A security monitoring method, system, device and medium for networked video

By building a front-end acquisition link and combining security management methods with video content detection, link monitoring and passive risk prediction, the problem of insufficient security of networked video acquisition is solved, and all-round security monitoring and improvement of video is achieved.

CN120128423BActive Publication Date: 2025-07-04SHENZHEN HONGYI TECH CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510578219.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-07-04
Estimated Expiration
2045-05-07

AI Technical Summary

Technical Problem

The security monitoring of networked videos in the prior art is incomplete, resulting in insufficient security in network transmission and storage of videos, and it is impossible to deal with multiple threats in complex network environments.

Method used

By building a front-end acquisition link, video content security detection, link real-time monitoring and passive security risk prediction are carried out, and combined with multiple authentication and security management of multiple communication links, all-round security monitoring of networked video acquisition is achieved.

Benefits of technology

It realizes comprehensive monitoring of the network-acquired video from content to link transmission and potential risks, and improves the security of video in network transmission and storage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128423B_ABST
    Figure CN120128423B_ABST
Patent Text Reader

Abstract

The present invention discloses a security monitoring method, system, device and medium for networked videos, relating to the technical field of video security monitoring. The method includes: constructing a front-end acquisition link to obtain networked acquisition videos; performing video content security detection on the networked acquisition videos to obtain a first video security detection result; performing security detection on the networked acquisition videos to obtain a second video security detection result; performing passive security risk prediction on the networked acquisition videos to obtain a third video security detection result; and performing security management on the networked acquisition videos. The present invention solves the technical problem in the prior art that the security monitoring of networked acquisition videos is incomplete, resulting in insufficient security during network transmission and storage of videos, and achieves the technical effect of comprehensively monitoring networked acquisition videos from content to link transmission and potential risks, and improving the security of videos during network transmission and storage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of video security monitoring, and particularly relates to a security monitoring method, system, device and medium for networked videos. Background Art

[0002] In the prior art, the security monitoring of networked collected videos is often one-sided, only focusing on the screening of sensitive information in the video content, or emphasizing the stability detection of the link transmission, lacking the ability to predict potential security risks, and it is difficult to cope with multiple threats such as data leakage, malicious tampering, and transmission interruption in a complex network environment, resulting in security risks for videos during network transmission and storage, and unable to meet the requirements of high-security scenarios.

[0003] The prior art has the technical problem that the security monitoring of networked collected videos is incomplete, resulting in insufficient security of videos during network transmission and storage. Summary of the Invention

[0004] The present application provides a security monitoring method, system, device and medium for networked videos, which are used to solve the technical problem that the security monitoring of networked collected videos in the prior art is incomplete, resulting in insufficient security of videos during network transmission and storage.

[0005] In view of the above problems, the present application provides a security monitoring method, system, device and medium for networked videos.

[0006] In the first aspect of the present application, a security monitoring method for networked videos is provided. The method includes:

[0007] When a front-end acquisition device that has completed multiple authentications accesses the network, a front-end acquisition link is constructed, and based on the front-end acquisition link, a networked collected video is obtained; the video content security of the networked collected video is detected according to a sensitive content recognition map to obtain a first video security detection result; the real-time monitoring data of the link of the front-end acquisition link is obtained, and based on the real-time monitoring data of the link, the security of the networked collected video is detected to obtain a second video security detection result; based on multiple other access nodes of the network, multiple other communication links are constructed, and based on the multiple other communication links, passive security risk prediction of the networked collected video is performed to obtain a third video security detection result; the networked collected video is managed for security according to the first video security detection result, the second video security detection result and the third video security detection result.

[0008] In the second aspect of the present application, a security monitoring system for networked videos is provided. The system includes:

[0009] An Internet-connected video acquisition module, configured to construct a front-end acquisition link when a front-end acquisition device that has completed multi-factor authentication accesses the network, and obtain an Internet-connected acquisition video according to the front-end acquisition link; a first detection result acquisition module, configured to perform video content security detection on the Internet-connected acquisition video according to a sensitive content recognition map, and obtain a first video security detection result; a second detection result acquisition module, configured to obtain real-time link monitoring data of the front-end acquisition link, and perform security detection on the Internet-connected acquisition video according to the real-time link monitoring data, and obtain a second video security detection result; a third detection result acquisition module, configured to construct a plurality of other communication links according to a plurality of other access nodes of the network, and perform passive security risk prediction on the Internet-connected acquisition video according to the plurality of other communication links, and obtain a third video security detection result; a security management module, configured to perform security management on the Internet-connected acquisition video according to the first video security detection result, the second video security detection result, and the third video security detection result.

[0010] In a third aspect of the present application, there is provided an electronic device, which includes: a processor; a memory for storing executable instructions of the processor; wherein, the processor is configured to execute a method for security monitoring of Internet-connected videos provided by the present application.

[0011] In a fourth aspect of the present application, there is provided a computer-readable storage medium storing a computer program for executing a method for security monitoring of Internet-connected videos provided by the present application.

[0012] One or more technical solutions provided in the present application have at least the following technical effects or advantages:

[0013] When a front-end acquisition device that has completed multi-factor authentication accesses the network, construct a front-end acquisition link, and obtain an Internet-connected acquisition video according to the front-end acquisition link; perform video content security detection on the Internet-connected acquisition video to obtain a first video security detection result; perform security detection on the Internet-connected acquisition video to obtain a second video security detection result; perform passive security risk prediction on the Internet-connected acquisition video to obtain a third video security detection result; perform security management on the Internet-connected acquisition video according to the first video security detection result, the second video security detection result, and the third video security detection result. The technical effect of comprehensively monitoring the Internet-connected acquisition video from content to link transmission and potential risks and improving the security of the video during network transmission and storage is achieved. Description of the Drawings

[0014] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0015] Figure 1 It is a schematic flowchart of a security monitoring method for networked video provided by an embodiment of the present application.

[0016] Figure 2 It is a schematic structural diagram of a security monitoring system for networked video provided by an embodiment of the present application.

[0017] Figure 3 It is a schematic structural diagram of an electronic device provided by the present application.

[0018] Explanation of reference numerals: Networked video acquisition module 10, first detection result acquisition module 20, second detection result acquisition module 30, third detection result acquisition module 40, security management module 50, processor 21, memory 22, input device 23, output device 24. Specific embodiments

[0019] The present application provides a security monitoring method, system, device and medium for networked video, aiming to solve the technical problem in the prior art that the security monitoring of networked video acquisition is not comprehensive, resulting in insufficient security during network transmission and storage of video.

[0020] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.

[0021] Embodiment 1, as Figure 1 shown, the present application provides a security monitoring method for networked video, and the method includes:

[0022] Step S100: When a front-end acquisition device that has completed multiple authentications accesses the network, construct a front-end acquisition link, and obtain networked acquisition video according to the front-end acquisition link.

[0023] Specifically, when a video capture device that has passed strict multi-factor authentication is connected to the network, this multi-factor authentication covers device authentication, permission verification, and security status detection, etc., to ensure that the connected device is legal and secure, and to prevent potential risks brought by the access of illegal devices. Once the authentication is passed, a front-end capture link is quickly constructed. This link is a comprehensive data transmission channel that includes physical connections, communication protocols, data interfaces, etc., and can ensure that video data is transmitted stably, efficiently, and securely from the video capture device. Relying on this established front-end capture link, the network-connected captured video is obtained.

[0024] Step S200: Perform video content security detection on the network-connected captured video according to the sensitive content recognition map, and obtain the first video security detection result.

[0025] Specifically, based on the pre-constructed sensitive content recognition map, a comprehensive video content security detection is carried out on the network-connected captured video obtained through the front-end capture link. This map covers the feature identifiers of various sensitive information, and the content features of each frame in the video are identified one by one. The identified features are transformed into content feature vectors for each frame. Subsequently, these vectors are input into the sensitive content recognition map for comparison and analysis, and then the sensitive content recognition results for each frame are obtained. On this basis, according to the evaluation criteria, a content security evaluation is carried out for each video frame, and the content security coefficient for each frame is calculated. Finally, the sensitive content recognition results for each frame and the corresponding content security coefficients are sorted and summarized to obtain the first video security detection result. This result intuitively reflects whether there is sensitive information in the video content itself.

[0026] Step S300: Obtain the real-time monitoring data of the front-end capture link, and perform security detection on the network-connected captured video according to the real-time monitoring data of the link, and obtain the second video security detection result.

[0027] Specifically, real-time acquisition of the real-time monitoring data of the front-end acquisition link, which covers the operation information of both the link network and hardware. Identify network security threat features such as network traffic anomalies, port scans, and signs of network attacks from the network monitoring data. At the same time, analyze hardware security threat features such as hardware failures, device overheating, and transmission signal attenuation from the hardware monitoring data, and then obtain the network security threat identification result and the hardware security threat identification result respectively. Based on the network security threat identification result, use the network threat video security risk detection model constructed by M learners trained with the network security threat identification sample set and the network threat video security risk detection sample set to calculate M network threat video security risk coefficients, and take their central value to obtain the first threat video security risk coefficient. Similarly, calculate the second threat video security risk coefficient according to the hardware security threat identification result. Finally, fuse these two coefficients according to the weight to generate the second video security detection result. This result comprehensively reflects the impact degree of the security risks at the link network and hardware levels on the video, which helps to timely discover and handle video security hidden dangers caused by link problems, such as blocking risky video transmissions and repairing link failures, etc., to ensure the security and stability of video transmission.

[0028] Step S400: Construct multiple other communication links according to the multiple other access nodes of the network, and perform passive security risk prediction on the networked acquisition video according to the multiple other communication links to obtain the third video security detection result.

[0029] Specifically, after completing the detection work related to the front-end acquisition link, analysis will be carried out on multiple other access devices in the network. These other access devices are of various types, and may be cameras, storage devices, or data forwarding devices in different regions, etc. Taking these devices as nodes, multiple other communication links are constructed to establish a network transmission path that is interconnected with the front-end acquisition link. Subsequently, the monitoring information of these newly built links is collected to obtain multiple other link monitoring data, including traffic fluctuations of the links, signal strength changes, device load conditions, etc. Using these data, security threat identification is performed on each other communication link respectively. For example, it is detected whether there are network attacks implied by abnormal traffic fluctuations, data leakage risks caused by abnormal device connections, etc., so as to obtain the threat identification results of each link. After that, based on the topological association dataset between each link and the front-end acquisition link, a global link topology model is constructed. With the help of this model, the propagation paths of threats on each link in the network are simulated, and then the security impacts of these threats on the front-end acquisition link are predicted to obtain multiple passive security impact characteristics of the front-end link, such as link congestion risks, data tampering risks, etc. By performing data fusion on these characteristics, the system obtains the prediction result of the passive security impact of the link. Finally, based on this prediction result, a security risk assessment is carried out on the networked acquisition video, fully considering the risks such as interference and data loss that may be caused to video transmission by potential threats on other links, and then the third detection result of video security is obtained.

[0030] Step S500: Perform security management on the networked acquisition video according to the first detection result of video security, the second detection result of video security, and the third detection result of video security.

[0031] Specifically, summarize the first video security detection results, which reflect whether the video content itself contains sensitive information; the second video security detection results, which reflect the security risks existing in the front-end acquisition link at the network and hardware levels, such as the impact of network attack threats, hardware failure risks, etc. on the video; and the third video security detection results, which predict the passive security risks of the current video transmission caused by potential threats in other communication links in the network. For example, the risk of video transmission interruption caused by adjacent link failures. Based on these three detection results, a series of targeted security management measures are initiated. If the first video security detection result shows that the video contains sensitive content, operations such as restricting the video dissemination range, censoring the video, or directly deleting it are taken; if the second video security detection result indicates that there are security threats in the link, the link will be repaired in a timely manner, the network configuration will be adjusted, or the affected video transmission will be blocked to ensure the stability and security of the video transmission process; if the third video security detection result indicates that the risks of other links may affect the current video, alternative transmission paths will be planned in advance, the risk links will be monitored more intensively, or the video data will be encrypted to reduce the impact of potential risks. By comprehensively using these three detection results for security management, the security of the networked acquired video is fully guaranteed, and the health and stability of the video transmission and usage environment are maintained.

[0032] In a possible implementation manner, step S200 further includes:

[0033] Step S210: Perform content feature recognition on each video frame in the networked acquired video, and construct content feature vectors for each frame.

[0034] Step S220: Input the content feature vectors of each frame into the sensitive content recognition map to obtain sensitive content recognition results for each frame.

[0035] Step S230: Perform content security evaluation on each video frame according to the sensitive content recognition results of each frame to obtain content security coefficients for each frame.

[0036] Step S240: Organize the sensitive content recognition results of each frame and the content security coefficients of each frame to obtain the first video security detection result.

[0037] Specifically, image recognition technology and machine learning algorithms are used to deeply analyze each video frame in the video one by one. In the image feature recognition stage, convolutional operations are performed on the video frames through a convolutional neural network (CNN) to extract basic visual features such as edges, textures, and color distributions from the pixel matrix of the video frames. These features help capture the object shapes, surface details, and color composition information in the video frames. At the same time, object detection algorithms are used to identify various objects in the video frames, determine their categories, positions, and sizes, further enriching the dimension of the content features. For the possible text information in the video frames, with the help of optical character recognition (OCR) technology, the text is converted into processable text data and its semantic features are extracted. Subsequently, the features of images, objects, text, etc. extracted from different levels are integrated and encoded. According to the vector space model, they are mapped into vector forms in a high-dimensional space to construct content feature vectors for each frame. These vectors, as the digital representations of the video frame content, accurately and comprehensively record the key information of each frame.

[0038] The constructed content feature vectors for each frame are input into the sensitive content recognition map one by one. This map is constructed based on deep learning technology and is pre-trained on a large amount of video data containing various sensitive and normal content. The internal structure of the map adopts a convolutional neural network (CNN) architecture. Through the convolutional layer, convolutional operations are performed on the input feature vectors to extract deep-level features. The convolutional kernels in the convolutional layer continuously slide and scan the feature vectors to capture local patterns therein, such as specific image shapes, color combinations, or semantic segments, etc. Subsequently, the pooling layer performs dimensionality reduction on the convolutional features, reducing the computational amount while retaining key information. After multiple convolutional and pooling operations, the feature vectors are further passed to the fully connected layer. The fully connected layer integrates the processed feature vectors and uses the softmax function for classification, outputting the probabilities of each video frame belonging to different sensitive content categories and normal content categories. According to the category with the highest probability, the sensitive content recognition result of this frame is determined, thereby judging whether the video frame contains sensitive content and what type of sensitive content it belongs to, providing a key basis for subsequent video security assessment.

[0039] Based on the recognition results, a comprehensive content security evaluation is carried out for each video frame to obtain the content security coefficient of each frame. The evaluation work is carried out according to the pre-set rules and weight system. If a certain video frame is recognized as containing sensitive content, it will be quantitatively scored according to the category and severity of the sensitive content. For video frames that do not contain sensitive content, a basic security score will be given according to the positive and healthy degree and compliance of their content. At the same time, the context information of the video frame will also be considered. If the same type of sensitive content exists in multiple consecutive frames, the deduction will be increased; if the content of the previous and subsequent frames can alleviate the sensitivity of the current frame, the deduction will be appropriately reduced. Finally, the content security coefficient of each frame is calculated by synthesizing various factors. This coefficient intuitively reflects the content security status of each video frame in numerical form, laying a foundation for the subsequent security evaluation of the entire video.

[0040] The recognition results of the sensitive content of each frame and the corresponding content security coefficient are stored in a structured data table. The rows of the table represent each frame, and the columns record the category coding of the recognition results and the numerical value of the content security coefficient respectively. Then, for the recognition results of different types of sensitive content, different weight values are assigned according to the pre-set severity. The weight corresponding to normal content is 0. Subsequently, the weighted security coefficient is calculated for each frame, that is, the content security coefficient of the frame is multiplied by the weight of the corresponding sensitive content category. After that, the sum of the weighted security coefficients of all frames in the entire video is calculated, and then divided by the total number of video frames to obtain the weighted average security coefficient. At the same time, the proportion of the number of frames with sensitive content in the total number of frames is counted. Finally, the weighted average security coefficient and the proportion of the appearance of sensitive content are judged against the pre-set risk threshold, and the video security status is divided into three levels: high risk, medium risk, and low risk, and the first detection result of video security is output.

[0041] In a possible implementation manner, step S300 further includes:

[0042] Step S310: Perform feature recognition based on the real-time monitoring data of the link to obtain link network monitoring feature data and link hardware monitoring feature data.

[0043] Step S320: Respectively perform security threat recognition on the link network monitoring feature data and the link hardware monitoring feature data to obtain a network security threat recognition result and a hardware security threat recognition result.

[0044] Step S330: Perform security risk detection on the networked collected video according to the network security threat recognition result to obtain the first threat video security risk coefficient.

[0045] Step S340: Perform security risk detection on the networked collected video according to the hardware security threat recognition result to obtain the second threat video security risk coefficient.

[0046] Step S350: Weightedly fuse the first threat video security risk coefficient and the second threat video security risk coefficient to generate the second detection result of video security.

[0047] Specifically, analyze the real-time monitoring data of the link to obtain the link network monitoring feature data and the link hardware monitoring feature data of the front-end acquisition device. First, use network traffic analysis tools to capture and parse the link network data in real time, collect information such as the size of the network traffic per second, the time points when the traffic peaks and valleys occur, and the transmission direction of data packets, and then calculate the fluctuation frequency of the network traffic to determine whether the network traffic is stable. At the same time, by monitoring the transmission delay of data packets, accurately record the time it takes for a data packet to travel from the sender to the receiver, as well as the packet loss rate, that is, the ratio of the number of lost data packets to the total number of sent data packets. These data constitute the key part of the link network monitoring feature data. For the link hardware monitoring of the front-end acquisition device, use the built-in sensors and monitoring software of the device to collect various parameters of the hardware operation in real time. Among them, focus on the CPU usage rate to measure the computing load of the device; monitor the memory occupancy rate to understand the usage degree of the device's storage resources. In addition, the temperature of the device is also an important monitoring indicator. Excessive temperature may indicate hardware heat dissipation problems or potential failure risks. At the same time, analyze the error logs of the hardware and count the various errors that occur during the operation of the hardware, such as the number of hard disk read / write errors and network interface failures. These data together constitute the link hardware (front-end acquisition device) monitoring feature data.

[0048] Conduct security threat identification work on the link network monitoring feature data and the link hardware monitoring feature data respectively. For the link network monitoring feature data, compare it with a preset network security threat sample library and use intrusion detection algorithms, such as algorithms based on anomaly detection, to analyze abnormal fluctuations in network traffic, changes in data packet transmission delay, and abnormal packet loss rates. If it is found that the network traffic fluctuates significantly in a short period of time and does not conform to the normal business model, or the data packet transmission delay suddenly increases and the packet loss rate rises significantly, it is determined that there is a network security threat, and then the network security threat identification result is obtained. For the link hardware monitoring feature data, establish a hardware failure model based on the normal operating parameter range and historical failure data of the hardware device. By comparing the monitoring data such as the current CPU usage rate, memory occupancy rate, device temperature, and hardware error rate of the hardware with the model parameters, when the CPU usage rate continues to be too high, the memory occupancy rate is close to the upper limit, the device temperature exceeds the safety threshold, or the hardware error rate rises frequently, a hardware security threat is identified, and the hardware security threat identification result is obtained.

[0049] Using the network security threat recognition sample set as input information and the network threat video security risk detection sample set as output information, supervise the training of M learners (M is a positive integer greater than 1). These learners can be different types of machine learning models, such as neural networks, decision trees, etc. After training, obtain M network threat video security risk detection models. Input the obtained network security threat recognition results into these M models, each model will output a network threat video security risk coefficient, and then calculate the central value of these M coefficients, such as the average value or the median, to generate the first threat video security risk coefficient. This coefficient reflects the degree of security risk caused by network security threats to the video collected through the network.

[0050] Using the hardware security threat recognition sample set as input and the hardware threat video security risk detection sample set as output, supervise the training of N learners (N is a positive integer greater than 1) to obtain N hardware threat video security risk detection models. Input the obtained hardware security threat recognition results into these N models to obtain N hardware threat video security risk coefficients, calculate the central value of these coefficients, and generate the second threat video security risk coefficient, which quantifies the security risk impact of hardware security threats on the video collected through the network.

[0051] According to the importance of the impact of network security threats and hardware security threats on video security, set weights for the first threat video security risk coefficient and the second threat video security risk coefficient respectively. For example, the weight corresponding to network security threats is α, and the weight corresponding to hardware security threats is β, and α + β = 1. Through weighted calculation, that is, multiplying the first threat video security risk coefficient by α and adding the second threat video security risk coefficient multiplied by β, fuse the two into one value, and this value is the second video security detection result. This result comprehensively reflects the overall security risk impact of the security threats existing in the network and hardware aspects of the front-end acquisition link on the video collected through the network, providing a key basis for subsequent video security management.

[0052] In a possible implementation manner, step S330 further includes:

[0053] Step S331: Using the network security threat recognition sample set as input information and the network threat video security risk detection sample set as output information, supervise the training of M learners to obtain M network threat video security risk detection models, where M is a positive integer greater than 1.

[0054] Step S332: Input the network security threat recognition results into the M network threat video security risk detection models to obtain M network threat video security risk coefficients.

[0055] Step S333: Calculate the central value of the security risk coefficients of the M network threat videos to generate the first threat video security risk coefficient.

[0056] Specifically, taking the random forest algorithm as an example, train the M network threat video security risk detection models. First, randomly extract multiple subsets from the network security threat recognition sample set and the network threat video security risk detection sample set, and each subset contains a certain number of sample data. For each subset, construct a decision tree as a learner. During the process of constructing the decision tree, when splitting at each node, randomly select some features to determine the best splitting method, which can increase the difference between decision trees. At the same time, according to the label information of the network threat video security risk detection sample set, use indicators such as information gain or Gini coefficient to measure the importance of features, and select the feature with the highest importance for splitting, so that the decision tree can better fit the data. After multiple splits, until the sample purity of the node reaches a certain standard or the depth of the tree reaches the preset value, a decision tree is constructed. Repeat the above process to construct M decision trees to form M random forest models, that is, M network threat video security risk detection models.

[0057] Input the obtained network security threat recognition results into these M trained network threat video security risk detection models. Each model will analyze and calculate the input network security threat recognition results according to the mapping relationship it has learned, and thus output a corresponding set of M network threat video security risk coefficients. These coefficients reflect the evaluation of the video security risk degree under the current network security threat by each model.

[0058] Process the obtained M network threat video security risk coefficients to generate the first threat video security risk coefficient. Collect and integrate these M coefficients into a data set, and then, according to the set central value calculation rule, select the calculation method of the median. Sort the M coefficients according to their numerical sizes. If M is odd, the coefficient value in the middle position is the median; if M is even, take the average of the two middle coefficients as the median. The central value obtained in this way can effectively reduce the interference of individual abnormal coefficients on the overall evaluation and more robustly reflect the impact degree of network security threats on video security risks. Finally, this central value is determined as the first threat video security risk coefficient.

[0059] In a possible implementation manner, step S400 further includes:

[0060] Step S410: Collect the monitoring information of the multiple other communication links to obtain multiple other link monitoring data.

[0061] Step S420: According to the multiple other link monitoring data, respectively identify security threats to the multiple other communication links to obtain threat identification results for each link.

[0062] Step S430: According to the threat identification results for each link, predict the security impact on the front-end acquisition link to obtain a predicted result of passive security impact on the link.

[0063] Step S440: According to the predicted result of passive security impact on the link, evaluate the security risk of the networked acquisition video to obtain the third detection result of video security.

[0064] Specifically, start the monitoring information collection program for multiple other communication links in the network. These other communication links are in the same network environment as the front-end acquisition link, and their operating states will have an indirect impact on the front-end acquisition link. Use various methods such as network probes, traffic monitoring tools, and device management interfaces to collect real-time traffic data for each link, including traffic volume, traffic fluctuation frequency, data transmission direction; packet-related information such as packet transmission delay, packet loss rate; network connection status such as connection stability, reconnection times; and hardware operating parameters of the devices involved in the link, such as CPU usage rate, memory occupancy rate, device temperature, etc. Organize and summarize this collected information to form multiple other link monitoring data, providing comprehensive and accurate basic data for subsequent analysis.

[0065] Compare these monitoring data with a pre-constructed security threat feature library, which covers the feature patterns of various common network attack behaviors such as DDoS attacks, port scans, and malware propagation. At the same time, perform real-time analysis on the network traffic, packet transmission situation, etc. of the link. For example, if it is found that the network traffic of a certain link surges abnormally in a short period of time, and the transmission direction and frequency of the packets do not conform to the normal business model, it is determined that the link may be suffering from a DDoS attack; if frequent port scanning behavior is detected, there may be a potential risk of hacker intrusion. For the operating state of the devices in the link, based on the normal operating parameter range of the devices, monitor the CPU usage rate, memory occupancy rate, device temperature, etc. in real time. When these parameters of the device exceed the normal range, such as the CPU usage rate remaining too high or the device temperature rising abnormally, identify possible hardware failures or software vulnerabilities. In addition, perform in-depth analysis on the data transmission content in the link, and detect whether there is sensitive information leakage, malicious code transmission, etc. through techniques such as keyword matching and protocol analysis. After comprehensive analysis and judgment of the monitoring data of each link, finally obtain the threat identification results for each link, clarifying whether there is a security threat for each link and the type and severity of the threat.

[0066] Based on the threat recognition results of each link, a security impact prediction is made for the front-end acquisition link. First, a topological association dataset between multiple other communication links and the front-end acquisition link stored in the database is called. These datasets detail information such as the connection relationships between links in the network, data transmission paths, and the degree of mutual dependence. Using this data, a global link topology model is constructed, which visually displays the structure of the entire network link in a graphical manner. Then, according to the global link topology model, a propagation path simulation of the threat recognition results of each link is carried out. For example, assume that a malware propagation event occurs on a certain other link. According to the topology model, analyze which paths the malware may spread to the front-end acquisition link and the possible impacts on the intermediate links during the propagation process. Through the simulation, the threat propagation paths of each link are obtained, and then based on these paths, a security impact prediction is made for the front-end acquisition link, obtaining multiple passive security impact characteristics of the front-end link, such as possible increased data transmission delay, increased packet loss rate, and unstable network connection in the front-end acquisition link. Finally, using a data fusion algorithm, these multiple passive security impact characteristics of the front-end link are comprehensively processed, considering the weights of each characteristic and their mutual correlation relationships, to generate a prediction result of the passive security impact of the link, comprehensively evaluating the potential impact of other link security threats on the front-end acquisition link.

[0067] Construct a comprehensive risk assessment index system that covers multiple dimensions such as the integrity, availability, and confidentiality of video data. For integrity, if the prediction results show that the link may experience packet loss, data corruption, etc., which will cause the video screen to have mosaic, freeze, or partial content missing, different integrity risk levels are set according to the proportion of video data that may be affected. For availability, factors such as link interruption duration and data transmission delay are considered. If the link is frequently interrupted or the delay is too high, it will cause the video to be unable to play normally or play smoothly, and the availability risk level is divided according to the interruption duration and delay degree. For confidentiality, if there is a risk of data leakage predicted, evaluate the sensitivity of the video content that may be leaked to determine the confidentiality risk level. Then, the fuzzy comprehensive evaluation method is used for quantitative evaluation, and corresponding weights are assigned to each risk assessment index, and these weights are determined according to the importance of the index in video security. For example, the integrity index has a higher weight because it directly affects the quality and viewing experience of the video. Map the prediction result of the passive security impact of the link to the risk levels of each index, and obtain the risk membership degree of each index through fuzzy operation. Finally, comprehensively consider the risk membership degree and weight of each index to calculate the comprehensive security risk score of the networked acquired video. According to the score range, the video security risk is divided into different levels, such as high, medium, and low risks, and this level is the third detection result of video security.

[0068] In a possible implementation manner, step S430 further includes:

[0069] Step S431: construct a global link topology model according to the topological association data sets between the multiple other communication links and the front-end acquisition link.

[0070] Step S432: performing propagation path simulation on the threat identification results of each link according to the global link topology model to obtain the threat propagation path of each link.

[0071] Step S433: predicting the security impact of the front-end acquisition link according to the threat propagation paths of each link, and obtaining multiple front-end link security passive impact features.

[0072] Step S434: performing data fusion on the plurality of front-end link safety passive impact features to generate the link safety passive impact prediction result.

[0073] Specifically, a global link topology model is constructed based on a pre-stored dataset of topological associations between multiple other communication links and front-end acquisition links. This dataset records in detail the connection relationship between each link, data transmission direction, node information, etc. By analyzing and integrating these data, the topology of the entire network link is presented in a graphical or mathematical model, clearly showing the association between other communication links and front-end acquisition links, providing a basic framework for subsequent threat propagation simulations.

[0074] With the help of the constructed global link topology model, the propagation path of the threat identification results of each link is simulated, and the propagation process of the threat in the network link is simulated according to the type and characteristics of the threat and the correlation between the links. For example, if a certain other link is attacked by DDoS, analyze which intermediate links the attack may propagate to the front-end collection link, and the possible changes in the intensity and scope of the threat during the propagation process. Through such simulation, the threat propagation path of each link is accurately obtained, and the specific path and method by which the threat may reach the front-end collection link are clarified.

[0075] Use an algorithm based on Bayesian network to predict the security impact on the front-end acquisition link and obtain multiple passive security impact characteristics of the front-end link. First, convert the threat propagation paths of each link into directed edges in the Bayesian network, and each link node serves as a variable node in the network. According to historical data and expert experience, determine the prior probability distribution of each variable node, that is, the probabilities of each link in the normal and threatened states. For each threat propagation path, calculate the posterior probability of each state variable (such as network delay, packet loss rate, bandwidth occupancy rate, etc.) of the front-end acquisition link after being affected by the threat propagation according to the inference rules of the Bayesian network. For example, when a certain threat propagates from other links to the front-end acquisition link, adjust the probability distribution of the bandwidth occupancy rate variable according to the impact of the threat type (such as DDoS attack, malware propagation, etc.) on the link bandwidth; at the same time, change the probability of the packet loss rate variable according to the data transmission error situation caused by the threat. Through the forward and backward inferences of the Bayesian network, predict different security impact scenarios that may occur in the front-end acquisition link and their occurrence probabilities. Convert these security impacts with higher probabilities into specific characteristics: if the posterior probability of network delay shows a high possibility of a significant increase in delay, then high network delay is used as a passive security impact characteristic of the front-end link; if the posterior probability of the packet loss rate indicates serious packet loss, then high packet loss rate is a characteristic. And so on, determine multiple passive security impact characteristics of the front-end link from multiple aspects, providing a comprehensive and quantitative basis for subsequent data fusion and link security assessment.

[0076] Data fusion is performed on multiple passive security impact features of the front-end link. First, for different types of passive security impact features, their respective weights are determined based on their importance and relevance to the security of the front-end acquisition link. For example, for features that directly affect the quality of video data transmission, such as high packet loss rate and severe network latency, higher weights are assigned; while for some features that indirectly affect or have a smaller impact, relatively lower weights are assigned. Then, the weighted average method is used for preliminary fusion. Multiply the value of each passive security impact feature of the front-end link by its corresponding weight, and then add these products to obtain a preliminary fusion result. This result comprehensively considers the impacts of various features, but there may still be some information omissions or overlaps. To further optimize the fusion effect, the principal component analysis (PCA) method is used. PCA transforms multiple related passive security impact features of the front-end link into a few uncorrelated principal components through orthogonal transformation of the data. These principal components retain most of the information of the original data while removing redundant information. According to the contribution rate of the principal components, the weights are adjusted again to perform secondary optimization on the preliminary fusion result. Finally, the fusion result optimized by PCA is analyzed and interpreted. If the fusion result shows that the comprehensive impact exceeds the preset security threshold, it indicates that the front-end acquisition link faces a relatively high security risk, and the prediction result will clearly point out the type and approximate degree of the existing risk; if it does not exceed the threshold, it means that the security risk is relatively low. Through such a data fusion process, an accurate and practically guiding prediction result of the passive security impact of the link is generated.

[0077] In a possible implementation manner, step S420 further includes:

[0078] Step S421: Extract the first other link monitoring data corresponding to the first other communication link according to the multiple other link monitoring data.

[0079] Step S422: Collect the basic information of the first other communication link to obtain the first other link basic data.

[0080] Step S423: Use the first other link basic data as the first constraint for security threat retrieval, and use the first other link monitoring data as the second constraint for security threat retrieval.

[0081] Step S424: Perform security threat sample retrieval according to the first constraint for security threat retrieval and the second constraint for security threat retrieval to obtain the first security threat sample retrieval set.

[0082] Step S425: Perform confidence fusion according to the first security threat sample retrieval set to obtain the first link threat recognition result, and add the first link threat recognition result to the respective link threat recognition results.

[0083] Specifically, first, it will traverse multiple other link monitoring data that has been obtained. These data contain rich information such as network traffic, packet transmission status, and device operation parameters of numerous communication links over a period of time. Through unique identification identifiers such as link identifiers or network addresses, the monitoring data corresponding to the first other communication link is located from the data set. For example, in a data set containing 100 other communication link monitoring data, according to the pre-set link identifier rules, a specific identifier representing the first other communication link is found. Then, based on this identifier, the network traffic change curve belonging to this link, the transmission delay time series of packets, the fluctuation data of the CPU usage rate and memory occupancy rate of the device over time, etc. are completely extracted from the overall data set. These extracted data constitute the first other link monitoring data.

[0084] Carry out basic information collection work for this link. By interacting with the network devices connected to the link and using tools such as the Simple Network Management Protocol (SNMP) and Command Line Interface (CLI), obtain the network topology information of the link, including the device types, IP addresses, subnet masks at both ends of the link, as well as the position and connection relationship of this link in the entire network topology structure. Then, collect information related to the communication protocols used by the link, such as TCP / IP, UDP, and the version numbers of the protocols. These information are crucial for judging the rules and security of data transmission. At the same time, also collect the hardware information of the devices involved in the link, such as device models, hardware configuration parameters (such as CPU models, memory capacities, hard disk sizes), because different hardware configurations have different capabilities in processing data and dealing with security threats. In addition, obtain the service information of the link, such as the type of service carried (video transmission, file transmission, or other services), service quality requirements, etc. Finally, integrate and sort out the information collected in these aspects of network topology, communication protocols, hardware devices, services, etc. to form a structured data format, which is the first other link basic data.

[0085] Use the first other link basic data as the first constraint condition for security threat retrieval, and at the same time use the first other link monitoring data as the second constraint condition. These two constraint conditions cooperate with each other to limit the scope of security threat retrieval from different dimensions. The first other link basic data stipulates the normal operation framework and basic attributes of the link, and situations that do not conform to this framework may pose security threats; while the first other link monitoring data reflects the real-time operation status of the link, and abnormal monitoring data is an important clue for the existence of security threats.

[0086] Retrieve the first constraint (i.e., the first other link basic data) and the second constraint (i.e., the first other link monitoring data) according to the determined security threats, and conduct security threat sample retrieval work in the pre-constructed security threat sample library. This security threat sample library contains various known security threat characteristics and relevant information, and is constructed based on a large number of security incidents and attack cases. First, according to the first other link basic data, samples that match the basic attributes such as the network topology structure, communication protocol, and hardware devices of this link are screened out. For example, if the first other link uses a specific version of the TCP / IP protocol, threat samples related to other protocols in the sample library are excluded. Then, among these initially screened samples, further screening is carried out based on the first other link monitoring data. If the monitoring data shows that the traffic of this link has increased abnormally recently, threat samples related to abnormal traffic in the sample library, such as DDoS attacks and malware propagation, are focused on. Through these two rounds of screening, all samples that both conform to the basic attributes of the first other link and match the abnormal conditions shown by the real-time monitoring data are found from the security threat sample library. These samples together constitute the first security threat sample retrieval set, providing a targeted sample basis for subsequent confidence fusion and accurate identification of the security threats of the first other communication link.

[0087] Perform confidence fusion on the first security threat sample retrieval set. Since each sample in the sample retrieval set indicates the degree of security threat to the first other communication link differently, corresponding confidence levels are assigned to each sample according to factors such as the matching degree of the sample with the link's basic data and monitoring data, the frequency of the sample's appearance in historical security events, and expert experience. For example, if a sample highly matches the network topology, protocol usage, and monitored abnormal traffic characteristics of the current link, and frequently appears in security events of similar links in the past, it will be assigned a higher confidence level; otherwise, a lower confidence level will be assigned. Then, using the weighted average method, a weighted calculation is performed according to the confidence levels of each sample to obtain a comprehensive confidence level value. After being processed by the fusion algorithm, according to the final comprehensive confidence level value, it is judged whether there is a security threat to the first other communication link. If so, the type (such as DDoS attack, data leakage, etc.) and severity of the threat are determined, which forms the first link threat identification result. Finally, the first link threat identification result is added to the set of threat identification results for each link. In this way, the set of threat identification results for each link contains the security threat identification situations of the first other communication link and other communication links, providing comprehensive data support for subsequent unified analysis and management of the security status of all communication links in the entire network.

[0088] Embodiment 2, based on the same inventive concept as a security monitoring method for networked video in the foregoing embodiment, as Figure 2As shown in the figure, the present application provides a security monitoring system for networked videos. The system and method embodiments in the present application are based on the same inventive concept. Among them, the system includes:

[0089] A networked video acquisition module 10, configured to build a front-end acquisition link when a front-end acquisition device that has completed multiple authentications accesses the network, and obtain networked acquisition videos according to the front-end acquisition link.

[0090] A first detection result acquisition module 20, configured to perform video content security detection on the networked acquisition videos according to a sensitive content recognition map, and obtain a first video security detection result.

[0091] A second detection result acquisition module 30, configured to obtain real-time link monitoring data of the front-end acquisition link, and perform security detection on the networked acquisition videos according to the real-time link monitoring data, and obtain a second video security detection result.

[0092] A third detection result acquisition module 40, configured to build multiple other communication links according to multiple other access nodes of the network, and perform passive security risk prediction on the networked acquisition videos according to the multiple other communication links, and obtain a third video security detection result.

[0093] A security management module 50, configured to perform security management on the networked acquisition videos according to the first video security detection result, the second video security detection result, and the third video security detection result.

[0094] Furthermore, the system is also used to implement the following functions:

[0095] Perform content feature recognition on each video frame in the networked acquisition videos to construct content feature vectors for each frame; input the content feature vectors for each frame into the sensitive content recognition map to obtain sensitive content recognition results for each frame; perform content security evaluation on each video frame according to the sensitive content recognition results for each frame to obtain content security coefficients for each frame; sort out the sensitive content recognition results for each frame and the content security coefficients for each frame to obtain the first video security detection result.

[0096] Furthermore, the system is also used to implement the following functions:

[0097] Perform feature recognition based on the real-time monitoring data of the link to obtain link network monitoring feature data and link hardware monitoring feature data; respectively perform security threat recognition on the link network monitoring feature data and the link hardware monitoring feature data to obtain a network security threat recognition result and a hardware security threat recognition result; perform security risk detection on the networked collected video according to the network security threat recognition result to obtain a first threat video security risk coefficient; perform security risk detection on the networked collected video according to the hardware security threat recognition result to obtain a second threat video security risk coefficient; perform weighted fusion on the first threat video security risk coefficient and the second threat video security risk coefficient to generate the second video security detection result.

[0098] Further, the system is also used to implement the following functions:

[0099] Use the network security threat recognition sample set as input information and the network threat video security risk detection sample set as output information to perform supervised training on M learners to obtain M network threat video security risk detection models, where M is a positive integer greater than 1; input the network security threat recognition result into the M network threat video security risk detection models to obtain M network threat video security risk coefficients; calculate the central value of the M network threat video security risk coefficients to generate the first threat video security risk coefficient.

[0100] Further, the system is also used to implement the following functions:

[0101] Collect the monitoring information of the multiple other communication links to obtain multiple other link monitoring data; respectively perform security threat recognition on the multiple other communication links according to the multiple other link monitoring data to obtain threat recognition results for each link; perform security impact prediction on the front-end acquisition link according to the threat recognition results for each link to obtain a link security passive impact prediction result; perform security risk evaluation on the networked collected video according to the link security passive impact prediction result to obtain the third video security detection result.

[0102] Further, the system is also used to implement the following functions:

[0103] Construct a global link topology model according to the topology association data set between the multiple other communication links and the front-end acquisition link; perform propagation path simulation on the threat recognition results for each link according to the global link topology model to obtain threat propagation paths for each link; perform security impact prediction on the front-end acquisition link according to the threat propagation paths for each link to obtain multiple front-end link security passive impact features; perform data fusion on the multiple front-end link security passive impact features to generate the link security passive impact prediction result.

[0104] Further, the system is also used to implement the following functions:

[0105] Extract the first other link monitoring data corresponding to the first other communication link according to the multiple other link monitoring data; collect the basic information of the first other communication link to obtain the first other link basic data; retrieve the first constraint with the first other link basic data as a security threat, and retrieve the second constraint with the first other link monitoring data as a security threat; perform a security threat sample retrieval according to the security threat retrieval first constraint and the security threat retrieval second constraint to obtain a first security threat sample retrieval set; perform confidence fusion according to the first security threat sample retrieval set to obtain a first link threat recognition result, and add the first link threat recognition result to the respective link threat recognition results.

[0106] Embodiment III Figure 3 FIG. is a schematic structural diagram of an electronic device provided in Embodiment III of the present invention, showing a block diagram of an exemplary electronic device suitable for implementing the embodiments of the present invention. Figure 3 The displayed electronic device is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present invention. As Figure 3 shown, the electronic device includes a processor 21, a memory 22, an input device 23, and an output device 24; the number of processors 21 in the electronic device can be one or more. Figure 3 Taking one processor 21 as an example, the processor 21, the memory 22, the input device 23, and the output device 24 in the electronic device can be connected by a bus or other means. Figure 3 Taking the connection by bus as an example.

[0107] Embodiment IV, the memory 22, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as program instructions / modules corresponding to a security monitoring method for networked video in the embodiments of the present application. The processor 21 executes various functional applications and data processing of the computer device by running the software programs, instructions, and modules stored in the memory 22, that is, implements the above-mentioned security monitoring method for networked video.

[0108] It should be noted that the above-mentioned sequence of the embodiments of the present application is only for description and does not represent the superiority or inferiority of the embodiments. And the above describes specific embodiments of the present specification. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0109] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

[0110] This specification and the drawings are only exemplary descriptions of the present application and are considered to cover any and all modifications, variations, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the present application and its equivalent technologies, the present application is intended to include these changes and modifications.

Claims

1. A security monitoring method for networked videos, characterized in that, The method includes: When a front-end acquisition device that has completed multi-factor authentication accesses the network, construct a front-end acquisition link, and obtain a networked acquisition video according to the front-end acquisition link; Perform video content security detection on the networked acquisition video according to a sensitive content recognition map, and obtain a first video security detection result; Obtain real-time link monitoring data of the front-end acquisition link, and perform security detection on the networked acquisition video according to the real-time link monitoring data, and obtain a second video security detection result; Construct multiple other communication links according to multiple other access nodes of the network, and perform passive security risk prediction on the networked acquisition video according to the multiple other communication links, and obtain a third video security detection result; Perform security management on the networked acquisition video according to the first video security detection result, the second video security detection result, and the third video security detection result.

2. The method according to claim 1, wherein Performing video content security detection on the networked acquisition video according to a sensitive content recognition map to obtain a first video security detection result includes: Perform content feature recognition on each video frame in the networked acquisition video to construct content feature vectors for each frame; Input the content feature vectors for each frame into the sensitive content recognition map to obtain sensitive content recognition results for each frame; Perform content security evaluation on each video frame according to the sensitive content recognition results for each frame to obtain content security coefficients for each frame; Collate the sensitive content recognition results for each frame and the content security coefficients for each frame to obtain the first video security detection result.

3. The method according to claim 1, characterized in that, Performing security detection on the networked acquisition video according to the real-time link monitoring data to obtain a second video security detection result includes: Perform feature recognition according to the real-time link monitoring data to obtain link network monitoring feature data and link hardware monitoring feature data; Perform security threat recognition on the link network monitoring feature data and the link hardware monitoring feature data respectively to obtain a network security threat recognition result and a hardware security threat recognition result; Perform security risk detection on the networked acquisition video according to the network security threat recognition result to obtain a first threat video security risk coefficient; Perform security risk detection on the networked acquisition video according to the hardware security threat recognition result to obtain a second threat video security risk coefficient; Fusion the first threat video security risk coefficient and the second threat video security risk coefficient with weights to generate the second video security detection result.

4. The method according to claim 3, wherein Performing security risk detection on the networked acquisition video according to the network security threat recognition result to obtain a first threat video security risk coefficient includes: Use the network security threat recognition sample set as input information and the network threat video security risk detection sample set as output information to perform supervised training on M learners to obtain M network threat video security risk detection models, where M is a positive integer greater than 1; Input the network security threat recognition result into the M network threat video security risk detection models to obtain M network threat video security risk coefficients; Calculate the central value of the security risk coefficients of the M network threat videos to generate the first threat video security risk coefficient.

5. The method according to claim 1, characterized in that, Perform passive security risk prediction on the networked collected videos according to the multiple other communication links to obtain a third video security detection result, including: Collect the monitoring information of the multiple other communication links to obtain multiple other link monitoring data; According to the multiple other link monitoring data, perform security threat identification on the multiple other communication links respectively to obtain threat identification results for each link; Perform security impact prediction on the front-end collection link according to the threat identification results for each link to obtain a passive impact prediction result for link security; Perform security risk evaluation on the networked collected videos according to the passive impact prediction result for link security to obtain the third video security detection result.

6. The method according to claim 5, wherein Perform security impact prediction on the front-end collection link according to the threat identification results for each link to obtain a passive impact prediction result for link security, including: Construct a global link topology model according to the topology association dataset between the multiple other communication links and the front-end collection link; Perform propagation path simulation on the threat identification results for each link according to the global link topology model to obtain threat propagation paths for each link; Perform security impact prediction on the front-end collection link according to the threat propagation paths for each link to obtain multiple passive impact characteristics for front-end link security; Perform data fusion on the multiple passive impact characteristics for front-end link security to generate the passive impact prediction result for link security.

7. The method according to claim 5, wherein According to the multiple other link monitoring data, perform security threat identification on the multiple other communication links respectively to obtain threat identification results for each link, including: Extract the first other link monitoring data corresponding to the first other communication link according to the multiple other link monitoring data; Collect the basic information of the first other communication link to obtain first other link basic data; Use the first other link basic data as the first constraint for security threat retrieval and the first other link monitoring data as the second constraint for security threat retrieval; Perform security threat sample retrieval according to the first constraint for security threat retrieval and the second constraint for security threat retrieval to obtain a first security threat sample retrieval set; Perform confidence fusion according to the first security threat sample retrieval set to obtain a first link threat identification result and add the first link threat identification result to the threat identification results for each link.

8. A security monitoring system for networked videos, characterized in that, The system is used to implement the security monitoring method for networked videos according to any one of claims 1-7. The system includes: A networked collected video acquisition module, configured to construct a front-end collection link when a front-end collection device that has completed multiple authentication accesses the network, and obtain networked collected videos according to the front-end collection link; A first detection result acquisition module, configured to perform video content security detection on the networked collected videos according to a sensitive content recognition map to obtain a first video security detection result; The second detection result acquisition module is configured to obtain the real-time monitoring data of the link of the front-end acquisition link, and perform security detection on the networked acquisition video according to the real-time monitoring data of the link to obtain the second detection result of video security; The third detection result acquisition module is configured to construct a plurality of other communication links according to the plurality of other access nodes of the network, and perform passive security risk prediction on the networked acquisition video according to the plurality of other communication links to obtain the third detection result of video security; The security management module is configured to perform security management on the networked acquisition video according to the first detection result of video security, the second detection result of video security, and the third detection result of video security.

9. An electronic device, characterized in that, The electronic device includes: A processor; A memory for storing executable instructions of the processor; Wherein, the processor is configured to execute the security monitoring method for networked video according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, and the computer program is configured to execute the security monitoring method for networked video according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Threat data processing method for information system

    CN107239707A

  • Systems configured to enable isolated client device interaction with building automation and control (BAC) networks, including third-party application access framework

    US20200396208A1