Security risk early warning system, method and equipment based on real-time information capture

Through a security risk warning system based on real-time information crawling, the problem of insufficient data source integration and dynamic adjustment capabilities in the existing technology is solved, and dynamic integration of multiple data sources and rapid response to risk events is achieved.

CN120163293APending Publication Date: 2025-06-17EXULT TECH COM LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510327640.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

Existing security risk warning systems rely on a single data source, making it difficult to effectively integrate multiple data sources, and lack the ability to automatically adjust in a dynamic environment, resulting in slow response or failure to respond to emergencies.

Method used

Provide a security risk warning system based on real-time information crawling, including information crawling module, information extraction module, prediction module, location integration module, frame selection module and distribution module. Through real-time crawling, key information extraction, risk impact scope prediction, geographical location integration and multi-level warning interval division, dynamic integration and automatic adjustment of multiple data sources can be achieved.

Benefits of technology

It realizes dynamic integration of multiple data sources, improves the accurate positioning of risk event sources and the accuracy of early warning information, and ensures rapid response and effective response to emergencies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120163293A_ABST
    Figure CN120163293A_ABST
Patent Text Reader

Abstract

The invention provides a security risk early warning system, method and device based on real-time information capture, and relates to the technical field of security risk early warning, and the system comprises an information capture module which is used for carrying out the real-time information capture, and obtaining a real-time risk information set; the information extraction module is used for extracting key information to obtain K pieces of risk event metadata; the prediction module is used for carrying out risk influence range prediction to obtain K risk influence ranges; the position integration module is used for carrying out geographic position integration and positioning M fitting risk sources; the frame selection module is used for frame selection of M multi-level early warning intervals; and the distribution module is used for starting M risk early warning distribution containers to carry out safety risk early warning distribution of M fitting risk influence ranges. The technical problem that in the prior art, safety risk early warning is often carried out based on a preset rule or a static model, the capability of automatic adjustment in a dynamic environment is lacked, and response to emergencies is slow or fails is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of security risk early warning, and particularly to a security risk early warning system, method and device based on real-time information capture. Background Art

[0002] Currently, various security risk early warning methods have been widely applied to the prediction and management of natural disasters and social security incidents. For example, meteorological departments capture weather data in real time through satellites and ground meteorological monitoring equipment, and combine historical data to issue early warnings for disasters such as typhoons and heavy rains. Similarly, earthquake monitoring agencies rely on seismic instruments and seismic source data to conduct real-time monitoring of seismic activities and issue early warning information in advance.

[0003] However, most of the existing early warning systems rely on certain specific data sources, such as meteorological data, seismic data, etc. These data sources are often relatively independent and difficult to effectively integrate with data in other fields. Since the occurrence of disasters and risk events is often intertwined with multiple factors, a single data source cannot comprehensively reflect the possible risks, resulting in possible misjudgments or omissions when the early warning system deals with complex and changing disasters. Moreover, the existing risk early warning systems often operate based on predetermined rules or static models and lack the ability to automatically adjust in a dynamic environment. When new information or data sources appear, traditional systems often cannot quickly adapt or adjust, resulting in slow or ineffective responses to emergencies. Summary of the Invention

[0004] This application provides a security risk early warning system, method and device based on real-time information capture, aiming to solve the technical problem that the security risk early warning in the prior art is often based on predetermined rules or static models and lacks the ability to automatically adjust in a dynamic environment, resulting in slow or ineffective responses to emergencies.

[0005] In the first aspect disclosed in this application, a security risk early warning system based on real-time information scraping is provided. The system includes: an information scraping module for scraping real-time information in a specified monitoring area based on a preset scraping content specification to obtain a real-time risk information set; an information extraction module for extracting key information from the real-time risk information set to obtain K risk event metadata; a prediction module for predicting the risk impact range in the specified monitoring area according to the K risk event positions of the K risk event metadata to obtain K risk impact ranges; a location integration module for geographically integrating the K risk impact ranges to locate M fitted risk sources, where the M fitted risk sources have M fitted risk types and M fitted risk impact range identifiers, and M is a positive integer less than K; a bounding module for starting from the M fitted risk sources and bounding M multi-level early warning intervals in the M fitted risk impact ranges according to the M fitted risk types; a distribution module for starting M risk early warning distribution containers according to the M multi-level early warning intervals to perform security risk early warning distribution for the M fitted risk impact ranges.

[0006] In the second aspect disclosed in this application, a security risk early warning method based on real-time information scraping is provided. The method is implemented by the above security risk early warning system based on real-time information scraping. The method includes: scraping real-time information in a specified monitoring area based on a preset scraping content specification to obtain a real-time risk information set; extracting key information from the real-time risk information set to obtain K risk event metadata; predicting the risk impact range in the specified monitoring area according to the K risk event positions of the K risk event metadata to obtain K risk impact ranges; geographically integrating the K risk impact ranges to locate M fitted risk sources, where the M fitted risk sources have M fitted risk types and M fitted risk impact range identifiers, and M is a positive integer less than K; starting from the M fitted risk sources and bounding M multi-level early warning intervals in the M fitted risk impact ranges according to the M fitted risk types; starting M risk early warning distribution containers according to the M multi-level early warning intervals to perform security risk early warning distribution for the M fitted risk impact ranges.

[0007] In the third aspect disclosed in this application, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the steps of the security risk early warning method based on real-time information scraping in the first aspect.

[0008] One or more technical solutions provided in this application have at least the following beneficial effects:

[0009] Real-time information scraping is performed on the specified monitoring area based on a preset content scraping specification, ensuring that the latest risk information can be obtained in a timely manner. This step can dynamically collect real-time data from various sources, providing basic data for subsequent risk analysis and early warning. By extracting key information from the real-time information set, the core data of various risk events can be accurately identified, ensuring that the most relevant and effective information is processed during the analysis, effectively improving the structured degree of the data and the usability of the information. Based on the geographical locations of K risk events, the affected areas can be accurately predicted, providing a spatial basis for subsequent decision-making. This ensures that the early warning information can be accurately sent to the affected areas. By accurately predicting the affected areas, emergency response measures can be better formulated and adjusted, improving the timeliness and effectiveness of the response. By integrating the affected areas of multiple risk events geographically, data from different sources can be combined to accurately locate and fit multiple risk sources. This integration improves the accurate positioning of the risk event sources and provides a clear starting point for subsequent analysis and early warning distribution. By dividing the affected areas of M fitted risk sources into multiple multi-level early warning intervals, grading can be carried out according to the severity and scope of the risks. This grading method can more finely evaluate the impact of risk events, providing customized early warning information for different risk levels of regions and time periods. By starting multiple risk early warning distribution containers to handle different multi-level early warning intervals, it is ensured that the risk early warning information for each region can be distributed in a timely manner according to the priority. Different containers can handle early warnings of different risk levels, improving the distribution efficiency of the early warning tasks.

[0010] The above description is only an overview of the technical solution of this application. In order to understand the technical means of this application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of this application more obvious and understandable, the following specifically gives the specific implementation manners of this application. Brief Description of the Drawings

[0011] Figure 1 It is a schematic structural diagram of a security risk early warning system based on real-time information scraping provided by an embodiment of this application.

[0012] Figure 2 It is a schematic flowchart of a security risk early warning method based on real-time information scraping provided by an embodiment of this application.

[0013] Figure 3 It is a schematic structural diagram of an exemplary computer device provided by an embodiment of this application.

[0014] Explanation of the accompanying drawings: information capture module 10, information extraction module 20, prediction module 30, location integration module 40, box selection module 50, distribution module 60, bus 300, receiver 301 processor 302, transmitter 303, memory 304, bus interface 305. DETAILED DESCRIPTION

[0015] The embodiments of the present application provide a security risk warning system, method and equipment based on real-time information capture, thereby solving the technical problem that the security risk warning in the prior art is often based on predetermined rules or static models, lacks the ability to automatically adjust in a dynamic environment, and leads to slow or ineffective response to emergencies.

[0016] After introducing the basic principles of the present application, various non-limiting implementation methods of the present application will be specifically introduced below in conjunction with the accompanying drawings of the specification. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0017] Embodiment 1, as Figure 1 As shown, the embodiment of the present application provides a security risk early warning system based on real-time information capture, and the system includes:

[0018] The information capture module 10 is used to capture real-time information in a designated monitoring area based on preset capture content specifications to obtain a real-time risk information set.

[0019] The information extraction module 20 is used to extract key information from the real-time risk information set to obtain K risk event metadata.

[0020] The prediction module 30 is used to predict the risk impact range in the designated monitoring area according to the K risk event locations of the K risk event metadata to obtain K risk impact ranges.

[0021] The location integration module 40 is used to integrate the geographical locations of the K risk impact ranges and locate M fitting risk sources, wherein the M fitting risk sources have M fitting risk types and M fitting risk impact range identifiers, and M is a positive integer less than K.

[0022] The selection module 50 is used to select M multi-level warning intervals in the M fitting risk impact ranges based on the M fitting risk types, taking the M fitting risk sources as the starting point.

[0023] The distribution module 60 is used to start M risk warning distribution containers according to the M multi-level warning intervals to distribute the security risk warnings of the M fitting risk impact ranges.

[0024] Furthermore, the information capture module 10 includes:

[0025] A feature extraction unit, configured to perform feature extraction on the historical risk information set of the specified monitoring area based on risk keyword annotation to obtain a multi-source risk keyword feature set.

[0026] A time limit preset unit, configured to preset an information release time limit interval.

[0027] A content specification definition unit, configured to define the crawling content specification based on the information release time limit interval, information source requirements, and multi-source risk keyword feature set, where the crawling content specification includes a multi-source crawling specification.

[0028] A cross-source data crawling unit, configured to perform multi-platform cross-source data crawling on the specified monitoring area based on the multi-source crawling specification to obtain the real-time risk information set, where the real-time risk information set includes multi-source real-time risk information.

[0029] Furthermore, the information extraction module 20 includes:

[0030] A structure preset unit, configured to preset a metadata structure, where the metadata structure includes an event type feature, an event location feature, an event time feature, an event description feature, and a risk level feature.

[0031] A text analysis and extraction unit, configured to perform text analysis and extraction on the multi-source real-time risk information according to the metadata structure by using NLP technology to obtain multiple groups of initial event metadata.

[0032] An aggregation unit, configured to aggregate the multiple groups of initial event metadata based on the event location feature to obtain K groups of initial event metadata.

[0033] A time series screening unit, configured to perform time series screening on the K groups of initial event metadata according to the event time feature and output the K risk event metadata.

[0034] Furthermore, the prediction module 30 includes:

[0035] A risk impact feature analysis unit, configured to analyze the risk impact features of multiple historical risk disaster data obtained through interaction to construct a risk impact prediction network.

[0036] A data formatting extraction unit, configured to perform local geographic data formatting extraction according to the K risk event locations to obtain K risk geographic data.

[0037] A synchronization unit, configured to synchronize the K risk geographic data and the K risk event metadata with the event location feature removed to the risk impact prediction network and output K initial impact ranges.

[0038] A risk impact scope acquisition unit, configured to localize the K initial impact scopes according to the positions of the K risk events, so as to obtain the K risk impact scopes.

[0039] Furthermore, the position integration module 40 includes:

[0040] An intersection analysis unit, configured to perform intersection analysis on the K risk impact scopes based on the consistency of event types, so as to obtain the M fitted risk types and the M fitted risk impact scopes.

[0041] A partitioning unit, configured to partition the K risk event metadata into M groups of risk event metadata according to the M fitted risk impact scopes.

[0042] A risk level replacement unit, configured to perform in-group risk level sorting on the M groups of risk event metadata according to risk levels, and then perform risk level replacement based on risk level extreme values, so as to obtain the M fitted risk levels of the M fitted risk types.

[0043] A trend fitting unit, configured to perform in-group risk evolution trend fitting on the M groups of risk event metadata according to risk levels, and locate M risk evolution starting points.

[0044] An information collection unit, configured to collect risk source information from the real-time risk information set according to the M risk evolution starting points, and locate the M fitted risk sources.

[0045] Furthermore, the feature extraction unit includes:

[0046] A historical risk information set calling channel, configured to call the historical risk information set of the specified monitoring area through the network.

[0047] A historical risk information set splitting channel, configured to split the historical risk information set into a multi-source risk information set according to information source requirements.

[0048] A risk keyword annotation channel, configured to perform risk keyword annotation on the multi-source risk information set, so as to obtain a multi-source risk keyword data set.

[0049] A data set aggregation channel, configured to aggregate the multi-source risk keyword data set, so as to obtain a multi-source risk keyword feature set.

[0050] Furthermore, the risk impact feature analysis unit includes:

[0051] The networked data acquisition channel is used to perform networked data acquisition according to the topographic and geomorphic composition of the specified monitoring area, and obtain the multiple historical risk disaster data, where the historical risk disaster data includes historical event types, historical event locations, historical influence ranges, and historical risk levels.

[0052] The formatted extraction channel is used to perform geographical data formatted extraction according to multiple historical event locations in the multiple historical risk disaster data, and obtain multiple historical geographical data.

[0053] The prediction network construction channel is used to use the multiple historical geographical data and multiple historical risk disaster data as training data to construct a risk impact prediction network with a CNN network structure.

[0054] Furthermore, the distribution module 60 includes:

[0055] The first allocation unit is used to allocate a first risk warning distribution container to the first multi-level warning interval, where the first risk warning distribution container includes multiple warning distribution task units.

[0056] The second allocation unit is used to decompose the first multi-level warning interval into W first warning intervals, and then call and allocate W warning distribution task units from the multiple warning distribution task units for the W first warning intervals.

[0057] The third allocation unit is used to allocate W distribution execution computing resources to the W warning distribution task units according to the straight-line distance between the first fitting risk source of the first multi-level warning interval and the W first warning intervals.

[0058] The first security risk warning distribution unit is used to use the W distribution execution computing resources to run the W warning distribution task units to perform security risk warning distribution for the first fitting risk impact range.

[0059] The second security risk warning distribution unit is used to, by analogy, start the M risk warning distribution containers according to the M multi-level warning intervals to perform security risk warning distribution for the M fitting risk impact ranges.

[0060] Through the subsequent detailed description of the security risk warning method based on real-time information scraping in this specification, those skilled in the art can clearly know the security risk warning system based on real-time information scraping in this embodiment. Since it corresponds to the method disclosed in the embodiment, it is described relatively simply. For related parts, refer to the description in the method part.

[0061] Embodiment 2, based on the same inventive concept as the security risk warning system based on real-time information scraping in the foregoing embodiment, as Figure 2As shown in the figure, the embodiment of the present application provides a security risk warning method based on real-time information scraping, and the method includes:

[0062] Based on a preset scraping content specification, perform real-time information scraping on a specified monitoring area to obtain a real-time risk information set.

[0063] Before starting the scraping, preset the scraping content specification according to actual needs. This specification defines the specific requirements of the scraping process, such as the type, format, timeliness, etc. of the scraped information, specifically including the keywords and content scope to be scraped, the requirements for scraping platforms and sources, the timeliness requirements, etc. The specified monitoring area is the geographical area to be monitored, which may be a city or other specific area, and the scraping process will specifically operate on the information within this area.

[0064] Based on the preset scraping content specification, perform real-time information scraping on the specified monitoring area. Real-time means continuously scraping and updating data to ensure that the latest risk-related information is scraped. The scraping result forms a real-time risk information set, which contains all the information related to the current risk. These information include news reports, social media posts, meteorological warnings, etc.

[0065] Extract K risk event metadata by extracting key information from the real-time risk information set.

[0066] Extract the key information related to the risk event from the real-time risk information set. This process usually uses natural language processing technology to identify the core information related to the risk event. The specific key information includes event type, event location, event time, event description, risk level, etc. Specifically, use natural language processing technology to analyze the scraped text. Through text analysis tools, structured information can be extracted from a large amount of unstructured text data to generate metadata about the event.

[0067] After extracting the preliminary key information, aggregate the information from multiple sources according to the location information of the event, such as the city name or coordinates, to ensure that the key information of each event comes from multiple reliable sources, thereby increasing the accuracy. At the same time, filter according to the time when the event occurs to ensure the timeliness and relevance of the information. After the above analysis and aggregation, finally obtain K risk event metadata, and each metadata contains the key information of the event.

[0068] According to the K risk event locations of the K risk event metadata, predict the risk impact range in the specified monitoring area to obtain K risk impact ranges.

[0069] To predict the impact scope of risk events, by analyzing historical risk data, typical impact patterns of different types of risk events are identified. These historical data include information such as the impact scope, geographical location where the events occurred, and the severity of the events of past similar risk events. Through learning the historical risk data, a prediction network is established to help infer the impact scope of each new event.

[0070] According to the locations of K risk events, relevant geographical data are extracted from the geographical information system, such as the longitude and latitude of a certain city, or the boundary data of a specific area. Based on these geographical data and the characteristics of the events, the potential impact scopes of these risk events are predicted through the prediction network, and K initially predicted risk impact scopes are output. Each risk event corresponds to an impact scope, which is calculated according to the location of the event and the impact pattern of the historical data.

[0071] Geographical location integration is performed on the K risk impact scopes to locate M fitted risk sources. Among them, the M fitted risk sources have M fitted risk types and M fitted risk impact scope identifiers, and M is a positive integer less than K.

[0072] After obtaining the K risk impact scopes, through geographical location integration technology, the overlapping areas and their distribution rules of these impact scopes are analyzed. Specifically, intersection analysis is performed on different impact scopes to find possible correlations between multiple risk events. In this way, event sets with similar risk types or similar impact patterns can be identified. If the impact scopes of multiple risk events are close or overlapping, they are merged into a larger or more representative risk source, which can be completed through a spatial clustering algorithm.

[0073] By integrating the K risk impact scopes, M fitted risk sources are located. M is a positive integer less than K, which means that when dealing with multiple risk events, fewer, more concentrated and representative risk sources are extracted from them. These fitted risk sources represent the concentrated areas of multiple risk events in the monitoring area, usually a fitted point or area formed after multiple events are merged geospatially. Each fitted risk source represents the comprehensive risk in a specific area.

[0074] Each fitted risk source corresponds to a fitted risk type, which can be determined according to the characteristics of multiple risk events related to it, such as natural disasters, social conflicts, etc.; according to the impact scopes of multiple risk events, a comprehensive fitted risk impact scope is also defined for each fitted risk source, and this impact scope can be the combination or weighted average of the impact scopes of all relevant events.

[0075] Starting from the M fitted risk sources, M multi-level early warning intervals are selected within the M fitted risk influence scopes according to the M fitted risk types.

[0076] Starting from the M fitted risk sources, according to the risk types and risk influence scopes of each fitted risk source, multiple early warning intervals are defined. These intervals can be divided into different levels. For example, high-risk areas, which are the closest to the risk sources and may be affected most severely, are defined as high-risk early warning areas; medium-risk areas, which are less affected but still have certain risks, are defined as medium-risk early warning areas; low-risk areas, which are farther from the risk sources and are relatively less affected, but still require low-risk warnings. The definition of these early warning intervals is based on the prediction of the influence scope, combined with the different requirements of risk types, to delimit different safety boundaries. The risk levels within each area are set according to their proximity to the risk source and the influence of similar events in historical data.

[0077] Among them, the system supports the function of reminding relatives and friends. Users can allow family members or friends to view their current locations in real time, and when the user approaches a risk area, they will automatically receive graded reminders synchronously. This function helps the relatives and friends of the user to master their locations in real time and take necessary preventive measures in advance, especially within high-risk areas.

[0078] According to the M multi-level early warning intervals, M risk early warning distribution containers are activated to conduct safety risk early warning distribution for the M fitted risk influence scopes.

[0079] For each fitted risk source and its corresponding multi-level early warning interval, a corresponding risk early warning distribution container is activated. Each distribution container is responsible for sending the risk early warning information related to it to the designated users. The activation of each distribution container is based on the pre-defined multi-level early warning intervals. According to the early warning level, regional scope, and user settings, the distribution container will adjust the sent early warning content. For example, within a high-risk area, the distribution container will immediately issue a strong alarm to prompt the user that they may face serious danger.

[0080] Each early warning distribution container will distribute risk early warnings to target users according to the pre-set multi-level intervals. The user's device will receive risk information for the area where they are located. The distribution of early warning information is customized according to different levels of risk. Users in high-risk areas will receive emergency notifications, such as through text messages, APP push notifications, or emergency alarm broadcasts, while users in medium- and low-risk areas may only receive reminder notifications to remind them to stay vigilant.

[0081] For the user-customized reminder function for relatives and friends, the system will also send synchronized risk warnings to the specified relatives and friends according to the permissions set by the user. In this way, when the user enters a high-risk area, the relatives and friends will receive relevant warning information to help them get prepared. Through the reminder function for relatives and friends, the user's relatives and friends can also obtain warning information in real time to jointly cope with potential risks.

[0082] Furthermore, based on the preset content scraping specifications, real-time information is scraped from the specified monitoring area to obtain a real-time risk information set. The method includes:

[0083] Feature extraction is performed on the historical risk information set of the specified monitoring area based on risk keyword annotation to obtain a multi-source risk keyword feature set; a preset information release time range is set; based on the information release time range, information source requirements, and multi-source risk keyword feature set, the content scraping specifications are defined, where the content scraping specifications include multi-source scraping specifications; multi-platform cross-source data scraping is performed on the specified monitoring area based on the multi-source scraping specifications to obtain the real-time risk information set, where the real-time risk information set includes multi-source real-time risk information.

[0084] Define keywords related to risks, which include natural disasters, social risks, or other security threats, etc. For the convenience of subsequent automatic scraping and analysis of data, keyword annotation needs to be performed on historical information. Keyword annotation refers to marking each historical information with the risk-related vocabulary associated with it, so that content related to risks can be quickly identified during subsequent scraping.

[0085] By analyzing each piece of information in the historical risk information set of the specified monitoring area, features related to risk events are extracted. The feature extraction process usually uses natural language processing technology. The extracted features include event type, location, time, severity, etc. By extracting these features, a multi-source risk keyword feature set is formed, which contains key information extracted from multiple information sources (such as news websites, social media, meteorological agencies, etc.). These features will provide a reference for subsequent real-time information scraping to ensure that the scraped content is consistent with the identification of risk events.

[0086] Preset the information release time range. The information release time range refers to the validity period of the information after it is released. For example, the immediate information after certain events occur may be more relevant than the information from several hours or days ago. Therefore, the time range helps the system screen out currently valid and timely information. The definition of the time range helps reduce the scraping of outdated information and ensures that the scraped real-time risk information has high timeliness.

[0087] The information source requirements are the normative requirements for the sources during the system's crawling process. This includes which platforms can serve as information sources, such as news websites, social media, public safety platforms, etc., and what types of information these platforms should provide, such as news reports, real-time updates, alerts or warnings, etc. This requirement ensures that the system collects information from multiple reliable and timely channels, avoiding one-sidedness or delay of information.

[0088] According to the above timeliness, source requirements, and keyword feature sets, define the crawling content specifications. The crawling content specifications include multi-source crawling specifications, that is, it is stipulated that the system crawls from multiple different sources to ensure the comprehensiveness of the information obtained, covering data from different sources and avoiding possible biases from a single source.

[0089] Based on the defined crawling content specifications, initiate data crawling across multiple platforms, including news websites, social media, public safety warning platforms, etc. By crawling data from multiple different platforms, it is possible to comprehensively obtain risk-related information, avoiding information lag or omission caused by relying on a single platform. During the data crawling process, filter out the information containing the preset keywords according to the specifications and summarize them to form a real-time risk information set. These information sets contain data from multiple sources, including but not limited to information from news reports, social media dynamics, and alert platforms, covering different types of risk information, such as natural disasters, social security, environmental hazards, etc.

[0090] Furthermore, by extracting key information from the real-time risk information set, K risk event metadata are obtained. The method includes:

[0091] Preset the metadata structure, where the metadata structure includes event type features, event location features, event time features, event description features, and risk level features; according to the metadata structure, use NLP technology to perform text analysis and extraction on the multi-source real-time risk information to obtain multiple groups of initial event metadata; aggregate the multiple groups of initial event metadata based on the event location features to obtain K groups of initial event metadata; perform chronological screening on the K groups of initial event metadata according to the event time features and output the K risk event metadata.

[0092] Define a standard metadata structure for risk events to facilitate subsequent processing and analysis of multi-source real-time risk information. Among them, the event type feature defines the category of risk events. For example, natural disasters such as floods, earthquakes, typhoons, etc., as well as social risks and public health events. The event type helps to initially classify risks for subsequent processing and analysis; the event location feature describes the geographical location where the event occurred, which can be a specific city, region, geographical coordinates, etc.; the event time feature defines the time point or time period when the event occurred, and the time feature helps to evaluate the timeliness of the event; the event description feature is a short description of the event occurrence, usually including the nature of the event, development situation, and possible impacts. For example, the cause of the flood, the affected areas, the current severity, etc.; the risk level feature defines the risk level of the event, usually represented by numbers or letters. For example, the danger level of the event is marked by numerical levels from level 1 to level 5.

[0093] In the real-time risk information set, the vast majority of information exists in the form of unstructured text. For example, news reports, social media dynamics, warning information, etc. To parse this text and extract key information, NLP (Natural Language Processing) technology is needed. NLP technology can help the system identify key event features from the text, including event type, location, time, etc. Specifically, through the named entity recognition technology in NLP, geographical locations, event types, and dates and times in the text are automatically recognized, and this information will be extracted and used as part of the metadata; through the classification analysis of the text content, it is identified which category the event belongs to, such as natural disasters, social events, etc., and the event type feature is marked in the metadata according to the analysis results; for the text describing the severity or risk of the event, sentiment analysis technology can also be used to evaluate its risk level. For example, if words such as "major" and "catastrophic" are mentioned in the description, it can be judged that the event belongs to the high-risk level.

[0094] By performing text analysis on each piece of information, extracting key information related to the event, and converting it into a format that conforms to the preset metadata structure, each information block constitutes an initial event metadata. In multi-source real-time risk information, each piece of information corresponds to multiple events. Therefore, multiple sets of event metadata are extracted from multiple information sources, and each event metadata corresponds to a specific risk event. These metadata will serve as the basis for subsequent analysis and processing.

[0095] The initial event metadata contains risk events from different sources and at different times. Each event has its corresponding geographical location characteristics. However, many events may occur in the same or adjacent geographical regions. To reduce redundancy, it is necessary to aggregate these events based on their location characteristics. For example, if multiple risk events occur in the same city or region, these events are classified into the same group. Each group of data will contain all the relevant risk event information that occurred at that location. The aggregation process helps eliminate duplicate information and irrelevant content, bringing together the risk events within the same geographical region. This can reduce the amount of data and improve the efficiency of subsequent analysis and processing. The result of aggregation is to group the events according to their location characteristics, thus obtaining K groups of initial event metadata. Each group of data represents multiple risk events within a specific geographical region, and these events share similar location characteristics.

[0096] Each risk event has a timestamp indicating the time of occurrence. Due to the strong timeliness of risk events, it is necessary to filter out the most relevant risk events based on time characteristics to ensure that the early warning system responds based on the latest and most reliable information. Temporal filtering ensures that among multiple events in the same geographical region, the most recently occurred event is given priority. Especially in high-risk areas, the most recent events often better reflect the current risk situation. Therefore, these events are considered the most credible and influential.

[0097] Set a time window, such as the most recent 24 hours, 48 hours, etc., to filter out the events that meet the time requirements. All events whose time exceeds this window will be considered outdated and thus excluded. For the K groups of aggregated event metadata, filter the risk events at each location. For multiple events at the same location, compare their occurrence times and select the most recently occurred event as the most credible event. If multiple events at a certain location occur within a similar time period, select the event closest to the current time based on the event timestamp as the main reference. After temporal filtering, output K risk event metadata. Each metadata contains the key information of the event, such as event type, time, location, description, and risk level, etc. These events are sorted based on the latest time and can represent the most relevant and credible risk events at present. These K filtered risk event metadata will serve as the data basis for subsequent analysis, prediction, early warning distribution, and other processes.

[0098] Furthermore, based on the K risk event locations of the K risk event metadata, predict the risk impact scope in the specified monitoring area to obtain K risk impact scopes. The method includes:

[0099] A risk impact prediction network is constructed by analyzing the risk impact characteristics of multiple historical risk disaster data obtained interactively; local geographic data is formatted and extracted according to the K risk event locations to obtain K risk geographic data; the K risk geographic data and the K risk event metadata with event location characteristics removed are synchronized to the risk impact prediction network, and K initial impact ranges are output; the K initial impact ranges are localized according to the K risk event locations to obtain the K risk impact ranges.

[0100] Multiple historical risk and disaster data are interactively obtained from multiple data sources, such as historical disaster records, public safety databases, meteorological warning systems, etc. These data include different types of risk events, such as natural disasters, social risks, etc. These data contain key information such as the type, location, time, scope of impact, intensity of occurrence, and loss of the event.

[0101] In order to accurately predict the impact of future risk events, we first analyze historical data and extract risk impact characteristics, including impact range, event type, spatiotemporal distribution, post-disaster impact, etc. By analyzing these impact characteristics, we can identify the different impact patterns of various risk events on the region.

[0102] Based on the extracted risk impact characteristics, a prediction network is trained. This prediction network can be constructed using machine learning algorithms, such as deep learning and neural networks. The model is trained with historical data so that it can predict the future impact range based on new risk events. The prediction network can not only make predictions based on historical data, but also combine real-time geographic information and event data to provide more accurate prediction results. The output of the trained risk impact prediction network is a prediction of the impact range of future risk events, which helps to respond to potential risks in a timely manner.

[0103] Each risk event has a clear geographical location feature, which can be the city or region where the event occurs, or more accurately, the specific longitude and latitude coordinates. In order to further analyze the geographical impact of these events, it is necessary to extract relevant local geographic data from the geographic information system and format the extracted local geographic data so that it can be used in combination with other data. After formatting, K risk geographic data are obtained, and each data contains geographic information related to the event.

[0104] The metadata of risk events includes information such as event type, location, time, description, etc., from which the event location features are excluded. Because the geographic location data has been extracted and formatted in the risk geographic data, the duplication of location features may affect the accuracy of the prediction. The risk geographic data includes the specific geographic location characteristics of the event. These data together describe the overall picture of the risk event and help the prediction model make more accurate estimates of the scope of impact.

[0105] The processed risk geographical data and event metadata are synchronously input into a risk impact prediction network. Based on the input data and combined with the existing impact patterns in historical data, this network calculates the possible impacts of each event on the surrounding areas and outputs K initial impact ranges. Each impact range corresponds to a specific risk event. This initial impact range is a region calculated through a prediction model based on characteristics such as the type, time, and geographical location of the event, indicating the possible impacts of the event on this region.

[0106] The initial impact range is the prediction result output by the prediction network. However, this predicted range does not fully consider the actual geographical environment and other local factors. Therefore, at this step, local adjustment is performed on the predicted impact range. Local adjustment refers to modifying the impact range according to the particularities of a specific region, such as terrain, climate, infrastructure, etc. For example, if the prediction model shows that the flood impact range is very wide, but certain geographical features, such as mountains and rivers, may limit the impact range, then the boundaries of the impact range will be adjusted accordingly. During the localization process, the actual geographical information is combined to adjust the risk impact range. After local adjustment, the K initial impact ranges will become more accurate, and the finally obtained K risk impact ranges have higher credibility and adaptability.

[0107] Furthermore, geographical location integration is performed on the K risk impact ranges to locate M fitted risk sources. The method includes:

[0108] Based on the consistency of event types, intersection analysis is performed on the K risk impact ranges to obtain the M fitted risk types and M fitted risk impact ranges; the K event metadata are divided into M groups of event metadata according to the M fitted risk impact ranges; after performing in-group risk level ranking on the M groups of event metadata according to the risk level, risk level replacement is performed based on the extreme values of the risk levels to obtain the M fitted risk levels of the M fitted risk types; in-group risk evolution trend fitting is performed on the M groups of event metadata according to the risk level to locate M risk evolution starting points; risk source information collection is performed in the real-time risk information set according to the M risk evolution starting points to locate the M fitted risk sources.

[0109] Each risk event has its specific type, such as flood, earthquake, fire, etc. These types have different characteristics, impact patterns, and response measures. In this step, it is necessary to identify the consistency of risk event types, ensure that similar types of events are classified and merged. Based on the analysis of historical data and the actual characteristics of the events, an intersection analysis is conducted on the K risk impact ranges. This means that the impact ranges of risk events of the same type are calculated for their intersection to determine their overlapping parts, so as to better evaluate the impact range of risk types. Intersection analysis refers to comparing and superimposing the impact ranges of multiple risk events. For example, if two flood events occur in the same area, the intersection of the impact ranges of these flood events is calculated to find the common impact area of these events. Through this intersection analysis, a more accurate set of impact ranges can be obtained, and these impact ranges represent the cumulative impact generated by risk events of the same type.

[0110] After the intersection analysis, based on the overlapping parts of the impact ranges, M fitted risk types are obtained. These fitted risk types are generated based on the intersection analysis results of different event types. For example, the intersection of multiple flood and rainstorm events may form a new fitted risk type, representing a flood-rainstorm hybrid risk. Each fitted risk type is associated with a fitted impact range, indicating the comprehensive impact that this type of risk event may have on a certain area. This range reflects the combined impact of multiple similar events in this area, which is more representative than the impact range of a single event and can provide more accurate disaster prediction and response strategies.

[0111] Compare the specific impact ranges of the K risk events and match them with the M fitted risk impact ranges. If the impact range of an event highly overlaps with the fitted risk impact range, then the event is classified into the corresponding group. Finally, the K risk event metadata are divided into M groups according to the fitted risk types and impact ranges, obtaining M groups of risk event metadata, and each group of data represents a specific risk type and its related risk events.

[0112] For the M groups of risk event metadata, the events are sorted according to their risk levels within the group. Each event is assigned a risk level based on factors such as its specific impact range, event type, occurrence intensity, etc. For example, the risk levels of events may be classified as low, medium, high, or extremely high, etc. The sorted risk levels reflect the relative risk magnitudes of each event within each group. Events with higher risk levels will be ranked in the front, and events with lower risks will be ranked behind.

[0113] Replace based on the extreme value (here it is the maximum value) of the risk level. The meaning of extreme value replacement is that for each group of risk events, the event with the highest risk level among all events within the group is taken as the representative risk level of the group. This replacement ensures that the risk level of each fitted risk type is determined by the most severe event within the group, thereby providing the highest risk assessment for this risk type, which can better reflect the maximum threat that this risk type may bring. Through risk level ranking and extreme value replacement, each fitted risk type will obtain a final risk level, and these fitted risk levels represent the severity of each risk type and will be used for formulating subsequent risk response strategies.

[0114] The impact of risk events is usually not static but evolves over time. Risk events may become more severe or weaken over time. Therefore, it is necessary to fit the risk evolution trend of each risk event. Evolution trend fitting is to model the change in the risk level of each event in the time dimension. For example, identify whether a certain risk event shows a gradually increasing trend (such as a typhoon gradually strengthening) or a gradually weakening trend (such as aftershocks gradually decreasing after an earthquake). For each event, identify its change in risk intensity and predict the possible evolution direction of this risk event in the next few days or hours. If some risk events show a gradually increasing trend, such as hurricanes, floods, etc., these events will be marked as high priority for more efficient response, while those risk events with gradually weakening risks may be marked as low priority.

[0115] Locate M risk evolution starting points according to the fitting results. The risk evolution starting point refers to the time point when a certain risk event begins to show obvious risk changes. By fitting the evolution trend, the evolution starting point of each risk event can be accurately located. This starting point is the key to subsequent decision-making because it marks the critical moment of risk change and usually determines the start time of emergency response or the priority of resource allocation.

[0116] After locating the evolution starting point of each risk event, based on these starting points, enter the real-time risk information set for information collection. The real-time risk information set contains a large amount of real-time data, and extract the information related to the current risk event from it. Through real-time data collection, locate M fitted risk sources. For example, for a gradually strengthening typhoon, its specific origin location, path, and predicted impact area can be determined, so as to provide detailed information for subsequent emergency response.

[0117] Furthermore, based on risk keyword annotation, extract features from the historical risk information set of the specified monitoring area to obtain a multi-source risk keyword feature set. The method includes:

[0118] Invoke the historical risk information set of the specified monitoring area via the network; split the historical risk information set into multi-source risk information sets according to the information source requirements; perform risk keyword annotation on the multi-source risk information sets to obtain a multi-source risk keyword data set; aggregate the multi-source risk keyword data set to obtain the multi-source risk keyword feature set.

[0119] Connect to relevant real-time data sources, such as meteorological bureaus, disaster monitoring agencies, public safety systems, etc. Collect historical risk event data of the specified monitoring area through these systems, covering aspects such as natural disasters, public safety events, and social conflicts. The historical risk information set is a collection of historical risk events in this area, and the data content includes information such as event type, occurrence time, location, impact scope, and losses caused. This information set provides necessary historical information for analyzing and predicting future risk events.

[0120] The historical risk information set contains data from multiple data sources, such as meteorological data, earthquake data, social conflict data, etc. The format, content, and focus of each data source may be different. Therefore, these data need to be split into multiple subsets. The splitting standard is based on the information source requirements. For example, data from the meteorological department contains information about natural disasters such as typhoons and floods; data from earthquake monitoring stations includes information such as earthquake epicenters and magnitudes. After splitting, each subset of data will be organized by source for subsequent processing and analysis. Finally, the historical risk information set will be split into multi-source risk information sets, and each subset contains data from a specific source. The purpose of doing this is to facilitate subsequent specialized processing and feature extraction for data from different sources.

[0121] Perform risk keyword annotation on the multi-source risk information sets. The content of the annotation is keywords related to this data. These keywords can be related to risk types, impact degrees, disaster scopes, etc. For example, risk keywords in meteorological data include typhoons, heavy rains, tropical storms, etc.; keywords in earthquake data include epicenters, magnitudes, aftershocks, etc. By annotating keywords for each data source, a multi-source risk keyword data set containing all important information is obtained. Each data set contains relevant keywords in the source data, and these keywords will be annotated as specific risk events or attributes.

[0122] Aggregate the multi-source risk keyword data set. The aggregation process is to merge the keywords in the data from all sources, remove redundant and duplicate content, and form a comprehensive multi-source risk keyword feature set. These feature sets include keywords related to all types of risks, providing comprehensive information for subsequent risk analysis.

[0123] Furthermore, by performing a risk impact feature analysis on multiple historical risk disaster data obtained through interactions, a risk impact prediction network is constructed. The method includes:

[0124] Collect networked data according to the topographical and geomorphic composition of the specified monitoring area to obtain the multiple historical risk disaster data. Among them, the historical risk disaster data includes historical event types, historical event locations, historical impact ranges, and historical risk levels; perform formatted extraction of geographical data based on multiple historical event locations in the multiple historical risk disaster data to obtain multiple historical geographical data; use the multiple historical geographical data and multiple historical risk disaster data as training data to construct a risk impact prediction network with a CNN network structure.

[0125] The topographical and geomorphic composition of each region has a direct impact on the occurrence and impact of risk events. For example, mountainous areas may be more prone to landslides or earthquakes, while coastal areas may face disasters such as typhoons and tsunamis. According to the topographical and geomorphic composition characteristics of the specified monitoring area, determine which historical data need to be collected. These geographical features will help analyze the occurrence pattern of disaster events and their impact degree. By accessing relevant historical risk disaster data through the network, these data come from meteorological departments, earthquake bureaus, disaster emergency management agencies, etc. The data content includes historical event types, such as floods, typhoons, earthquakes, etc.; historical event locations, such as geographical coordinates; historical impact ranges, that is, the coverage area of the disaster; historical risk levels, that is, the severity of the event.

[0126] The multiple historical risk disaster data contains multiple event locations, such as cities, regions, longitude and latitude, etc. Format these location data so that they can be used together with other types of data, such as risk levels, event types, etc., for analysis. The formatting process includes converting the location data into a standard geographical coordinate system or other applicable geographical information system formats, so that these data can be conveniently processed and analyzed. The multiple historical geographical data obtained after formatting contains the specific locations and geographical features of each historical event. These geographical data will be used as inputs for subsequent risk analysis and prediction to evaluate the risk impacts in different geographical regions.

[0127] Combine historical risk disaster data with formatted geographical data to construct a risk impact prediction network based on a CNN network (Convolutional Neural Network) for risk assessment. Specifically, the CNN network is a deep learning model widely used in fields such as image recognition and speech processing. Here, the CNN is used to process and analyze the combination of historical risk disaster data and geographical data to predict future risk impacts. Input the historical risk disaster data and historical geographical data as training data into the CNN network. In this way, the model will be able to learn the relationship between disaster events and the geographical environment, thereby improving the accuracy of prediction. Obtain a risk impact prediction model through training. This model can analyze the patterns in historical data and predict the impacts that future risk events may have on specific regions. The trained network will be able to perform risk predictions based on new input data.

[0128] Furthermore, start M risk warning distribution containers according to the M multi-level warning intervals for safety risk warning distribution of the M fitted risk impact ranges. The method includes:

[0129] Allocate a first risk warning distribution container to the first multi-level warning interval. Among them, the first risk warning distribution container includes multiple warning distribution task units; after decomposing the first multi-level warning interval into W first warning intervals, allocate W warning distribution task units for the W first warning intervals by invoking from the multiple warning distribution task units; according to the straight-line distances between the first fitted risk sources of the first multi-level warning interval and the W first warning intervals, allocate W distribution execution computing resources to the W warning distribution task units; use the W distribution execution computing resources to run the W warning distribution task units to perform safety risk warning distribution for the first fitted risk impact range; and so on, start the M risk warning distribution containers according to the M multi-level warning intervals for safety risk warning distribution of the M fitted risk impact ranges.

[0130] The first multi-level warning interval is any one of the M multi-level warning intervals, and these intervals represent different risk levels or event impact ranges. For example, they are divided into high-risk, medium-risk, and low-risk intervals. The first risk warning distribution container is a container structure used to manage and distribute different warning tasks. The container contains multiple warning distribution task units, and each task unit is responsible for processing and distributing specific warning information. The task unit is a specific module for publishing, notifying, or reporting warning information for different warning intervals. Each task unit will perform corresponding warning distribution operations according to different warning interval types. For example, some task units are responsible for transmitting warning information for high-risk intervals, while other task units are responsible for low-risk intervals. This helps ensure that different types of warning information can be conveyed to relevant personnel or systems in a timely and accurate manner.

[0131] The first multi - level warning interval is decomposed into multiple more specific sub - intervals, usually based on more detailed risk assessment results or geographical area divisions. For example, a high - risk area is further subdivided into different small areas, or the warning interval is divided into multiple shorter time periods according to time. Through decomposition, different risk areas and times can be monitored and warned more precisely. After decomposition, W first - level warning intervals are obtained, and each warning interval is divided based on more detailed risk assessment and geographical or time characteristics, with higher precision.

[0132] For the W first - level warning intervals obtained by decomposition, W corresponding warning distribution task units are called and assigned from multiple warning distribution task units. These task units will be responsible for handling tasks related to specific warning intervals, such as issuing warning notices, notifying relevant departments or personnel, triggering emergency responses, etc. Each task unit is only responsible for one specific warning interval, so the task assignment and execution will be more targeted and flexible.

[0133] Calculate the straight - line distance between the first - fitted risk source and the W first - level warning intervals. The straight - line distance reflects the spatial relationship between the risk source and each warning interval. This distance is very important when allocating computing resources because it can help the system decide how to optimize the task execution order and resource allocation. Warning intervals with a shorter distance may require more computing resources to ensure a quick response, while those with a longer distance may require fewer resources. According to the calculated straight - line distance, appropriate computing power resources are allocated to each warning distribution task unit, and W distributed execution computing power resources are obtained after allocation.

[0134] Using the allocated computing power resources, run the W warning distribution task units. These task units will process specific warning interval data and execute relevant warning tasks according to their respective allocated resources. The core task of these task units is to distribute the safety risk warning for the influence range of the first - fitted risk. Specifically, according to the first - fitted risk source and its influence range, send information such as alarms, notices, and emergency response suggestions to relevant personnel, departments, or systems. The warning distribution process may include multi - channel notifications, such as text messages, phone calls, emails, social media platforms, emergency command systems, etc., to ensure that all parties can obtain risk information in a timely manner.

[0135] For the M multi - level warning intervals, repeat the above process, respectively start the corresponding warning distribution containers. Each container also contains multiple task units, which will be responsible for handling all risk warning information related to that interval. After starting, the warning distribution containers will, through the corresponding task units, conduct warning distribution for different fitted risk influence ranges. These warning distributions cover different regions and risk levels to ensure that each region can receive the latest risk warning information in a timely manner.

[0136] Furthermore, for the areas where early warning risks have been distributed, hourly information monitoring will be initiated to analyze the latest local information in real time. Once it is analyzed and determined that the risk has been lifted, the risk warning for that area will be immediately removed. This ensures the dynamic and real-time nature of risk warnings, enabling warning information to promptly reflect the current real risk situation.

[0137] Specifically, the removal of risk warnings will automatically judge the risk removal according to preset removal conditions, such as the disappearance of risk factors, the improvement of environmental conditions, etc. When the removal conditions are met, the marked status of the risk warning area will be automatically updated, the risk warning distribution for that area will be stopped, and relevant users and departments will be notified to avoid unnecessary panic and resource waste.

[0138] In summary, the security risk warning method based on real-time information scraping provided by the embodiments of this application has the following technical effects:

[0139] Real-time information scraping is performed on the specified monitoring area based on the preset scraping content specifications, ensuring that the latest risk information can be obtained in a timely manner. This step can dynamically collect real-time data from various sources, providing basic data for subsequent risk analysis and warning; by extracting key information from the real-time information set, the core data of various risk events can be accurately identified, ensuring that the most relevant and effective information is processed during the analysis process, effectively improving the structured degree of data and the usability of information; based on the geographical locations of K risk events, the affected ranges are predicted, enabling the accurate identification of the areas that each risk event may affect, providing a spatial basis for subsequent decision-making. This ensures that warning information can be accurately sent to the affected areas, and by accurately predicting the affected range, emergency response measures can be better formulated and adjusted, improving the timeliness and effectiveness of the response; through the geographical location integration of the affected ranges of multiple risk events, data from different sources can be combined to accurately locate and fit multiple risk sources. This integration improves the accurate positioning of risk event sources and provides a clear starting point for subsequent analysis and warning distribution; by dividing the affected ranges of M fitted risk sources into multiple multi-level warning intervals, grading can be performed according to the severity and scope of the risk. This grading method can more finely evaluate the impact of risk events, providing customized warning information for different risk-level areas and time periods; by starting multiple risk warning distribution containers to handle different multi-level warning intervals, it is ensured that the risk warning information for each area can be distributed in a timely manner according to the priority. Different containers can handle warnings of different risk levels, improving the distribution efficiency of warning tasks.

[0140] Embodiment 3, as Figure 3 shown, is a schematic structural diagram of an exemplary computer device of this application. InFigure 3 Among them, the bus architecture is represented by bus 300. Bus 300 may include any number of interconnected buses and bridges. Bus 300 connects various circuits of one or more processors represented by processor 302 and memory represented by memory 304 together. Bus 300 may also connect various other circuits together, such as peripheral devices, voltage regulators, and power management circuits, etc., which are well known in the art. Therefore, they will not be further described herein. Bus interface 305 provides an interface between bus 300 and receiver 301 and transmitter 303. Receiver 301 and transmitter 303 may be the same element, i.e., a transceiver, providing a unit for communicating with various other devices on the transmission medium. Processor 302 is responsible for managing bus 300 and general processing, while memory 304 may be used to store data used by processor 302 when performing operations.

[0141] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0142] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to these embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A security risk early warning system based on real-time information capture, characterized by: The system comprises: The information capture module is used to capture real-time information in the designated monitoring area based on the preset capture content specifications to obtain a real-time risk information set; An information extraction module, configured to extract key information from the real-time risk information set to obtain K risk event metadata; A prediction module, configured to predict the risk impact range in the designated monitoring area according to the K risk event locations of the K risk event metadata, to obtain K risk impact ranges; A location integration module is used to integrate the geographical locations of the K risk impact ranges and locate M fitting risk sources, wherein the M fitting risk sources have M fitting risk types and M fitting risk impact range identifiers, and M is a positive integer less than K; A selection module is used to select M multi-level warning intervals in the M fitting risk impact ranges based on the M fitting risk types, taking the M fitting risk sources as the starting point; A distribution module is used to start M risk warning distribution containers according to the M multi-level warning intervals to distribute security risk warnings of the M fitting risk impact ranges.

2. The security risk early warning system based on real-time information capture as claimed in claim 1, characterized in that: The information capture module includes: A feature extraction unit, used for extracting features from the historical risk information set of the designated monitoring area based on the risk keyword annotations to obtain a multi-source risk keyword feature set; A time limit preset unit is used to preset the time limit for information release; A content specification definition unit, used to define the crawling content specification based on the information release time interval, information source requirements and multi-source risk keyword feature set, wherein the crawling content specification includes a multi-source crawling specification; A cross-source data capture unit is used to perform multi-platform cross-source data capture on the designated monitoring area based on the multi-source capture specification to obtain the real-time risk information set, wherein the real-time risk information set includes multi-source real-time risk information.

3. The security risk early warning system based on real-time information capture as claimed in claim 2, characterized in that: The information extraction module comprises: A structure presetting unit, used for presetting a metadata structure, wherein the metadata structure includes event type features, event location features, event time features, event description features and risk level features; A text analysis and extraction unit, configured to perform text analysis and extraction on the multi-source real-time risk information using NLP technology according to the metadata structure, to obtain multiple groups of initial event metadata; an aggregation unit, configured to aggregate the multiple groups of initial event metadata based on event location features to obtain K groups of initial event metadata; A time series screening unit is used to perform time series screening on the K groups of initial event metadata according to event time characteristics, and output the K risk event metadata.

4. The security risk early warning system based on real-time information capture as claimed in claim 1, characterized in that: The prediction module comprises: A risk impact characteristic analysis unit is used to construct a risk impact prediction network by analyzing the risk impact characteristics of multiple historical risk disaster data obtained interactively; A data formatting and extraction unit, used for formatting and extracting local geographic data according to the K risk event locations to obtain K risk geographic data; A synchronization unit, used to synchronize the K risk geographic data and the K risk event metadata excluding event location features to the risk impact prediction network, and output K initial impact ranges; The risk impact range acquisition unit is used to localize the K initial impact ranges according to the K risk event locations to obtain the K risk impact ranges.

5. The security risk early warning system based on real-time information capture as claimed in claim 4, characterized in that: The location integration module includes: An intersection analysis unit, configured to perform an intersection analysis on the K risk impact ranges based on event type consistency to obtain the M fitting risk types and the M fitting risk impact ranges; A division unit, configured to divide the K risk event metadata into M groups of risk event metadata according to the M fitted risk impact ranges; A risk level replacement unit, configured to replace the risk level based on the risk level extreme value after sorting the M groups of risk event metadata by risk level within the group according to the risk level, so as to obtain M fitting risk levels of the M fitting risk types; A trend fitting unit, used to perform risk evolution trend fitting on the M groups of risk event metadata according to the risk levels, and locate M risk evolution starting points; The information collection unit is used to collect risk source information in the real-time risk information set according to the M risk evolution starting points, and locate the M fitting risk sources.

6. The security risk early warning system based on real-time information capture as claimed in claim 2, characterized in that: The feature extraction unit comprises: A historical risk information set calling channel, used for online calling of the historical risk information set of the designated monitoring area; A historical risk information set splitting channel, used to split the historical risk information set into multi-source risk information sets according to information source requirements; A risk keyword labeling channel, used to label the multi-source risk information set with risk keywords to obtain a multi-source risk keyword data set; The data set aggregation channel is used to aggregate the multi-source risk keyword data set to obtain the multi-source risk keyword feature set.

7. The security risk early warning system based on real-time information capture as claimed in claim 4, characterized in that: The risk impact characteristic analysis unit comprises: An online data collection channel is used to collect online data according to the topographical composition of the designated monitoring area to obtain the plurality of historical risk and disaster data, wherein the historical risk and disaster data include historical event types, historical event locations, historical impact ranges, and historical risk levels; A formatted extraction channel is used to format and extract geographic data according to multiple historical event locations in the multiple historical risk and disaster data to obtain multiple historical geographic data; The prediction network construction channel is used to use the multiple historical geographic data and the multiple historical risk and disaster data as training data to construct a risk impact prediction network with a CNN network structure.

8. The security risk early warning system based on real-time information capture as claimed in claim 1, characterized in that: The distribution module comprises: A first allocation unit, configured to allocate a first risk warning distribution container to a first multi-level warning interval, wherein the first risk warning distribution container includes a plurality of warning distribution task units; A second allocation unit is configured to allocate W warning distribution task units to the W first warning intervals after decomposing the first multi-level warning intervals to obtain W first warning intervals, from the multiple warning distribution task units; A third allocation unit is used to allocate W distribution execution computing power resources to the W warning distribution task units according to the straight-line distance between the first fitting risk source of the first multi-level warning interval and the W first warning intervals; A first security risk warning distribution unit is used to use the W distribution execution computing power resources to run the W warning distribution task units to distribute security risk warnings to the first fitting risk impact range; The second security risk warning distribution unit is used to, by analogy, start the M risk warning distribution containers to distribute security risk warnings for the M fitting risk impact ranges according to the M multi-level warning intervals.

9. A security risk early warning method based on real-time information capture, characterized in that: Based on the implementation of the security risk early warning system based on real-time information capture according to any one of claims 1 to 8, the method comprises: Based on the preset crawling content specifications, real-time information is captured for the designated monitoring area to obtain a real-time risk information set; By extracting key information from the real-time risk information set, K risk event metadata are obtained; According to the K risk event locations of the K risk event metadata, predict the risk impact range in the designated monitoring area to obtain K risk impact ranges; The K risk impact ranges are geographically integrated to locate M fitting risk sources, wherein the M fitting risk sources have M fitting risk types and M fitting risk impact range identifiers, and M is a positive integer less than K; Taking the M fitting risk sources as the starting point, selecting M multi-level warning intervals in the M fitting risk impact ranges according to the M fitting risk types; According to the M multi-level warning intervals, M risk warning distribution containers are started to distribute security risk warnings for the M fitting risk impact ranges.

10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: The processor executes the computer program to implement the steps of the security risk warning method based on real-time information capture as described in any one of claims 1 to 8.