in fields such as text classification, question answering systems, machine translation, and information retrieval.

[0051] Combine the target network information release time with the end time of the data reception operation of each suspected source user corresponding to the current user to construct the time-sequence propagation influence factor of each suspected source user.

[0052] Preferably, calculate the difference between the target network information release time of the current user and the end time of the data reception operation to obtain the corresponding information release response time, and calculate the ratio with the preset reference response time to obtain the time-sequence propagation influence factor.

[0053] It should be explained that the time-sequence propagation influence factor is mainly used to measure the propagation of information in chronological order. If the information release response time is short, that is, the time interval between the end time of the data reception operation and the information release time is small, it means that the suspected source user receives the information in a more timely manner, has a greater impact on information propagation, and the time-sequence propagation influence factor is higher.

[0054] It should be explained that in this network information traceability analysis system, the information release response time is a key indicator for evaluating the timeliness of information propagation and the importance of suspected source users. When evaluating the information propagation confidence of suspected source users, the information release response time is an important basis for constructing the time-sequence propagation influence factor. A shorter response time will make the time-sequence propagation influence factor larger. When jointly calculating the information propagation confidence with the information correlation index, it can improve the credibility of this suspected source user as an information source. Because users who receive information in a timely manner are more likely to obtain information in the early stage of information propagation and are closer to the information source.

[0055] Determine the information dissemination confidence analysis method according to the levels of each suspected source user, and then perform information dissemination confidence analysis based on different information dissemination confidence analysis methods.

[0056] In a preferred embodiment of the present invention, the specific analysis method for the information correlation index of the data reception information corresponding to each suspected source user is as follows: Extract the keywords of the target network information and their validity probabilities based on the BERT algorithm.

[0057] Based on the traffic data, operation logs, and social media usage records of the current user corresponding to the target network information within a preset valid period, obtain the data reception information corresponding to each suspected source user, and then use the BERT algorithm to obtain the keywords of the corresponding data reception information.

[0058] Match the keywords of the target network information with the keywords of the data reception information corresponding to each suspected source user, and count the number of successfully matched keywords and the total number of keywords of the target network information.

[0059] Construct the validity influence weight factor of each successfully matched keyword based on the validity probability corresponding to the successfully matched keyword, and then perform information correlation analysis by combining the ratio of the number of successfully matched keywords and the total number of keywords of the target network information to obtain the information correlation index of the data reception information corresponding to each suspected source user.

[0060] Preferably, the specific analysis method for the validity influence weight factor: Perform ratio analysis on the validity probability corresponding to the successfully matched keyword and the sum of the corresponding validity probabilities to obtain the validity influence weight factor of each successfully matched keyword.

[0061] Preferably, the specific analysis process for the information correlation index of the data reception information corresponding to each suspected source user is as follows: Calculate the ratio of the number of successfully matched keywords and the total number of keywords of the target network information, and then calculate the sum of the validity influence weight factors corresponding to the successfully matched keywords. Multiply the above calculation results to obtain the information correlation index of the data reception information corresponding to each suspected source user.

[0062] It should be noted that the information correlation index is calculated based on the BERT algorithm. By extracting the keywords of the target network information and the data reception information corresponding to the suspected source user, and combining the validity probability of the keywords, the similarity degree and the correlation tightness of the information content between the two are measured. For example, if the keywords of the target network information have a high matching degree with the keywords of the data reception information of the suspected source user, and the validity probability of the successfully matched keywords is large, then the information correlation index is high, indicating a high degree of correlation in the information content between the two, and the possibility of this suspected source user being the information source is also greater.

[0063] In a preferred embodiment of the present invention, the specific method for analyzing the information dissemination confidence based on different information dissemination confidence analysis methods is as follows: If the subordinate node of the suspected source user is the current user corresponding to the target network information, calculate the information dissemination confidence of the suspected source user based on its information correlation index and the time-series dissemination influence factor.

[0064] It should be explained that the "node" in the above text refers to an abstract identifier representing a user or an information dissemination entity in the network information dissemination path, and is used to construct and analyze the information dissemination relationship. The current user, the suspected source user, and the ultimate source node described in the present invention all exist in the network information dissemination path. Among them, the current user corresponding to the target network information refers to the "final node" or "lowest-level node" in the network information dissemination path. The suspected source user is a temporary term that exists in the intermediate analysis process during the identification of the upper-level node. The ultimate source node refers to the "initial node" or "first-level node" in the network information dissemination path. Since the present invention performs traceability analysis for a specific target network information, there is only one current user corresponding to the target network information, and there may be one or more ultimate source nodes at the same time.

[0065] Preferably, the analysis method for the information dissemination confidence of the suspected source user is: Calculate the product of the information correlation index and the time-series dissemination influence factor of the suspected source user.

[0066] It should be explained that calculating the product of the information correlation index and the time-series dissemination influence factor can comprehensively consider the influence of these two key factors, namely information content association and time-order dissemination, on the information dissemination confidence. A high degree of information content association indicates a strong similarity between the information received by the suspected source user and the target network information; while a high time-series dissemination influence factor means that the user receives the information more timely and has an advantage in the dissemination chain. Multiplying the two can obtain an information dissemination confidence that can more comprehensively and accurately reflect the credibility of the suspected source user as an information source. For example, when the information correlation index is 0.8 and the time-series dissemination influence factor is 0.7, the product of the two is 0.56. Compared with using only one of the factors alone, this comprehensive result can more accurately evaluate the importance and credibility of the suspected source user in information dissemination, providing a more reliable basis for subsequent judgment of whether it is an information source user.

[0067] If the subordinate node is not the current user corresponding to the target network information, it is necessary to obtain the information dissemination confidence of the subordinate node user and calculate the information dissemination confidence of the suspected source user in combination with its information correlation index and the time-series dissemination influence factor.

[0068] Preferably, the analysis method for the information propagation confidence of the suspected source user is obtained by calculating the product of the information propagation confidence, information correlation index, and time-series propagation influence factor of the lower-level node users of the suspected source user.

[0069] In a preferred embodiment of the present invention, the specific method for the dynamic confidence threshold according to node hierarchy analysis is as follows: By using the propagation hierarchy exponential decay analysis model, the decay index of the hierarchy weight is calculated in combination with the node hierarchy of each suspected source user, thereby dynamically generating the dynamic confidence threshold of the suspected source user matching each node hierarchy.

[0070] Preferably, the specific analysis method for the dynamic confidence threshold of the suspected source user matching each node hierarchy: Using the formula to analyze and obtain the dynamic confidence threshold of the suspected source user matching each node hierarchy , where represents the preset initial threshold, represents the natural constant, represents the preset decay coefficient, represents the node hierarchy number, , represents the number of node hierarchies.

[0071] It should be explained that the propagation hierarchy exponential decay is the core mechanism in the network information traceability analysis system for dynamically generating the dynamic confidence threshold of the suspected source user. Based on the characteristics of information propagation, considering that as the propagation hierarchy increases, the reliability or propagation value of the information may gradually decrease, and this decrease is not a linear change but conforms to the exponential decay law. Specifically: 1. Calculation model and principle: The system uses the propagation hierarchy exponential decay analysis model to calculate the decay index of the hierarchy weight in combination with the node hierarchy of each suspected source user. Specifically, through the formula . In this formula, the initial threshold is a preset basic value, which provides a starting standard for the dynamic confidence threshold. The preset decay coefficient is a key parameter adjusted according to the characteristics of information propagation and domain characteristics, and its value is different for different types of information propagation scenarios. The node hierarchy number represents the position of the suspected source user in the information propagation path. Starting from the current user and tracing upwards, the hierarchy number increases by 1 for each user passed.

[0072] Role in the system: In the user traceability verification module, this mechanism determines whether a suspected source user is the actual information source user based on the calculated dynamic confidence threshold. For suspected source users with a lower level (closer to the current user), since the level weight attenuation is less, the dynamic confidence threshold is relatively high. This means that the requirements for such users to be information source users are more stringent, and a higher information dissemination confidence is required for confirmation. For example, if a suspected source user is at the level adjacent to the current user, its dynamic confidence threshold may be 0.8, and it will only be marked as an information source user when its information dissemination confidence is greater than 0.8. For suspected source users with a higher level (farther from the current user), the level weight attenuation is more, and the dynamic confidence threshold is relatively low. This is because after information is propagated through multiple layers, the interference factors increase, making it difficult to verify as strictly as direct propagation. Therefore, the verification standard is lowered, and as long as its information dissemination confidence reaches the corresponding lower threshold, it may be identified as an information source user.

[0073] In a preferred embodiment of the present invention, the specific method for triggering the traceability iterative analysis is as follows: If the information dissemination confidence of the current user corresponding to a suspected source user is greater than its dynamic confidence threshold, mark it as the information source user corresponding to the current user.

[0074] Record the suspected source user as the new current user, and trigger a new round of iterative analysis processes of data collection, potential user identification, and traceability verification.

[0075] In a preferred embodiment of the present invention, the specific method for obtaining the final source node of each branch is as follows: Compare the information dissemination confidence of all suspected source users corresponding to the current user of a branch with each automatic dynamic confidence threshold one by one. If the information dissemination confidence of all suspected source users is less than their corresponding dynamic confidence thresholds, then determine that the current user is the final source node of this branch.

[0076] Exemplarily, an analysis result of the final source node is as Figure 3 , in the figure, there are four propagation paths, corresponding to four final source nodes respectively, and the node levels of each final source node are different.

[0077] It needs to be further explained that when comparing the information dissemination confidence of each suspected source user with its respective dynamic confidence threshold, if the information dissemination confidence of all suspected source users is less than their corresponding thresholds, this means that in this branch, the information dissemination confidence of no other user reaches a sufficient standard to be identified as a more upstream information source user. Therefore, in this case, the current user is determined as the final source node of this branch, that is, the propagation of information in this branch starts from the current user, and the subsequent traceability analysis in this branch ends here.

[0078] It should be noted that the present invention sets up a dual-threshold dynamic adjustment mechanism, which analyzes the traceability process by starting two steps of pre-identification and confidence verification. The pre-identification screens out suspected source users with the help of multi-source data, narrowing the traceability scope and improving the analysis efficiency; the confidence verification determines the true source by accurately calculating the information propagation confidence, improving the traceability accuracy. The cooperation of the two can adapt to complex network environments, construct a complete traceability chain, and facilitate in-depth analysis.

[0079] The traceability graph generation module is used to establish a weight transfer function for multi-level traceability paths according to the information propagation confidence, calculate the traceability credibility index of each final source node, and generate a traceability graph accordingly.

[0080] In a preferred embodiment of the present invention, the specific method for calculating the traceability credibility index of each final source node is as follows: extract the information propagation confidence of all levels of users in the branches to which each final source node belongs, and calculate the traceability credibility index of each final source node through layer-by-layer multiplication.

[0081] In a preferred embodiment of the present invention, the specific analysis process of the traceability graph is as follows: arrange each final source node in descending order of the traceability credibility index to generate a traceability node list, form a traceability graph with the traceability node list and the corresponding traceability credibility index, and mark the propagation influence level.

[0082] Among them, the propagation influence level is determined by comparing the traceability credibility index with the preset recognition thresholds for each propagation influence level. The propagation influence levels are divided into level one, level two, and level three.

[0083] It should be noted that the present invention calculates the traceability credibility index of each final source node and generates a traceability graph, which improves the efficiency and visualization effect of system analysis and provides a reliable basis for subsequent decision-making.

[0084] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to obtain a formula closest to the actual situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0085] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0086] Finally, the above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A network information tracing and analysis system for multi-source data fusion, characterized in that: include: The multi-source data collection module obtains the target network information corresponding to the current user's traffic data, operation logs and social media usage records within a preset effective period based on multi-source data collection technology; Potential user identification module, which pre-identifies the source of target network information of the current user based on traffic data, operation logs and social media usage records to generate a set of suspected source users. If there is no suspected source user, the current user is directly marked as the final source node; The user traceability verification module verifies the information similarity of the suspected source user set to obtain the information dissemination confidence of each suspected source user. If it exceeds the dynamic confidence threshold based on the node level analysis, it will be marked as the information source user and trigger the traceability iteration analysis until the final source node of each branch is obtained. Otherwise, the path traceability of the branch is terminated; The traceability graph generation module establishes a weight transfer function of a multi-level traceability path according to the information propagation confidence, calculates the traceability credibility index of each final source node, and generates a traceability graph accordingly.

2. A network information tracing and analysis system for multi-source data fusion as claimed in claim 1, characterized in that: The specific method of generating the suspected source user set is as follows: Extract the release time of the target network information based on the current user's operation log and social media usage record within a preset effective period; Based on the current user's traffic data, operation logs, and social media usage records within a preset effective period, the start and end times corresponding to each data receiving operation of the current user before the release time of the target network information are obtained, and then the difference calculation is performed to obtain the data access duration corresponding to each data receiving operation; Obtaining target users corresponding to each data receiving operation based on the traffic data of the current user within a preset effective period; Obtain the network information data volume corresponding to each data receiving operation, and then construct the reference data access duration corresponding to each data receiving operation; Compare the data access duration of each data receiving operation with the corresponding reference data access duration to obtain an access effectiveness evaluation index corresponding to each data receiving operation; The release time of the target network information and the end time corresponding to each data receiving operation are calculated by difference, and then the timeliness analysis is performed to obtain the timeliness index of each data receiving operation; According to the timeliness index of each data receiving operation, the preset access validity evaluation index threshold is modified to obtain the access validity evaluation index threshold corresponding to each data receiving operation; The access validity evaluation index of each data receiving operation is compared with the corresponding access validity evaluation index threshold to determine whether each data receiving operation is a valid data receiving operation, and the target user corresponding to each valid data receiving operation is recorded as a suspected source user, thereby constructing a set of suspected source users.

3. A network information source tracing and analysis system for multi-source data fusion as claimed in claim 1, characterized in that: The specific analysis method of the information dissemination confidence of each suspected source user is as follows: Calculate the information relevance index of the corresponding data received by each suspected source user based on the BERT algorithm; The target network information release time is combined with the data receiving operation end time of each suspected source user corresponding to the current user to construct the temporal propagation influence factor of each suspected source user; The information propagation confidence analysis method is determined according to the user level of each suspected source, and then the information propagation confidence analysis is performed based on different information propagation confidence analysis methods.

4. A network information source tracing and analysis system for multi-source data fusion as claimed in claim 3, characterized in that: The specific analysis method of the information relevance index of the corresponding data receiving information of each suspected source user is as follows: Extract target network information keywords and their validity probability based on BERT algorithm; Based on the target network information corresponding to the current user's traffic data, operation logs, and social media usage records within a preset effective period, the corresponding data reception information of each suspected source user is obtained, and then the BERT algorithm is used to obtain the keywords of the corresponding data reception information; Match each keyword of the target network information with the keyword of the corresponding data received information of each suspected source user, and count the number of successfully matched keywords and the total number of keywords of the target network information; Based on the effectiveness probability corresponding to the successfully matched keywords, the effectiveness influencing weight factor of each successfully matched keyword is constructed, and then the information relevance analysis is performed on the ratio of the number of successfully matched keywords and the total number of keywords of the target network information to obtain the information relevance index of the data received by each suspected source user.

5. A network information source tracing and analysis system for multi-source data fusion as claimed in claim 3, characterized in that: The specific method of performing information propagation confidence analysis based on different information propagation confidence analysis methods is as follows: If the subordinate node of the suspected source user is the current user corresponding to the target network information, the information propagation confidence of the suspected source user is calculated based on its information relevance index and time series propagation impact factor; If the non-target network information of the subordinate node corresponds to the current user, it is necessary to obtain the information propagation confidence of the user of its subordinate node, and calculate the information propagation confidence of the suspected source user in combination with its information relevance index and time series propagation impact factor.

6. A network information source tracing and analysis system for multi-source data fusion as claimed in claim 1, characterized in that: The specific method of the dynamic confidence threshold according to the node level analysis is as follows: The propagation level exponential decay analysis model is used to calculate the decay exponent of the level weight in combination with the node level of each suspected source user, thereby dynamically generating a dynamic confidence threshold of the suspected source user that matches each node level.

7. A network information source tracing and analysis system for multi-source data fusion as claimed in claim 6, characterized in that: The specific method of triggering the traceability iterative analysis is as follows: If the information dissemination confidence of the current user corresponding to a suspected source user is greater than its dynamic confidence threshold, it is marked as the information source user corresponding to the current user; The suspected source user is recorded as the new current user, triggering a new round of iterative analysis process of data collection, potential user identification and traceability verification.

8. A network information source tracing and analysis system for multi-source data fusion as claimed in claim 6, characterized in that: The specific method of obtaining the final source node of each branch is as follows: The information propagation confidence of the current user of a branch corresponding to all suspected source users is compared with their respective dynamic confidence thresholds one by one. If the information propagation confidence of all suspected source users is less than their corresponding dynamic confidence thresholds, the current user is determined to be the final source node of the branch.

9. The network information source tracing and analysis system for multi-source data fusion according to claim 1, characterized in that: The specific method of calculating the traceability credibility index of each final source node is as follows: The information propagation confidence of all levels of users in the branch to which each final source node belongs is extracted, and the traceability credibility index of each final source node is generated by layer-by-layer multiplication calculation.

10. The network information source tracing analysis system for multi-source data fusion according to claim 1, characterized in that: The specific analysis process of the traceability map is as follows: Arrange the final source nodes from high to low according to the traceability credibility index to generate a traceability node list, form a traceability map with the traceability node list and the traceability credibility index corresponding to the list, and mark the propagation impact level; The communication impact level is determined by comparing the traceability credibility index with the preset identification thresholds of each communication impact level, and the communication impact level is divided into level one, level two and level three.

Citation Information

Patent Citations

  • Traceability method and device of mobile network information

    CN104750694A

  • Tracking and tracing method based on network information

    CN118733765A

  • Identifier-based data tracking and tracing method

    CN116579008A

  • Network public opinion recognition processing method and device based on data trend analysis

    CN118964714A

  • System and method for constructing multi-source data analysis process

    CN119202353A

Cited By

  • Data mining-based tourist attraction competition environment analysis method and system

    CN120598391A

  • Tourist attraction competitive environment analysis method and system based on data mining

    CN120598391B