Security risk early warning method and system based on low-code cloud platform

Through digital simulation and multi-level analysis of the low-code cloud platform, a security warning management framework is built, user interaction instructions are received, and real-time management models are generated, which solves the problem that the fixed warning mode in the existing technology cannot adapt to multiple working modes, realizes automated and intelligent security monitoring, and improves risk identification accuracy and response speed.

CN120236382AInactive Publication Date: 2025-07-01JIANGXI KEHAO ANYUN SMART TECHNOLOGY CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510562996.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-07-01
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The fixed safety warning mode in the prior art cannot adapt to multiple working modes in the same working scenario, resulting in insufficient safety risk warning capabilities.

Method used

Receive monitoring device installation information through low-code cloud platform for digital simulation, build monitoring architecture models, conduct multi-level security risk analysis, build early warning management framework and tag collection, receive user interaction instructions, generate real-time management models, deploy equipment working parameters, switch monitoring modes, perform time-space correlation and trend analysis, and realize automated and intelligent security monitoring.

Benefits of technology

It improves the accuracy and response speed of risk identification, enhances the flexibility and customizability of the system, and can adapt to the safety risk management needs of different working modes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120236382A_ABST
    Figure CN120236382A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of safety early warning, and discloses a safety risk early warning method and system based on a low-code cloud platform, and the method comprises the steps: receiving the installation information of monitoring equipment, carrying out the digital simulation, generating a monitoring architecture model, carrying out the multi-level safety risk analysis, constructing an early warning management framework and a label set, and receiving a user interaction instruction. The method comprises the following steps: scheduling a label set, generating a real-time management model, deploying equipment working parameters, switching a monitoring mode, collecting data and carrying out space-time association and trend analysis to obtain an early warning result, realizes automatic and intelligent safety monitoring, improves the risk identification precision and response speed, enhances the flexibility and customizability of the system, and improves the safety of the system. The problem that in the prior art, a fixed early warning mode cannot adapt to all working modes of the same working scene is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of security warning, and in particular to a security risk warning method and system based on a low-code cloud platform. Background Art

[0002] In modern society, with the continuous development of informatization and intelligence, security risk management has become a major challenge faced by various institutions and enterprises. Real-time security warning and risk management systems are crucial for ensuring the stability and security of the system. In order to cope with complex and ever-changing security threats, traditional security monitoring methods are gradually unable to meet the rapidly developing needs. For a working scenario equipped with monitoring devices, the probabilities of security risk events faced under different working modes of this working scenario are different. If a fixed monitoring device management mode is applied to deal with various different working modes, the security risk warning ability will not be able to reach the best condition following the changes in the working mode. Summary of the Invention

[0003] The purpose of the present invention is to provide a security risk warning method and system based on a low-code cloud platform, aiming to solve the problem that the fixed warning mode in the prior art cannot adapt to all working modes of the same working scenario.

[0004] The present invention is implemented as follows. In the first aspect, the present invention provides a security risk warning method based on a low-code cloud platform, including: Receiving, through a designated security warning cloud platform, the monitoring device installation information registered by a user account, and performing digital simulation of the monitoring system architecture on the monitoring device installation information to obtain a corresponding monitoring architecture digital model; Performing multi-level analysis of the security risk warning requirements on the monitoring architecture digital model, and constructing a security warning management framework and a security warning management label set corresponding to the security warning management framework based on the results of the multi-level analysis; Receiving, through the security warning cloud platform, an interaction instruction of the user account, and scheduling the security warning management labels in the security warning management label set according to the interaction instruction to fill the security warning management framework to generate a real-time management model; Deploying device working parameters for the monitoring devices registered by the user account according to the real-time management model to drive the monitoring devices to switch to a designated monitoring mode to collect monitoring data, and performing security warning analysis on the monitoring data in terms of the overall spatio-temporal correlation dimension and the continuous spatio-temporal trend dimension through the real-time management model to obtain a security risk warning result.

[0005] Second aspect, the present invention provides a security risk early warning system based on a low-code cloud platform for implementing a security risk early warning method based on a low-code cloud platform as described in any one of the first aspect, including: An architecture analysis module, configured to receive installation information of monitored devices registered by a user account through a specified security early warning cloud platform, and perform digital simulation of the monitored system architecture on the installation information of the monitored devices to obtain a corresponding monitored architecture digital model; A framework construction module, configured to perform multi-level analysis of security risk early warning requirements on the monitored architecture digital model, and construct a security early warning management framework and a set of security early warning management labels corresponding to the security early warning management framework based on the results of the multi-level analysis; A real-time management module, configured to receive an interaction instruction of a user account through the security early warning cloud platform, and schedule security early warning management labels in the set of security early warning management labels according to the interaction instruction to fill the security early warning management framework to generate a real-time management model; A security early warning module, configured to deploy device working parameters for the monitored devices registered by the user account according to the real-time management model, drive the monitored devices to switch to a specified monitoring mode to collect monitoring data, and perform security early warning analysis on the monitoring data in the overall space-time correlation dimension and the continuous space-time trend dimension through the real-time management model to obtain a security risk early warning result.

[0006] The present invention provides a security risk early warning method based on a low-code cloud platform, which has the following beneficial effects: The present invention receives installation information of monitored devices and performs digital simulation to generate a monitored architecture model, conducts multi-level security risk analysis, constructs an early warning management framework and a set of labels, receives user interaction instructions, schedules the set of labels, generates a real-time management model, deploys device working parameters, switches the monitoring mode, collects data and conducts space-time correlation and trend analysis to obtain an early warning result. This method realizes automated and intelligent security monitoring, improves the accuracy and response speed of risk identification, enhances the flexibility and customizability of the system, and solves the problem that the fixed early warning mode in the prior art cannot adapt to all working modes in the same working scenario. Description of the Drawings

[0007] Figure 1 is a step schematic diagram of a security risk early warning method based on a low-code cloud platform provided by an embodiment of the present invention; Figure 2 is a structural schematic diagram of a security risk early warning system based on a low-code cloud platform provided by an embodiment of the present invention. Detailed Embodiments

[0008] In order to make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0009] The implementation of the present invention will be described in detail below in conjunction with specific embodiments.

[0010] Referring to Figure 1 、 Figure 2 as shown, a preferred embodiment of the present invention is provided.

[0011] In a first aspect, the present invention provides a security risk warning method based on a low-code cloud platform, including: S1: Receiving, through a designated security warning cloud platform, the installation information of monitoring devices registered by a user account, and performing digital simulation of the monitoring system architecture on the installation information of the monitoring devices to obtain a corresponding monitoring architecture digital model; S2: Performing multi-level analysis of security risk warning requirements on the monitoring architecture digital model, and constructing a security warning management framework and a set of security warning management labels corresponding to the security warning management framework based on the results of the multi-level analysis; S3: Receiving, through the security warning cloud platform, an interaction instruction of the user account, and scheduling the security warning management labels in the set of security warning management labels according to the interaction instruction to fill the security warning management framework to generate a real-time management model; S4: Deploying device working parameters for the monitoring devices registered by the user account according to the real-time management model to drive the monitoring devices to switch to a designated monitoring mode to collect monitoring data, and performing security warning analysis on the monitoring data in terms of the overall spatio-temporal correlation dimension and the continuous spatio-temporal trend dimension through the real-time management model to obtain a security risk warning result.

[0012] Specifically, in step S1 of the embodiment provided by the present invention, the user account registers the installation information of its monitoring devices through the security warning cloud platform. These information include the type, model, installation location, configuration parameters, working requirements, etc. of the devices. The system receives the device installation information from the user through a low-code platform or other interfaces, stores the data through the cloud platform, and calls it when needed.

[0013] More specifically, the monitoring device installation information provided by the user is parsed into a standardized data format that the system can recognize and process. The system needs to map the physical attributes, functional attributes, etc. of these devices and ensure the matching of the devices with the environment (such as the matching of the device installation location with the monitoring range, the monitoring type with the target, etc.). Based on data parsing and mapping technologies (such as JSON, XML data formats), the device information is structurally processed to ensure that the information can be recognized by the digital model of the monitoring system architecture.

[0014] More specifically, according to the parsed device installation information, the system automatically or semi-automatically constructs a digital monitoring system architecture model. This model needs to include elements such as the location, function, connection relationship, configuration parameters, etc. of each device. The virtual model of the device is constructed using digital twin technology, and this model is consistent with the actual monitoring device and its configuration parameters, reflecting the performance of the monitoring device in the real environment. It is necessary to combine 3D modeling technology to express the physical layout and environmental interaction of the monitoring device. The system architecture model is automatically generated through algorithms to associate the monitoring device with its surrounding environment (such as sensors, cameras, alarm devices, etc.).

[0015] More specifically, through the constructed digital model, the system can simulate different monitoring scenarios and evaluate the device performance and the overall effectiveness of the system. This process can help determine whether the monitoring system can meet the security warning requirements and make necessary adjustments and optimizations. Through the digital model, various functions of the monitoring system (such as coverage range, response time, data transmission, etc.) are simulated and modeled to predict the performance of the device in the actual environment, evaluate the performance of the device and the system architecture, and optimize according to the simulation results (such as adjusting device parameters, optimizing the layout, etc.).

[0016] More specifically, after completing the simulation and optimization, the system finally generates a complete digital model of the monitoring architecture. This model covers information such as the configuration, layout, and function of the device and has a visualization function, which is convenient for users to understand and operate. This digital model is stored on the security warning cloud platform, and users can view, edit, and update it at any time. With the help of visualization technologies (such as 3D graphics, virtual reality), the digital model is presented to users for easy analysis and management.

[0017] It can be understood that through digital simulation, users can intuitively see the design and layout of the monitoring device and the system architecture, making the design process of the system more transparent and easy to understand. Users can view the monitoring architecture in real time, adjust the device configuration, and optimize the system layout to ensure that the monitoring effect reaches the best state. Digital simulation provides a test platform where users can simulate different operation scenarios and environmental changes, and timely discover potential device performance problems, system deficiencies, and risk points. This enables effective performance evaluation and optimization of the system before system deployment, thereby improving the reliability and stability of the system.

[0018] More specifically, by automatically building a digital model of the monitoring architecture, manual intervention is reduced, and the efficiency and accuracy of system deployment are improved. At the same time, simulation technology can support data-based intelligent decision-making, optimize device configuration and monitoring solutions, and enhance the intelligence level of the system. The digital model provides a real-time and dynamic perspective for the system, and can quickly adjust monitoring strategies and device configurations according to the actual operating conditions of the devices or changes in the environment. This real-time response ability is the key to improving the reaction speed and response ability of the security warning system. The digital model has strong adaptability and can support the configuration of different types of monitoring devices (such as cameras, sensors, etc.) and various complex environments. Whether it is for the configuration of a single device or the comprehensive monitoring requirements across devices and environments, effective adaptation can be achieved through digital simulation.

[0019] Specifically, in step S2 of the embodiment provided by the present invention, various security risks in the actual working environment are first classified hierarchically, and the event patterns of each level are defined and analyzed. Specifically, the risks can be divided into the following levels: Physical level risks: involving risk events in the physical environment, such as equipment failures, fires, natural disasters, building structure problems, etc.; Operational level risks: related to security risks in the daily operation process, including operator errors, improper work, machine operation errors, etc.; Personnel level risks: involving the safety and health risks of personnel in the workplace, including employee fatigue, accidental injuries, disease transmission, mental health problems, etc.; Environmental level risks: referring to external factors that affect the working environment, such as changes in physical environments such as temperature, humidity, and air quality, which may cause equipment failures or affect personnel health.

[0020] More specifically, for physical level risks, monitoring means such as environmental sensors and fire alarm systems can be used to detect abnormal environmental conditions and give early warnings. For operational level risks, by monitoring operation processes, device operating states, etc., combined with real-time data analysis, the correctness of operations and the stability of devices are ensured. For personnel level risks, health monitoring devices (such as wearable devices to monitor the health status of employees) and fatigue management systems are used to monitor the working status of employees. For environmental level risks, combined with environmental perception devices, such as meteorological monitoring systems, temperature and humidity sensors, etc., the changes in the working environment are tracked in real time.

[0021] More specifically, the above different risk types are defined as multiple levels or modes, and corresponding event handling and response mechanisms are formulated. Each level has an independent monitoring and processing process. At the same time, the levels can influence and cooperate with each other. The framework structure is designed as follows: The physical level monitors the safety of the working environment in real time through an environmental monitoring and fault detection system. The operation level combines data such as operation logs and equipment monitoring to conduct operation process analysis and early warning. The personnel level conducts the health and safety management of employees through data such as employee health monitoring and working hours analysis. The environmental level conducts real-time monitoring and early warning of environmental changes through a sensor network (such as temperature and humidity sensors, air quality monitoring, etc.).

[0022] More specifically, each level can independently monitor and give early warning of the risks within it. However, at the same time, through a linkage mechanism, the event information of different levels needs to be shared to form a comprehensive early warning management system. The key points of the framework design include the real-time collection of events. By deploying environmental monitoring equipment, operation monitoring systems, employee health management tools, etc., various types of data are collected. The real-time analysis of events. According to the risk characteristics of different levels, suitable analysis algorithms are designed. For example, for equipment failure events, a fault diagnosis algorithm can be used, and for personnel health risks, a health assessment model can be used. Corresponding response strategies are required for security events at each level. For example, when an equipment anomaly is detected, the system can automatically generate a maintenance task; when an employee health risk is detected, the system can automatically notify the safety officer or manager.

[0023] More specifically, data is collected through means such as sensors, log systems, and employee health monitoring tools, and event analysis is carried out through data processing technologies (such as real-time stream processing, event detection algorithms, etc.). Historical data is analyzed using technologies such as data mining and machine learning to discover potential risk patterns and predict future possible risks. Based on the event analysis results, the response mechanism is triggered through an automated system, and the system adjusts the risk early warning strategy according to real-time data to ensure the timeliness and accuracy of the system response.

[0024] It should be noted that the security warning management framework is a basic framework for constructing a real-time management model. The role of this framework is to provide a low-code cloud platform to construct a real-time management model corresponding to a specific working environment in real time. The security warning management label set contains multiple security warning management labels. By substituting these labels into the security warning management framework, the effect of low-code programming can be achieved to generate a real-time management model for real-time data collection and security risk warning of the working environment where monitoring devices are deployed. This multi-level analysis framework and label management system have flexible scalability and can adapt to the security risk management requirements in different working environments. As the environment changes or the risk pattern changes, the framework and labels can be continuously adjusted and optimized. Through these steps and technical implementations, the entire security warning management framework can effectively manage multi-level security risks in the actual working environment and improve the safety and emergency response capabilities of the workplace.

[0025] Specifically, in step S3 of the embodiment provided by the present invention, the user inputs interaction instructions through the interface of the security warning cloud platform, and these instructions may include the following contents: adding, deleting or modifying a certain security warning label, adjusting the priority, relevance or triggering condition of the label, configuring an alarm rule, defining a response process, etc.

[0026] More specifically, for parsing and validating the instructions, the security warning cloud platform first receives the user's instructions and parses them. The parsing steps include: validating the format of the instructions input by the user and judging the rationality of the instruction content. For example, checking whether the label already exists, whether it conforms to the predefined security event type, or whether the priority matches the severity of the event. If the instruction is legal and effective, the relevant operation is executed; if the instruction is invalid, an error prompt is returned to the user.

[0027] More specifically, for scheduling and allocating labels, the security warning cloud platform schedules the labels according to the user's instructions. These operations may involve the following contents: label creation: when the user requests to add a new label, the platform assigns a unique identifier to the label and defines the attributes of the label, such as priority, triggering condition, etc.; label modification: if the user requests to modify an existing label (such as modifying the name, description or priority of the label), the platform updates the data of the label and ensures that the label correctly reflects the changes in the system; label deletion: if the user deletes a label, the platform removes the label from the system and updates the relevant data structures to ensure data consistency.

[0028] More specifically, according to the severity or urgency of the tags, their processing order is adjusted. For example, tags related to personnel safety may be processed with priority, while tags for equipment failures are placed in a secondary position. Based on the triggering conditions and severity of different tags, the platform will automatically assign corresponding response strategies to the tags, such as alarm sending, task allocation, etc. Once the tags are scheduled and updated, the platform will dynamically fill the tag information into the security warning management framework, and these tags will be associated with information such as event models, risk patterns, and alarm rules in the warning system to ensure that the system can generate appropriate response mechanisms based on the latest tag information.

[0029] More specifically, for the construction of the real-time management model of security warnings, the security warning cloud platform integrates the scheduled tags into the real-time management model. The real-time management model is a management framework automatically generated based on the current set of tags, warning events, and response mechanisms. It can automatically generate processing procedures, risk predictions, and alarm mechanisms through the association of existing tags. The specific process of model generation includes: Data integration: The platform integrates information such as tags, event data, and user configurations into a dynamic management framework. Decision-making mechanism: According to the priority, risk type, and severity of the tags, the platform will formulate a set of decision-making models for handling events. For example, when a certain security event occurs, the system will automatically deduce response measures based on the priority and rules of the tags. Each time the user modifies a tag or adds a new tag through an interactive instruction, the system will regenerate a real-time management model and automatically update the existing response mechanism.

[0030] More specifically, based on the constructed real-time management model, when the platform detects a new security event, it can immediately activate the warning mechanism for relevant tags. For example, if the system detects an abnormal temperature and this abnormality triggers the tag of "too high temperature", the system will automatically generate a warning and notify relevant personnel. When the warning condition of a certain tag is met, the system will automatically execute the corresponding response strategy, which may include: automatically sending alarms (text messages, emails, etc.), starting the emergency response process, automatically generating reports and recording logs.

[0031] It can be understood that by receiving user interactive instructions through the cloud platform and scheduling the security warning management tags according to the instructions, the system can efficiently respond to security events, and users can flexibly adjust the tag content and rules to ensure that in a dynamically changing working environment, security warning management can adapt and optimize in a timely manner. The system can dynamically adjust tags according to user instructions, thereby generating a real-time updated security warning management model. This flexibility ensures that in the case of different security events, the platform can timely adjust the warning strategy and automate and quickly respond to various security events.

[0032] More specifically, the generation of the real-time management model and label scheduling enable the system to automatically respond based on predefined rules and decision-making mechanisms. The system can not only monitor risks but also intelligently predict future possible events, reducing human intervention and improving response efficiency. Users input instructions through an intuitive interaction interface, and the system quickly executes operations through the cloud platform, reducing the complexity of safety management and enhancing users' control over safety management. This system has high scalability and flexibility and can handle different scales and types of working environments. In the future, the platform can adapt to new safety requirements by adding new labels or modifying existing label rules.

[0033] Specifically, in step S4 of the embodiment provided by the present invention, users register and manage the information of monitoring devices through the interface provided by the safety warning cloud platform. Each device has a unique identifier in the system, as well as its related working parameters (such as device type, sensor type, acquisition frequency, working mode, etc.). Based on the real-time management model set by the user, the platform first determines the device working parameters that need to be deployed according to the type and working requirements of the monitoring device. These parameters may include: monitoring mode (such as video monitoring, temperature monitoring, humidity monitoring, pressure monitoring, etc.), acquisition frequency (such as collecting data once per second, once per minute, etc.), the range and coverage area of data acquisition. The system sends deployment instructions to the device according to the strategy generated by the real-time management model, guiding the device to switch to the specified monitoring mode and adjusting its working state according to the set parameters.

[0034] More specifically, after receiving the parameter deployment instruction, the monitoring device will switch to the corresponding working mode according to the setting. For example, if it is a video monitoring device, it may switch to the high-definition mode; if it is a sensor device, it may start high-frequency real-time data acquisition. After the device switches to the specified monitoring mode, it starts to collect monitoring data. The data types may include temperature, humidity, pressure, camera images, motion detection, etc. The device regularly transmits data to the cloud platform according to the preset acquisition frequency.

[0035] More specifically, the real-time management model conducts an overall spatio-temporal correlation analysis on the data collected by different monitoring devices, that is, it correlates the data of multiple monitoring devices spatio-temporally to construct a global security monitoring view. This process includes: analyzing the data change situations of each monitoring device within the same time period, identifying the spatial correlations between devices. For example, there may be a certain spatial correlation between a temperature monitoring device and a video monitoring device. If the temperature in a certain area rises abnormally, the video monitoring may show corresponding fire or other abnormal activities. Within the same time range, compare the data collected by different monitoring devices to discover potential security risks. For example, if the temperature of a sensor in a certain area suddenly rises, and at the same time, the video monitoring device in this area shows abnormal movement, the system will identify the correlation between the two and prompt the possible existence of security hazards.

[0036] More specifically, the continuous spatio-temporal trend analysis focuses on tracking and analyzing the change trends of the continuous data of devices on the time axis. The specific steps include: conducting time series analysis on continuous monitoring data (such as temperature, humidity, pressure, etc.) to check whether it shows abnormal trends or fluctuations. For example, the continuous increase in temperature may indicate a fire risk, and the sudden decrease in humidity may indicate equipment failure. By comparing with historical data, judge whether the current data deviates from the normal trend range. For example, the temperature change trend in the past week was stable, but today's temperature rise exceeds the set threshold, and the system will issue a warning. Combining the overall spatio-temporal correlation analysis and the continuous spatio-temporal trend analysis, the real-time management model identifies potential abnormal patterns through machine learning or rule engines. For example, when multiple monitoring devices show the same abnormal behavior, the model will mark this pattern as a possible security risk.

[0037] More specifically, based on the results of the spatio-temporal correlation analysis and trend analysis, the real-time management model comprehensively evaluates the data collected by all devices and generates a risk assessment report. According to the type, duration, and frequency of abnormal data, the model will judge the current security risk level. For example, if the temperature in a certain area rises abnormally and is accompanied by an equipment alarm signal, the system may determine it as a high risk and immediately trigger an alarm. Classify the identified abnormal patterns into specific security events (such as fire, equipment failure, intrusion detection, etc.). Once a security risk is determined, the system will trigger a security warning. After receiving the warning, relevant personnel can handle the security event and feedback the handling results to the cloud platform. According to the information of the handling feedback, the real-time management model may make corresponding adjustments to optimize future risk warnings.

[0038] It is understandable that by dynamically adjusting the working mode and parameters of the monitoring devices, the system can obtain the monitoring data collected by various devices in real time, ensuring the timeliness and accuracy of the data. Through overall spatio-temporal correlation analysis and continuous spatio-temporal trend analysis, the system can accurately identify security risks across devices and time, providing more comprehensive data support for the early warning system, effectively discovering potential security hazards, and giving early warnings.

[0039] More specifically, the system automatically analyzes the monitoring data, generates security risk warnings, and provides an immediate response mechanism based on a real-time management model, greatly improving the efficiency and accuracy of security management, reducing the need for manual intervention. The platform can automatically adjust the security monitoring strategy according to the warning results and feedback, flexibly respond to different types of security events, ensure that various security issues can be handled in a timely manner, and the system will continuously optimize the monitoring model and risk assessment strategy according to new data feedback, gradually improving the accuracy and efficiency of early warnings, ensuring the sustainability and scalability of security management.

[0040] The present invention provides a security risk early warning method based on a low-code cloud platform, which has the following beneficial effects: The present invention receives the installation information of monitoring devices and conducts digital simulation to generate a monitoring architecture model, conducts multi-level security risk analysis, constructs an early warning management framework and a tag set, receives user interaction instructions, schedules the tag set, generates a real-time management model, deploys the working parameters of the devices, switches the monitoring mode, collects data and conducts spatio-temporal correlation and trend analysis to obtain early warning results. This method realizes automated and intelligent security monitoring, improves the accuracy and response speed of risk identification, enhances the flexibility and customizability of the system, and solves the problem that the fixed early warning mode in the prior art cannot adapt to all working modes in the same working scenario.

[0041] Preferably, the steps of receiving the installation information of the monitoring devices registered by the user account through a designated security early warning cloud platform and conducting digital simulation of the monitoring system architecture for the installation information of the monitoring devices to obtain a corresponding digital monitoring architecture model include: S11: The designated security early warning cloud platform allows the user account to log in to the platform and receives the working environment layout information of the monitoring devices to be pre-deployed, the performance information of the monitoring devices to be pre-deployed in the working environment, and the positioning information of the monitoring devices to be pre-deployed in the working environment. The performance information and positioning information of the same monitoring device are combined into the installation information of the monitoring device; S12: Conduct digital simulation of the working environment layout form of the monitoring system composed of the monitoring devices according to the working environment layout information to obtain a digital working environment layout model; S13: Perform digital simulation of each monitoring device on the digital model of the work environment layout according to the installation information of each monitoring device, so as to construct a digital model of a monitoring unit corresponding to each monitoring device on the digital model of the work environment layout, and perform associated connection processing on each digital model of the monitoring unit, thereby obtaining a digital model of the monitoring architecture.

[0042] Specifically, the user first logs in to the account through the designated security warning cloud platform. During the login process, the user verifies the identity information to ensure the security and confidentiality of the data. After successful login, the user uploads the information related to the monitoring devices to be pre-deployed, including: Work environment layout information: This information describes the physical layout and installation location of the monitoring devices in the work environment, usually including the floor plan or 3D model of the environment, specifically including the deployment area of the monitoring devices, the coverage range of the devices, and the specific dimensions of the monitoring area; Monitoring device performance information: including hardware performance parameters such as the type, model, monitoring functions (such as cameras, sensors, alarms, etc.), sensor accuracy, and operating frequency of the devices; Monitoring device positioning information: including the specific installation location of the monitoring devices in the work environment (such as the coordinate position of the devices, the distance relative to the devices, the direction angle, etc.). After being processed by the system, these information are combined into the installation information of each monitoring device for subsequent digital simulation.

[0043] More specifically, after obtaining the work environment layout information, the security warning cloud platform performs digital simulation on the monitoring system composed of monitoring devices. This process includes that according to the work environment layout information, the system generates a digital work environment model, which can be a 2D floor plan or a 3D space model. Specifically, a suitable model type is selected according to the complexity of the environment. The system simulates the specific deployment positions and their coverage ranges of each monitoring device in the digital environment. Through digital simulation, the user can intuitively view the deployment effect of the monitoring devices in the work environment and perform rationality inspection and adjustment.

[0044] More specifically, the performance information and positioning information of each monitoring device are combined and further simulated in the work environment layout model. The specific steps include: According to the performance information of the devices, the system assigns specific functions to each device, such as video monitoring, sound monitoring, temperature and humidity sensing, etc., and sets the operating parameters of each device, such as the shooting angle, sensor range, etc. According to the positioning information of the devices, the system determines the specific positions of each monitoring device in the work environment model to ensure the correct docking of the devices with other objects or areas in the environment.

[0045] More specifically, for each monitoring device, the system constructs a "monitoring unit digital model" on the working environment layout model. This model describes information such as the monitoring function of the device, the effective coverage area, and the working status of the device. Each monitoring unit digital model may include the following: Field of view of the device: such as the shooting angle of a camera or the detection range of a sensor, Monitoring target: specific targets or areas that the device can monitor, such as specific doorways, areas, etc., Device attributes: the operating status, performance, etc. of the device. Each monitoring unit digital model forms a complete monitoring architecture through connection with other device models.

[0046] More specifically, the system associates and connects each monitoring unit digital model to establish the relationships of data flow, functional collaboration, and spatial layout among devices. The specific methods include: The monitoring areas of each monitoring device are connected according to the physical location and field of view of the device to ensure seamless coverage of the monitoring area. If the monitoring range of a certain device cannot cover a certain area, the system will automatically prompt the need to add new monitoring devices. Establish a data communication and collaboration mechanism among multiple devices. For example, multiple video monitoring devices can work together to form a complete monitoring network, and the data between devices can be shared to jointly improve the overall monitoring effect.

[0047] More specifically, after completing the connection of all monitoring units, the system finally forms a complete monitoring architecture digital model. This model describes the structure, device functions, spatial layout, and device collaboration relationships of the entire monitoring system. Users can intuitively view the working status, optimized areas, and possible blind spots of the entire monitoring system through this model.

[0048] More specifically, after generating the monitoring architecture digital model, users can perform visual display of the model through the cloud platform to check the device layout, working status, and collaboration effect. Users can operate on the digital model, such as zooming in and out, rotating, etc., to check whether the connections between each monitoring unit are reasonable. Based on the verification results, users can adjust the deployment location, performance parameters, etc. of the device, and the adjusted model will be automatically updated to optimize the performance and coverage of the monitoring system. The platform can also generate deployment suggestions for monitoring devices based on the optimized monitoring architecture digital model to further improve the monitoring effect.

[0049] It can be understood that through digital simulation, the overall architecture of the monitoring system can be efficiently and intuitively constructed and displayed. Without the need for users to manually draw or debug the device layout, they can view the layout effect in real time through the digital model, avoiding errors and omissions in traditional manual deployment. The combination of the performance information and positioning information of the devices ensures the precise positioning of each monitoring device in the working environment. Through the collaborative connection between devices, a non-blind-spot monitoring network can be efficiently constructed, improving the overall coverage and monitoring quality of the monitoring system. By constructing the digital model of the working environment layout and the digital model of the monitoring architecture, users can achieve real-time visualization through the cloud platform. The system can dynamically display the deployment effect of the monitoring devices and the area coverage. Users can adjust and optimize through the intuitive model to ensure the effect of the monitoring system in actual deployment.

[0050] More specifically, the construction and optimization of the digital model of the monitoring architecture help users accurately evaluate the performance and working status of the devices before deployment, avoiding blind deployment. Through real-time simulation, it can ensure a quick response during the actual deployment process, timely adjust the device configuration, reduce monitoring blind spots and dead corners. The monitoring architecture model after digital simulation can not only help users optimize the device configuration, but also provide support for subsequent data analysis and security warning. Based on the digital model, the system can perform more accurate real-time data collection and analysis, helping to discover potential security risks and giving timely warnings.

[0051] Preferably, the steps for multi-level analysis of the security risk warning requirements for the digital model of the monitoring architecture include: S21: Regarding the digital model of the monitoring architecture as the occurrence site of security risk events, analyze the ways of using the occurrence site to obtain the security risk warning objects that the digital model of the monitoring architecture can feedback; among them, the security risk warning objects are the basic-level warning requirements of the digital model of the monitoring architecture; S22: Conduct a likelihood deduction process of security risk warning events on the digital model of the monitoring architecture according to the security risk warning objects to obtain the set of potential warning events corresponding to the security risk warning objects of the digital model of the monitoring architecture; S23: Conduct a specific scenario simulation of the occurrence of events for the set of potential warning events corresponding to the security risk warning objects of the digital model of the monitoring architecture to obtain the specific event scenarios of each warning event corresponding to the set of potential warning events, and conduct scenario classification processing on the specific event scenarios of each warning event to obtain the scenario classification characteristics of each warning event; S24: Classify each warning event of the security risk warning object according to the scenario classification characteristics of each warning event, so as to classify and summarize each warning event into several event scenario patterns; wherein, the event scenario pattern is the deep-level warning requirement of the monitoring architecture digital model.

[0052] Specifically, take the monitoring architecture digital model as the site where security risk events occur, analyze the layout of the working environment, the functions of monitoring devices and their positioning information in this digital model. These information will help determine the areas where potential security risk events may occur and the monitoring scope of each device. The monitoring architecture digital model presents the positions of monitoring devices, working areas, sensor coverage ranges, etc., and can help the system identify possible security risk areas and monitoring blind spots.

[0053] More specifically, analyze the application ways of the monitoring architecture digital model. The purpose of this analysis is to understand how the monitoring system monitors different areas during actual use and the types of security risks that may occur in different scenarios. By analyzing these paths, the basic level of warning requirements can be identified, and finally determine which areas or devices in the monitoring architecture digital model need to be monitored and warned keyly.

[0054] More specifically, according to the results of the site application way analysis, identify the security risk warning objects in the monitoring architecture digital model. These warning objects can be specific monitoring devices, monitoring areas or potential security threats (such as intrusion, fire, etc.) in specific scenarios. For example: If there are blind spots in the monitoring area, the blind spots themselves may become warning objects. If some devices may cause warning failures due to performance problems (such as sensor failures), then these devices should also be used as warning objects.

[0055] More specifically, the warning requirements at the basic level are mainly the preliminary warnings for these security risk warning objects, covering simple event monitoring and response, such as detecting abnormalities (such as unauthorized entry, object movement, etc.) of specific behaviors and areas through device sensors or video monitoring.

[0056] More specifically, based on the warning objects at the basic level, deduce the possible security risk warning events. This step simulates various possible risk situations. For example: intrusion event: whether there are unauthorized personnel entering the monitoring area; fire event: whether there are abnormal temperature changes or smoke in a specific area; device failure event: whether the monitoring device fails or stops working. Each warning event has a possibility, and the system will deduce the occurrence probability and severity of these events based on the performance of the monitoring device, the working environment and historical data.

[0057] More specifically, for each potential warning event, specific scenario simulations are conducted. The simulation process includes: through the monitoring architecture digital model, simulating the specific situations of event occurrence under different conditions, such as the time periods when intrusion events may occur, the environmental states when equipment failures occur, etc. The scenario simulations should consider various factors in the actual environment, such as the working states of monitoring devices, environmental changes, potential risk factors, etc.

[0058] More specifically, the various event scenarios simulated are classified. The purpose of this process is to classify the event scenarios and identify the common characteristics under different scenarios, that is, the working environment of the deployed monitoring devices has multiple working modes, and different working modes will result in different types of warning events. After the scenario classification, it can help the system identify the characteristics of different scenarios and provide a reference for subsequent warning responses.

[0059] More specifically, according to the characteristics of the scenario classification, the security risk warning events are classified and processed, which includes: classifying the events according to factors such as the type, severity, and occurrence frequency of the warning events. For example, possible events include equipment failures, intrusions, fires, leaks, etc. According to the nature of the events, different warning levels are set, such as high, low, and medium priorities. Finally, through the classification of the warning events, the system can generate multiple event scenario models, and each model describes the occurrence characteristics of different types of warning events in a specific scenario. For example: Equipment failure mode: false alarms, missed alarms, etc. caused by equipment failures; Intrusion mode: factors such as the occurrence probability, time, and location of intrusion events; Fire mode: the detection timing, early warning response, etc. of fire events. These models reflect the deep-level warning requirements of the monitoring architecture digital model.

[0060] More specifically, through the above steps, the system gradually deduces from the basic-level warning requirements to the deep-level warning requirements. The deep-level warning requirements include complex event pattern recognition and response mechanisms to ensure that the monitoring system can respond quickly and accurately when real security risk events occur.

[0061] It can be understood that through multi-level analysis, the system can accurately identify the security risk objects and potential warning events in the monitoring architecture digital model. This prediction method based on simulation and deduction makes risk management more accurate. The warning mechanism can identify potential threats early. Through the simulation and classification processing of event scenarios, the system can construct multiple event scenario models, which provides a more in-depth warning requirement analysis for the monitoring system. These deep-level requirements can cover various different security risk situations, thus improving the flexibility and response speed of security prevention.

[0062] More specifically, event scenario simulation and scenario classification enable the monitoring system to have higher adaptability. The system can not only operate under fixed conditions, but also adjust the monitoring strategy according to different environmental changes and potential threats, which makes the system more efficient in dealing with complex and changeable security environments. Based on the classification and in-depth analysis of event patterns, the monitoring system can respond more precisely to security events. The system automatically adjusts the response strategy according to the classification priority of events, optimizes the alarm and handling processes, thereby reducing the occurrence of false alarms and missed alarms. Through multi-level early warning analysis, users can identify and prevent potential security risks in advance, so as to achieve proactive management of security events and reduce the probability and losses of security events. This risk management mode based on digital models and simulations will greatly improve the overall performance and security of the monitoring system.

[0063] Preferably, the steps of constructing a security early warning management framework based on the results of multi-level analysis and a set of security early warning management tags corresponding to the security early warning management framework include: S25: Analyze the management elements of each of the several event scenario patterns included in the security risk early warning object based on the monitoring architecture digital model to obtain the management element feature distributions of each event scenario pattern corresponding to the monitoring architecture digital model; wherein, the management element feature distribution includes several pattern management elements and the logical connection relationships between each of the pattern management elements, and the pattern management elements are used to control the device working parameters of each monitoring device corresponding to the monitoring architecture digital model; S26: Conduct a commonality analysis on the management element feature distributions of each of the event scenario patterns, and based on the results of the commonality analysis, summarize the management element feature distributions of each of the event scenario patterns to obtain the basic management elements for the commonality generalization of each of the event scenario patterns and the logical connection relationships between each of the basic management elements; S27: Integrate the processes of each of the basic management elements according to the logical connection relationships to obtain a security early warning management framework; S28: Analyze the security early warning management setting requirements for each of the event scenario patterns of the security risk early warning object according to the security early warning management framework to obtain the security early warning management setting schemes of the security early warning management framework corresponding to each of the event scenario patterns; wherein, the security early warning management setting scheme includes the element setting content of each basic management element corresponding to the event scenario pattern; S29: Parse and unify the element setting content of each of the security early warning management setting schemes to convert the element setting content into security early warning management tags, and each of the security early warning management tags together constitutes a set of security early warning management tags.

[0064] Specifically, first, based on the digital model of the monitoring architecture, for each event scenario pattern (such as equipment failure, intrusion, fire, etc.), an analysis of management elements is carried out. The management elements include: the working status of monitoring devices, performance parameters (such as temperature, humidity, sensor data, etc.), the working conditions of devices (such as power, network connection, etc.), and the control logic of devices (such as alarm response, device restart, data transmission, etc.). These management element features describe the working behaviors and states of devices under event scenario patterns and provide a basis for subsequent control and early warning strategies.

[0065] More specifically, for each event scenario pattern, by analyzing the management element features of different monitoring devices, the feature distribution among devices is obtained. For example, in the intrusion pattern, the working parameters of sensors and cameras, such as alarm thresholds, video stream transmission quality, etc., are key monitored. In the fire pattern, the working conditions and response parameters of temperature sensors and smoke detectors are monitored. By analyzing these management elements, the feature differences among devices and the relevance of their management elements in different scenario patterns can be discovered.

[0066] More specifically, a commonality analysis is carried out on the management element feature distributions of various event scenario patterns. The purpose of the commonality analysis is to find the similarities between different event scenario patterns. For example, there may be common management elements such as device status monitoring and environmental monitoring in all event scenario patterns. By comparing the management elements of different scenario patterns, the common features and applicable scopes of these elements are identified.

[0067] More specifically, based on the results of the commonality analysis, a general summary of management elements is carried out to obtain basic management elements. These basic management elements have wide applicability and can cover the management requirements under multiple event scenario patterns. The basic management elements include: device status monitoring, environmental monitoring, data transmission and storage, security response and alarm mechanisms, etc. These basic management elements will become the core content of the subsequent security early warning management framework.

[0068] More specifically, after obtaining the basic management elements, process integration is carried out according to their logical connection relationships. For example, device status monitoring may rely on the real-time data of environmental monitoring, the results of real-time data monitoring may affect the security response strategy, and the security response strategy is combined with the alarm mechanism to form an automated response process. Through these logical connections, a complete security early warning management framework is constructed. This framework describes the entire process from data collection, status monitoring to response operations.

[0069] More specifically, according to the security warning management framework, a requirements analysis is conducted for the security warning requirements of each event scenario mode. For example, for the intrusion event mode, it may be necessary to set alarm thresholds, an automatic alarm triggering mechanism, record event data, etc. For the fire event mode, it may be necessary to set temperature change alarms, automatically start fire-fighting equipment, etc. These analyses will provide a basis for formulating specific security warning management plans.

[0070] More specifically, based on the requirements analysis, a security warning management setting plan is constructed for each event scenario mode. This plan includes: the setting content of each basic management element, such as setting temperature thresholds, alarm mechanisms, event handling rules, etc. The plan will clarify the management requirements for each event scenario mode and achieve warning and response through specific settings.

[0071] More specifically, the element setting content of each security warning management setting plan is analyzed and unified. The element setting content includes: the management parameter settings of various devices (such as device working status, environmental parameters, etc.), the settings of security response mechanisms (such as alarm response, data processing, etc.). These contents will be standardized to ensure the consistency of management element settings in different devices and scenarios.

[0072] More specifically, according to the element setting content, corresponding security warning management labels are generated. Each label will represent specific management element setting content. For example: Intrusion alarm label: including intrusion detection threshold, alarm level, etc., Fire alarm label: including temperature range, alarm level, response measures, etc. All the generated labels will jointly form a security warning management label set, which contains the warning management requirements for all event scenario modes.

[0073] More specifically, finally, all the security warning management labels will be summarized into a set, which is the core part of the security warning management framework. The label set enables the system to flexibly adjust and apply different warning management strategies based on different security scenarios.

[0074] It can be understood that by analyzing and summarizing the commonality of management elements for different event scenario modes, the settings of management elements can be standardized. This not only ensures the unity of management elements but also improves the adaptability of security management strategies and the operability across scenarios. By constructing a comprehensive security warning management framework and setting plan, it can be ensured that the system can quickly identify and make effective responses when facing different security events. The system can automatically adjust warning strategies and optimize response processes according to the characteristics of different event scenario modes.

[0075] More specifically, through the unified processing of element settings, the system can quickly generate corresponding security warning management tags. These tags can accurately describe the management requirements of each event scenario mode and can be flexibly applied to each device in the monitoring system, greatly improving the configuration efficiency and operation simplicity of the system. The generated set of security warning management tags can be flexibly adjusted according to actual needs, enabling the system to quickly achieve personalized configuration of warning management for different monitoring scenarios and devices. This flexibility greatly enhances the ability of the monitoring system to respond to complex security threats. Through the analysis and setting based on the event scenario mode, the constructed security warning management framework has strong scalability. In the future, if new security risk scenarios or devices are added, the system can quickly generate tags and adjust the warning management strategy according to the new scenario characteristics.

[0076] Preferably, the steps of receiving an interaction instruction of a user account through the security warning cloud platform and scheduling security warning management tags for the set of security warning management tags according to the interaction instruction to fill into the security warning management framework to generate a real-time management model include: S31: Receive an interaction instruction of a user account through the security warning cloud platform; wherein, the interaction instruction of the user account is used for the user to perform an operation matching the current event scenario mode on the security warning management framework and the set of security warning management tags; S32: Schedule security warning management tags for the set of security warning management tags according to the interaction instruction to fill the security warning management tags onto the basic management elements in the security warning management framework, and endow the basic management elements with element characteristics according to the security warning management tags, so that the basic management elements of the security warning management framework adapt to the current event scenario mode; S33: Conduct an overall logical connection analysis on each basic management element filled with security warning management tags in the security warning management framework to obtain a real-time management model.

[0077] Specifically, the user sends an interaction instruction through the operation interface of the security warning cloud platform (such as the Web side or the mobile APP). The instruction content includes: the current event scenario mode (such as network intrusion, environmental anomaly, device disconnection, etc.), the security policy that the user hopes to enable or adjust; specific warning policy targets (such as real-time alarm, automatic response, data retention, etc.). The cloud platform analyzes the user account permissions and the instruction content and identifies the management tags and policy adjustment targets to be activated.

[0078] More specifically, according to the identified event scenario pattern, the system filters out a subset of tags that match the current scenario pattern from the set of security warning management tags. The tag content includes control rules, set parameters, and behavior response patterns for a certain management element. The selected security warning management tags are filled in one by one according to the mapping relationship of the basic management elements of the warning management framework. Each basic management element is assigned specific security characteristic values (such as set thresholds, alarm levels, processing time limits, etc.). The characteristic parameters defined in the filled tags will be injected into the corresponding management elements, thereby realizing the personalized customization and parameterization of each management element.

[0079] More specifically, after the management elements are assigned values, the system conducts a verification of the overall logical relationship and dynamic analysis of the entire security warning management framework. The analysis content includes: whether the dependency relationship between elements is closed-loop; whether the data flow, control flow, and response flow are smooth; whether there are logical conflicts or policy redundancies.

[0080] More specifically, a real-time management model is constructed. This model: reflects the optimal security control strategy under the current event scenario pattern, supports real-time monitoring of event evolution, supports dynamic adjustment and intelligent response. The model will run continuously in the background to guide the system to conduct dynamic monitoring and real-time warning of device or environmental data.

[0081] It can be understood that through the user interaction instruction, the precise docking with the current actual scenario is achieved, enabling the security warning management tags to be dynamically scheduled according to the actual situation, realizing the real-time coupling of management content and event scenarios. The system dynamically combines targeted management strategies by filling the tags into the basic elements of the management framework, meeting the personalized warning requirements in different industries and different scenarios, and greatly improving the strategy adaptability and scalability.

[0082] More specifically, through the automatic tag scheduling and logical analysis mechanism, a real-time management model adapted to the current event is quickly generated, ensuring that the system can enter the working state in an extremely short time, improving the real-time performance and response efficiency of the warning. Each security warning management tag defines the management content with the smallest granularity. After filling, a security policy structure with clear granularity and detailed control is formed, which is conducive to later policy maintenance, optimization, and AI automatic learning and upgrading. The user instruction becomes an important trigger mechanism for model scheduling, making the cooperation between humans and machines close; the cloud platform not only executes the policy but also can guide, recommend, or feedback better management paths, forming a closed-loop warning optimization system.

[0083] Preferably, the steps of deploying device working parameters for the monitoring devices registered in the user account according to the real-time management model to drive the monitoring devices to switch to a specified monitoring mode to collect monitoring data, and performing security warning analysis on the monitoring data by the real-time management model in terms of the overall spatio-temporal correlation dimension and the continuous spatio-temporal trend dimension to obtain a security risk warning result include: S41: Deploy device working parameters for the monitoring devices registered in the user account according to the real-time management model to drive the monitoring devices to adjust device performance according to the deployed device working parameters, so as to switch the monitoring devices to a monitoring mode that conforms to the real-time management model; S42: Substitute the monitoring data collected by each monitoring device into the monitoring architecture digital model, and extract the distribution form of key data features of the monitoring architecture digital model into which the monitoring data is substituted, so as to obtain the real-time management data features of each time node; S43: Perform node vector conversion of the overall spatio-temporal layout on the real-time management data features through the real-time management model to obtain an overall spatio-temporal feature vector matrix corresponding to the real-time management data features, and perform cross-validation between each feature vector of the overall spatio-temporal feature vector matrix, so as to perform security warning analysis on the real-time management data features in terms of the overall spatio-temporal correlation dimension according to the cross-validation result, and obtain the overall spatio-temporal correlation warning feature distribution of the current time node; S44: Perform time series change analysis on the overall spatio-temporal feature vector matrices of each time node to obtain the continuous spatio-temporal trend dimension features shown by the overall spatio-temporal feature vector matrices of each time node in the continuous spatio-temporal trend dimension, and perform reference verification and warning evaluation on the overall spatio-temporal correlation warning feature distribution of the current time node according to the continuous spatio-temporal trend dimension features, so as to obtain a security risk warning result.

[0084] Specifically, the system automatically sets working parameters for each monitoring device registered under the user account according to the monitoring strategy defined in the real-time management model. The parameter content includes: selection of monitoring mode (such as panoramic monitoring, dynamic monitoring, abnormal behavior detection mode, etc.), device acquisition frequency, data format, threshold setting, etc.

[0085] More specifically, according to the deployed parameters, the monitoring device will perform corresponding performance adjustments (such as adjusting resolution, sensor sensitivity, acquisition period, etc.), and the device switches to a monitoring mode that conforms to the real-time management model and is ready to start collecting data.

[0086] More specifically, each monitoring device starts collecting monitoring data according to the set parameters, such as images, videos, temperature and humidity sensor data, device status data, etc. The collected data is substituted into a pre-designed digital model of the monitoring architecture, which defines the data flow and management framework. By substituting the data, the system generates corresponding real-time management data features for each time node.

[0087] More specifically, feature extraction is performed on the substituted data to obtain the distribution information of the monitoring data in key dimensions. For example, activity recognition features in the video stream, change features of temperature and humidity data, abnormal fluctuations in device status, etc. are extracted.

[0088] More specifically, the real-time management model is used to perform an overall spatio-temporal layout on the extracted real-time management data features, converting the data into the form of node vectors. Each node vector represents all the monitoring features of a time node, including spatio-temporal position and data features in the time series. Through the conversion of the node vectors in the spatio-temporal layout, an overall spatio-temporal feature vector matrix is formed, which expresses the relationship between all time nodes and spatio-temporal features.

[0089] More specifically, cross-validation is performed among the various feature vectors in the spatio-temporal feature vector matrix. By calculating the correlation between features, it is detected whether there are abnormal or potential risk patterns. According to the results of the cross-validation, a security warning analysis of the spatio-temporal correlation dimension is carried out to obtain the overall spatio-temporal correlation warning feature distribution of the current time node.

[0090] More specifically, a temporal variation analysis is performed on the overall spatio-temporal feature vector matrix of each time node to extract continuous spatio-temporal trend dimension features. This analysis helps to identify long-term trends and fluctuation patterns in the monitoring data. Based on the temporal variation analysis, continuous spatio-temporal trend dimension features are extracted, which are helpful for capturing the continuous change trends of the data in time and space.

[0091] More specifically, according to the continuous spatio-temporal trend dimension features, reference verification and warning evaluation are carried out to analyze whether there are potential security risks. If some features deviate significantly from the historical trends, the system will issue a warning and generate a security risk warning result.

[0092] It is understandable that through the dynamic deployment of the real-time management model and the adjustment of device parameters, it is ensured that the monitoring device can quickly and accurately switch to the most suitable monitoring mode to meet the security requirements in different scenarios. This automated management ability greatly improves the adaptability and efficiency of the device. Through the feature extraction and spatio-temporal correlation analysis of monitoring data, the system can extract key features from a large amount of monitoring data and conduct accurate security risk assessments. This analysis provides powerful data visualization and correlation analysis capabilities, facilitating the discovery of potential security hazards. Through time series analysis and the extraction of continuous spatio-temporal trend dimensions, the system can identify the changing trends in the data and predict possible future security risks. This trend prediction ability helps to identify potential problems in advance and issue early warnings, thereby reducing the response time and optimizing decision-making. The combination of overall spatio-temporal correlation and continuous spatio-temporal trend dimensions ensures the comprehensiveness and depth of security warning analysis, enabling three-dimensional analysis of monitoring data in multiple dimensions and realizing the comprehensive identification and warning of abnormal behaviors, system failures, and security threats.

[0093] Referring to Figure 2 As shown, in a second aspect, the present invention provides a security risk warning system based on a low-code cloud platform for implementing a security risk warning method based on a low-code cloud platform according to any one of the first aspects, including: An architecture analysis module, configured to receive the monitoring device installation information registered by a user account through a specified security warning cloud platform and perform digital simulation of the monitoring system architecture on the monitoring device installation information to obtain a corresponding monitoring architecture digital model; A framework construction module, configured to perform multi-level analysis of the security risk warning requirements on the monitoring architecture digital model and construct a security warning management framework and a set of security warning management labels corresponding to the security warning management framework based on the results of the multi-level analysis; A real-time management module, configured to receive an interaction instruction of a user account through the security warning cloud platform and schedule the security warning management labels in the set of security warning management labels according to the interaction instruction to fill the security warning management framework to generate a real-time management model; A security warning module, configured to deploy device working parameters for the monitoring devices registered by the user account according to the real-time management model to drive the monitoring devices to switch to a specified monitoring mode to collect monitoring data, and perform security warning analysis on the monitoring data in terms of overall spatio-temporal correlation dimension and continuous spatio-temporal trend dimension through the real-time management model to obtain a security risk warning result.

[0094] In this embodiment, for the specific implementation of each module in the above system embodiment, please refer to that described in the above method embodiment, and details will not be repeated here.

[0095] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. A security risk early warning method based on a low-code cloud platform, characterized in that: include: Receiving monitoring equipment installation information registered by a user account through a designated security early warning cloud platform, and performing digital simulation of a monitoring system architecture on the monitoring equipment installation information to obtain a corresponding monitoring architecture digital model; Performing a multi-level analysis of security risk warning requirements on the monitoring architecture digital model, and constructing a security warning management framework and a set of security warning management tags corresponding to the security warning management framework based on the results of the multi-level analysis; Receiving interactive instructions from the user account through the security warning cloud platform, and scheduling the security warning management tags for the security warning management tag set according to the interactive instructions, so as to fill in the security warning management framework to generate a real-time management model; The device working parameters of the monitoring device registered by the user account are deployed according to the real-time management model to drive the monitoring device to switch to the specified monitoring mode to collect monitoring data, and the monitoring data is subjected to security warning analysis in the overall spatiotemporal correlation dimension and the continuous spatiotemporal trend dimension through the real-time management model to obtain security risk warning results.

2. The security risk early warning method based on the low-code cloud platform according to claim 1 is characterized in that: The steps of receiving monitoring equipment installation information registered by a user account through a designated security warning cloud platform, and performing digital simulation of a monitoring system architecture on the monitoring equipment installation information to obtain a corresponding monitoring architecture digital model include: The designated security early warning cloud platform is used for user account login, and the work environment layout information of the monitoring equipment to be deployed, the performance information of the monitoring equipment to be deployed in the work environment, and the positioning information of the monitoring equipment to be deployed in the work environment uploaded by the user account are received. The monitoring equipment performance information and positioning information of the same monitoring equipment are combined into the monitoring equipment installation information; According to the working environment layout information, a digital simulation of the working environment layout of the monitoring system composed of monitoring devices is performed to obtain a digital model of the working environment layout; The digital model of the working environment layout is digitally simulated for each monitoring device according to the monitoring device installation information of each monitoring device, so as to construct a monitoring unit digital model corresponding to each monitoring device on the digital model of the working environment layout, and the digital models of each monitoring unit are associated and connected to obtain a monitoring architecture digital model.

3. The security risk early warning method based on the low-code cloud platform according to claim 1 is characterized in that: The steps of performing a multi-level analysis of the security risk warning requirements on the monitoring architecture digital model include: The monitoring architecture digital model is used as the occurrence site of the security risk event, and the site application path of the occurrence site is analyzed to obtain the security risk warning object that the monitoring architecture digital model can feedback; wherein the security risk warning object is the basic level warning demand of the monitoring architecture digital model; According to the security risk warning object, the monitoring architecture digital model is subjected to a possibility deduction process of a security risk warning event, so as to obtain a potential warning event set of the monitoring architecture digital model corresponding to the security risk warning object; The specific scenario of the occurrence of the potential warning event set corresponding to the security risk warning object of the digital model of the monitoring architecture is simulated to obtain the specific event scenario of each warning event corresponding to the potential warning event set, and the specific event scenario of each warning event is classified to obtain the scene classification characteristics of each warning event; The various warning events of the security risk warning object are classified and processed according to the scene classification characteristics of each warning event, so as to classify each warning event into several event scene modes; wherein the event scene mode is the deep level warning requirement of the digital model of the monitoring architecture.

4. The security risk early warning method based on the low-code cloud platform according to claim 3 is characterized in that: The steps of constructing a security warning management framework and a security warning management tag set corresponding to the security warning management framework based on the results of the multi-level analysis include: Based on the monitoring architecture digital model, the management elements of the several event scenario modes included in the security risk warning object are analyzed respectively to obtain the management element characteristic distribution of the various event scenario modes corresponding to the monitoring architecture digital model; wherein the management element characteristic distribution includes several mode management elements and the logical connection relationship between each of the mode management elements, and the mode management elements are used to control the equipment working parameters of each monitoring device corresponding to the monitoring architecture digital model; Performing commonality analysis on the management element characteristic distribution of various event scenario modes, and summarizing the management element characteristic distribution of various event scenario modes based on the commonality analysis results, so as to obtain the basic management element used for commonality summary of various event scenario modes and the logical connection relationship between each of the basic management elements; According to the logical connection relationship, the processes of the basic management elements are integrated to obtain a safety early warning management framework; According to the security warning management framework, a security warning management setting demand analysis is performed on various event scenario modes of the security risk warning object to obtain a security warning management setting scheme of the security warning management framework corresponding to various event scenario modes; wherein the security warning management setting scheme includes element setting contents of various basic management elements corresponding to the event scenario mode; The element setting contents of various security warning management setting schemes are analyzed and unified to convert the element setting contents into security warning management tags, and each of the security warning management tags together constitutes a security warning management tag set.

5. The security risk early warning method based on the low-code cloud platform according to claim 4 is characterized in that: The step of receiving the interaction instruction of the user account through the security warning cloud platform, and scheduling the security warning management tag set according to the interaction instruction to fill the security warning management framework to generate a real-time management model includes: Receiving an interactive instruction of a user account through the security warning cloud platform; wherein the interactive instruction of the user account is used for the user to operate the security warning management framework and the security warning management tag set to match the current event scenario mode; Scheduling the security warning management tag of the security warning management tag set according to the interactive instruction, so as to fill the security warning management tag into the basic management element in the security warning management framework, and assigning element features to the basic management element according to the security warning management tag, so as to make the basic management element of the security warning management framework adapt to the current event scenario mode; An overall logical connection analysis is performed on various basic management elements filled with security warning management tags in the security warning management framework to obtain a real-time management model.

6. The security risk early warning method based on the low-code cloud platform according to claim 1 is characterized in that: The steps of deploying device working parameters for the monitoring device registered by the user account according to the real-time management model to drive the monitoring device to switch to a specified monitoring mode to collect monitoring data, and performing security early warning analysis on the monitoring data in the overall spatiotemporal correlation dimension and the continuous spatiotemporal trend dimension through the real-time management model to obtain a security risk early warning result include: Deploy device operating parameters for the monitoring device registered by the user account according to the real-time management model, so as to drive the monitoring device to adjust device performance according to the deployed device operating parameters, so as to switch the monitoring device to a monitoring mode that complies with the real-time management model; Substituting the monitoring data collected by each monitoring device into the monitoring architecture digital model, and extracting the key data feature distribution form of the monitoring architecture digital model into which the monitoring data is substituted, so as to obtain the real-time management data features of each time node; The real-time management model is used to perform node vector conversion of the overall spatiotemporal layout of the real-time management data features to obtain an overall spatiotemporal feature vector matrix corresponding to the real-time management data features, and the overall spatiotemporal feature vector matrix is ​​interactively verified between the feature vectors, so as to perform security early warning analysis of the overall spatiotemporal correlation dimension on the real-time management data features according to the results of the interactive verification, and obtain the overall spatiotemporal correlation early warning feature distribution of the current time node; The overall spatiotemporal feature vector matrix of each time node is subjected to time series change analysis to obtain the continuous spatiotemporal trend dimension characteristics of the overall spatiotemporal feature vector matrix of each time node on the continuous spatiotemporal trend dimension, and the overall spatiotemporal correlation warning feature distribution of the current time node is subjected to reference verification and warning evaluation on the continuous spatiotemporal trend dimension based on the continuous spatiotemporal trend dimension characteristics to obtain the safety risk warning result.

7. A security risk early warning system based on a low-code cloud platform, characterized in that: A security risk warning method based on a low-code cloud platform for implementing any one of claims 1 to 6, comprising: An architecture analysis module, used to receive monitoring equipment installation information registered by a user account through a designated security warning cloud platform, and perform digital simulation of the monitoring system architecture on the monitoring equipment installation information to obtain a corresponding monitoring architecture digital model; A framework construction module, used to perform a multi-level analysis of the security risk warning requirements on the monitoring architecture digital model, and to construct a security warning management framework and a security warning management tag set corresponding to the security warning management framework based on the results of the multi-level analysis; A real-time management module, used to receive interactive instructions from user accounts through the security warning cloud platform, and schedule security warning management tags for the security warning management tag set according to the interactive instructions, so as to fill in the security warning management framework to generate a real-time management model; The security warning module is used to deploy the equipment working parameters of the monitoring equipment registered by the user account according to the real-time management model, so as to drive the monitoring equipment to switch to the specified monitoring mode to collect monitoring data, and perform security warning analysis on the monitoring data in the overall spatiotemporal correlation dimension and the continuous spatiotemporal trend dimension through the real-time management model to obtain security risk warning results.

Citation Information

Cited By

  • Special equipment life cycle supervision method and system based on characteristic parameter monitoring

    CN120951282A