Networking space asset real-time perception and risk early warning system based on neural network
Through the hybrid detection engine based on neural networks and multimodal feature fusion technology, the shortcomings in real-time and accuracy of traditional network security methods are solved, and dynamic perception and accurate risk assessment of network asset status are realized, which significantly improves the scanning coverage rate and vulnerability detection rate.
Patent Information
- Application Number
- CN202510173015.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-06-27
AI Technical Summary
Traditional network security methods have problems such as insufficient real-time, poor accuracy, and difficulty in dealing with large-scale data. They cannot effectively monitor network asset status, integrate multimodal data in real time, and quickly warn of potential risks.
A hybrid detection engine based on neural network is adopted, combining multimodal feature fusion and deep learning model to realize dynamic perception and accurate risk assessment of network asset status. Specific steps include data acquisition, feature fusion, model training and risk warning.
Improve real-time and accuracy, significantly improve scanning coverage and vulnerability detection rates, reduce false alarm response time, and adapt to complex network environments.
Smart Images

Figure CN120223352A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a real-time perception and risk warning system for cyberspace assets based on neural networks, which is used to monitor the status of network assets in real time, fuse multi-modal data and quickly warn of potential risks. Background Art
[0002] With the exponential growth of the scale of cyberspace assets, network security threats have become increasingly diverse, such as malware attacks, vulnerability exploitation, etc. Traditional methods rely on regular scanning and rule engines, and there are problems such as insufficient real-time performance, poor accuracy, and difficulty in processing large-scale data. For example, the long scanning cycle makes it impossible to detect changes in asset status in time, the predefined rules cannot adapt to new types of attacks, and the performance of processing large-scale data is limited. Therefore, there is an urgent need for an intelligent and efficient system to realize real-time perception and dynamic risk warning of network assets.
[0003] Terms and Abbreviation Full Names
[0004] ·MSTE: Multi-modal Spatio-Temporal Encoder
[0005] ·GAT: Graph Attention Network
[0006] ·STCC: Spatio-Temporal Causal Convolution
[0007] ·CVE / NVD: Common Vulnerabilities and Exposures / National Vulnerability Database Summary of the Invention
[0008] The object of the present invention is to provide a real-time perception and risk warning system for cyberspace assets based on neural networks, which can collect asset information in real time through a hybrid detection engine, and combine multi-modal feature fusion and deep learning models to realize dynamic perception of network asset status and accurate risk assessment.
[0009] Technical Solution
[0010] To achieve the above object, the present invention adopts the following technical solutions:
[0011] Data collection: Obtain asset information through active scanning and traffic mirroring.
[0012] Feature fusion: Align network traffic (processed by MLP) and asset graph (encoded by GAT).
[0013] Model training: Use the STCC network to extract spatio-temporal features and superimpose the causal attention mechanism.
[0014] Risk warning: Output the risk score in real time and visualize the attack path through D3.js.
[0015] Effect of the embodiment
[0016] The scanning coverage rate is increased to 98%, and the vulnerability detection rate reaches 95%.
[0017] The false alarm rate is reduced to 5%, and the warning response time < 1 second.
[0018] Beneficial effects
[0019] The present invention has the following beneficial effects:
[0020] · Improve real-time performance: The asset status update delay is reduced from 30 minutes to 2 minutes.
[0021] · Improve accuracy: The new attack detection rate is increased to 92% (the traditional method is 65%).
[0022] · Optimize resource consumption: The bandwidth occupancy is reduced by 40%.
[0023] · Enhance adaptability: Dynamically adjust the strategy through reinforcement learning to adapt to complex network environments. Description of the drawings
[0024] Figure 1 It is the system architecture diagram of the present invention, showing the collaborative working process of the asset perception layer, the feature processing layer and the risk warning layer. Specific implementation manners
[0025] The following further describes the present invention in conjunction with specific implementation manners:
[0026] Embodiment 1
[0027] Deploy this system in Guangxi Power Grid Corporation, and the network scale covers more than 10,000 assets (servers, switches, etc.). The implementation steps are as follows:
[0028] 1. Core steps
[0029] 1.1 Data collection
[0030] Active scanning: Dynamically adjust the scanning strategy through distributed agents to optimize the scanning efficiency and bandwidth consumption.
[0031] Passive traffic analysis: Capture protocol data such as HTTP and DNS, extract five-tuple information and associate it with asset fingerprints.
[0032] 1.2 Data preprocessing
[0033] Standardize the network traffic data to ensure a unified input format.
[0034] The vulnerability database information is converted into numerical vectors through Word2Vec.
[0035] 1.3 Feature Engineering
[0036] Select key features: IP address, port, protocol type, vulnerability severity level, asset association graph, etc.
[0037] Multimodal alignment: Force the network traffic to be consistent with the feature space distribution of the asset graph through a cross-modal loss function.
[0038] 1.4 Improved Neural Network Model Training
[0039] Dynamic Asset Awareness Model: Optimize the scanning strategy using reinforcement learning, with the formula:
[0040]
[0041] Risk Warning Network: Based on spatio-temporal causal convolution (STCC) and causal attention mechanism, with the formula:
[0042]
[0043] 1.5 Risk Warning and Visualization
[0044] Output a risk score R ∈ [0, 1], and trigger a warning when the threshold R ≥ 0.7.
[0045] Generate a visualization graph of the attack path through D3.js, and dynamically highlight high-risk nodes and propagation paths.
[0046] The following is a detailed description of the implementation of the above steps:
[0047] 2. System Architecture
[0048] The real-time cyber asset perception and risk warning system based on neural network proposed by the present invention adopts a three-level collaborative module architecture ( Figure 1 ), which consists of an asset perception layer, a feature processing layer, and a risk warning layer. Each level collaborates closely to achieve real-time perception and risk warning of cyber assets.
[0049] (1) Asset Perception Layer
[0050] As the cornerstone of the entire system, the asset perception layer is responsible for collecting relevant information of cyberspace assets in real time and generating asset fingerprint vectors. Its core component is the hybrid detection engine, which innovatively combines active scanning and passive traffic analysis to achieve a comprehensive perception of network assets.
[0051] Active scanning: By actively initiating scanning tasks, it detects information such as devices, services, and ports in the network. This method can quickly discover new devices and changes in asset status, but to a certain extent, it may affect network bandwidth and device performance.
[0052] Passive traffic analysis: By capturing network traffic and deeply analyzing information such as protocols and packet contents, it understands the dynamic behavior of assets. This method has less interference to network devices, but its accuracy highly depends on the integrity and accuracy of traffic data.
[0053] Output result: The hybrid detection engine finally generates the asset fingerprint vector V a ∈R 128 . This 128-dimensional vector contains various key features of the asset, such as IP address, port, service type, protocol type, etc., providing an important data basis for subsequent feature processing and risk assessment.
[0054] (2) Feature processing layer
[0055] The main function of this layer is to fuse and encode the multi-modal data obtained from the asset perception layer, and extract valuable information for risk assessment. The multi-modal spatio-temporal encoder (MSTE) is the core of this layer.
[0056] · Input data:
[0057] Network traffic X t : Traffic data captured from the network in real time, covering rich information such as packet size, frequency, and protocol type.
[0058] Vulnerability database X v : Vulnerability information obtained from vulnerability databases (such as CVE / NVD), including vulnerability descriptions, affected scopes, severity levels, etc.
[0059] Asset graph X g : A graph structure data representing the relationships between assets, clearly reflecting the connection relationships, dependency relationships, etc. between devices in the network.
[0060] · Multi-modal spatio-temporal encoder (MSTE):
[0061] MLP (Multi-Layer Perceptron): Specifically used to process network traffic features X t, the 1000-dimensional original traffic data is mapped to a 128-dimensional feature space.
[0062] GAT (Graph Attention Network): Used to encode the asset graph X g and learn the association relationships between assets using the graph attention mechanism, also outputting a 128-dimensional graph embedding vector.
[0063] Cross-modal alignment loss function: By minimizing the Euclidean distance between the network traffic features and the asset graph features in the feature space, effective alignment and fusion of different modal data are achieved.
[0064] · Output result:
[0065] A fused feature vector is generated, which integrates the processed and fused asset features, traffic features, and vulnerability information, providing key input data for the risk warning layer.
[0066] (3) Risk warning layer
[0067] As the final output layer of the system, the risk warning layer evaluates the risks of network assets based on the fused feature vector provided by the feature processing layer and generates risk scores and attack path visualization information.
[0068] · Cascade dual-channel network:
[0069] Spatio-temporal convolution module: Applies spatio-temporal causal convolution (STCC) to capture local dependencies, with the formula where * represents temporal convolution, used to capture dependencies in the time series; represents spatial diffusion convolution, used to capture spatial dependencies, and can effectively handle the dynamic changes of network traffic and asset states.
[0070] Causal attention module: Further enhances the model's attention to important features through the causal attention mechanism, with the formula Mask matrix M causal ensures that only historical information participates in the calculation, avoiding the leakage of future information and more realistically simulating the causal relationships in the actual scenario.
[0071] · Output result:
[0072] Risk score R ∈ [0, 1]: Used to represent the degree of risk currently faced by network assets. The closer the value is to 1, the higher the risk.
[0073] Visualization of attack paths: Uses visualization technology to display possible attack paths, helping security personnel quickly locate and respond to potential threats.
[0074] This hierarchical architecture design endows the system with powerful capabilities, enabling it to efficiently handle complex network environments, achieve real-time perception of asset status, fuse multi-modal data, and perform risk warnings quickly and accurately.
[0075] 3. Core Algorithms
[0076] (1) Dynamic Asset Perception Model
[0077] Optimize the detection strategy using reinforcement learning:
[0078]
[0079] The formula explanations are as follows:
[0080] · Q(s,a): State-action value function, representing the expected cumulative reward for executing action a in state s.
[0081] · α: Learning rate, controlling the rate at which new information overrides old information.
[0082] · r: Immediate reward, calculated by to optimize the scanning efficiency.
[0083] · γ: Discount factor, balancing the importance of current and future rewards.
[0084] · The state s includes historical response time and protocol type distribution; the action a is a combined strategy of scanning frequency and depth.
[0085] (2) Multi-modal Feature Fusion
[0086] Design a cross-modal alignment loss function:
[0087]
[0088] The formula explanations are as follows:
[0089] · Achieve feature space alignment of multi-modal data by minimizing the Euclidean distance between network traffic features (processed by MLP) and asset graph features (processed by GAT).
[0090] · MLP (Multi-Layer Perceptron): Extract the temporal features of network traffic Xt.
[0091] · GAT (Graph Attention Network): Encode the structural relationships of the asset graph Xg, weighting adjacent node features through the attention mechanism.
[0092] (3) Risk Warning Network
[0093] Spatio-temporal causal convolution (STCC) captures local dependencies:
[0094]
[0095] The formula is explained as follows:
[0096] *: Temporal convolution, capturing the temporal dependencies of traffic data (such as periodic network behaviors).
[0097] Spatial diffusion convolution, capturing the spatial correlations between assets (such as communication paths between devices).
[0098] Wt and Ws are the temporal and spatial convolution kernel parameters respectively.
[0099] Superimposed causal attention mechanism:
[0100]
[0101] Mask matrix M causal Ensuring that only historical information participates in the calculation.
[0102] 4. Implementation process of functional modules
[0103] (1) Specific process of the asset perception layer
[0104] · Active scanning:
[0105] Using distributed scanning agents, dynamically adjusting the scanning period according to the reinforcement learning strategy (such as adjusting from every hour to every 10 minutes).
[0106] Scanning task priority allocation: Based on asset criticality (such as core servers first) and vulnerability history records.
[0107] · Passive traffic parsing:
[0108] Deploying traffic mirroring nodes to capture protocol data such as HTTP, DNS, and NetFlow in real time.
[0109] After packet parsing, extract the five-tuple (source IP, destination IP, source port, destination port, protocol type) and associate the asset fingerprint.
[0110] (2) Data alignment in the feature processing layer
[0111] · Steps for multimodal alignment:
[0112] 1) Network traffic features Xt are mapped to 128-dimensional vectors through MLP.
[0113] 2) Asset graphs Xg are encoded into 128-dimensional graph embedding vectors through GAT.
[0114] 3) The alignment loss function enforces the same distribution of the two types of vectors in the feature space (such as cosine similarity > 0.8).
[0115] 4) The vulnerability library Xv is converted into vectors through Word2Vec and concatenated with the above features.
[0116] (3) Inference logic of the risk warning layer
[0117] · Spatiotemporal convolution module:
[0118] The input is the fused 256-dimensional feature vector, and the spatiotemporal pattern is extracted through 3 layers of STCC.
[0119] The output feature map size is T×N×64 (T is the time step, and N is the number of assets).
[0120] · Causal attention module:
[0121] When calculating the attention weight, the mask matrix Mcausal only allows the current time step to focus on historical information (such as from t-10 to t).
[0122] The final risk score R is generated by the fully connected layer + Sigmoid activation, and the warning is triggered when the threshold is set to R≥0.7.
[0123] 5. Implementation process of attack path generation
[0124] 5.1 Input data processing and key node identification
[0125] (1) Input data definition
[0126] · Risk score R∈[0,1]: Output by the cascaded dual-channel network of the risk warning layer, representing the real-time risk level of each asset node (such as servers, network devices).
[0127] · Asset association graph G=(V,E):
[0128] Node V: Asset information (IP address, service type, vulnerability status).
[0129] Edge E: Connection relationship between assets (communication protocol, traffic frequency, historical attack records).
[0130] (2) Screening of key attack nodes
[0131] Threshold setting: Set the risk threshold according to business requirements (R≥0.7) and mark it as a high-risk node.
[0132] Dynamic adjustment: Based on historical attack data, use the sliding window algorithm to automatically optimize the threshold (the 90th percentile of the risk score distribution within the past 24 hours).
[0133] (3) Analysis of attack propagation paths
[0134] · Path generation algorithm:
[0135] Breadth-First Search (BFS): Starting from high-risk nodes, traverse associated assets to detect potential attack paths (jump-point attacks).
[0136] Risk propagation weight: Calculate the path risk value P according to the attributes of the edges (such as the number of abnormal connections in traffic logs). risk = ∑ e∈path w(e), where
[0137] · Path priority sorting: Sort in descending order by P risk and select the top N (Top 5) as highlighted paths.
[0138] 5.2 D3.js Visualization Implementation Steps (1) Visualization framework setup
[0139] · Canvas initialization: Create an SVG container, set the dimensions (such as 1200 × 800 pixels), and add zooming and panning interaction functions.
[0140] · Force-directed graph layout configuration:
[0141] The JavaScript code is as follows:
[0142] const simulation = d3.forceSimulation()
[0143] .force("link", d3.forceLink().id(d => d.id).distance(100))
[0144] .force("charge", d3.forceManyBody().strength(-300))
[0145] .force("center", d3.forceCenter(width / 2, height / 2));
[0146] distance: Controls the length of the edges; strength: Adjusts the repulsive force between nodes.
[0147] (2) Data binding of nodes and edges
[0148] · Node drawing:
[0149] Basic style: Circular nodes, with the radius dynamically adjusted according to the risk score R (r = 5 + 20R).
[0150] High-risk node marking: If R ≥ 0.7, fill it with red and add a glowing filter effect (CSS filter:url(#glow)).
[0151] · Edge drawing:
[0152] Normal edge: Gray dashed line, transparency 0.3.
[0153] Highlighted path: Red solid line, arrow mark ( <marker>Element definition: triangular arrow), line width according to P risk Increase (stroke-width = 1 + 2P risk )
[0154] (3) Dynamic interaction function
[0155] Node hover hint: Display Tooltip, including asset IP, risk score, associated vulnerability list (such as CVE number).
[0156] Path highlighting linkage: When clicking on a high-risk node, trigger the path search algorithm and only display the TopN attack paths related to this node.
[0157] Real-time update mechanism: Receive risk scores and graph changes through WebSocket, and call simulation.restart() to refresh the layout.
[0158] 5.3 Visualization logic of attack paths
[0159] (1) Visualization generation process
[0160] Step 1: Input risk scores and asset graph data, and preprocess to generate a node list and an edge list.
[0161] Step 2: Run the BFS algorithm, starting from high-risk nodes, and extract risk propagation paths.
[0162] Step 3: Bind data to D3.js and draw an initial force-directed graph.
[0163] Step 4: Dynamically render highlighted paths (red arrows) and associated nodes according to path priorities.
[0164] The embodiments of the present invention are not limited to the above description, and the detection strategy, feature dimensions, and model parameters can be adjusted according to the actual network environment, and such improvements all fall within the protection scope of the present invention.< / marker>
Claims
1. A real-time perception and risk warning system for cyberspace assets based on neural networks, characterized in that: include: The asset perception layer, whose core component is a hybrid detection engine, which combines active scanning and passive traffic analysis to collect information about cyberspace assets in real time and generate a 128-dimensional asset fingerprint vector, which contains key features such as the asset's IP address, port, service type, and protocol type; ● Feature processing layer, including a multimodal spatiotemporal encoder (MSTE), which includes MLP, GAT, and a cross-modal alignment loss function, and is used to fuse and encode the multimodal data of network traffic, vulnerability library, and asset map obtained from the asset perception layer to generate a fused feature vector; ●The risk warning layer adopts a cascaded dual-channel network, which includes a spatiotemporal convolution module and a causal attention module. It evaluates the risk of network assets based on the fused feature vector provided by the feature processing layer, outputs a risk score R∈[0,1], and generates attack path visualization information. When the risk score R≥0.7, a warning is triggered.
2. The real-time perception and risk warning system for cyberspace assets based on neural network according to claim 1 is characterized in that: The active scanning dynamically adjusts the scanning cycle according to the reinforcement learning strategy through the distributed scanning agent, and assigns scanning task priority based on asset criticality and vulnerability history records; the passive traffic parsing deploys traffic mirroring nodes to capture HTTP, DNS, NetFlow and other protocol data in real time, extracts five-tuples after parsing the data packets, and associates them with asset fingerprints.
3. The real-time perception and risk warning system for cyberspace assets based on neural network according to claim 1 is characterized in that: The MLP maps the 1000-dimensional raw traffic data to a 128-dimensional feature space, the GAT encodes the asset graph and outputs a 128-dimensional graph embedding vector, and the cross-modal alignment loss function is Effective alignment and fusion of multimodal data is achieved by minimizing the Euclidean distance between network traffic features and asset graph features in the feature space.
4. The real-time perception and risk warning system for cyberspace assets based on neural network according to claim 1 is characterized in that: The spatiotemporal convolution module uses spatiotemporal causal convolution (STCC) to capture local dependencies, and the formula is Where * represents time convolution, which is used to capture the dependencies on time series. represents spatial diffusion convolution, which is used to capture spatial dependencies, W t and W s are the time and space convolution kernel parameters respectively; the causal attention module enhances the attention to important features through the causal attention mechanism, and the formula is Mask matrix M causal Ensure that only historical information is included in the calculation.
5. A method for real-time perception and risk warning of cyberspace assets based on neural network, characterized in that: The following steps are involved: ●Data collection and asset fingerprint generation: Using the hybrid detection engine of the asset perception layer, we collect cyberspace asset information through active scanning and passive traffic analysis to generate asset fingerprint vectors; ●Multimodal data fusion and feature extraction: The feature processing layer obtains the data of the asset perception layer, processes it through MLP and GAT, and uses the cross-modal alignment loss function to fuse the multimodal data and generate a fused feature vector; ●Risk assessment and warning: The risk warning layer calculates the risk score through a cascaded dual-channel network based on the fused feature vector. When the risk score R ≥ 0.7, a warning is triggered and attack path visualization information is generated; ● Attack path generation and visualization: Based on risk scores and asset association maps, key attack nodes are screened, and the attack propagation path is analyzed using a breadth-first search algorithm. Visualization is performed through D3.js, including canvas initialization, force-directed graph layout configuration, node and edge data binding, and the realization of dynamic interaction functions.
6. The method for real-time perception and risk warning of cyberspace assets based on neural network according to claim 5 is characterized in that: In the data collection and asset fingerprint generation steps, active scanning uses distributed scanning agents, dynamically adjusts the scanning cycle according to the reinforcement learning strategy, and assigns scanning task priorities based on asset criticality and vulnerability history records; passive traffic analysis deploys traffic mirroring nodes, captures HTTP, DNS, NetFlow and other protocol data, extracts quintuples and associates asset fingerprints.
7. The method for real-time perception and risk warning of cyberspace assets based on neural network according to claim 5 is characterized in that: In the multimodal data fusion and feature extraction steps, the network traffic feature X t Through MLP mapping to a 128-dimensional vector, the asset map X g The GAT is used to encode the 128-dimensional graph embedding vector. The alignment loss function forces the two types of vectors to be distributed consistently in the feature space (e.g., cosine similarity > 0.8). v Convert it into a vector through word embedding (Word2Vec) and concatenate it with the above features.
8. The method for real-time perception and risk warning of cyberspace assets based on neural network according to claim 5 is characterized in that: In the risk assessment and early warning step, the spatiotemporal convolution module inputs the fused 256-dimensional feature vector, extracts the spatiotemporal pattern through three layers of STCC, and outputs a feature map of size T×N×64 (T is the time step, N is the number of assets); when the causal attention module calculates the attention weight, the mask matrix M causal Only the current time step is allowed to focus on historical information (such as t-10 to t), and the final risk score R is generated by the fully connected layer + sigmoid activation.
9. The method for real-time perception and risk warning of cyberspace assets based on neural network according to claim 5 is characterized in that: In the attack path generation and visualization step, the path risk value P is calculated based on the attributes of the edge (such as the number of abnormal connections in the traffic log). risk =∑ e∈path w(e), where Press P risk Select the top N (Top 5) in descending order as the highlighted paths; create an SVG container for visualization, set the size (such as 1200×800 pixels) and add zoom and pan interactive functions, configure the force-directed graph layout, dynamically adjust the radius according to the risk score R (r=5+20R) when drawing nodes, specially mark high-risk nodes, distinguish between ordinary edges and highlighted paths when drawing edges, and implement node hover prompts, path highlight linkage and real-time update mechanisms.
10. A computer-readable storage medium, characterized in that: The medium stores a computer program, which is configured to execute the steps of the method for real-time perception and risk warning of cyberspace assets based on a neural network as described in any one of claims 5-9.
11. A computer program product, characterized in that The product includes computer executable instructions, which are used to implement the functions of the real-time perception and risk warning method of cyberspace assets based on neural network as described in any one of claims 5-9.
Citation Information
Cited By
Network data security protection system based on artificial intelligence and big data
CN120896800A
A network data security protection system based on artificial intelligence and big data
CN120896800B