Multi-value chain collaborative evaluation method
By using the fuzzy comprehensive evaluation method, hierarchical analysis method and graph neural network combined with dynamic programming algorithm in multi-value chain collaborative evaluation, the problems of limited expression ability and low accuracy of multi-value chain collaborative evaluation in the existing technology are solved, and efficient multi-value chain collaboration and detailed collaborative evaluation report generation are achieved.
Patent Information
- Application Number
- CN202510307062.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-15
- Publication Date
- 2025-06-13
AI Technical Summary
The existing GNN models cannot effectively process large-scale graph data while processing multi-value chain collaboration, and it is difficult to fully capture the deep-level interaction patterns between different value chains, resulting in limited expressive capabilities of the model, affecting the accuracy and reliability of collaboration and collaborative evaluation.
A multi-value chain collaborative evaluation method is proposed. By collecting multi-source heterogeneous data, using fuzzy comprehensive evaluation method and hierarchical analysis method for weight allocation and interaction relationship analysis, building node feature matrix and adjacency matrix, inputting the graph neural network to obtain node embedding vectors, and path search is performed in combination with improved dynamic programming algorithms to determine the optimal decision path to achieve collaborative evaluation.
It realizes efficient coordination between multi-value chains, reduces resource waste, improves response speed, reduces security risks, and generates detailed collaborative evaluation reports to provide scientific decision-making support to management.
Smart Images

Figure CN120146692A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of multi-chain collaboration and big data processing, and particularly relates to a multi-value chain collaboration evaluation method, system, device, and computer-readable storage medium. Background Art
[0002] In the field of security and trust, especially in sensitive industries such as finance, healthcare, and government agencies, ensuring data security and system reliability is of utmost importance. With the rapid development of information technology, the types and complexity of security threats are also increasing continuously. Traditional security management methods have become difficult to cope with these challenges. Traditional security management methods often focus on single-layer security protection, such as firewalls, intrusion detection systems, etc., lacking cross-system and cross-departmental collaboration mechanisms, resulting in incomplete coverage of security vulnerabilities and low response efficiency. In addition, traditional security management methods usually rely on static rules and preset protection measures, making it difficult to adapt to the constantly changing security threat environment.
[0003] In modern enterprises, security systems usually consist of multiple value chains, each responsible for different security functions. For example, the network security chain is responsible for preventing external attacks and internal threats, the data security chain is responsible for protecting data integrity and privacy, the physical security chain is responsible for protecting the security of physical facilities, and the personnel security chain is responsible for training and managing security awareness. There are complex interactions and dependencies between these value chains, and the failure of any one value chain may increase the security risks of the entire system.
[0004] In recent years, Graph Neural Network (GNN) technology has shown great potential in processing complex relational data and can effectively capture and analyze the interaction relationships between different security subsystems. Through graph structure modeling, GNN can handle the non-linear relationships between nodes, thereby more accurately identifying and predicting security events.
[0005] However, existing GNN models are unable to effectively process large-scale graph data when dealing with multi-value chain collaboration, making it difficult to fully capture the deep interaction patterns between different value chains, resulting in limited expressive power of the models and affecting the accuracy and reliability of collaboration and collaboration evaluation.
[0006] Therefore, the present invention proposes a multi-value chain collaboration evaluation method, which comprehensively considers the interactions between value chains, combines the GNN network and the dynamic path planning algorithm to achieve efficient collaboration and collaboration evaluation between multi-value chains, reduce resource waste, improve response speed, and reduce security risks. Summary of the Invention
[0007] To solve the above problems in the prior art, that is, to solve the problem that the prior art cannot achieve the efficient coordination and coordination evaluation of multiple value chains, resulting in a relatively high risk of the security system, in the first aspect of the present invention, a method for collaborative evaluation of multiple value chains is proposed for the collaboration of multiple value chains and generating a collaborative evaluation report. The method includes:
[0008] S10, collecting multi-source heterogeneous data of various influencing factors on the multiple value chains of the enterprise security system;
[0009] S20, based on the multi-source heterogeneous data, using the fuzzy comprehensive evaluation method to allocate weights to the influencing factors on each value chain to obtain the influencing factor sets on each value chain;
[0010] S30, according to the influencing factor sets on each value chain, using the analytic hierarchy process to obtain the interaction relationships between each value chain;
[0011] S40, based on the influencing factor sets on each value chain and the interaction relationships between each value chain, constructing a node feature matrix and an adjacency matrix, and inputting them into a pre-constructed graph neural network to obtain the final node embedding vector;
[0012] S50, using an improved dynamic programming algorithm, combined with the final node embedding vector, to perform path search, and then determine the optimal decision path; according to the optimal decision path, perform the collaboration of the enterprise's multiple value chains and generate a collaborative evaluation report;
[0013] Among them, the method for determining the optimal decision path is:
[0014] Initialize the path set and path cost, and based on the final node embedding vector, calculate the node similarity and node importance;
[0015] Based on the node similarity and the node importance, combined with the path length, calculate the heuristic value of each node through heuristic pruning;
[0016] Based on the heuristic value, combined with the dynamic change factor of the edge and the path stability between nodes, dynamically adjust the path cost, and select the optimal decision path according to the adjusted path cost.
[0017] In some preferred embodiments, the multiple value chains of the enterprise security system include data security, network security, physical security, and personnel security; the influencing factors include the number of data leakage events, the number of intrusion attempts, the number of firewall interceptions, and the number of abnormal events in surveillance videos.
[0018] In some preferred embodiments, the graph neural network is constructed based on a first graph convolutional block, a first graph pooling layer, a first feature reconstruction layer, a gated unit layer, a channel mixing layer, a perceptron, an attention layer, a second graph pooling layer, a residual connection layer, a second graph convolutional block, a third graph pooling layer, a second feature reconstruction layer, and a graph readout layer connected in sequence; the input of the graph neural network is a node feature matrix and an adjacency matrix;
[0019] Both the first graph convolutional block and the second graph convolutional block are constructed based on a GCN network, a GAT network, and GraphSAGE connected in sequence;
[0020] The first graph pooling layer is used to pool the output of the first graph convolutional block to obtain a first node feature matrix;
[0021] The first feature reconstruction layer is used to perform feature reconstruction on the first node feature matrix through an autoencoder, and fuse the node feature matrix after feature reconstruction with the output of the first graph convolutional block to obtain a second node feature matrix;
[0022] The gated unit layer is used to dynamically adjust the importance of features based on the second node feature matrix through GRU units according to context information to obtain a third node feature matrix;
[0023] The channel mixing layer is used to perform channel fusion on the third node feature matrix and the second node feature matrix to obtain a fourth node feature matrix;
[0024] The perceptron is used to perform a non-linear transformation on the fourth node feature matrix to obtain a fifth node feature matrix;
[0025] The attention layer is used to weight the fifth node feature matrix to obtain a sixth node feature matrix;
[0026] The second graph pooling layer is used to pool the sixth node feature matrix;
[0027] The residual connection layer is used to perform a residual connection between the fifth node feature matrix and the pooled sixth node feature matrix to obtain a seventh node feature matrix, and input it to the second graph convolutional block for processing;
[0028] The third graph pooling layer is used to pool the node feature matrix output by the second graph convolutional block to obtain an eighth node feature matrix;
[0029] The second feature reconstruction layer is used to perform feature reconstruction on the eighth node feature matrix through an autoencoder, and fuse the node feature matrix after feature reconstruction with the output of the second graph convolutional block to obtain a ninth node feature matrix;
[0030] The graph reading layer is used to perform max pooling and fully connected processing on the ninth node feature matrix in sequence to obtain the final node embedding vector.
[0031] In some preferred embodiments, the loss function of the graph neural network during training is:
[0032]
[0033] where L represents the loss function, N represents the total number of nodes, represents the set of neighbor nodes of node i, ξ represents the cross-entropy loss function, y i , y i1 respectively represent the predicted result and the true label corresponding to node i output by the graph neural network, H i , H j respectively represent the hidden representations of node i and node j, A ij represents the element in the adjacency matrix, α and β both represent hyperparameters, sim is the similarity function, C ij is the collaboration strength between node i and node j, λ 1 , λ 2 , λ 3 , λ 4 all represent the weight coefficients of the corresponding loss function terms, γ i represents the adaptive weight, δ ij represents the dynamically adjusted element of the adjacency matrix.
[0034] In some preferred embodiments, the method for obtaining the dynamically adjusted element of the adjacency matrix is:
[0035] δ ij = A ij + η(y i1 - y i )(y j1 - y j )
[0036] where η represents the learning rate, y j , y j1 respectively represent the predicted result and the true label corresponding to node j output by the graph neural network.
[0037] In some preferred embodiments, the heuristic value of each node is calculated through heuristic pruning, and the method is:
[0038]
[0039] where h(i, j) represents the heuristic value, sim(H i , Hj ) represents the similarity between node i and node j, H i , H j represents the embedding vectors of node i and node j, I j represents the importance of the node, and α1, α2, α3, α4, α5 all represent weights.
[0040] In some preferred embodiments, the path cost is dynamically adjusted, and the optimal decision path is selected according to the adjusted path cost. The method is as follows:
[0041] Calculate the adjusted path cost:
[0042] c(i,j) = w ij -h(i,j) + α6·Δ ij + α7·S ij
[0043] where c(i,j) represents the path cost, w ij represents the weight of edge (i,j), Δ ij represents the dynamic change factor of edge (i,j), S ij represents the path stability factor between node i and node j, and α6, α7 both represent weights;
[0044] Select the path corresponding to the least adjusted path cost as the optimal decision path.
[0045] In the second aspect of the present invention, a multi-value chain collaborative evaluation system is proposed for multi-value chain collaboration and generating a collaborative evaluation report. The system includes:
[0046] A data acquisition module configured to collect multi-source heterogeneous data of various influencing factors on the multi-value chain of the enterprise security system;
[0047] A weight allocation module configured to, based on the multi-source heterogeneous data, use the fuzzy comprehensive evaluation method to allocate weights to the influencing factors on each value chain to obtain the influencing factor sets on each value chain;
[0048] A weight allocation module configured to, based on the multi-source heterogeneous data, use the fuzzy comprehensive evaluation method to allocate weights to the influencing factors on each value chain to obtain the influencing factor sets on each value chain;
[0049] A graph learning module configured to, based on the influencing factor sets on each value chain and the interaction relationships between each value chain, construct a node feature matrix and an adjacency matrix, and input them into a pre-constructed graph neural network to obtain the final node embedding vectors;
[0050] The multi-chain collaboration module is configured to use an improved dynamic programming algorithm, combine the final node embedding vectors, perform path search, and then determine the optimal decision path; collaborate on the enterprise's multi-value chains according to the optimal decision path, and generate a collaboration evaluation report;
[0051] Among them, the method for determining the optimal decision path is as follows:
[0052] Initialize the path set and path cost, and calculate node similarity and node importance based on the final node embedding vectors;
[0053] Based on the node similarity, the node importance, and in combination with the path length, calculate the heuristic value of each node through heuristic pruning;
[0054] Based on the heuristic value, in combination with the dynamic change factor of the edge and the path stability between nodes, dynamically adjust the path cost, and select the optimal decision path according to the adjusted path cost.
[0055] In the third aspect of the present invention, a multi-value chain collaboration evaluation device is proposed. The device includes:
[0056] At least one processor, and a memory communicatively connected to at least one of the processors;
[0057] Among them, the memory stores instructions executable by the processor, and the instructions are used to be executed by the processor to implement the above-mentioned multi-value chain collaboration evaluation method.
[0058] In the fourth aspect of the present invention, a computer-readable storage medium is proposed. The computer-readable storage medium stores computer instructions, and the computer instructions are used to be executed by a computer to implement the above-mentioned multi-value chain collaboration evaluation method.
[0059] The beneficial effects of the present invention:
[0060] 1) The present invention realizes the efficient collaboration between multi-value chains by learning the deep interaction patterns between different value chains through GNN. This not only reduces the repeated investment and waste of resources, but also improves the resource utilization efficiency and the system response speed. In the face of sudden security incidents, each subsystem can quickly coordinate actions, take response measures quickly, and reduce the impact range and duration of the incident;
[0061] 2) The present invention combines the GNN network and the dynamic programming algorithm to select the optimal decision path, and the system can adjust the operation strategies of each value chain in real time. When a new security incident or environmental change is detected, the system can quickly respond, adjust the path selection and resource allocation, and ensure the stability and security of the system;
[0062] 3) The present invention generates a detailed multi-value chain collaborative evaluation report, providing a comprehensive basis for collaborative evaluation to the management. The report not only includes the key performance indicators (KPIs) of each node, but also analyzes the interaction relationships between the nodes, pointing out the main factors affecting the path selection. This provides scientific decision-making support to the management, helping them formulate more reasonable strategies and policies. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] Other features, objects, and advantages of the present application will become more apparent by reading the detailed description of the non-limiting embodiments with reference to the following drawings.
[0064] Figure 1 is a schematic flowchart of a multi-value chain collaborative evaluation method according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0065] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0066] The present application will be further described in detail below with reference to the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only for explaining the relevant invention and not for limiting the invention. Additionally, it should be noted that only the parts related to the relevant invention are shown in the drawings for the convenience of description.
[0067] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other.
[0068] A multi-value chain collaborative evaluation method according to the first embodiment of the present invention is used for multi-value chain collaboration and generating a collaborative evaluation report, as Figure 1 shown, and includes the following steps:
[0069] S10. Collect multi-source heterogeneous data of various influencing factors on the multi-value chain of the enterprise security system;
[0070] S20. Based on the multi-source heterogeneous data, use the fuzzy comprehensive evaluation method to assign weights to the influencing factors on each value chain to obtain the influence factor sets on each value chain;
[0071] S30. According to the influence factor sets on each value chain, use the analytic hierarchy process to obtain the interaction relationships between the value chains;
[0072] S40. Based on the impact factor sets on each value chain and the interaction relationships between the value chains, construct a node feature matrix and an adjacency matrix, and input them into a pre-constructed graph neural network to obtain the final node embedding vectors;
[0073] S50. Use an improved dynamic programming algorithm, combined with the final node embedding vectors, to perform path search, and then determine the optimal decision path; conduct the collaboration of the enterprise's multiple value chains according to the optimal decision path, and generate a collaboration evaluation report;
[0074] Among them, the method for determining the optimal decision path is:
[0075] Initialize the path set and path cost, and calculate the node similarity and node importance based on the final node embedding vectors;
[0076] Based on the node similarity and the node importance, combined with the path length, calculate the heuristic value of each node through heuristic pruning;
[0077] Based on the heuristic value, combined with the dynamic change factor of the edge and the path stability between nodes, dynamically adjust the path cost, and select the optimal decision path according to the adjusted path cost.
[0078] To more clearly illustrate a multi-value chain collaboration evaluation method of the present invention, the following details each step in an embodiment of the method of the present invention in combination with the accompanying drawings.
[0079] S10. Collect multi-source heterogeneous data of various influencing factors on the multi-value chain of the enterprise security system;
[0080] In this embodiment, collect various types of data of the multi-value chain of the enterprise security system, including network security (such as intrusion detection logs, firewall logs), data security (such as encryption algorithm effectiveness, data leakage events), physical security (such as access control records, surveillance videos), personnel security (such as training records, accident reports), etc.
[0081] The influencing factors on each value chain, for example, in the security system of the financial structure, network security includes the number of intrusion attempts and the number of firewall interceptions; data security includes the number of data leakage events and the encryption algorithm effectiveness score; physical security includes the number of access control violations and the number of abnormal events in surveillance videos; personnel security includes the training completion rate and the number of accident reports;
[0082] S20. Based on the multi-source heterogeneous data, use the fuzzy comprehensive evaluation method to allocate weights to the influencing factors on each value chain to obtain the impact factor sets on each value chain;
[0083] In this embodiment, a fuzzy evaluation matrix is constructed, a membership function is determined, and a comprehensive evaluation value is calculated. By combining expert scoring and a mathematical model, the weights of various influencing factors are determined, and an influence factor set for each value chain is formed (this is prior art and will not be elaborated here). For example, for network security: the number of intrusion attempts (weight 0.6), the number of firewall interceptions (weight 0.4); for data security: the number of data leakage incidents (weight 0.7), the effectiveness score of the encryption algorithm (weight 0.3); for physical security: the number of access control violations (weight 0.5), the number of abnormal events in surveillance videos (weight 0.5); for personnel security: the training completion rate (weight 0.6), the number of accident reports (weight 0.4).
[0084] S30. According to the influence factor sets on each value chain, the analytic hierarchy process is used to obtain the interaction relationships between the value chains;
[0085] In this embodiment, a hierarchical structure model is established, a judgment matrix is constructed, the consistency ratio is calculated, the weights are determined, and the interactions and importance between the value chains are evaluated. For example, a financial institution uses the AHP method to evaluate the interactions between the security subsystems. The interaction coefficient between network security and data security is 0.6, the interaction coefficient between network security and physical security is 0.4, the interaction coefficient between data security and physical security is 0.5, and the interaction coefficient between personnel security and network security is 0.7.
[0086] S40. Based on the influence factor sets on each value chain and the interaction relationships between the value chains, a node feature matrix and an adjacency matrix are constructed and input into a pre-constructed graph neural network to obtain the final node embedding vectors;
[0087] In this embodiment, each value chain and its interaction relationships are represented as a graph structure. The graph neural network (GNN) technology is used to learn these graph structures to capture the deep interaction patterns between different value chains, and then a more accurate multi-value chain collaborative evaluation network is constructed.
[0088] Among them, the graph neural network is constructed based on successively connected first graph convolutional blocks, a first graph pooling layer, a first feature reconstruction layer, a gated unit layer, a channel mixing layer, a perceptron, an attention layer, a second graph pooling layer, a residual connection layer, a second graph convolutional block, a third graph pooling layer, a second feature reconstruction layer, and a graph readout layer; the input of the graph neural network is the node feature matrix and the adjacency matrix; that is, the feature vectors of the influencing factors of each value chain are combined into a node feature matrix, and the interaction relationships between the value chains are represented as an adjacency matrix. Taking the network security of the financial institution given above as an example, the number of intrusion attempts is 10, the weight is 0.6, the number of firewall interceptions is 5, and the weight is 0.4. The node feature matrix is: [10×0.6 5×0.4]. The first graph convolutional block and the second graph convolutional block are both constructed based on a GCN network, a GAT network, and a GraphSAGE network connected in sequence; Suppose the number of nodes corresponding to the network security of a financial institution is 5 (including servers, firewalls, databases, terminal devices, and log systems), and the feature dimension is 64 (the features of each node are extended to 64 dimensions after being calculated from multiple security metrics). Only the first two dimensions are given as examples, and the rest are extended according to the set security metrics: Node 1: [6.0, 2.0, 0.5, 1.3,..., 0.0] (Number of intrusion attempts × 0.6 = 6.0, Firewall interception × 0.4 = 2.0, and the other 62 dimensions are other metrics or padding); Node 2: [3.0, 1.5, 0.8, 0.0,..., 0.2] (Number of intrusion attempts = 5 times × 0.6 = 3.0, Firewall interception = 3 times × 0.5 = 1.5) Node 3: [9.0, 4.0, 0.0, 2.1,..., 0.7] (Number of intrusion attempts = 15 times × 0.6 = 9.0, Firewall interception = 10 times × 0.4 = 4.0); Node 4: [5.0, 3.0, 1.2, 0.4,..., 0.3] (Number of intrusion attempts = 8 times × 0.6 = 4.8 ≈ 5.0, Firewall interception = 7 times × 0.4 = 2.8 ≈ 3.0); Node 5: [7.0, 2.5, 0.6, 0.0,..., 0.9] (Number of intrusion attempts = 12 times × 0.6 = 7.2 ≈ 7.0, Firewall interception = 6 times × 0.4 = 2.4 ≈ 2.5); Adjacency matrix: A = [0, 1, 1, 0, 0] [1, 0, 0, 1, 0] [1, 0, 0, 0, 1] [0, 1, 0, 0, 1] [0, 0, 1, 1, 0] Among them, [0, 1, 1, 0, 0] indicates that Node 1 (server) is connected to Node 2 (firewall) and Node 3 (database); [1, 0, 0, 1, 0] indicates that Node 2 (firewall) is connected to Node 1 (server) and Node 4 (terminal device); [1, 0, 0, 0, 1] indicates that Node 3 (database) is connected to Node 1 (server) and Node 5 (log system); [0, 1, 0, 0, 1] indicates that Node 4 (terminal device) is connected to Node 2 (firewall) and Node 5 (log system) [0, 0, 1, 1, 0] indicates that Node 5 (log system) is connected to Node 3 (database) and Node 4 (terminal device) The input dimension of the GCN network in the first graph convolution block is 5×64, the weight matrix is 46×128, and the output is 5×128; The input dimension of the GAT network is 5×128, the weight matrix is 128×64, and the output is 5×64; The input of the GraphSAGE network is 5×64, the weight matrix is 128×64, and the output is 5×64; The input of the first graph pooling layer is 5×64, and the Top3 nodes are selected for pooling, and the output is 3×64; In the first feature reconstruction layer, the activation functions of the encoder and decoder in the autoencoder are ReLU and Sigmoid respectively; the input of the autoencoder is 3×64, and the output after reconstruction is 3×64; The input of the gated unit layer is 3×64, the number of hidden units of the GRU is 64, and the number of time steps is 1, and the output is 3×64; Channel mixing layer: When weighted fusion, the second node feature matrix and the third node feature matrix are set to 0.6 and 0.4 respectively; the output is 3×64; Perceptron: The activation function is ReLu, and the output is 3×64; Attention layer: The output is 3×64; The input of the second graph pooling layer is 3×64, and the Top2 nodes are selected for pooling, and the output is 2×64; Residual link layer: The output is 3×64; The input and output of the second graph convolution block are both 3×64; The third graph pooling layer uses global average pooling, the input is 3×64, and the output is 1×64; The output of the second feature reconstruction layer is 1×64; In the graph readout layer, the output of the max pooling layer is 1×64, and the output of the fully connected layer is 1×32, that is, a 32-dimensional embedding vector.
[0089] The first graph pooling layer is used to output the output (H (1) =σ(AXW (0) ), where H (1) represents the output of the GCN network in the first graph convolution block, X represents the input node feature matrix, X∈R N×F , where N is the number of nodes, F is the feature dimension of each node, set to 64, σ is the activation function, W (0) is the weight matrix, H 1 represents the size of the hidden layer, set to 128, A represents the adjacency matrix, that is, the connection relationship between nodes, A∈R N×N H (2) =σ(∑α ijW (1) H j (1) ), α ij represents the attention coefficient, which is obtained by calculating the similarity between nodes i and j. represents the set of neighbor nodes of node i, W (1) represents the weight matrix. H 2 is set to 64, H (2) represents the output of the GAT network in the first graph convolutional block. H (3) is the output of GraphSAGE in the first graph convolutional block. MEAN represents the mean aggregation method) for pooling to obtain the first node feature matrix;
[0090] The first feature reconstruction layer is used to reconstruct the features of the first node feature matrix through an autoencoder, and fuse the node feature matrix after feature reconstruction with the output of the first graph convolutional block to obtain the second node feature matrix; further enhance the feature representation.
[0091] The gated unit layer is used to dynamically adjust the importance of features based on the second node feature matrix through GRU units according to the context information to obtain the third node feature matrix; further control the flow of information;
[0092] The channel mixing layer is used to perform channel fusion on the third node feature matrix and the second node feature matrix (that is, first weight the third node feature matrix and the fourth feature matrix through weight parameters, and then process through an activation function) to obtain the fourth node feature matrix; further fuse the information of different channels.
[0093] The perceptron is used to perform a non-linear transformation on the fourth node feature matrix to obtain the fifth node feature matrix;
[0094] The attention layer is used to weight the fifth node feature matrix, and self-attention mechanism or cyclic column shift invariant attention can be selected to obtain the sixth node feature matrix;
[0095] The second graph pooling layer is used to pool the sixth node feature matrix; in this embodiment, it is global average pooling;
[0096] The residual connection layer is used to perform a residual connection between the fifth node feature matrix and the pooled sixth node feature matrix to obtain the seventh node feature matrix and input it to the second graph convolutional block for processing;
[0097] The third graph pooling layer is used to pool the node feature matrix output by the second graph convolutional block to obtain the eighth node feature matrix;
[0098] The second feature reconstruction layer is used to reconstruct the features of the eighth node feature matrix through an autoencoder, and fuse the node feature matrix after feature reconstruction with the output of the second graph convolutional block to obtain the ninth node feature matrix;
[0099] The graph readout layer is used to perform max pooling (i.e., used to generate graph-level representations from node features) and fully connected (i.e., further process the graph-level representations through a fully connected layer to generate the final prediction result) processing on the ninth node feature matrix in sequence to obtain the final node embedding vector Z, which not only contains rich feature information, reflects the attributes of the node itself, but also fuses its interaction relationship with other nodes.
[0100] The loss function of the graph neural network during training is:
[0101]
[0102] where L represents the loss function, N represents the total number of nodes, represents the set of neighbor nodes of node i, ξ represents the cross-entropy loss function, y i , y i1 respectively represent the prediction result and the true label corresponding to node i output by the graph neural network, H i , H j respectively represent the hidden representations of node i and node j, A ij represents the element in the adjacency matrix, α and β both represent hyperparameters, α is set to 1, and the recommended range is [0.5, 2], β is set to 0.1, and the recommended range is [0.01, 1], sim is the similarity function, C ij is the collaboration strength between node i and node j, set to 0.5, λ 1 , λ 2 , λ 3 , θ 4 all represent the weight coefficients of the corresponding loss function terms, and are set to 1, 0.5, 0.2, and 0.1 in sequence, γ i represents the adaptive weight, set to 1.0, δ ij represents the dynamically adjusted element of the adjacency matrix, set to 0.5, δ ij = A ij + η(y i1 - y i )(y j1 - y j ), η represents the learning rate, set to 0.1, y j , y j1 respectively represent the prediction result and the true label corresponding to node j output by the graph neural network.
[0103] S50 uses an improved dynamic programming algorithm, combines the final node embedding vectors, conducts path search, and then determines the optimal decision path; collaborates on the enterprise's multiple value chains according to the optimal decision path, and generates a collaboration evaluation report.
[0104] Existing path planning algorithms are very time-consuming in path search in large-scale graph structures, and the paths cannot handle the dynamic changes and uncertainties of the graph structure. Therefore, in this embodiment, by combining the learning results of GNN with the dynamic programming algorithm, through strategies such as heuristic pruning and dynamic path cost adjustment, the robustness and diversity of path search are improved, ensuring the efficiency and reliability of the optimal decision path, and ensuring to find the most effective collaboration method. Specifically as follows: Initialize the path set and path cost, and based on the final node embedding vectors, calculate the node similarity (calculated by common similarity formulas), node importance (obtained through a function for evaluating node importance, which can be based on the norm of the embedding vector, for reference but not limited to https: / / blog.csdn.net / weixin_43886163 / article / details / 129628016, not elaborated here);
[0106] Based on the node similarity, the node importance, and in combination with the path length, calculate the heuristic value of each node through heuristic pruning.
[0107] In the present invention, a dynamic programming algorithm (such as Dijkstra's algorithm or A* algorithm) is used to conduct path search in combination with GNN node embedding vectors. Among them, when conducting path search, by introducing a heuristic pruning strategy, unnecessary path expansions are reduced, and the heuristic function is shown in the following formula:
[0108]
[0109] Among them, h(i,j) represents the heuristic value, sim(H i ,H j ) represents the similarity between node i and node j, H i 、H j represent the embedding vectors of node i and node j, I j represents the importance of the node. Assume there are 5 nodes, and the importances are 0.8, 0.6, 0.9, 0.7, 0.5 respectively. α1, α2, α3, α4, α5 all represent weights, and are set to 0.5, 0.1, 0.01, 0.5, 0.1 respectively;
[0110] Based on the heuristic value, in combination with the dynamic change factor of the edge and the path stability between nodes, the path cost is dynamically adjusted, and the optimal decision path is selected according to the adjusted path cost.
[0111] In the present invention, the path cost of multiple generated paths is dynamically adjusted according to the real-time change of the graph structure, as shown in the following formula:
[0112] c(i,j) = w ij -h(i,j) + α6·Δ ij +α7·S ij
[0113] where c(i,j) represents the path cost, w ij represents the weight of the edge (i,j), which is set to 1, Δ ij represents the dynamic change factor of the edge (i,j), which is set to 0.1, S ij represents the path stability factor between node i and node j, which is set to 0.5, and α6 and α7 both represent weights, which are set to 0.5 and 0.1 respectively.
[0114] Select the path corresponding to the least adjusted path cost as the optimal decision path, and use the optimal decision path to adjust the operation strategies of each value chain in combination with the real-time feedback mechanism (for example, through steps such as real-time data collection, status monitoring, performance evaluation, and strategy adjustment to ensure that the operation strategies of each value chain can respond to environmental changes in a timely manner), optimize the overall synergy effect, summarize the key performance indicators, influence factor weights, interaction importance coefficients, optimal decision paths, and optimization suggestions of each value chain, etc., and generate a final multi-value chain collaborative evaluation report.
[0115] Taking the above financial institution as an example, the financial institution uses an improved dynamic programming algorithm to determine the most effective collaborative path between each security subsystem. For example, in the event of a network security incident, it quickly calls the response measures of data security and physical security to form an efficient emergency response mechanism. The financial institution collects the operation data of each security subsystem through a real-time monitoring system, combines the optimal decision path, and dynamically adjusts the operation strategies of each subsystem. For example, according to the real-time intrusion detection results, it adjusts the encryption algorithm of data security and the patrol frequency of physical security, generates a detailed collaborative evaluation report, and provides decision support for the management.
[0116] In summary, through the improved GNN network structure, the present invention can more comprehensively capture the complex interaction relationships between different security subsystems, significantly improving the model's expressive ability and the accuracy of multi-value chain collaborative evaluation. Based on the improved GNN network and algorithm, combined with strategies such as heuristic pruning and dynamic path cost adjustment for path dynamic planning, the efficiency and robustness of path search are significantly improved. This enables rapid determination of the optimal decision path in actual multi-value chain collaborative applications, generation of a detailed multi-value chain collaborative evaluation report, effective response to security incidents, and improvement of the overall collaborative effect and response speed.
[0117] A multi-value chain collaborative evaluation system according to the second embodiment of the present invention is used for multi-value chain collaboration and generating a collaborative evaluation report. The system includes:
[0118] A data acquisition module configured to collect multi-source heterogeneous data of various influencing factors on the multi-value chain of the enterprise security system;
[0119] A weight assignment module configured to, based on the multi-source heterogeneous data, use the fuzzy comprehensive evaluation method to assign weights to the influencing factors on each value chain to obtain an influencing factor set on each value chain;
[0120] A weight assignment module configured to, based on the multi-source heterogeneous data, use the fuzzy comprehensive evaluation method to assign weights to the influencing factors on each value chain to obtain an influencing factor set on each value chain;
[0121] A graph learning module configured to, based on the influencing factor set on each value chain and the interaction relationships between each value chain, construct a node feature matrix and an adjacency matrix, and input them into a pre-constructed graph neural network to obtain the final node embedding vector;
[0122] A multi-chain collaboration module configured to use an improved dynamic programming algorithm, combined with the final node embedding vector, to perform path search, and then determine the optimal decision path; collaborate on the enterprise multi-value chain according to the optimal decision path, and generate a collaborative evaluation report;
[0123] Among them, the method for determining the optimal decision path is:
[0124] Initialize the path set and path cost, and based on the final node embedding vector, calculate the node similarity and node importance;
[0125] Based on the node similarity and the node importance, combined with the path length, calculate the heuristic value of each node through heuristic pruning;
[0126] Based on the heuristic value, combined with the dynamic change factor of the edge and the path stability between nodes, dynamically adjust the path cost, and select the optimal decision path according to the adjusted path cost.
[0127] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working process and related explanations of the above-described system can refer to the corresponding process in the foregoing method embodiments, and will not be elaborated herein.
[0128] It should be noted that the multi-value chain collaborative evaluation system provided in the above embodiment is only illustrated by the division of the above functional modules. In actual application, the above functions can be allocated to different functional modules as needed, that is, the modules or steps in the embodiments of the present invention can be further decomposed or combined. For example, the modules in the above embodiment can be combined into one module, or further split into multiple sub-modules to complete all or part of the functions described above. The names of the modules and steps involved in the embodiments of the present invention are only for distinguishing each module or step, and are not regarded as an improper limitation of the present invention.
[0129] A multi-value chain collaborative evaluation device according to the third embodiment of the present invention includes at least one processor; and a memory communicatively connected to at least one of the processors; wherein, the memory stores instructions executable by the processor, and the instructions are used to be executed by the processor to implement the above multi-value chain collaborative evaluation method.
[0130] A computer-readable storage medium according to the fourth embodiment of the present invention stores computer instructions, and the computer instructions are used to be executed by the computer to implement the above multi-value chain collaborative evaluation method.
[0131] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working process and related explanations of the above-described multi-value chain collaborative evaluation device and readable storage medium can refer to the corresponding process in the foregoing method examples, and will not be elaborated herein.
[0132] Those skilled in the art should be able to realize that the modules and method steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. The programs corresponding to the software modules and method steps can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field. To clearly illustrate the interchangeability of electronic hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in the form of electronic hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0133] The terms "first", "second", "third", etc. are used to distinguish similar objects, rather than to describe or represent a specific order or sequence.
[0134] So far, the technical solution of the present invention has been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will all fall within the protection scope of the present invention.
Claims
1. A multi-value chain collaborative evaluation method for multi-value chain collaboration and generating collaborative evaluation reports, characterized in that: The method comprises the following steps: S10, collects multi-source heterogeneous data of various influencing factors on the multi-value chain of enterprise security systems; S20, based on the multi-source heterogeneous data, using a fuzzy comprehensive evaluation method to assign weights to the influencing factors on each value chain, and obtaining an influencing factor set on each value chain; S30, based on the set of influencing factors on each value chain, the hierarchical analysis method is used to obtain the interaction relationship between each value chain; S40, based on the influencing factor set on each value chain and the interaction relationship between each value chain, a node feature matrix and an adjacency matrix are constructed, and input into a pre-constructed graph neural network to obtain the final node embedding vector; S50, using an improved dynamic programming algorithm, combined with the final node embedding vector, to perform path search, and then determine the optimal decision path; perform the collaboration of multiple value chains of the enterprise according to the optimal decision path, and generate a collaboration evaluation report; Among them, the method for determining the optimal decision path is: Initialize a path set and path cost, and calculate node similarity and node importance based on the final node embedding vector; Based on the node similarity, the node importance, and the path length, a heuristic value of each node is calculated by heuristic pruning; Based on the heuristic value, combined with the dynamic change factor of the edge and the path stability between the nodes, the path cost is dynamically adjusted, and the optimal decision path is selected according to the adjusted path cost.
2. The multi-value chain collaborative evaluation method according to claim 1, characterized in that: The multi-value chain of the enterprise security system includes data security, network security, physical security, and personnel safety; the influencing factors include the number of data leakage incidents, the number of intrusion attempts, the number of firewall interceptions, and the number of abnormal surveillance video incidents.
3. The multi-value chain collaborative evaluation method according to claim 1, characterized in that: The graph neural network is constructed based on the first graph convolution block, the first graph pooling layer, the first feature reconstruction layer, the gated unit layer, the channel mixing layer, the perceptron, the attention layer, the second graph pooling layer, the residual connection layer, the second graph convolution block, the third graph pooling layer, the second feature reconstruction layer, and the graph readout layer connected in sequence; the input of the graph neural network is the node feature matrix and the adjacency matrix; The first graph convolution block and the second graph convolution block are both constructed based on a GCN network, a GAT network, and a GraphSAGE network connected in sequence; The first graph pooling layer is used to pool the output of the first graph convolution block to obtain a first node feature matrix; The first feature reconstruction layer is used to reconstruct the first node feature matrix through an autoencoder, and fuse the reconstructed node feature matrix with the output of the first graph convolution block to obtain a second node feature matrix; The gated unit layer is used to dynamically adjust the importance of features according to context information through a GRU unit based on the second node feature matrix to obtain a third node feature matrix; The channel mixing layer is used to perform channel fusion on the third node feature matrix and the second node feature matrix to obtain a fourth node feature matrix; The perceptron is used to perform a nonlinear transformation on the fourth node feature matrix to obtain a fifth node feature matrix; The attention layer is used to weight the fifth node feature matrix to obtain a sixth node feature matrix; The second graph pooling layer is used to pool the sixth node feature matrix; The residual connection layer is used to perform residual connection on the fifth node feature matrix and the pooled sixth node feature matrix to obtain a seventh node feature matrix, and input the matrix into the second graph convolution block for processing; The third graph pooling layer is used to pool the node feature matrix output by the second graph convolution block to obtain an eighth node feature matrix; The second feature reconstruction layer is used to perform feature reconstruction on the eighth node feature matrix through an autoencoder, and fuse the node feature matrix after feature reconstruction with the output of the second graph convolution block to obtain a ninth node feature matrix; The graph readout layer is used to perform maximum pooling and full connection processing on the ninth node feature matrix in sequence to obtain a final node embedding vector.
4. The multi-value chain collaborative evaluation method according to claim 3, characterized in that: The loss function of the graph neural network during training is: Among them, L represents the loss function, N represents the total number of nodes, represents the set of neighbor nodes of node i, ξ represents the cross entropy loss function, y i ,y i1 They represent the prediction result and true value label corresponding to the output node i of the graph neural network, respectively. i , H j Represent the hidden representation of node i and node j respectively, A ij represents the elements in the adjacency matrix, α and β represent hyperparameters, sim is the similarity function, C ij is the collaboration strength between node i and node j, λ1, λ2, λ3, λ4 all represent the weight coefficients of the corresponding loss function terms, γ i represents the adaptive weight, δ ij Represents a dynamically adjusted adjacency matrix element.
5. The multi-value chain collaborative evaluation method according to claim 4, characterized in that: The dynamically adjusted adjacency matrix elements are obtained by: δ ij =A ij +η(and i1 -and i )(and j1 -and j ) Among them, η represents the learning rate, y j ,y j1 They respectively represent the prediction result and true value label corresponding to the output node j of the graph neural network.
6. The multi-value chain collaborative evaluation method according to claim 5, characterized in that: The heuristic value of each node is calculated by heuristic pruning, and the method is: Among them, h(i,j) represents the heuristic value, sim(H i ,H j ) represents the similarity between node i and node j, H i , H j Represents the embedding vector of node i and node j, I j Indicates the importance of the node, and α1, α2, α3, α4, and α5 all represent weights.
7. The multi-value chain collaborative evaluation method according to claim 6, characterized in that: Dynamically adjust the path cost and select the optimal decision path based on the adjusted path cost. The method is as follows: Calculate the adjusted path cost: c(i,j)=w ij -h(i,j)+α6·Δ ij +α7·S ij Among them, c(i,j) represents the path cost, w ij represents the weight of edge (i,j), Δ ij Represents the dynamic change factor of edge (i,j), S ij represents the path stability factor between node i and node j, α6 and α7 both represent weights; The path with the lowest adjusted path cost is selected as the optimal decision path.
8. A multi-value chain collaborative evaluation system for multi-value chain collaboration and generating collaborative evaluation reports, characterized in that: The system comprises: A data acquisition module configured to collect multi-source heterogeneous data of various influencing factors on multiple value chains of enterprise security systems; A weight allocation module is configured to allocate weights to the influencing factors on each value chain using a fuzzy comprehensive evaluation method based on the multi-source heterogeneous data to obtain a set of influencing factors on each value chain; A hierarchy analysis module is configured to obtain the interaction relationship between each value chain using a hierarchy analysis method based on a set of influencing factors on each value chain; The graph learning module is configured to construct a node feature matrix and an adjacency matrix based on the influencing factor set on each value chain and the interaction relationship between each value chain, and input the pre-built graph neural network to obtain the final node embedding vector; The multi-chain collaboration module is configured to use an improved dynamic programming algorithm, combined with the final node embedding vector, to perform path search, thereby determining an optimal decision path; perform collaboration of multiple value chains of the enterprise according to the optimal decision path, and generate a collaboration evaluation report; Among them, the method for determining the optimal decision path is: Initialize a path set and path cost, and calculate node similarity and node importance based on the final node embedding vector; Based on the node similarity, the node importance, and the path length, a heuristic value of each node is calculated by heuristic pruning; Based on the heuristic value, combined with the dynamic change factor of the edge and the path stability between the nodes, the path cost is dynamically adjusted, and the optimal decision path is selected according to the adjusted path cost.
9. An electronic multi-value chain collaborative evaluation device, characterized in that: The electronic device comprises: at least one processor, and a memory communicatively coupled to at least one of the processors; The memory stores instructions executable by the processor, and the instructions are used to be executed by the processor to implement the multi-value chain collaborative evaluation method described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to be executed by a computer to implement a multi-value chain collaborative evaluation method as described in any one of claims 1-7.
Citation Information
Patent Citations
Complex network topological graph representation learning method, prediction method and server
CN113065649A
Enterprise collaborative manufacturing decision-making method based on double-layer heterogeneous graph neural network
CN113988786A
Cross-domain network security policy automatic generation and protection policy collaboration method and system
CN119449428A
Cited By
Multi-party collaborative enterprise data AI intelligent analysis and storage method
CN121166040A
Multi-party collaborative enterprise data AI intelligent analysis storage method
CN121166040B