A network information traceability analysis system for multi-source data fusion
Through the multi-source data fusion network information traceability analysis system, the multi-source data acquisition and user traceability verification module are used to generate a collection of suspected source users and calculate the information propagation confidence, solving the problems of excessive traceability analysis and lack of confidence in the existing technology, and achieving efficient and accurate network information traceability analysis.
Patent Information
- Application Number
- CN202510543892.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-28
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-04-28
AI Technical Summary
The prior art lacks pre-identification of users of the suspected source of target information in network information traceability analysis, resulting in too large information retrieval and analysis scope, and lacks comprehensive analysis of the confidence or traceability level of traceability results, resulting in opacity in key node weights and poor visual interaction.
A network information traceability analysis system with multi-source data fusion is adopted to obtain traffic data, operation logs and social media usage records through the multi-source data acquisition module, and a collection of suspected users is generated by the potential user identification module, and information similarity verification is carried out through the user traceability verification module, information dissemination confidence is calculated, and traceability map is generated.
Through the dual-threshold dynamic adjustment mechanism, the traceability range is narrowed, the analysis efficiency and accuracy are improved, information integrity is enhanced, and information is adapted to complex network environments, and the accuracy, comprehensiveness and efficiency of traceability analysis are improved, providing reliable visual support.
Smart Images

Figure CN120075074B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network information traceability, and relates to a network information traceability analysis system for multi-source data fusion. Background Art
[0002] Network information traceability refers to tracking the source, propagation path, and related entities of network information through various technical means and methods to determine the initial publisher of the information, key nodes in the propagation process, etc. Network information traceability is of crucial significance for combating network crimes, maintaining network security, guiding public opinion, and ensuring social stability and normal information dissemination order. Therefore, the research on network information traceability analysis is of great significance.
[0003] There are also technical solutions for network information traceability in the prior art. For example, a Chinese invention patent application for a method for tracking and tracing network information with the publication number CN118733765A includes: determining key sectors of a specific public opinion event, extracting discussion content and posting keywords for each topic, establishing an event corpus, and constructing eigen and derivative object sub-corpora. Constructing and training an LSTM model to classify the discussion content. Determining the discussion duration and dividing time periods, and accordingly determining the inflection points of public opinion, comparing the accounts and remarks near the inflection points, and obtaining associated accounts.
[0004] In addition, a Chinese invention patent application for a method and device for tracing mobile network information with the publication number CN104750694A includes storing firewall logs and signaling record data according to time, setting a time period and delay information, and obtaining data corresponding to a corresponding duration and the number of time periods before obtaining the delay information. Calculating the keyword fields into hash codes respectively, starting a corresponding number of matching processes to match the hash codes, and generating complete traceability information upon successful matching. This method can improve the matching efficiency of information traceability.
[0005] Although the above two solutions propose some solutions for network information traceability, there are still certain limitations. For example, on the one hand, taking the above-mentioned comparative document one as an example, the prior art solutions lack pre-identification of suspected source users of the target information during the traceability analysis process, and directly extract keywords based on a specific public opinion event, and then conduct relevant account analysis, which increases the scope of information retrieval and analysis and reduces the system analysis efficiency.
[0006] On the other hand, taking the above-mentioned comparative document two as an example, the prior art solutions usually only output traceability information results during the output of traceability analysis results, lacking comprehensive analysis and output of the corresponding confidence level or traceability level, which will lead to opaque weights of key nodes, lack of quantitative basis for propagation confidence, and poor visual interaction. Summary of the Invention
[0007] In view of this, to solve the problems raised in the above-mentioned background technology, a network information traceability analysis system for multi-source data fusion is proposed.
[0008] The object of the present invention can be achieved by the following technical solutions: A network information traceability analysis system for multi-source data fusion, including: A multi-source data collection module, which acquires traffic data, operation logs, and social media usage records corresponding to the target network information of the current user within a preset valid time period based on multi-source data collection technology.
[0009] A potential user identification module, which pre-identifies the source of the target network information of the current user based on the traffic data, operation logs, and social media usage records to generate a set of suspected source users. If there are no suspected source users, the current user is directly marked as the final source node.
[0010] A user traceability verification module, which performs information similarity verification on the set of suspected source users to obtain the information dissemination confidence of each suspected source user. When it exceeds the dynamic confidence threshold analyzed according to the node hierarchy, it is marked as the information source user and triggers traceability iterative analysis until the final source nodes of each branch are obtained. Otherwise, the path traceability of this branch is terminated.
[0011] A traceability graph generation module, which establishes a weight transfer function for multi-level traceability paths based on the information dissemination confidence to calculate the traceability credibility index of each final source node, and generates a traceability graph accordingly.
[0012] Compared with the prior art, the beneficial effects of the present invention are as follows: (1) By setting a dual-threshold dynamic adjustment mechanism, the present invention analyzes the pre-identification and confidence verification steps during the traceability process. The pre-identification uses multi-source data to screen out suspected source users, narrowing the traceability scope and improving the analysis efficiency; the confidence verification judges the true source by accurately calculating the information dissemination confidence, improving the traceability accuracy. The combination of the two can adapt to complex network environments, construct a complete traceability chain, and facilitate in-depth analysis.
[0013] (2) By calculating the traceability credibility index of each final source node and generating a traceability graph, the present invention improves the efficiency and visualization effect of system analysis, providing a reliable basis for subsequent decision-making.
[0014] (3) By setting a multi-source heterogeneous data deep coupling mechanism, the present invention provides information from multiple dimensions, complements and verifies each other, enhances information integrity, improves analysis efficiency through parallel processing, and can flexibly adapt to complex and changeable network environments, thereby improving the accuracy, comprehensiveness, and efficiency of network information traceability analysis. Description of the Drawings
[0015] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0016] Figure 1 It is a schematic diagram of the connection of each module of the system of the present invention.
[0017] Figure 2 It is a schematic diagram of the working process of the user traceability verification module corresponding to an embodiment provided by the present invention.
[0018] Figure 3 It is a schematic diagram of the propagation path corresponding to an embodiment provided by the present invention.
[0019] Reference numerals: 1 - the current user corresponding to the target network information, 2 - the final source node. Detailed implementation manners
[0020] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0021] Please refer to Figure 1 As shown, the present invention provides a network information traceability analysis system for multi-source data fusion, including a multi-source data acquisition module, a potential user identification module, a user traceability verification module, and a traceability map generation module. Among them, the multi-source data acquisition module is connected to the potential user identification module, the potential user identification module is connected to the user traceability verification module, and the user traceability verification module is connected to the traceability map generation module.
[0022] The multi-source data acquisition module is used to obtain the traffic data, operation logs, and social media usage records of the current user corresponding to the target network information within a preset valid time period based on multi-source data acquisition technology.
[0023] It should be noted that the present invention enhances the integrity of information by setting a deep coupling mechanism for multi-source heterogeneous data, providing information from multiple dimensions, mutually supplementing and verifying, improving the analysis efficiency through parallel processing, and being able to flexibly adapt to complex and changeable network environments, thereby improving the accuracy, comprehensiveness, and efficiency of network information traceability analysis.
[0024] The potential user identification module is used to pre-identify the source of target network information of the current user based on traffic data, operation logs and social media usage records to generate a set of suspected source users. If there is no suspected source user, the current user is directly marked as the final source node.
[0025] It needs to be explained that the potential user identification module plays a key role in the preliminary screening and judgment of the source of information in the network information tracing and analysis system. The following is a detailed explanation from three aspects: data application, pre-identification process and final source node determination: 1. Application of multi-source data: Traffic data reflects the data interaction between the current user and other network nodes, covering the transmission object, time, frequency and data volume, etc., which can be used to mine potential related users; operation logs record the user's operation behavior in the system, including login, browsing, etc., which is used to analyze the way to obtain information and the source of information dissemination; social media usage records include interactive behaviors such as publishing and commenting, which can reveal the information dissemination chain and potential source channels in social networks.
[0026] 2. Pre-identification process: Based on multi-source data, the module first extracts the target network information release time from the operation log and social media usage records. Then, it combines multi-source data to obtain the start and end time of the data reception operation, calculates the exchange duration, determines the target user, obtains the data volume to build a reference duration, and compares the access effectiveness evaluation index. Then, the timeliness index is obtained through the difference between the release and reception end time and the timeliness analysis, and the recognition rate threshold is corrected. Finally, the recognition rate is compared with the corrected threshold to determine the effectiveness of the operation, and the target users corresponding to the effective operation are included to build a set of suspected source users.
[0027] 3. Final source node determination: If no suspected source user that meets the conditions is found after analysis and calculation, it means that the current user has no other source of information transmission in the information acquisition path, and it is directly marked as the final source node. This determination method can accurately identify isolated information release behavior or transmission starting point, providing a clear starting point for subsequent tracing.
[0028] In a preferred embodiment of the present invention, the specific method of generating the suspected source user set is as follows: extracting the release time of the target network information based on the operation log and social media usage record of the current user within a preset effective period.
[0029] It should be explained that within the preset effective period: 1. Its significance in data collection: In the multi-source data collection module, it limits the time span of data collection. For example, when collecting the target network information corresponding to the current user's traffic data, operation logs, and social media usage records, it is not to obtain all the user's historical data without restriction, but to collect it within this preset time period. Doing so can ensure that the collected data is closely related to the current information to be traced, eliminate the interference of obsolete and irrelevant data, and improve data processing efficiency and the pertinence of traceability analysis.
[0030] 2. Role in the analysis process: In subsequent processes such as potential user identification and information dissemination confidence calculation, the data collected "within the preset effective period" serves as the basis for analysis. It enables the system to focus on users' behaviors and data interactions within a specific time period, accurately determining the information source and dissemination path. For example, when calculating the timeliness index of data reception operations, it is based on the time difference between the information release time of the target network and the end time of data reception operations within this period. Without this clear time period limit, time comparison and timeliness analysis would lose their accuracy and significance, thereby affecting the reliability of the entire traceability analysis result.
[0031] Obtain the start and end times corresponding to each data reception operation of the current user before the information release time of the target network based on the traffic data, operation logs, and social media usage records of the current user within the preset effective period, and obtain the target users corresponding to each data reception operation based on the traffic data of the current user within the preset effective period.
[0032] It should be explained that the target user mentioned refers to the source user from whom the current user receives traffic data within the preset effective period.
[0033] It should be noted that the present invention conducts traceability analysis for target network information. Therefore, only the data reception operations of the current user are analyzed, and data sending operations are not considered.
[0034] Obtain the network information data volume corresponding to each data reception operation, and then construct the reference data access duration corresponding to each data reception operation.
[0035] It should be noted that the construction duration of the reference data access duration: Obtain the data volume and actual access duration of several data of the same type, and then calculate the average value of the actual access duration to obtain the reference data access duration of this type of data. The reference access durations of different types of data may vary. During actual construction, those skilled in the art shall select according to the actual situation.
[0036] It should be noted that the purpose of constructing the reference data access duration corresponding to each data reception operation: constructing the reference data access duration based on the obtained data volume is to set a reasonable standard to evaluate whether the actual data access duration is normal. Under normal circumstances, different data volumes will have different corresponding access durations. Constructing the reference data access duration is like setting a "ruler" for each data reception operation. Suppose that during a certain data reception operation, the normal access duration required for every 10 MB of data is 30 seconds. Then, when the data volume obtained in a certain data reception operation is 20 MB, the constructed reference data access duration may be 60 seconds. In this way, in subsequent analysis, by comparing the actual data access duration with the reference data access duration, it is possible to determine whether there is an abnormality in this data reception operation and whether it is a valid data reception operation, thereby helping to screen out suspected source users.
[0037] Compare the data access duration of each data reception operation with the corresponding reference data access duration to obtain the access effectiveness evaluation index corresponding to each data reception operation.
[0038] Preferably, the analysis method of the access effectiveness evaluation index: calculate the ratio of the data access duration of each data reception operation to the corresponding reference data access duration to obtain the access effectiveness evaluation index corresponding to each data reception operation, and the maximum value of the access effectiveness evaluation index is 1.
[0039] Calculate the difference between the release time of the target network information and the end time corresponding to each data reception operation, and then conduct timeliness analysis to obtain the timeliness index of each data reception operation.
[0040] A preferably timeliness index analysis method, assuming that the release time of the target network information is , and the end time of a certain data reception operation is , where represents the number of the data reception operation, , represents the number of data reception operations.
[0041] Use the formula to analyze and obtain the timeliness index of each data reception operation , where is a preset attenuation coefficient, which is adjusted according to the characteristics of information dissemination and domain characteristics. For information with fast dissemination speed and frequent updates (such as entertainment news, sports event information), takes a larger value, and the information timeliness decays rapidly; for relatively stable and slowly updated information (such as some professional academic materials), takes a smaller value. For example, in the scenario of social hot spot information dissemination, through testing and setting of empirical values, . Indicates a preset reference interval duration.
[0042] The value range of the timeliness index is between (0, 1]. The closer it is to 1, the stronger the timeliness, which means that this data reception operation is closer to the information release in time, and the value and reliability of the information are relatively higher; the closer it is to 0, the weaker the timeliness, and the information may have experienced a long time during the dissemination process, and its accuracy and relevance to the source may be affected. When calculating the threshold of the access effectiveness evaluation index subsequently, the timeliness index can be used as an important correction factor, so that the entire traceability analysis system can more accurately judge the effectiveness of the data reception operation, thereby improving the accuracy of network information traceability.
[0043] The preset access effectiveness evaluation index threshold is corrected according to the timeliness index of each data reception operation to obtain the access effectiveness evaluation index threshold corresponding to each data reception operation.
[0044] Preferably, the timeliness index of each data reception operation is multiplied by the corresponding preset access effectiveness evaluation index threshold to obtain the access effectiveness evaluation index threshold corresponding to each data reception operation.
[0045] Compare the access effectiveness evaluation index of each data reception operation with the corresponding access effectiveness evaluation index threshold to determine whether each data reception operation is a valid data reception operation. Record the target users corresponding to each valid data reception operation as suspected source users, and then construct a set of suspected source users.
[0046] Preferably, the specific determination method for whether each data reception operation is a valid data reception operation is as follows: If the access effectiveness evaluation index of a certain data reception operation is greater than or equal to the corresponding access effectiveness evaluation index threshold, identify that data reception operation as a valid data reception operation; otherwise, identify the data reception operation as an invalid data reception operation.
[0047] It should be further explained that for the data reception operations determined to be valid, the system records the target users corresponding to these operations. Because these users show high information effectiveness during the data reception process, they are very likely to be important nodes in the information dissemination process or even the source of the information. The system aggregates the target users corresponding to all these valid data reception operations to construct a set of suspected source users. This set provides key clues and a screening range for subsequent further in-depth traceability analysis, greatly reducing the search space for traceability and improving the efficiency and accuracy of traceability analysis.
[0048] Please refer to Figure 2As shown, the user traceability verification module is used to perform information similarity verification on the set of suspected source users to obtain the information dissemination confidence of each suspected source user. If it exceeds the dynamic confidence threshold analyzed according to the node hierarchy, it is marked as the information source user and triggers traceability iterative analysis until the final source node of each branch is obtained; otherwise, the path traceability of this branch is terminated.
[0049] In a preferred embodiment of the present invention, the specific analysis method of the information dissemination confidence of each suspected source user is as follows: Calculate the information correlation index of the data reception information corresponding to each suspected source user based on the BERT algorithm.
[0050] It should be explained that the BERT algorithm is a pre-trained language model based on the Transformer architecture. Through masked language model and next sentence prediction for large-scale unsupervised pre-training, it can deeply understand the text semantics and capture the meaning of words in context bidirectionally. After completing the pre-training, it can be fine-tuned for different natural language processing tasks and is widely used in fields such as text classification, question answering systems, machine translation, and information retrieval.
[0051] Combine the target network information release time with the end time of the data reception operation of each suspected source user corresponding to the current user to construct the time-series propagation influence factor of each suspected source user.
[0052] Preferably, calculate the difference between the target network information release time of the current user and the end time of the data reception operation to obtain the corresponding information release response time, and calculate the ratio with the preset reference response time to obtain the time-series propagation influence factor.
[0053] It should be explained that the time-series propagation influence factor is mainly used to measure the propagation of information in chronological order. If the information release response time is short, that is, the time interval between the end time of the data reception operation and the information release time is small, it means that the suspected source user receives the information in a more timely manner, has a greater impact on information dissemination, and the time-series propagation influence factor is higher.
[0054] It should be explained that in this network information traceability analysis system, the information release response time is a key indicator for evaluating the timeliness of information dissemination and the importance of suspected source users. When evaluating the information dissemination confidence of suspected source users, the information release response time is an important basis for constructing the time-series propagation influence factor. A shorter response time will make the time-series propagation influence factor larger, and when jointly calculating the information dissemination confidence with the information correlation index, it can improve the credibility of this suspected source user as the information source. Because users who receive information in a timely manner are more likely to obtain information in the early stage of information dissemination and are closer to the information source.
[0055] Determine the information dissemination confidence analysis method according to the levels of each suspected source user, and then conduct information dissemination confidence analysis based on different information dissemination confidence analysis methods.
[0056] In a preferred embodiment of the present invention, the specific analysis method of the information relevance index of the data reception information corresponding to each suspected source user is as follows: Extract the keywords of the target network information and their validity probabilities based on the BERT algorithm.
[0057] Based on the traffic data, operation logs, and social media usage records of the current user corresponding to the target network information within a preset valid period, obtain the data reception information corresponding to each suspected source user, and then use the BERT algorithm to obtain the keywords of the corresponding data reception information.
[0058] Match the keywords of the target network information with the keywords of the data reception information corresponding to each suspected source user, and count the number of successfully matched keywords and the total number of keywords of the target network information.
[0059] Construct the validity impact weight factor of each successfully matched keyword based on the validity probability corresponding to the successfully matched keyword, and then conduct information relevance analysis by combining the ratio of the number of successfully matched keywords and the total number of keywords of the target network information to obtain the information relevance index of the data reception information corresponding to each suspected source user.
[0060] Preferably, the specific analysis method of the validity impact weight factor: Conduct a proportion analysis of the validity probability corresponding to the successfully matched keyword and the sum of the corresponding validity probabilities to obtain the validity impact weight factor of each successfully matched keyword.
[0061] Preferably, the specific analysis process of the information relevance index of the data reception information corresponding to each suspected source user is as follows: Calculate the proportion of the number of successfully matched keywords and the total number of keywords of the target network information, and then calculate the sum of the validity impact weight factors corresponding to the successfully matched keywords. Multiply the above calculation results to obtain the information relevance index of the data reception information corresponding to each suspected source user.
[0062] It should be noted that the information relevance index is calculated based on the BERT algorithm. By extracting the keywords of the target network information and the data reception information corresponding to the suspected source user, and combining the validity probability of the keywords, the similarity degree and the degree of association tightness of the information content between the two are measured. For example, if the keywords of the target network information have a high matching degree with the keywords of the data reception information of the suspected source user, and the validity probability of the successfully matched keywords is large, then the information relevance index is high, indicating a high degree of association in the information content between the two, and the possibility of this suspected source user being the information source is also greater.
[0063] In a preferred embodiment of the present invention, the specific method for analyzing the information dissemination confidence based on different information dissemination confidence analysis methods is as follows: If the subordinate node of the suspected source user is the current user corresponding to the target network information, calculate the information dissemination confidence of the suspected source user based on its information correlation index and the time-series dissemination influence factor.
[0064] It should be noted that the "node" in the above text refers to an abstract identifier representing a user or an information dissemination entity in the network information dissemination path, and is used to construct and analyze the information dissemination relationship. The current user, the suspected source user, and the ultimate source node described in the present invention all exist in the network information dissemination path. Among them, the current user corresponding to the target network information refers to the "final node" or "lowest-level node" in the network information dissemination path. The suspected source user is a temporary term that exists in the intermediate analysis process during the identification of the upper-level node. The ultimate source node refers to the "initial node" or "first-level node" in the network information dissemination path. Since the present invention performs traceability analysis on specific target network information, there is only one current user corresponding to the target network information, and there may be one or more ultimate source nodes at the same time.
[0065] Preferably, the analysis method for the information dissemination confidence of the suspected source user is: Calculate the product of the information correlation index and the time-series dissemination influence factor of the suspected source user.
[0066] It should be noted that calculating the product of the information correlation index and the time-series dissemination influence factor can comprehensively consider the influence of these two key factors, namely information content association and time-order dissemination, on the information dissemination confidence. A high information content association indicates a strong similarity between the information received by the suspected source user and the target network information; while a high time-series dissemination influence factor means that the user receives the information more timely and has an advantage in the dissemination chain. Multiplying the two can obtain an information dissemination confidence that can more comprehensively and accurately reflect the credibility of the suspected source user as an information source. For example, when the information correlation index is 0.8 and the time-series dissemination influence factor is 0.7, the product of the two is 0.56. Compared with using only one of the factors alone, this comprehensive result can more accurately evaluate the importance and credibility of the suspected source user in information dissemination, providing a more reliable basis for subsequent judgment of whether it is an information source user.
[0067] If the subordinate node is not the current user corresponding to the target network information, it is necessary to obtain the information dissemination confidence of the subordinate node user, and calculate the information dissemination confidence of the suspected source user in combination with its information correlation index and the time-series dissemination influence factor.
[0068] Preferably, the analysis method of the information dissemination confidence of the suspected source user is: multiplying the information dissemination confidence, information correlation index, and time-series dissemination influence factor of the subordinate node users of the suspected source user.
[0069] In a preferred embodiment of the present invention, the specific method for the dynamic confidence threshold according to the node level analysis is as follows: By using the propagation level exponential decay analysis model, the decay index of the level weight is calculated in combination with the node level of each suspected source user, so as to dynamically generate the dynamic confidence threshold of the suspected source user matching each node level.
[0070] Preferably, the specific analysis method of the dynamic confidence threshold of the suspected source user matching each node level: Using the formula Analyze to obtain the dynamic confidence threshold of the suspected source user matching each node level , where represents the preset initial threshold, represents the natural constant, represents the preset decay coefficient, represents the node level number, , represents the number of node levels.
[0071] It should be explained that the propagation level exponential decay is the core mechanism in this network information traceability analysis system for dynamically generating the dynamic confidence threshold of the suspected source user. It is based on the characteristics of information dissemination. Considering that as the propagation level increases, the reliability or dissemination value of information may gradually decrease, and this decrease is not a linear change but conforms to the exponential decay law. Specifically: 1. Calculation model and principle: The system uses the propagation level exponential decay analysis model to calculate the decay index of the level weight in combination with the node level of each suspected source user. Specifically through the formula . In this formula, the initial threshold is a preset basic value, which provides a starting standard for the dynamic confidence threshold. The preset decay coefficient is a key parameter adjusted according to the characteristics of information dissemination and domain characteristics, and its value is different for different types of information dissemination scenarios. The node level number represents the position of the suspected source user in the information dissemination path. Starting from the current user and tracing upwards, the level number increases by 1 for each user passed.
[0072] Role in the system: In the user traceability verification module, this mechanism determines whether a suspected source user is the actual information source user based on the calculated dynamic confidence threshold. For suspected source users with a lower level (closer to the current user), since the level weight attenuation is less, the dynamic confidence threshold is relatively high. This means that the requirements for such users to be information source users are more stringent, and a higher information dissemination confidence is required for confirmation. For example, if a suspected source user is at the level adjacent to the current user, its dynamic confidence threshold may be 0.8, and it will only be marked as an information source user when its information dissemination confidence is greater than 0.8. For suspected source users with a higher level (farther from the current user), the level weight attenuation is more, and the dynamic confidence threshold is relatively low. This is because after the information is propagated through multiple layers, the interference factors increase, and it is difficult to verify as strictly as direct propagation. Therefore, the verification standard is lowered, and as long as its information dissemination confidence reaches the corresponding lower threshold, it may be identified as an information source user.
[0073] In a preferred embodiment of the present invention, the specific method for triggering the traceability iterative analysis is as follows: If the information dissemination confidence of the current user corresponding to a suspected source user is greater than its dynamic confidence threshold, mark it as the information source user corresponding to the current user.
[0074] Record the suspected source user as the new current user, and trigger a new round of iterative analysis processes of data collection, potential user identification, and traceability verification.
[0075] In a preferred embodiment of the present invention, the specific method for obtaining the final source node of each branch is as follows: Compare the information dissemination confidence of all suspected source users corresponding to the current user of a branch with each automatic confidence threshold one by one. If the information dissemination confidence of all suspected source users is less than their corresponding dynamic confidence thresholds, determine that the current user is the final source node of this branch.
[0076] Exemplarily, an analysis result of the final source node is as Figure 3 , there are four propagation paths in the figure, corresponding to four final source nodes respectively, and the node levels of each final source node are different.
[0077] It should be further explained that when comparing the information dissemination confidence of each suspected source user with its respective corresponding dynamic confidence threshold, if the information dissemination confidence of all suspected source users is less than their corresponding thresholds, this means that in this branch, the information dissemination confidence of no other user reaches the sufficient standard to be identified as a more upstream information source user. Therefore, in this case, the current user is determined to be the final source node of this branch, that is, the propagation of information in this branch starts from the current user, and the subsequent traceability analysis ends here in this branch.
[0078] It should be noted that the present invention adopts a dual-threshold dynamic adjustment mechanism, and starts two steps of pre-identification and confidence verification for the traceability process. The pre-identification uses multi-source data to screen out suspected source users, narrow the traceability scope, and improve the analysis efficiency; the confidence verification determines the true source by accurately calculating the information propagation confidence, and improves the traceability accuracy. The cooperation of the two can adapt to complex network environments, construct a complete traceability chain, and facilitate in-depth analysis.
[0079] The traceability graph generation module is used to establish a weight transfer function for multi-level traceability paths according to the information propagation confidence, calculate the traceability credibility index of each final source node, and generate a traceability graph accordingly.
[0080] In a preferred embodiment of the present invention, the specific method for calculating the traceability credibility index of each final source node is as follows: extract the information propagation confidence of all levels of users in the branch to which each final source node belongs, and calculate the traceability credibility index of each final source node through layer-by-layer multiplication.
[0081] In a preferred embodiment of the present invention, the specific analysis process of the traceability graph is as follows: arrange each final source node in descending order of the traceability credibility index to generate a traceability node list, form a traceability graph with the traceability node list and the corresponding traceability credibility index, and mark the propagation influence level.
[0082] The propagation influence level is determined by comparing the traceability credibility index with the preset recognition thresholds for each propagation influence level. The propagation influence levels are divided into level one, level two, and level three.
[0083] It should be noted that the present invention calculates the traceability credibility index of each final source node and generates a traceability graph, which improves the efficiency and visualization effect of system analysis and provides a reliable basis for subsequent decision-making.
[0084] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to obtain a formula closest to the actual situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.
[0085] The above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed in this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
[0086] Finally, the above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A network information traceability analysis system for multi-source data fusion, characterized in that, Including: A multi-source data collection module that obtains traffic data, operation logs, and social media usage records of the current user corresponding to the target network information within a preset valid period based on multi-source data collection technology; A potential user identification module that pre-identifies the source of the target network information for the current user based on the traffic data, operation logs, and social media usage records to generate a set of suspected source users. If there are no suspected source users, the current user is directly marked as the final source node; A user traceability verification module that verifies the information similarity of the set of suspected source users to obtain the information dissemination confidence of each suspected source user. If it exceeds the dynamic confidence threshold analyzed according to the node hierarchy, it is marked as the information source user and triggers traceability iterative analysis until the final source nodes of each branch are obtained. Otherwise, the path traceability of this branch is terminated; A traceability graph generation module that establishes a weight transfer function for multi-level traceability paths based on the information dissemination confidence to calculate the traceability credibility index of each final source node, and generates a traceability graph accordingly; Extract the information dissemination confidence of all levels of users in the branches to which each final source node belongs, and generate the traceability credibility index of each final source node through layer-by-layer product calculation; The specific method for generating the set of suspected source users is as follows: Extract the publication time of the target network information based on the operation logs and social media usage records; Based on the traffic data, operation logs, and social media usage records, obtain the start and end times corresponding to each data reception operation of the current user before the publication time of the target network information, and perform difference calculation to obtain the data access duration corresponding to each data reception operation; Obtain the target users corresponding to each data reception operation based on the traffic data; Obtain the network information data volume corresponding to each data reception operation, and then construct the reference data access duration corresponding to each data reception operation; Calculate the ratio of the data access duration of each data reception operation to the corresponding reference data access duration to obtain the access effectiveness evaluation index corresponding to each data reception operation; Using the formula Analyze and obtain the timeliness index of each data reception operation , where is a preset attenuation coefficient, represents the target network information release time, represents the end time of a certain data reception operation, where represents the number of the data reception operation, , represents the number of data reception operations; Multiply by the corresponding preset access validity evaluation index threshold to obtain the access validity evaluation index threshold corresponding to each data reception operation; Compare the access effectiveness evaluation index of each data reception operation with the corresponding access effectiveness evaluation index threshold to determine whether each data reception operation is a valid data reception operation. Record the target users corresponding to each valid data reception operation as suspected source users, and then construct a set of suspected source users; The specific analysis method for the information dissemination confidence of each suspected source user is as follows: Calculate the information relevance index of the data reception information corresponding to each suspected source user based on the BERT algorithm; Combine the publication time of the target network information with the end time of the data reception operation of each suspected source user corresponding to the current user to construct the temporal propagation influence factor of each suspected source user; Determine the information dissemination confidence analysis method according to the level of each suspected source user, and then perform information dissemination confidence analysis based on different information dissemination confidence analysis methods.
2. The network information traceability analysis system for multi-source data fusion according to claim 1, wherein: The specific analysis method for the information relevance index of the data reception information corresponding to each suspected source user is as follows: Extract the keywords of the target network information and their effectiveness probabilities based on the BERT algorithm; Based on the target network information, obtain the data reception information corresponding to each suspected source user for the traffic data, operation logs, and social media usage records of the current user within the preset valid period. Then, use the BERT algorithm to obtain the keywords of the corresponding data reception information. Match the keywords of the target network information with the keywords of the data reception information corresponding to each suspected source user, and count the number of successfully matched keywords and the total number of keywords of the target network information. Based on the validity probability corresponding to the successfully matched keywords, construct the validity influence weight factor of each successfully matched keyword. Then, combine the ratio of the number of successfully matched keywords and the total number of keywords of the target network information to conduct information relevance analysis to obtain the information relevance index of the data reception information corresponding to each suspected source user.
3. The network information traceability analysis system for multi-source data fusion according to claim 1, characterized in that: The specific method for performing information dissemination confidence analysis based on different information dissemination confidence analysis methods is as follows: If the lower-level node of the suspected source user is the current user corresponding to the target network information, calculate the information dissemination confidence of the suspected source user based on its information relevance index and the time-series propagation influence factor. If the lower-level node is not the current user corresponding to the target network information, it is necessary to obtain the information dissemination confidence of the lower-level node user and calculate the information dissemination confidence of the suspected source user in combination with its information relevance index and the time-series propagation influence factor.
4. A network information traceability analysis system for multi-source data fusion according to claim 1, characterized in that: The specific method for the dynamic confidence threshold according to node-level analysis is as follows: Through the propagation level exponential decay analysis model, calculate the decay index of the level weight based on the node level of each suspected source user, so as to dynamically generate the dynamic confidence threshold of the suspected source user matching each node level.
5. The network information traceability analysis system for multi-source data fusion according to claim 4, characterized in that: The specific method for triggering the traceability iteration analysis is as follows: If the information dissemination confidence of the current user corresponding to a certain suspected source user is greater than its dynamic confidence threshold, mark it as the information source user corresponding to the current user. Record the suspected source user as the new current user, and trigger a new round of iterative analysis processes of data collection, potential user identification, and traceability verification.
6. The network information traceability analysis system for multi-source data fusion according to claim 4, characterized in that: The specific method for obtaining the final source node of each branch is as follows: Compare the information dissemination confidence of all suspected source users corresponding to the current user of a certain branch with each automatic dynamic confidence threshold one by one. If the information dissemination confidence of all suspected source users is less than their corresponding dynamic confidence thresholds, it is determined that the current user is the final source node of this branch.
7. The network information traceability analysis system for multi-source data fusion according to claim 1, characterized in that: The specific analysis process of the traceability graph is as follows: Arrange the final source nodes in descending order of the traceability credibility index to generate a traceability node list. Form a traceability graph with the traceability node list and the corresponding traceability credibility index, and mark the propagation influence level. Among them, the propagation influence level is determined by comparing the traceability credibility index with the preset recognition thresholds of each propagation influence level. The propagation influence levels are divided into level one, level two, and level three.
Citation Information
Patent Citations
Traceability method and device of mobile network information
CN104750694A
Tracking and tracing method based on network information
CN118733765A
Identifier-based data tracking and tracing method
CN116579008A
Network public opinion recognition processing method and device based on data trend analysis
CN118964714A