Cross-network risk association analysis prevention and control decision system and method based on knowledge graph

Through frequency classification and logistic regression algorithm based on knowledge graph, changing data is screened and accurate or split traversal methods are selected, the risk missed detection problem in cross-network risk data identification is solved, and the recognition efficiency and accuracy are improved.

CN120263447APending Publication Date: 2025-07-04WUXI INFINITY ZHIAN TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510308195.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-17
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

The prior art fails to effectively handle the changes in cross-network risk data and risk combination packages when identifying cross-network risk data, resulting in missed risk detection.

Method used

Through frequency classification and fuzzy reasoning based on knowledge graphs, change data are filtered out, file package thresholds are formulated using logistic regression algorithms, accurate or split traversal methods are selected for matching, and cross-network risk data combination packages are identified.

Benefits of technology

It improves the recognition efficiency and accuracy of cross-network risk data in the knowledge graph, reduces risk missed detection, and enhances the speed and accuracy of data proofreading.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263447A_ABST
    Figure CN120263447A_ABST
Patent Text Reader

Abstract

The invention discloses a cross-network risk association analysis prevention and control decision-making system and method based on a knowledge graph, relates to the technical field of data risk analysis, and is used for improving the risk missing detection problem caused by a risk combination packet in cross-network risk data. Attribute information of different types of cross-network risk data is obtained, frequency classification is carried out on the various types of cross-network risk data through fuzzy reasoning, the current cross-network risk data is checked before and after being transmitted, and change data is screened out. Transmission information and compression information of the change data are obtained, a logic regression algorithm is used for formulating a file package threshold value, whether the change data belong to a cross-network risk data combination package or not is judged, and accurate traversal or split traversal is selected to be conducted on the change data according to the judgment result; and finally, matching the change data with the cross-network risk data stored in the knowledge graph by using accurate traversal or split traversal, obtaining a matching output result, and transmitting the matching output result to a user side.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data risk analysis, and more specifically, to a cross-network risk association analysis, prevention and control decision-making system and method based on a knowledge graph. Background Art

[0002] Data risk analysis technology is a process of evaluating risk data through analysis methods and tools to identify, analyze, manage, and prompt risks. Applying a knowledge graph to cross-network risk management analysis and prevention and control decision-making can effectively improve the efficiency of identifying risk data.

[0003] The prior art has the following deficiencies:

[0004] When identifying cross-network risk data in the past, the changing situation of cross-network risk data and the existence of risk combination packages were not considered. The received data or data packets were directly compared with the stored database records for identification. When there are multiple risk data in the cross-network risk data, it may lead to missed risk detection. Summary of the Invention

[0005] In order to overcome the above-mentioned defects of the prior art, an embodiment of the present invention provides a cross-network risk association analysis, prevention and control decision-making method based on a knowledge graph. By classifying the frequency of comparison information in the knowledge graph, analyzing the received cross-network risk data, screening out the changing data, judging whether the changing data belongs to the cross-network risk data combination package, and selecting different traversal methods to match and proofread the risks of the changing data according to the judgment result and frequency classification to solve the problems raised in the above background art.

[0006] To achieve the above object, the present invention provides the following technical solutions:

[0007] A cross-network risk association analysis, prevention and control decision-making method based on a knowledge graph, comprising the following steps:

[0008] Step S1: Identify each cross-network risk data stored in the knowledge graph, obtain the attribute information of different types of cross-network risk data, and classify the frequency of the cross-network risk data stored in the knowledge graph according to the attribute information;

[0009] Step S2: Identify the current cross-network risk data, proofread the cross-network risk data before and after transmission, screen out the changing data, and obtain the transmission information and compression information of the changing data;

[0010] Step S3: Formulate a file package threshold for the changing data based on the transmission information and compression information of the changing data, and judge whether the changing data belongs to the cross-network risk data combination package according to the file package threshold;

[0011] Step S4: Select to perform precise traversal or split traversal on the changed data according to the judgment result, and use precise traversal or split traversal to match the changed data with the cross-network risk data stored in the knowledge graph.

[0012] In a preferred embodiment, in step S1, the attribute information of the cross-network risk data is the occurrence frequency of the cross-network risk data and the historical identification duration, and the historical identification duration is the total duration of each identification of the corresponding cross-network risk data in the history;

[0013] Use fuzzy inference to classify the cross-network risk data according to the occurrence frequency and historical identification duration of different types of cross-network risk data in the knowledge graph.

[0014] In a preferred embodiment, in step S1, the specific steps of using fuzzy recommendation to classify the network risk data according to frequency are as follows:

[0015] Input definition: Define the occurrence frequency and historical identification duration of the cross-network risk data as input variables and divide them into different fuzzy sets;

[0016] Output definition: Define the frequency classification of the cross-network risk data as the output variable;

[0017] Formulate rules: Formulate a set of fuzzy rules to describe the influence of different input variables on the output variable;

[0018] Perform fuzzy inference: Classify and mark different output variables obtained from fuzzy inference.

[0019] In a preferred embodiment, in step S2, when identifying the current cross-network risk data, proofread the file packages before and after the transmission of the current cross-network risk data, obtain the differential data packets before and after the transmission of the cross-network risk data, and screen out the differential data packets as the changed data of the cross-network risk data;

[0020] The differential data packet is the data file that is inconsistent before and after the transmission of the cross-network risk data;

[0021] The transmission information of the changed data is the maximum data file transmission duration in the changed data and the total transmission duration of the changed data; the compressed data of the changed data is the file storage space value before and after compression before the transmission of the changed data.

[0022] In a preferred embodiment, in step S3, use the ratio of the maximum data file transmission duration in the transmission information to the total transmission duration of the changed data as the transmission coefficient of the cross-network risk data; use the ratio of the file storage space value before transmission to the file storage space value after transmission in the compression information as the compression coefficient of the cross-network risk data;

[0023] Select a period of time as the analysis time. During the analysis time, obtain multiple cross-network risk data and calculate the transmission coefficient and compression coefficient respectively. Use the logistic regression algorithm to set the file package threshold according to the transmission coefficient and compression coefficient of each cross-network risk data.

[0024] In a preferred embodiment, in step S3, the specific steps of using the logistic regression algorithm to set the file package threshold are as follows:

[0025] Data preprocessing: Combine the transmission coefficients in each cross-network risk data into a transmission data set, and combine the compression coefficients in each cross-network risk data into a compression data set;

[0026] Data merging: Randomly select data from the transmission data set and the compression data set as logistic regression parameters, and construct a logistic regression method to calculate the logistic regression result: L = 1 / (1 + e -z , where L is the logistic regression result, e is the natural base, and z is the logistic regression intermediate parameter and z is the sum result of the data randomly selected from the transmission data set and the compression data set;

[0027] Data processing: Set the number of selections to n times. By selecting data from the transmission data set and the compression data set each time and calculating the logistic regression result, take the average value of the n logistic regression results as the threshold reference value for setting the file package threshold;

[0028] Set the file package threshold: Take the reciprocal of the threshold reference value as the file package threshold.

[0029] In a preferred embodiment, in step S3, use the following steps to determine whether the changed data belongs to the cross-network risk data combination package according to the changed data:

[0030] Step 1: Obtain the transmission coefficient and compression coefficient of the changed data;

[0031] Step 2: Calculate the logistic regression result through the logistic regression formula using the transmission coefficient and compression coefficient of the changed data;

[0032] Step 3: Take the reciprocal of the logistic regression result of the changed data and compare it with the file package threshold. If it exceeds the file package threshold, it is determined that the current changed data belongs to the cross-network risk data combination package; if it is lower than the file package threshold, it is determined that the current changed data belongs to the cross-network risk single data.

[0033] In a preferred embodiment, in step S4, when the judgment result of the changed data is a single cross-network risk data, precise traversal is performed to collect the attribute information of the changed data, obtain the occurrence frequency and recognition duration of the changed data, obtain the output result of the changed data through fuzzy reasoning and mark it. Traverse and match all cross-network risk data with the same classification mark stored in the knowledge graph. If the match is successful, send the location of the corresponding cross-network risk data in the knowledge graph to the user terminal. If the match fails, locate the current data in the changed data and send it to the user terminal;

[0034] When the judgment result of the changed data is a cross-network risk data combination package, split traversal is performed. The data in the changed data is sorted from largest to smallest and retrieved in the knowledge graph in the order from largest to smallest;

[0035] Randomly select a cross-network risk data under a classification mark from all classification marks in the knowledge graph for traversal and matching. If the match fails, randomly select one from the remaining classification marks for traversal and matching;

[0036] Repeat the operation. When the match is successful, switch to the next data in the sorting for retrieval; When the data in the changed data still fails to match after traversing all cross-network risk data with all classification marks in the knowledge graph, locate the current data in the changed data and send it to the user terminal.

[0037] The cross-network risk association analysis and prevention and control decision-making system based on the knowledge graph is used to implement the above-mentioned cross-network risk association analysis and prevention and control decision-making method based on the knowledge graph, including a data collection module, a graph classification module, a change analysis module, and a data matching module;

[0038] The data collection module is used to collect the attribute information, transmission information, and compression information of cross-network risk data and pass them into the graph classification module and the change analysis module;

[0039] The graph classification module classifies the cross-network risk data stored in the knowledge graph according to the attribute information of the cross-network risk data and passes it into the data matching module;

[0040] The change analysis module is used to screen out the changed data from the current cross-network risk data, formulate file package data according to the transmission information and compression information of the cross-network risk data, and judge whether the changed data belongs to the cross-network risk data combination package, and pass the judgment result into the data matching module;

[0041] The data matching module is used to receive the judgment result of the change analysis module and select to perform precise traversal or split traversal on the changed data according to the judgment result, and pass the output result obtained after the operation into the user terminal.

[0042] Technical effects and advantages of the cross-network risk association analysis and prevention and control decision-making system and method based on a knowledge graph according to the present invention:

[0043] The present invention identifies cross-network risk data stored in a knowledge graph, obtains attribute information of different types of cross-network risk data and classifies them by frequency. Before and after the current cross-network risk data is transmitted, it is proofread and the changed data is screened out. The screened changed data is used to narrow the proofreading range and improve the recognition efficiency. The transmission information and compression information of the changed data are obtained. Based on the transmission information and compression information of the changed data, a file package threshold for the changed data is formulated and it is determined whether the changed data belongs to a cross-network risk data combination package. According to the judgment result, precise traversal or split traversal is selected for the changed data. Different traversal methods are used to improve the speed and accuracy of traversal. Finally, the changed data is matched with the cross-network risk data stored in the knowledge graph by precise traversal or split traversal, thereby improving the recognition efficiency of cross-network risk data in the knowledge graph. Brief Description of the Drawings

[0044] Figure 1 It is a schematic diagram of the cross-network risk association analysis and prevention and control decision-making method based on a knowledge graph according to the present invention.

[0045] Figure 2 It is a flowchart of the cross-network risk association analysis and prevention and control decision-making system based on a knowledge graph according to the present invention. Detailed Embodiments

[0046] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0047] The present invention identifies cross-network risk data stored in a knowledge graph, obtains attribute information of different types of cross-network risk data and classifies them by frequency. Before and after the current cross-network risk data is transmitted, it is proofread and the changed data is screened out. The transmission information and compression information of the changed data are obtained. Based on the transmission information and compression information of the changed data, a file package threshold for the changed data is formulated and it is determined whether the changed data belongs to a cross-network risk data combination package. According to the judgment result, precise traversal or split traversal is selected for the changed data. Finally, the changed data is matched with the cross-network risk data stored in the knowledge graph by precise traversal or split traversal, thereby improving the recognition efficiency of cross-network risk data in the knowledge graph.

[0048] Example 1, a cross-network risk association analysis and prevention and control decision-making method based on a knowledge graph, as Figure 1As shown in the figure, it includes the following steps:

[0049] Step S1: Identify each cross-network risk data stored in the knowledge graph, obtain the attribute information of different types of cross-network risk data, and classify the cross-network risk data stored in the knowledge graph according to the attribute information by frequency;

[0050] Step S2: Identify the current cross-network risk data, proofread the cross-network risk data before and after transmission and screen out the changed data, and obtain the transmission information and compression information of the changed data;

[0051] Step S3: Formulate a file package threshold for the changed data based on the transmission information and compression information of the changed data, and determine whether the changed data belongs to the cross-network risk data combination package according to the file package threshold;

[0052] Step S4: Select to perform precise traversal or split traversal on the changed data according to the judgment result, and use the precise traversal or split traversal to match the changed data with the cross-network risk data stored in the knowledge graph.

[0053] The specific implementation is as follows:

[0054] In step S1, the attribute information of the cross-network risk data is the occurrence frequency of the cross-network risk data recorded in the historical database and the historical recognition duration. The historical recognition duration is the total duration of each recognition of the corresponding cross-network risk data in the history.

[0055] A knowledge graph is a structured graphical model for representing and organizing knowledge. By means of nodes and edges, it describes entities and the relationships between them. Matching the current cross-network risk data with the node information stored in the knowledge graph can obtain the specific information of the current cross-network risk data, so as to make better decision-making responses.

[0056] The specific steps for classifying the cross-network risk data by frequency using fuzzy inference according to the occurrence frequency and historical recognition duration of different types of cross-network risk data in the knowledge graph are as follows:

[0057] Input definition: Define the occurrence frequency and historical recognition duration of the cross-network risk data as input variables and divide them into different fuzzy sets. For example, correspond "High", "Normal", "Low" to the occurrence frequency of the cross-network risk data, and correspond "Long", "Medium", "Short" to the historical recognition duration of the cross-network risk data.

[0058] Output definition: Define the frequency classification of the cross-network risk data as the output variable. For example, correspond "ONE", "TWO", "THREE" to the frequency classification of the cross-network risk data.

[0059] Rule formulation: Formulate a set of fuzzy rules to describe the impact of different input variables on the output variable. For example, if the occurrence frequency of cross-network risk data is marked as C, the historical identification duration of cross-network risk data is marked as T, and the frequency classification of cross-network risk data is marked as P, then it can be defined as

[0060] Rule1: IF (C is High) AND (T is Long) THEN (P is ONE)

[0061] Rule2: IF (C is Normal) AND (T is Medium) THEN (P is TWO)

[0062] Rule3: IF (C is Low) AND (T is Short) THEN (P is THREE) ...

[0064] Fuzzy inference: When the output result is "ONE", mark the frequency classification of cross-network risk data as high; when the output result is "TWO", mark the frequency classification of cross-network risk data as medium; when the output result is "THREE", mark the frequency classification of cross-network risk data as low, and classify and mark all cross-network risk data stored in the knowledge graph.

[0065] It should be noted that the historical database is a database used to store and manage historical data, which is used to obtain the occurrence frequency and historical identification duration of cross-network risk data. The classification categories of fuzzy sets can be adjusted according to the actual situation to make subsequent data matching faster and more convenient. In this example, only three fuzzy sets are used for illustration. In addition, the judgment of high, medium, and low for the occurrence frequency and historical identification duration of cross-network risk data in this example can be set according to the required accuracy. For example, when the occurrence frequency of cross-network risk data exceeds 20 times and the historical identification duration exceeds 24 hours, it is marked as "High" and "Long", etc., which will not be elaborated here.

[0066] In step S2, monitor the cross-network risk data through the security information system, proofread the cross-network risk data before and after transmission, obtain the differential data packets of the cross-network risk data before and after transmission, and screen out the differential data packets as the changed data of the cross-network risk data;

[0067] The transmission information of the changed data is the maximum data file transmission duration and the total transmission duration of the changed data; the compressed data of the changed data is the file storage space value before and after compression of the changed data before transmission;

[0068] The longer the maximum data file transfer duration in the variable data, the more likely the largest data file is to have a risk file implanted, and the more attention is required; the larger the occupied space of the files before and after transmission compression in the variable data, the greater the detection difficulty of implanting small risk files, and the more attention is required;

[0069] It should be noted that the security information system is a system for collecting, storing, analyzing, and managing security-related data. In this example, it is used to proofread cross-network risk data before and after transmission and screen out new data that appears during transmission, that is, the variable data that appears during the transmission process.

[0070] In step S3, the collected transmission information and compression information are processed. The ratio of the maximum data file transfer duration in the transmission information to the total variable data transfer duration is used as the transmission coefficient of the cross-network risk data; the ratio of the occupied space value of the file before transmission to the occupied space value of the file after transmission in the compression information is used as the compression coefficient of the cross-network risk data;

[0071] Select a period of time as the analysis time. Obtain multiple cross-network risk data within the analysis time and calculate the transmission coefficient and compression coefficient respectively. Use the logistic regression algorithm to set the file package threshold according to the transmission coefficient and compression coefficient of each cross-network risk data. The specific steps are as follows:

[0072] Data preprocessing: Combine the transmission coefficients in each cross-network risk data into a transmission data set, and combine the compression coefficients in each cross-network risk data into a compression data set;

[0073] Data merging: Randomly select data in the transmission data set and the compression data set as logistic regression parameters, and construct a logistic regression method to calculate the logistic regression result: L = 1 / (1 + e -z , where L is the logistic regression result, e is the natural logarithm base, and z is the logistic regression intermediate parameter and z is the sum result of the data randomly selected from the transmission data set and the compression data set;

[0074] Data processing: Set the number of selections to n times. By selecting data in the transmission data set and the compression data set each time and calculating the logistic regression result, take the average value of the n logistic regression results as the threshold reference value for setting the file package threshold;

[0075] Set the file package threshold: Take the reciprocal of the threshold reference value as the file package threshold.

[0076] After obtaining the file package threshold, use the following steps to determine whether the variable data belongs to the cross-network risk data combination package according to the variable data:

[0077] Step 1: Obtain the transmission coefficient and compression coefficient of the variable data;

[0078] Step 2: Calculate the logistic regression result through the logistic regression formula by varying the transmission coefficient and compression coefficient of the data;

[0079] Step 3: Take the reciprocal of the logistic regression result of the varying data and compare it with the file package threshold. If it exceeds the file package threshold, it is determined that the current varying data belongs to the cross-network risk data combination package; if it is lower than the file package threshold, it is determined that the current varying data belongs to the cross-network risk single data.

[0080] It should be noted that the greater the transmission coefficient or compression coefficient in the cross-network risk data, the greater the potential network security risk, the more likely it is to have a cross-network risk data combination package, and the more necessary it is to lower the file package threshold. The logistic regression result calculated from the transmission coefficient and compression coefficient has a positive correlation with the two influencing parameters. The reciprocal of the logistic regression result can be taken to change the positive correlation to a negative correlation, thereby achieving the purpose of lowering the file package threshold.

[0081] In step S4, when the judgment result of the varying data is cross-network risk single data, a precise traversal operation is performed. The specific operation steps are as follows:

[0082] Collect the attribute information of the varying data, obtain the occurrence frequency and estimated attribution classification of the varying data by identifying the duration, obtain the output result of the varying data through fuzzy reasoning and mark it. Traverse and match all cross-network risk data with the same classification mark stored in the knowledge graph. If the match is successful, send the location of the corresponding cross-network risk data in the knowledge graph to the user side;

[0083] When the judgment result of the varying data is cross-network risk data combination package, a split traversal is performed. The specific operation steps are as follows:

[0084] First, sort the data in the varying data from largest to smallest and retrieve it in the knowledge graph in the order from largest to smallest;

[0085] Randomly select a cross-network risk data under a classification mark from all classification marks in the knowledge graph for traversal and matching. If the match fails, randomly select one from the remaining classification marks for traversal and matching;

[0086] Repeat the operation. When the match is successful, switch to the next data in the sorting for retrieval; when the data in the varying data still fails to match after traversing all cross-network risk data with all classification marks in the knowledge graph, locate the current data in the varying data and send it to the user side.

[0087] By performing precise traversal or separate traversal on the varying data, the recognition efficiency of cross-network risk data in the knowledge graph is improved, which is also convenient for subsequent users to further analyze and process it.

[0088] Embodiment 2, a cross-network risk association analysis and prevention and control decision-making system based on a knowledge graph, as follows Figure 2 shown, for implementing the above-mentioned cross-network risk association analysis and prevention and control decision-making method based on a knowledge graph, including a data collection module, a graph classification module, a change analysis module, and a data matching module;

[0089] The data collection module is used to collect the attribute information, transmission information, and compression information of cross-network risk data and transmit them to the graph classification module and the change analysis module;

[0090] The graph classification module classifies the cross-network risk data stored in the knowledge graph according to the attribute information of the cross-network risk data and transmits it to the data matching module;

[0091] The change analysis module is used to screen out the changed data in the current cross-network risk data, formulate file package data according to the transmission information and compression information of the cross-network risk data, and determine whether the changed data belongs to the cross-network risk data combination package, and transmit the judgment result to the data matching module;

[0092] The data matching module is used to receive the judgment result of the change analysis module and select to perform precise traversal or split traversal on the changed data according to the judgment result, and transmit the output result obtained after the operation to the user side.

[0093] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product.

[0094] Those of ordinary skill in the art can realize that the modules and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and the inventive constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0095] In addition, the functional modules in each embodiment of the present application can be integrated into one processing module, or each module can exist physically alone, or two or more modules can be integrated into one module.

[0096] As described above, only the specific implementation manners of the present application are provided, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0097] Finally, the above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. A cross-network risk association analysis and prevention and control decision-making method based on a knowledge graph, characterized in that including the following steps, Step S1: Identify each cross-network risk data stored in the knowledge graph, obtain the attribute information of different types of cross-network risk data, and classify the cross-network risk data stored in the knowledge graph according to the frequency based on the attribute information; Step S2: Identify the current cross-network risk data, proofread and screen out the changed data before and after the transmission of the cross-network risk data, and obtain the transmission information and compression information of the changed data; Step S3: Formulate a file package threshold for the changed data based on the transmission information and compression information of the changed data, and determine whether the changed data belongs to the cross-network risk data combination package according to the file package threshold; Step S4: Select to perform precise traversal or split traversal on the changed data according to the judgment result, and use precise traversal or split traversal to match the changed data with the cross-network risk data stored in the knowledge graph.

2. The cross-network risk association analysis and prevention and control decision-making method based on a knowledge graph according to claim 1, characterized in that: In step S1, the attribute information of the cross-network risk data is the occurrence frequency and historical identification duration of the cross-network risk data, and the historical identification duration is the total duration of each identification of the corresponding cross-network risk data in history; Use fuzzy reasoning to classify the cross-network risk data according to the occurrence frequency and historical identification duration of different types of cross-network risk data in the knowledge graph.

3. The cross-network risk association analysis and prevention and control decision-making method based on a knowledge graph according to claim 2, characterized in that: In step S1, the specific steps of using fuzzy recommendation to classify the network risk data according to frequency are as follows: Input definition: Define the occurrence frequency and historical identification duration of the cross-network risk data as input variables and divide them into different fuzzy sets; Output definition: Define the frequency classification of the cross-network risk data as the output variable; Formulate rules: Formulate a set of fuzzy rules to describe the influence of different input variables on the output variable; Perform fuzzy reasoning: Classify and label different output variables obtained from the fuzzy reasoning.

4. The cross-network risk association analysis and prevention and control decision-making method based on a knowledge graph according to claim 1, characterized in that: In step S2, when identifying the current cross-network risk data, proofread the file package of the current cross-network risk data before and after transmission, obtain the differential data package of the cross-network risk data before and after transmission, and screen out the differential data package as the changed data of the cross-network risk data; The differential data package is the data file that is inconsistent before and after the transmission of the cross-network risk data; The transmission information of the changed data is the maximum data file transmission duration and the total transmission duration of the changed data; the compressed data of the changed data is the file storage space value before and after compression of the changed data before transmission.

5. The cross-network risk association analysis and prevention and control decision-making method based on a knowledge graph according to claim 4, characterized in that: In step S3, the ratio of the maximum data file transfer duration in the transmission information to the total variable data transfer duration is used as the transmission coefficient of the cross-network risk data; the ratio of the pre-transmission file storage space value to the post-transmission file storage space value in the compression information is used as the compression coefficient of the cross-network risk data; Select a period of time as the analysis time. Obtain multiple cross-network risk data within the analysis time and calculate the transmission coefficient and compression coefficient respectively. Use the logistic regression algorithm to formulate a file package threshold based on the transmission coefficient and compression coefficient of each cross-network risk data.

6. The cross-network risk association analysis and prevention and control decision-making method based on a knowledge graph according to claim 5, wherein: In step S3, the specific steps of using the logistic regression algorithm to formulate a file package threshold are as follows: Data preprocessing: Combine the transmission coefficients in each cross-network risk data into a transmission data set, and combine the compression coefficients in each cross-network risk data into a compression data set; Data merging: Randomly select data from the transmission dataset and the compressed dataset as the logistic regression parameters, and construct a logistic regression method to calculate the logistic regression result: L = 1 / (1 + e -z , where L is the logistic regression result, e is the natural base, and z is the logistic regression intermediate parameter and z is the sum of the data randomly selected from the transmission dataset and the compressed dataset; Data processing: Set the number of selections to n times. By selecting data in the transmission data set and the compression data set each time and calculating the logistic regression result, take the average of the n logistic regression results as the threshold reference value for formulating the file package threshold; Formulate a file package threshold: Take the reciprocal of the threshold reference value as the file package threshold.

7. The cross-network risk association analysis and prevention and control decision-making method based on a knowledge graph according to claim 6, wherein: In step S3, according to the variable data, use the following steps to determine whether it belongs to a cross-network risk data combination package: Step 1: Obtain the transmission coefficient and compression coefficient of the variable data; Step 2: Calculate the logistic regression result through the logistic regression formula using the transmission coefficient and compression coefficient of the variable data; Step 3: Take the reciprocal of the logistic regression result of the variable data and compare it with the file package threshold. If it exceeds the file package threshold, it is determined that the current variable data belongs to a cross-network risk data combination package; If it is lower than the file package threshold, it is determined that the current variable data belongs to a cross-network risk single data.

8. The cross-network risk association analysis and prevention and control decision-making method based on a knowledge graph according to claim 7, wherein: In step S4, when the judgment result of the variable data is cross-network risk single data, perform precise traversal, collect the attribute information of the variable data, obtain the occurrence frequency and recognition duration of the variable data, obtain the output result of the variable data through fuzzy reasoning and mark it. Traverse and match all cross-network risk data with the same classification mark stored in the knowledge graph. If the match is successful, send the location of the corresponding cross-network risk data in the knowledge graph to the user terminal. If the match fails, locate the current data in the variable data and send it to the user terminal; When the judgment result of the variable data is a cross-network risk data combination package, perform split traversal, sort the data in the variable data from large to small, and retrieve it in the knowledge graph in the order from large to small; Randomly select a cross-network risk data under a classification mark from all classification marks in the knowledge graph for traversal and matching. If the match fails, randomly select one from the remaining classification marks for traversal and matching; Repeat the operation. When the match is successful, switch to the next data in the sorting for retrieval; when the data in the changed data has not been successfully matched after traversing all the cross-network risk data with classification tags in the knowledge graph, locate the current data in the changed data and send it to the user side.

9. A cross-network risk correlation analysis and prevention and control decision-making system based on a knowledge graph, based on the cross-network risk correlation analysis and prevention and control decision-making method according to any one of claims 1-8, characterized in that, It includes a data acquisition module, a graph classification module, a change analysis module, and a data matching module; The data acquisition module is used to collect the attribute information, transmission information, and compression information of the cross-network risk data and pass them into the graph classification module and the change analysis module; The graph classification module classifies the cross-network risk data stored in the knowledge graph according to the attribute information of the cross-network risk data and passes it into the data matching module; The change analysis module is used to screen out the changed data from the current cross-network risk data, formulate file package data according to the transmission information and compression information of the cross-network risk data, and judge whether the changed data belongs to the cross-network risk data combination package, and pass the judgment result into the data matching module; The data matching module is used to receive the judgment result of the change analysis module and select to perform precise traversal or split traversal on the changed data according to the judgment result, and pass the output result obtained after the operation into the user side.