Malware response system and method based on artificial intelligence

By introducing artificial intelligence-based distributed perception, intelligent analysis, dynamic quantization and adaptive defense technologies into malware detection and response systems, the shortcomings of existing systems in data collection, threat identification, risk assessment and defense strategies have been solved, and more efficient and flexible malware response capabilities have been achieved.

CN120162785APending Publication Date: 2025-06-17GUANGDONG POWER GRID CO LTD +1
View PDF 0 Cites 4 Cited by

Patent Information

Application Number
CN202510311040.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-17
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

Existing malware detection and response systems have shortcomings in data acquisition efficiency, threat identification capabilities, risk assessment accuracy and defense strategy flexibility, making it difficult to deal with threats in complex dynamic environments.

Method used

The malware response system based on artificial intelligence is adopted to realize the intelligence and adaptability of the system through distributed perception, intelligent analysis, dynamic quantization and adaptive defense means, including data perception module, intelligent analysis module, risk quantization module and dynamic defense module.

Benefits of technology

It significantly improves data acquisition efficiency, threat identification capabilities, risk assessment accuracy and flexibility in defense strategies, ensuring efficient operation and effective response to unknown threats in complex dynamic environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120162785A_ABST
    Figure CN120162785A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and discloses a malicious software response system and system based on artificial intelligence, and the system comprises a data sensing module, an intelligent analysis module, a risk quantification module and a dynamic defense module. The method corresponds to the system. According to the application, an efficient, intelligent and flexible malicious software response system is constructed by integrating key technologies such as distributed sensing, intelligent analysis, dynamic quantification and adaptive defense, the limitations in the aspects of data acquisition, threat identification, risk assessment and defense strategies are overcome, and the system also has strong self-learning ability and wide applicability; and a new direction and a new solution are provided for technical innovation in the field of network security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and specifically to a malware response system and system based on artificial intelligence. Background Art

[0002] With the rapid development of information technology, malware attacks have become one of the main threats in the field of network security. Traditional malware detection and response systems usually rely on rule matching or static feature analysis, and these methods are inadequate when facing new threats. For example, signature-based detection methods cannot identify unknown malware, while static feature analysis is easily bypassed by advanced persistent threats (APTs).

[0003] In recent years, the introduction of artificial intelligence technology has brought new possibilities to malware detection and response. However, the existing technologies still have the following deficiencies:

[0004] Low data collection efficiency:

[0005] The data collection modules of existing systems mostly adopt fixed sampling strategies and fail to dynamically adjust the sampling frequency according to environmental changes, resulting in too much redundant data or loss of key information.

[0006] Limited threat recognition ability:

[0007] Traditional feature extraction methods mainly rely on a single model (such as CNN or LSTM) and are difficult to comprehensively capture complex threat patterns. In addition, the lack of in-depth analysis of event relevance easily leads to missed reports or false reports.

[0008] Insufficient risk assessment accuracy:

[0009] Existing risk quantification methods mostly adopt linear weighting or static threshold judgment and cannot adapt to the threat evolution law in complex dynamic environments.

[0010] Poor flexibility of defense strategies:

[0011] Dynamic defense modules usually rely on predefined rules, lack self-learning and adaptive capabilities, and are difficult to cope with unknown threats or rapidly changing attack scenarios.

[0012] Therefore, there is an urgent need for a new technology to solve these problems. A malware response system based on artificial intelligence. Summary of the Invention

[0013] The purpose of this application is to provide a malware response system and system based on artificial intelligence, aiming to overcome the defects in the existing technology and comprehensively improve the intelligence level and security of the system through means such as distributed perception, intelligent analysis, dynamic quantification, and adaptive defense.

[0014] To achieve the above object, the present application discloses the following technical solutions:

[0015] In a first aspect, the present application discloses a malware response system based on artificial intelligence, including:

[0016] A data perception module, configured to: collect multi-dimensional environmental data in real time through a distributed sensor network, and optimize the data acquisition efficiency by using an adaptive sampling algorithm;

[0017] An intelligent analysis module, configured to: perform multi-level semantic parsing on the environmental data based on a hybrid deep learning framework, extract potential threat signals, and generate a dynamic threat map;

[0018] A risk quantification module, configured to: combine context awareness technology and a probability inference model to quantitatively evaluate threat signals, and output a risk level and an impact range as a risk assessment result;

[0019] A dynamic defense module, configured to: generate an optimal defense plan through a self-organizing strategy optimization algorithm according to the risk assessment result, and perform defense operations in a distributed manner; and the dynamic defense module is further configured to: automatically evolve defense strategies through a meta-learning mechanism.

[0020] Preferably, the optimization of the data acquisition efficiency by using the adaptive sampling algorithm specifically includes: dynamically adjusting the sensor sampling frequency through a time series prediction model; wherein, the expression of the time series prediction model is:

[0021]

[0022] wherein, F sample is the sampling priority, ω t is the time weight, S t is the data value at the t-th moment, is the mean value of the data.

[0023] Preferably, the multi-level semantic parsing specifically includes: extracting spatial features and relationship features in the environmental data through the combination of a convolutional neural network and a graph neural network; the adopted attention mechanism is specifically:

[0024]

[0025] wherein, A att is the attention weight matrix, Q, K, and V are the query, key, and value matrices respectively, and d k is the dimension of the key vector.

[0026] Preferably, the intelligent analysis module is further configured to: reduce the feature dimension after performing dimensionality reduction processing on the collected multi-dimensional environmental data.

[0027] Preferably, the quantitative evaluation of threat signals specifically includes: capturing the temporal dependence and causal relationship of threat events by constructing a dynamic Bayesian network.

[0028] Preferably, the risk quantification module is further configured to: analyze the historical behavior data of users and dynamically adjust the output risk level.

[0029] Preferably, the automatic evolution of defense strategies through the meta-learning mechanism is specifically: learning defense strategies through a reinforcement learning framework and balancing security and performance overhead through a multi-objective optimization function.

[0030] Preferably, the multi-objective optimization function includes the optimization of the number of threats successfully blocked and the optimization of response costs;

[0031] The optimization of the number of threats successfully blocked specifically includes: constructing an association graph of threat events and aggregating and analyzing multiple related threat events using a graph neural network; the success probability analysis formula used is:

[0032]

[0033] where R i is the risk value of the i-th event, and υ i is the weight of this event;

[0034] The optimization of the response cost specifically includes: using a dynamic cost allocation model to automatically adjust the resource allocation ratio according to the current operating state of the system and the threat level; the dynamic cost allocation model is:

[0035] C cost = α·C resource + β·C impact + γ·C risk

[0036] where C cost is the total response cost, C resource is the resource consumption cost, C impact is the business impact cost, C risk is the security risk cost, and α, β, and γ are weight coefficients respectively.

[0037] Preferably, the data perception module is further configured to: construct an anomaly detection model based on probability distribution through statistical methods and machine learning techniques, and the anomaly detection model is used to monitor and eliminate abnormal data points in real time during the data collection process.

[0038] Second aspect, the present application discloses a malware response method based on artificial intelligence, which is applied to the malware response system based on artificial intelligence described in the above item. The method includes the following steps:

[0039] Collect multi-dimensional environmental data in real time through a distributed sensor network, and optimize the data acquisition efficiency by using an adaptive sampling algorithm;

[0040] Perform multi-level semantic parsing on the environmental data based on a hybrid deep learning framework, extract potential threat signals, and generate a dynamic threat map;

[0041] Combine context awareness technology and a probability inference model to quantitatively evaluate the threat signals, and output the risk level and the affected range as the risk assessment result;

[0042] According to the risk assessment result, generate an optimal defense plan through a self-organizing strategy optimization algorithm, and perform defense operations in a distributed manner; and the dynamic defense module is further configured to: automatically evolve the defense strategy through a meta-learning mechanism.

[0043] Compared with the prior art, the malware response system and system based on artificial intelligence of the present application have the following beneficial effects: The data perception module dynamically adjusts the sensor sampling frequency through an adaptive sampling algorithm, ensuring the capture of key information while reducing the amount of redundant data; The intelligent analysis module extracts multi-level features and generates a dynamic threat map, significantly improving the recognition ability of complex threats; The risk quantification module captures the time dependence and causal relationship of threat events, realizing more accurate risk prediction; The dynamic defense module learns the optimal defense strategy to ensure efficient operation in a complex dynamic environment. Therefore, the malware response system and system based on artificial intelligence of the present application can adaptively adjust parameters, realizing intelligent data collection, threat recognition and dynamic defense. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative efforts.

[0045] Figure 1 It is a structural block diagram of the malware response system based on artificial intelligence provided in this embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0046] The technical solutions in the embodiments of the present application will be described clearly and completely below. Apparently, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0047] In this article, the term "including" is intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such a process, method, article, or device. Without more limitations, the elements defined by the statement "including..." do not exclude the existence of additional identical elements in the process, method, article, or device including the elements.

[0048] In the first aspect, this embodiment provides a malicious software response system based on artificial intelligence as Figure 1 shown, including: a data perception module, an intelligent analysis module, a risk quantification module, and a dynamic defense module.

[0049] Specifically

[0050] The data perception module is configured to: collect multi-dimensional environmental data in real time through a distributed sensor network and optimize the data acquisition efficiency by using an adaptive sampling algorithm. The data perception module collects multi-dimensional environmental data (such as network traffic, terminal behavior, hardware status, etc.) in real time through a distributed sensor network, and dynamically adjusts the sampling frequency according to the current environmental changes, ensuring the capture of key information while reducing redundant data. For example, during high-threat activities, the system will automatically increase the sampling frequency to capture more details.

[0051] The intelligent analysis module is configured to: perform multi-level semantic parsing on the environmental data based on a hybrid deep learning framework, extract potential threat signals, and generate a dynamic threat map. In the hybrid deep learning framework (CNN + GNN), CNN is responsible for extracting spatial features (such as static file features), while GNN captures the relationship features between nodes (such as abnormal communication patterns in network traffic). This combined method can identify complex threats more comprehensively.

[0052] The risk quantification module is configured to: combine context awareness technology and a probability inference model to quantitatively evaluate threat signals and output the risk level and impact range as the risk assessment result. In the risk quantification module, context awareness technology improves the accuracy of threat assessment by analyzing context information such as user behavior and device status; the probability inference model (such as DBN) is used to capture the temporal dependence and causal relationship of threat events, thereby achieving more accurate risk prediction.

[0053] The dynamic defense module is configured to: generate an optimal defense plan through a self-organizing strategy optimization algorithm according to the risk assessment result, and execute defense operations in a distributed manner; and the dynamic defense module is further configured to: automatically evolve defense strategies through a meta-learning mechanism. The dynamic defense module learns defense strategies through a reinforcement learning framework according to the risk assessment result, and introduces a multi-objective optimization function to balance security and performance overhead.

[0054] In this embodiment, the data acquisition efficiency is optimized by using an adaptive sampling algorithm, significantly reducing the amount of redundant data while enhancing the ability to capture key data. Specifically, it includes: dynamically adjusting the sensor sampling frequency through a time series prediction model; where the expression of the time series prediction model is:

[0055]

[0056] where F sample is the sampling priority, and the higher the value, the more important the data at that moment, and it should be collected preferentially; ω t is the time weight, which is used to reflect the importance of the time dimension, and the more recent data is usually more important; S t is the data value at the t-th moment, reflecting the state of the current environment; is the mean value of the data, which is used to measure the volatility of the data. The larger the denominator, the more stable the data and the lower the sampling priority.

[0057] During the operation of the model, the sampling frequency of the sensor is dynamically adjusted by calculating the sampling priority at each time point. When it is detected that the traffic of a certain server suddenly surges, the value of S t will increase significantly, resulting in an increase in F sample and thus triggering a higher sampling frequency to capture more details. In a stable state, the system will reduce the sampling frequency to save resources. For example, in an enterprise network, when it is detected that the traffic of a certain server suddenly surges, the system will automatically increase the sampling frequency of that server to monitor its behavior more carefully.

[0058] In this embodiment, the multi-level semantic parsing specifically includes: extracting spatial features and relationship features in the environmental data by combining a convolutional neural network and a graph neural network, introducing an attention mechanism to enhance the ability to focus on key threat signals, and avoiding the information loss problem caused by global averaging in the prior art. The specific attention mechanism adopted is:

[0059]

[0060] where A attis the attention weight matrix, which is used to assign the importance of different features; Q, K, and V are the query, key, and value matrices respectively, where Q and K are used to calculate similarity, and V is the actual feature value; d k is the dimension of the key vector, which is used to scale the similarity calculation to avoid the problem of gradient disappearance or explosion caused by excessive numerical values.

[0061] When paying attention to key threat signals, resources are dynamically allocated through the attention mechanism, focusing on the features that are most likely to contain threats. For example, when analyzing a network traffic segment, the system will allocate more computing resources to abnormal large-scale data transmission behaviors rather than uniformly processing all traffic data.

[0062] As a preferred implementation, the intelligent analysis module is further configured to: reduce the feature dimension after performing dimensionality reduction processing on the collected multi-dimensional environmental data. Specifically, an improved principal component analysis method is adopted, and more feature information is retained through non-linear mapping, overcoming the problem of information loss in the existing linear PCA method. The specific formula of the principal component analysis method is as follows:

[0063] Z = f(X; W) = σ(W·X + b)

[0064] where, Z is the feature after dimensionality reduction, reflecting the main information of the original data; X is the original feature, containing all the information of the high-dimensional data; W and b are mapping parameters, used to define the non-linear transformation rule; σ is the non-linear activation function, used to introduce non-linear characteristics and retain more complex feature information.

[0065] During the dimensionality reduction process, the high-dimensional data is compressed into a low-dimensional space through the non-linear PCA method, while retaining the key threat features. For example, when processing high-dimensional network log data, the system compresses the data into a low-dimensional space through the non-linear PCA method while retaining the key threat features.

[0066] In this embodiment, the quantification and evaluation of threat signals specifically include: by constructing a dynamic Bayesian network (DBN) to capture the time dependence and causal relationship of threat events, so as to achieve more accurate risk prediction. Specifically, the risk assessment formula is as follows:

[0067]

[0068] where, R is the risk state, E is the observed evidence, P(R|E) is the probability of the risk state R under the condition of observing the observed evidence E; P(E|R) is the conditional probability, indicating the possibility of the observed evidence E appearing under the risk state R; P(R) is the prior probability, indicating the initial possibility of the risk state R; P(E) is the marginal probability of the observed evidence E, used for normalization calculation.

[0069] During the risk assessment process, the probability distribution of the risk state is gradually updated through a dynamic Bayesian network to capture the temporal evolution law of threat events. For example, when the system detects that a device has logged in successfully after multiple consecutive login failures, the dynamic Bayesian network will associate it with previous abnormal behaviors and calculate a higher risk probability.

[0070] As a preferred embodiment, the risk quantification module is further configured to: analyze the historical behavior data of the user and dynamically adjust the output risk level. The core function of the risk quantification module is to combine context awareness technology and a probability inference model to quantitatively evaluate threat signals and output the risk level and the scope of influence. The output of the risk level is achieved through a threat scoring formula. As can be seen from the prior art, the threat scoring formula is used to convert threat signals into quantifiable risk levels, thereby providing a basis for subsequent defense strategies. That is, the threat scoring formula is a key component in the risk quantification module, and its functions include: (1) Quantifying threat signals: converting raw data (such as network traffic, terminal behavior, etc.) into threat scores to reflect the severity of potential threats; (2) Supporting dynamic adjustment: dynamically adjusting the parameters in the scoring formula according to context information (such as user behavior patterns, historical threat events, etc.) to adapt to different scenarios; (3) Providing a decision-making basis: the output risk level directly guides the selection of response strategies for the dynamic defense module. The risk quantification module uses a probability inference model (such as DBN) to capture the temporal dependence and causal relationship of threat events. The threat scoring formula is one of the mathematical expression forms of this model. In a prior art, a typical threat scoring formula can be as follows: where L represents the final threat score; ξ i is the weight of the i-th type of threat factor, reflecting its importance; F i is the original score value of the i-th type of threat factor; log(1 + |F i |) is a non-linear weighting function used to balance the influence of high scores and low scores. ξi can be dynamically adjusted according to context information. For example, for users who often access external resources, the weight related to external connections may be reduced. The original score value Fi can be calculated through a dynamic Bayesian network (DBN) to capture the temporal dependence and causal relationship of threat events. Using the log(1 + |F i |) function avoids the limitations of the linear weighting method in the prior art and makes the scoring more in line with the actual threat situation. Therefore, through the design of the threat scoring formula, it is possible to combine context awareness technology and a probability inference model to generate accurate risk assessment results, thereby guiding the selection of response strategies for the dynamic defense module.

[0071] In this embodiment, the automatic evolution of defense strategies through the meta-learning mechanism is specifically: learning defense strategies through a reinforcement learning framework, and balancing security and performance overhead through a multi-objective optimization function. Specifically, the goal of reinforcement learning is to maximize the long-term reward function:

[0072] JL=τ1·C success -τ2·C cost

[0073] Where JL represents the long-term reward function, which is used to evaluate the effectiveness of the defense strategy; C success Indicates the number of times the threat is successfully blocked. The higher the value, the better the defense effect. cost Represents the response cost, including resource consumption and service interruption, etc. The lower the value, the better. τ1 and τ2 are weight coefficients used to weigh the relationship between security and performance.

[0074] Through reinforcement learning, the defense strategy is continuously adjusted to find the best solution that ensures security while minimizing performance overhead. For example, when a ransomware attack is detected, the system will choose to isolate the affected terminal and start the backup recovery process instead of directly restarting the entire network, thereby ensuring security while reducing business interruption.

[0075] As a preferred implementation manner, the multi-objective optimization function includes optimization of the number of successful threat blocking and optimization of response costs.

[0076] The optimization of the number of successful threat blocking times specifically includes: constructing a threat event correlation graph, using a graph neural network to aggregate and analyze multiple related threat events, so as to more accurately predict the success rate of overall threat blocking. The success probability analysis formula used is:

[0077]

[0078] Among them, P success It indicates the success probability of threat prevention. The higher the value, the more effective the system is. i is the risk value of the event, reflecting the degree of harm of the event; i is the weight of the event, which is used to assign the importance of different events.

[0079] During the optimization process, the correlation between threat events is analyzed through graph neural networks, and resources are concentrated to prioritize core threats. For example, when multiple devices are detected to be attacked by the same type of attack at the same time, the system will associate these events and concentrate resources to prioritize high-risk devices, that is, prioritize core threats.

[0080] The optimization of the response cost specifically includes: using a dynamic cost allocation model to automatically adjust the resource allocation ratio according to the running state and threat level of the current system; the dynamic cost allocation model is:

[0081] C cost = α·C resource + β·C impact + γ·C risk

[0082] where C cost is the total response cost, and the lower the value, the more efficient the system; C resource is the resource consumption cost, reflecting the consumption of hardware and computing resources during system operation; C impact is the business impact cost, reflecting the impact of defense operations on user business; C risk is the security risk cost, reflecting the potential losses caused by incomplete threat prevention; α, β, and γ are weight coefficients respectively, used to weigh the importance of different cost factors.

[0083] During the optimization process, the resource allocation is dynamically adjusted through a multi-objective optimization function to ensure maximizing security while minimizing costs. For example, during a large-scale attack, the system will choose to prioritize protecting critical business systems, even if it means a short interruption of other non-critical systems.

[0084] In this embodiment, the data awareness module is further configured to: construct an anomaly detection model based on probability distribution through statistical methods and machine learning techniques, and the anomaly detection model is used to monitor and eliminate abnormal data points in real time during the data collection process. Specifically, the model determines whether a data point belongs to the normal range by calculating its probability density. The probability density value of each data point is calculated through statistical methods, and data points below the set threshold are regarded as abnormal. In addition, the machine learning model is trained with historical data to further improve the accuracy of anomaly detection. For example, when monitoring network traffic, the system finds that the traffic of a certain device is much higher than the historical average level but does not exceed the fixed threshold, and it will still be marked as abnormal.

[0085] In summary, the malware response system based on artificial intelligence in this embodiment constructs an efficient, intelligent, and flexible malware response system by integrating key technologies such as distributed awareness, intelligent analysis, dynamic quantification, and adaptive defense. It not only overcomes the limitations of the prior art in aspects such as data collection, threat identification, risk assessment, and defense strategies, but also has a strong self-learning ability and wide applicability, providing a new direction and solution for technological innovation in the field of network security.

[0086] In a second aspect, this embodiment provides a malware response method based on artificial intelligence, which is applied to the malware response system based on artificial intelligence as described above. The method includes the following steps:

[0087] Collect multi-dimensional environmental data in real time through a distributed sensor network, and optimize the data acquisition efficiency by using an adaptive sampling algorithm;

[0088] Perform multi-level semantic parsing on the environmental data based on a hybrid deep learning framework, extract potential threat signals, and generate a dynamic threat map;

[0089] Combine context awareness technology and a probability inference model to quantitatively evaluate the threat signals, and output the risk level and the scope of influence as the risk assessment result;

[0090] According to the risk assessment result, generate an optimal defense plan through a self-organizing strategy optimization algorithm, and execute the defense operation in a distributed manner; and the dynamic defense module is further configured to: automatically evolve the defense strategy through a meta-learning mechanism.

[0091] It should be noted that in this embodiment, this method corresponds to the aforementioned malware response system based on artificial intelligence. Therefore, for the parts not described in detail in this method (not limited to specific technical means and technical effects), reference can be made to the specific descriptions in the aforementioned malware response system based on artificial intelligence, and no further elaboration will be provided in this text.

[0092] Finally, it should be noted that the above are only the preferred embodiments of the present application and are not used to limit the present application. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. An artificial intelligence-based malware response system, characterized in that: include: The data perception module is configured to: collect multi-dimensional environmental data in real time through a distributed sensor network and optimize data acquisition efficiency using an adaptive sampling algorithm; An intelligent analysis module is configured to: perform multi-level semantic analysis on the environmental data based on a hybrid deep learning framework, extract potential threat signals, and generate a dynamic threat map; The risk quantification module is configured to: combine context-aware technology and probabilistic reasoning models to quantitatively evaluate threat signals and output risk levels and impact ranges as risk assessment results; The dynamic defense module is configured to: generate the optimal defense plan through a self-organizing strategy optimization algorithm based on the risk assessment results, and perform defense operations in a distributed manner; and the dynamic defense module is also configured to: automatically evolve the defense strategy through a meta-learning mechanism.

2. The artificial intelligence-based malware response system according to claim 1, characterized in that: The method of optimizing data acquisition efficiency by using an adaptive sampling algorithm specifically includes: dynamically adjusting the sensor sampling frequency through a time series prediction model; wherein the expression of the time series prediction model is: Among them, Fsample is the sampling priority, ωt is the time weight, St is the data value at the tth moment, is the mean of the data.

3. The artificial intelligence-based malware response system according to claim 1, characterized in that: The multi-level semantic parsing specifically includes: extracting spatial features and relational features in environmental data by combining convolutional neural networks with graph neural networks; the attention mechanism used is specifically: Among them, Aatt is the attention weight matrix, Q, K and V are query, key and value matrices respectively, and dk is the dimension of the key vector.

4. The artificial intelligence-based malware response system according to claim 3, characterized in that: The intelligent analysis module is also configured to reduce the feature dimension by performing dimensionality reduction processing on the collected multi-dimensional environmental data.

5. The artificial intelligence-based malware response system according to claim 1, characterized in that: The quantitative evaluation of threat signals specifically includes: capturing the time dependency and causal relationship of threat events by constructing a dynamic Bayesian network.

6. The artificial intelligence-based malware response system according to claim 5, characterized in that: The risk quantification module is also configured to: analyze the user's historical behavior data and dynamically adjust the output risk level of the output.

7. The artificial intelligence-based malware response system according to claim 1, characterized in that: The automatic evolution of defense strategies through a meta-learning mechanism is specifically as follows: learning defense strategies through a reinforcement learning framework, and balancing security and performance overhead through a multi-objective optimization function.

8. The artificial intelligence-based malware response system according to claim 7, characterized in that: The multi-objective optimization function includes optimization of the number of successful threat blocking and optimization of response cost; The optimization of the number of successful threat blocking times specifically includes: constructing a threat event correlation graph, using a graph neural network to perform aggregate analysis on multiple related threat events; the success probability analysis formula used is: Among them, Ri is the risk value of the event, and υi is the weight of the event; The optimization of the response cost specifically includes: using a dynamic cost allocation model to automatically adjust the resource allocation ratio according to the current system operation status and threat level; the dynamic cost allocation model is: Ccost=α·Cresource+β·Cimpact+γ·Crisk Among them, Ccost is the total response cost, Cresource is the resource consumption cost, Cimpact is the business impact cost, Crisk is the security risk cost, and α, β and γ are weight coefficients respectively.

9. The artificial intelligence-based malware response system according to claim 1, characterized in that: The data perception module is also configured to: construct an anomaly detection model based on probability distribution through statistical methods and machine learning technology, and the anomaly detection model is used to monitor and eliminate abnormal data points in real time during the data collection process.

10. An artificial intelligence-based malware response method, applied to the artificial intelligence-based malware response system according to any one of claims 1 to 9, characterized in that: The method comprises the following steps: Collect multi-dimensional environmental data in real time through a distributed sensor network, and use an adaptive sampling algorithm to optimize data acquisition efficiency; Perform multi-level semantic analysis on the environmental data based on a hybrid deep learning framework, extract potential threat signals, and generate a dynamic threat map; Combine context-aware technology and probabilistic reasoning models to quantitatively evaluate threat signals and output risk levels and impact ranges as risk assessment results; According to the risk assessment results, an optimal defense plan is generated through a self-organizing strategy optimization algorithm, and defense operations are performed in a distributed manner; and the dynamic defense module is also configured to automatically evolve the defense strategy through a meta-learning mechanism.

Citation Information

Cited By

  • Anti-monitoring protection method, system and device applied to hotel telephone set

    CN120856825A

  • A method, system and device for preventing eavesdropping applied to a hotel telephone

    CN120856825B

  • Power grid malicious flow detection method and system based on adaptive integration

    CN121309205A

  • A power grid malicious traffic detection method and system based on adaptive integration

    CN121309205B