Distributed network threat intelligent monitoring method and system based on artificial intelligence
By dynamically controlling the granularity of data sampling and building behavioral graphs and causal graphs, identifying main cause nodes, quantifying attack path risks, and generating response strategies, the problems of large resource consumption and insufficient perception capabilities of distributed network threat detection systems are solved, and detection efficiency is improved and clear decision support is provided.
Patent Information
- Application Number
- CN202510732485.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-04
- Publication Date
- 2025-07-04
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, distributed network threat detection systems consume a lot of resources, lack the ability to perceive key threat behaviors, and cannot restore the evolution path of attack behavior. Moreover, the output results of the AI model are difficult to interpret or be used for actual security responses due to the lack of context semantics.
A distributed network threat intelligent monitoring method based on artificial intelligence is adopted to calculate the intensity and focus value of behavior mutations, dynamically regulate the granularity of data sampling, construct behavioral graphs and causal graphs, identify main cause nodes, quantify attack path risks, and generate traceable response strategies.
It realizes accurate resource allocation and threat area focus, improves system detection efficiency, provides clear attack interpretation diagrams and decision support, and enhances the credibility and explanatory nature of system output.
Smart Images

Figure CN120263544A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of intelligent monitoring, and particularly relates to an intelligent monitoring method and system for distributed network threats based on artificial intelligence. Background Technique
[0002] In modern distributed network architectures, with the widespread deployment of edge computing, cloud platforms, and Internet of Things terminals, network boundaries have become more blurred, and attack paths have become more diverse and complex. Attackers usually use multiple nodes for distributed and phased latent and penetration operations, such as typical threat methods like APT attacks, lateral penetration, and low-frequency slow scans. Such threats often span time dimensions, device boundaries, and protocol levels, showing fragmented behaviors, hidden semantics, and delayed responses, posing significant challenges to traditional network security defense systems.
[0003] Currently, mainstream threat detection systems mostly rely on centralized processing by central nodes or deploy lightweight detection models at the edge for local analysis. However, these methods generally have several technical limitations: (1) Adopting a data reporting strategy with fixed frequencies and fixed granularities leads to high system resource consumption and insufficient perception of key threat behaviors; (2) Most models are static classifiers and cannot reconstruct the evolution path of attack behaviors, lacking the ability to model the sequence logic and causal chains of threat occurrences; (3) The information processing and reasoning modules are fragmented, and edge nodes cannot adjust detection strategies based on context, while the central system cannot comprehensively grasp the evolution trend of node behaviors; (4) Although current AI models have certain learning and generalization abilities, due to the lack of context semantics and unclear causal structures, the output results are difficult to interpret or used for actual security responses.
[0004] Therefore, we propose an intelligent monitoring method and system for distributed network threats based on artificial intelligence to solve the above problems. Summary of the Invention
[0005] The purpose of the present invention is to solve the problems in the prior art, such as high system resource consumption, insufficient perception of key threat behaviors, and inability to reconstruct the evolution path of attack behaviors, and to propose an intelligent monitoring method and system for distributed network threats based on artificial intelligence.
[0006] To achieve the above purpose, the present invention adopts the following technical solutions:
[0007] An intelligent monitoring method for distributed network threats based on artificial intelligence, comprising:
[0008] S1: Input a first behavior feature vector and a second behavior feature vector;
[0009] Calculate the behavior mutation intensity of a node within a time window based on the first behavior feature vector and the second behavior feature vector;
[0010] Calculate the behavior focus value of the node in combination with the complexity entropy of the behavior distribution;
[0011] S2: Establish a piecewise mapping function to map the behavior focus value to the sampling level;
[0012] Output the sampling level, and obtain a set of structured sampling data packets based on the determined granularity after the sampling level;
[0013] S3: Perform a normalization mapping on the set of structured sampling data packets to obtain a standard event representation vector;
[0014] Incorporate the standard event representation vectors of all nodes in all time windows into a unified graph structure to obtain a behavior graph. The node set of the behavior graph is the set of standard event representation vectors, and the edge set is the speculative association between events; the edge set is obtained through multi-dimensional similarity matching;
[0015] S4: Construct a new set of directional edges based on the behavior graph. For any two nodes, each edge represents that the event of node one is a possible cause of the event of node two, and quantify its causal strength through the edge weight; establish a causal graph;
[0016] Perform main cause node identification, which is calculated through the causal activation degree index; the causal activation degree index calculates the behavior risk score of the node, which is statically mapped from its action type;
[0017] The set of nodes with the highest causal activation degree index forms the main cause node set;
[0018] S5: Calculate the risk score of the attack path. The attack path is a corresponding attack path structure composed of a set of ordered event nodes; the risk score is calculated based on the weights and path lengths of the edges of the attack path in the causal graph;
[0019] S6: Map the attack path to a phased behavior label, and construct a response score matrix according to the attack path structure and the corresponding label sequence. The elements of the response score matrix represent the adaptability to different response strategies in the attack path;
[0020] Integrate the path risk score and the strategy adaptability to generate a final response intensity vector;
[0021] The response strategy intensity vector represents the type of strategy recommended to be executed on the attack path and its priority.
[0022] Preferably, the first behavior feature vector represents the statistical result of a certain time period, which is generated in real time by the local network behavior collection component on the edge node; the second behavior feature vector is the statistical result of the previous time period of the first behavior feature vector, which is saved by the local cache of the edge node.
[0023] Preferably, the complexity entropy of the behavior distribution is estimated through a protocol frequency histogram, which is used to represent the structural diversity.
[0024] Preferably, a non-linear reinforcement term is introduced into the piecewise mapping function to amplify the granularity response at high focus values. The piecewise mapping function balances the granularity consistency between nodes through the granularity difference value between a node and its neighboring nodes in the subnet it belongs to.
[0025] Preferably, the sampling level value range is {0, 1, 2}, corresponding to low, medium, and high granularity respectively.
[0026] Preferably, the main cause node is a node whose number of edges with high causal weights exceeds a preset threshold number, and the number of high-risk behavior nodes cumulatively triggered in its subsequent path is higher than the preset threshold.
[0027] Preferably, the response scoring matrix constructs a set of recommended response actions to be executed for each path.
[0028] An artificial intelligence-based distributed network threat intelligent monitoring system includes:
[0029] A node evaluation module that inputs a first behavior feature vector and a second behavior feature vector; calculates the behavior mutation intensity of a node within a time window based on the first behavior feature vector and the second behavior feature vector; and calculates the behavior focus value of the node in combination with the complexity entropy of the behavior distribution.
[0030] A granularity control module that establishes a piecewise mapping function, maps the behavior focus value to the sampling level; outputs the sampling level, and obtains a structured sampling data packet set based on the sampling level to determine the granularity.
[0031] A behavior graph module that performs a normalization mapping on the structured sampling data packet set to obtain a standard event representation vector; incorporates the standard event representation vectors of all nodes in all time windows into a unified graph structure to obtain a behavior graph. The node set of the behavior graph is a set of standard event representation vectors, and the edge set is the speculated association between events; the edge set is matched through multi-dimensional similarity.
[0032] A causal graph module that constructs a new set of directed edges based on the behavior graph. For any two nodes, each edge represents that the event of node one is a possible cause of the event of node two, and quantifies its causal strength through the edge weight; establishes a causal graph; performs main cause node identification through calculation of the causal activation degree index; the causal activation degree index calculates the behavior risk score of a node, which is statically mapped from its action type; the main cause node set is composed of nodes with the highest causal activation degree index.
[0033] A path analysis module that calculates the risk score of an attack path, where the attack path is a corresponding attack path structure composed of a set of ordered event nodes; the risk score is calculated based on the weights and path lengths of the edges of the attack path in the causal graph.
[0034] A policy generation module that maps the attack path to stage behavior labels, constructs a response score matrix according to the attack path structure and the corresponding label sequence, where the elements of the response score matrix represent the adaptability to different response policies in the attack path; synthesizes the path risk score and the policy adaptability to generate a final response intensity vector; the response policy intensity vector represents the types of policies recommended to be executed on the attack path and their priorities.
[0035] In summary, the technical effects and advantages of the present invention are as follows: By perceiving the changing trend of the behavior of network nodes, the present invention intelligently regulates the data sampling granularity and feature reporting frequency, realizes the precise allocation of resources and focuses on the threat area, and improves the overall detection efficiency of the system. On this basis, the present invention further constructs a cross-node and cross-time context behavior model, uniformly organizes distributed event information, identifies potential threat chains and behavior logic structures, and effectively solves the problem of behavior fragmentation. In addition, to enhance the credibility and interpretability of the system output, the present invention introduces a causal relationship-based reasoning mechanism, conducts structural analysis and causal extraction on the identified behavior paths, thereby generating a traceable attack explanation graph to provide clear decision-making support for security personnel. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 It is a flowchart of the method steps in the present invention;
[0037] Figure 2 It is a schematic diagram of the system structure in the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0038] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments.
[0039] As Figure 1 shown, the distributed network threat intelligent monitoring method based on artificial intelligence includes: S1: Input the first behavior feature vector and the second behavior feature vector;
[0040] Calculate the behavior mutation intensity of the node within the time window based on the first behavior feature vector and the second behavior feature vector;
[0041] Calculate the behavior focus value of the node in combination with the complexity entropy of the behavior distribution;
[0042] S2: Establish a piecewise mapping function to map the behavior focus value to the sampling level;
[0043] Output the sampling level, and obtain a set of structured sampling data packets based on the determined granularity after the sampling level;
[0044] S3: Perform normalization mapping on the set of structured sampling data packets to obtain a standard event representation vector;
[0045] Incorporate the standard event representation vectors of all nodes in all time windows into a unified graph structure to obtain a behavior graph. The node set of the behavior graph is the set of standard event representation vectors, and the edge set is the speculative association between events; the edge set is obtained through multi-dimensional similarity matching;
[0046] S4: Construct a new set of directional edges based on the behavior graph. For any two nodes, each edge represents that the event of node one is a possible cause of the event of node two, and quantify its causal strength through the edge weight; establish a causal graph;
[0047] Perform main cause node identification through the calculation of the causal activation degree index; the causal activation degree index calculates the behavior risk score of the node, which is statically mapped from its action type;
[0048] Collect the nodes with the highest causal activation degree index to form the main cause node set;
[0049] S5: Calculate the risk score of the attack path. The attack path is a corresponding attack path structure composed of a set of ordered event nodes; the risk score is calculated based on the weights and path lengths of the edges of the attack path in the causal graph;
[0050] S6: Map the attack path to stage behavior labels, and construct a response score matrix according to the attack path structure and the corresponding label sequence. The elements of the response score matrix represent the adaptability to different response strategies in the attack path;
[0051] Integrate the path risk score and the strategy adaptability to generate the final response intensity vector;
[0052] The response strategy intensity vector represents the types of strategies recommended to be executed on the attack path and their priorities.
[0053] The specific method steps are as follows:
[0054] Step 1: Edge node behavior mutation evaluation and focus value calculation
[0055] In a distributed network system, due to limited resources, edge nodes cannot always maintain high-frequency and high-granularity data collection. Therefore, a mechanism is needed to dynamically identify which nodes are behaving abnormally during the current period and are worthy of entering the "high-density sampling" state. The task of this step is to calculate a quantitative indicator reflecting the "degree of behavioral mutation" from the network behavior statistics periodically collected locally by each node. This indicator is used to evaluate whether a node may currently be in the precursor stage of a threat. To ensure the feasibility of deployment, all calculations should be completed locally at the edge and do not rely on deep learning models. The key to the solution lies in designing a lightweight indicator function that comprehensively considers the amplitude of behavioral changes and the complexity of behavioral structures, thereby outputting a comparable "focus value".
[0056] The input of this step includes behavioral feature vectors at two time points, representing the statistical results of the current period and the previous period respectively, named as:
[0057] : representing the node within the current time window The behavioral feature vector. This vector is generated in real time by the local network behavior collection component on the edge node. Common interfaces include eBPF hooks, regular reading of iptables logs, or lightweight sampling modules based on NetFlow. The format is , where is the behavioral dimension (usually 3 to 5). For example, a typical vector is:
[0058]
[0059] Each item represents in turn: TCP connection change rate, number of DNS requests, proportion of non-standard ports, connection failure rate, protocol distribution entropy. The vector is a floating point number and has been normalized locally.
[0060] : the behavioral feature vector of the node in the previous time window, which is saved in the local cache of the node and is used in the same way as .
[0061] Details of the step:
[0062] This step includes two calculation stages: behavioral mutation measurement and behavioral complexity evaluation.
[0063] First, calculate the behavioral mutation intensity value:
[0064]
[0065] Where:
[0066] : The behavior mutation intensity of the node within the current time window ;
[0067] : Vector The value of the -th dimension in
[0068] : The behavior weight of each dimension, with a value range of [0,1], distributed by the central configuration;
[0069] : The number of dimensions of the behavior vector, limited to 3 - 5.
[0070] Then, combined with the complexity entropy of the behavior distribution, calculate the final focus value:
[0071]
[0072] Where:
[0073] : The behavior focus value of the current node, which is the final output; ;
[0074] : The balance coefficient, usually set to ;
[0075] : The Shannon entropy of the protocol usage distribution of the node at the current time period, estimated through the protocol frequency histogram, representing structural diversity.
[0076] During the calculation, is the entropy value calculated after constructing a histogram from the protocol distribution part (such as the TCP / UDP ratio) included in .
[0077] For example: If a certain node has 30 TCP connections and diverse port types during , and the number of TCP connections rises to 180 during , and more than 90% of the accesses are to the same port (such as 445), then will increase significantly, will decrease, resulting in increasing sharply, indicating potential threat behavior of the node.
[0078] Output:
[0079] : The behavior focus value, used for the determination of the next granularity regulation;
[0080] : The behavior mutation intensity value is used to assist in grading and judging the rate of change of node states.
[0081] Step 2: Dynamic Granularity Control and Data Sampling Scheduling
[0082] This step aims to, based on the focusing value calculated in the previous step and the mutation intensity , adaptively regulate the current data sampling granularity of edge nodes, and determine the data density and accuracy that each node should collect in the current cycle. This mechanism serves the core goal of this patent system - to achieve resource-controllable high-quality threat perception in a large-scale distributed network. Different from traditional sampling mechanisms based on static rule configurations, this step not only makes a hierarchical judgment based on the degree of behavior mutation, but also introduces a non-linear mapping function with regular constraints to avoid data structure instability caused by sampling fluctuations, and ensure the structural continuity and semantic integrity of the subsequent context behavior graph. In addition, aiming at problems such as data heterogeneity, time asynchrony, and attack diversity existing in distributed networks, this step also designs a cross-node sampling consistency adjustment mechanism to prevent sampling strategy deviations of multiple edge nodes from being too large in the same attack scenario and affecting the global graph modeling effect.
[0083] To determine the data sampling granularity according to the severity of behavior changes, this step adopts an innovative piecewise mapping function, which not only realizes the to sampling level smooth allocation, but also introduces two important innovations:
[0084] One is to add a non-linear adjustment term for behavior changes to avoid frequent switching of sampling granularity caused by slight fluctuations in behavior mutations;
[0085] The second is to introduce a cross-node sampling balance term in the calculation formula to control the variance of granularity differences among multiple nodes in the same subnet and ensure consistent information density when constructing the global event graph.
[0086] The core mapping function is as follows:
[0087]
[0088] Where:
[0089] : The sampling level of node at time , and the value range is , corresponding to low, medium, and high granularities respectively;
[0090] : The non-linear strengthening term is used to amplify the granularity response under high focusing values; is the non-linear modulation factor (such as );
[0091] : The enhanced item of the standardized behavior mutation value, with a default value of ;
[0092] : Node The granularity difference value (mean square error) between it and its neighboring nodes in the subnet to balance the granularity consistency among nodes;
[0093] 、 : Respectively, the weight adjustment parameters for the mutation enhancement item and the consistency penalty item (such as , );
[0094] : The function of rounding to the nearest integer, which is used to discretize into three levels of granularity.
[0095] This design has the following innovative advantages:
[0096] By amplifying the impact of high-threat behaviors and improving the sampling resolution in abnormal situations;
[0097] Using to control the sampling granularity offset of multiple nodes in the same attack scenario and prevent the situation where one node is at a high granularity while other nodes are still at a low granularity, resulting in the breakage of the attack chain structure in the graph model;
[0098] The entire mapping function does not require complex learning, only depends on known input variables, can be calculated online, and is adapted to the edge environment.
[0099] During actual execution, the edge node calculates the local state every period and, according to calls the locally configured sampling policy script. Taking the OpenWRT system as an example, the granularity policy can be executed in the following way:
[0100] Level-0: iptables regularly counts port numbers and outputs logs;
[0101] Level-1: Use the NetFlow plugin to collect five-tuple information and send it to the edge cache module in JSON format;
[0102] Level-2: Call the libpcap packet capture interface to obtain the complete TCP / IP header + HTTP headers information, which is saved in the local ring-buffer or reported using the MQTT protocol.
[0103] To balance node performance and data availability, the acquisition fields, sampling frequencies, and storage formats corresponding to each sampling level are predefined in the system initialization configuration file. Granularity changes only switch identifiers and execution modules, without the need to dynamically load code, ensuring operational stability.
[0104] Output:
[0105] : Node The sampling level of the node during the current period, for use by subsequent event normalization and behavior graph construction modules;
[0106] : A set of structured sampling data packets, with the granularity controlled by and the field types standardized by the system template, serving as the input for Step 3.
[0107] Step 3: Context Event Normalization and Multi-Node Behavior Graph Construction
[0108] This step plays a crucial role in the entire distributed intelligent monitoring system, connecting the upper and lower levels. Its purpose is to transform the multi-node heterogeneous sampling data output from Step 2 through semantic unification and spatio-temporal relationship induction into standardized context event nodes and construct a globally resolvable context behavior graph . The graph structure not only needs to adapt to the inconsistencies in sampling granularity of edge nodes but also possess the ability to reconstruct attack chains across nodes and time windows. Since Step 2 adopted a dynamic sampling mechanism, there are significant differences in the structure and accuracy of node outputs. Therefore, this step requires an adaptive modeling ability in graph construction methods. To this end, this solution introduces two innovations: (1) a granularity compensation normalization mechanism based on sampling levels to unify event representations; (2) introducing a graph structure regularization term to construct an edge weight function, enhancing the structure of low-sampling-quality regions during graph construction to improve path coherence. This design fully considers two core practical problems in the patent target scenario: edge heterogeneity and behavior chain fragmentation.
[0109] The input for this step comes from Step 2:
[0110] : Edge node The sampling level at time , taking values of 0, 1, 2, controlling the data density;
[0111] : Node The set of structured data collected by the node, in the form of a JSON array, and its field set is restricted by :
[0112] If , it only contains summary information such as connection count and protocol type;
[0113] If , it contains standard five-tuples, ports, and flag bits;
[0114] If , it contains original packet fields such as URL, User-Agent, Host header, etc.
[0115] All data is collected by edge nodes through NetFlow, libpcap, or a custom acquisition module, and cached in JSON format before being uploaded.
[0116] First, perform a normalization mapping operation on each structured data record in , and map it to a standard event representation vector . The mapping process does not directly depend on a deep learning model, but is implemented by combining a static template and a structure compensation function , that is:
[0117]
[0118] Among them:
[0119] represents the th data record;
[0120] is the normalization mapping function, which contains multiple structure templates inside to perform semantic mapping on fields;
[0121] The mapping result is a structured vector with a fixed length, containing event type, timestamp, node ID, target address, action label, etc.
[0122] The innovation lies in that will automatically insert structure compensation items according to . For example, when , the missing key fields (such as the target port) will be filled with "type placeholder + prediction mode", and the uncertainty level will be marked. This mechanism ensures that even at the coarsest granularity, events can still be included in the graph for analysis instead of being excluded.
[0123] After completing the construction of all , we incorporate the events of all nodes in all time windows into a unified graph structure , the node set , the edge set Indicates the speculative association between events. Edge construction depends on multi-dimensional similarity matching, including temporal proximity, contextual semantics, address similarity, etc. However, due to incomplete sampling of some nodes and the lack of direct connection fields between event pairs, we introduce the following edge weight calculation formula with regular constraints:
[0124]
[0125] Where:
[0126] : The weight of the edge in the graph ;
[0127] : The contextual similarity of behavioral events (based on fields such as event type, protocol, source IP, etc.);
[0128] : Represents the granularity level difference between the source nodes of two events;
[0129] : Edge structure regular term, calculating the "structural deviation degree" of two events in the historical attack chain;
[0130] : Adjustment parameter, controlling the balance between semantics, granularity, and structure.
[0131] The calculation of depends on the path prior of the known attack graph. For example, if in past attack samples, the event type combination "external connection" → "repeated failed login" has a high attack path support degree, and the current and have a similar structure but the order is reversed, then the value increases, thus inhibiting the edge weight.
[0132] After edge construction, the graph is stored in a sparse adjacency list structure and allows dynamic node addition. The structure can be exported as a tensor representation for use by subsequent inference models. The entire graph construction process is completed at the central node, and the processing period can be configured (e.g., incrementally updated every 5 minutes).
[0133] Output:
[0134] : Behavioral context graph, with normalized events as nodes, contextual and temporal relationships as edges, and edge weights;
[0135] : Set of normalized events, standard structure vectors, for input to subsequent path analysis and causal models.
[0136] Step 4: Attack causal chain modeling and main cause identification
[0137] The goal of this step is: based on the context behavior graph generated in Step 3 and the normalized event node set to establish a causal modeling structure for attack chain analysis.
[0138] The core task of causal graph modeling is: based on the behavior graph to construct a new set of directed edges where each edge represents that event is a possible cause of event and quantifies its causal strength through the edge weight Since the original behavior graph only contains semantic / temporal connections of adjacent events but cannot distinguish whether the "sequence" is a true causal trigger, this step adopts a structural modeling strategy for "causal structure learning".
[0139] We introduce a lightweight structure learning mechanism here, adopting a causal graph modeling idea inspired by the NOTEARS method, but making non-modeling optimization simplification improvements to adapt to the actual engineering environment where the graph input source is structured events. Our modeling is not based on differentiable graph optimization algorithms, but judges whether to establish causal edges between events through causal condition construction rules, as follows:
[0140] For any two nodes judge whether to establish an edge and its causal weight and calculate using the following rules:
[0141]
[0142] Where:
[0143] : Logical indicator function to ensure the temporal consistency of causal relationships (i.e., must be earlier than );
[0144] : Context matching function to calculate the attribute correlation degree between two events;
[0145] : The "causal candidacy" score of event to measure its potential ability to trigger other events.
[0146] The specific implementation of is as follows: if the action type of If the target IP address appears in the scanned port list, it is considered that the context relevance between the two is high. The value is close to 1; if there is no overlapping attribute, the value approaches 0. Then, based on the statistical calculation of historical behavior patterns, such as the frequency of "main cause candidate types" (for example, types such as port scanning and privilege escalation are more often used as starting events), the implementation method is table-lookup weighted, which is convenient for engineering implementation.
[0147] For example:
[0148] Node represents the "lateral scanning" behavior at 10:01, with the node ID being edge device #2 and the target being the internal network IP segment 192.168.0.0 / 24;
[0149] Node represents that at 10:04, a failed RDP login to a device in this IP segment was recorded on another node #3;
[0150] Then this behavior satisfies , is close to 1, obtained by looking up the table from the event type (lateral scanning is a strong candidate factor), so an edge is established and is given a
[0151] After the graph construction is completed, we perform the main cause node recognition in . Define the main cause node as: a node that has more outgoing edges with "high causal weights" and the number of "high-risk behavior nodes" (such as privilege modification and data exfiltration) triggered cumulatively in its subsequent paths is significantly more. Calculate using the following causal activation degree index:
[0152]
[0153] Among them:
[0154] : The set of downstream nodes reachable from ;
[0155] : The behavior risk score of node , statically mapped by its action type (for example, "remote control" has a score of 0.9, and "HTTP access" has a score of 0.3);
[0156] : The causal activation degree, indicating the intensity of triggering downstream threats.
[0157] Finally, select The top several nodes form the main cause node set , which is used to support the subsequent risk assessment and response recommendation processes.
[0158] Output
[0159] : Attack causal graph, where the nodes are normalized events , the edges are connected in the causal direction and carry the causative weights generated by the rules;
[0160] : Main cause node set, which are the high-activation starting behavior nodes identified from the causal graph.
[0161] Step 5: Quantification of threat level based on the attack path
[0162] The core task of this step is to score each attack chain item by item to form a quantitative threat level . The scoring is based on three key dimensions of the path: propagation depth, structural strength, and risk accumulation. Among them, the propagation depth reflects the length of the attack chain and the penetration ability, the structural strength measures the average credibility of the causal edges, and the risk accumulation evaluates the risk weights of the key behaviors on the path.
[0163] First, for each attack path , calculate its overall risk score as follows:
[0164]
[0165] Where:
[0166] : Attack path 's risk score;
[0167] : Path length;
[0168] : The weight of the edge in the causal graph, which comes from the causal strength calculated in step four;
[0169] : Behavior risk factor, which is obtained by looking up the table according to the type of the event (for example, "remote control" = 0.9, "HTTP request" = 0.3);
[0170] : Path depth adjustment coefficient, usually set to 0.1 to 0.3;
[0171] : The logarithm of the path length, which is used to control the excessive growth of the deep path score.
[0172] To further improve the stability of scoring and control the problem of over - scoring caused by "jumping edges" in some structures in the causal graph, a structure suppression factor is introduced in this step , and the calculation is as follows:
[0173]
[0174] Where:
[0175] : The structure suppression factor of the path score;
[0176] : The path The standard deviation of all edge weights in, representing the structural stability. The larger it is, the stronger the jump;
[0177] If approaches 0, it means the structure is uniform and the scoring credibility is high; otherwise, the score is compressed.
[0178] The final path risk score is:
[0179]
[0180] This score is used to rank the risk levels of attack paths and is called by the next - step response suggestion module.
[0181] Output:
[0182] : The normalized attack path risk score. The higher the value, the more serious the threat level;
[0183] : The corresponding attack path structure (i.e., an ordered set of event nodes), serving as the basis for scoring reference.
[0184] Step 6: Generation of intelligent response strategies
[0185] The core task of this step is to generate an operable intelligent response strategy based on the attack path risk score and the path structure output in the previous step.
[0186] This step first maps the attack path to a set of phased behavior labels to identify whether there are key operation types in the attack chain, such as "lateral movement", "privilege escalation", "external communication", etc. This operation is achieved through matching in the rule template library. For example, when the action type field in is "login failure retry" and the target port is 3389 (RDP), it can be marked as .
[0187] Next, a response score matrix is constructed based on the path structure and the corresponding label sequence , whose elements represent the attack path In the The adaptability of the class response strategy. There are three types of response types, each of which contains several sub-strategies:
[0188] Type A: Edge processing, such as blocking source IP and restricting port communication;
[0189] Type B: Center collaboration, such as sending manual analysis alerts and generating reports;
[0190] Type C: Policy-level adjustments, such as increasing node sampling levels and adjusting model sensitivity.
[0191] Response Matrix The construction logic is as follows:
[0192]
[0193] in:
[0194] :event Strategy The recommendation strength is assigned by the policy mapping rule base (for example, the weight of "isolation source IP" corresponding to lateral movement is 0.8);
[0195] : indicator function, if the label Belongs to strategy category If it is type A action, then it is 1, otherwise it is 0;
[0196] :path Response strategy The fit score.
[0197] This matrix constructs a set of recommended response actions for each path, and strategies with high scores will be prioritized for execution.
[0198] Finally, the comprehensive path risk score And the strategy adaptation degree, generate the final response intensity vector :
[0199]
[0200] in:
[0201] : is the path The execution priority vector of all the policies above;
[0202] : A normalization function to ensure that all policy scores are normalized and comparable;
[0203] Multiple policies can be executed concurrently or executed by threshold screening.
[0204] For example, for a certain path score of , its policy vector is:
[0205]
[0206] Then the system will give priority to executing Policy 1 (such as blocking ports), execute Policy 2 (such as alarm reporting) secondly, and finally consider Policy 3 (such as increasing the sampling level).
[0207] After all the policies are generated, they will be converted into a structured response task list (JSON format) and scheduled for execution by the edge response agent or the central control platform.
[0208] Output
[0209] : The response policy strength vector, indicating the types of policies recommended to be executed on the attack path and their priorities;
[0210] : The list of response actions, generated by in sorted order, including information such as policy category, execution parameters, target nodes, etc.
[0211] The technical solutions in the embodiments of the present application at least have the following technical effects or advantages: By perceiving the change trend of network node behaviors, the present invention intelligently regulates the data sampling granularity and feature reporting frequency, realizes the precise allocation of resources and focuses on threat areas, and improves the overall detection efficiency of the system. On this basis, the present invention further constructs a cross-node and cross-time context behavior model, uniformly organizes distributed event information, identifies potential threat chains and behavior logic structures, and effectively solves the problem of behavior fragmentation. In addition, to enhance the credibility and interpretability of the system output, the present invention introduces a causal relationship-based reasoning mechanism, conducts structural analysis and causal extraction on the identified behavior paths, thereby generating a traceable attack explanation graph to provide clear decision support for security personnel.
[0212] The embodiments of the present application also provide a distributed network threat intelligent monitoring system based on artificial intelligence, as Figure 2 shown, including:
[0213] Node evaluation module, which inputs the first row of feature vectors and the second row of feature vectors; calculates the behavior mutation intensity of nodes within a time window based on the first row of feature vectors and the second row of feature vectors; and calculates the behavior focus value of nodes in combination with the complexity entropy of behavior distribution.
[0214] Granularity control module, which establishes a segmented mapping function to map the behavior focus value to the sampling level; outputs the sampling level, and obtains a set of structured sampling data packets based on the determined granularity after the sampling level.
[0215] Behavior graph module, which performs normalized mapping on the set of structured sampling data packets to obtain a standard event representation vector; incorporates the standard event representation vectors of all nodes in all time windows into a unified graph structure to obtain a behavior graph, where the node set of the behavior graph is the set of standard event representation vectors, and the edge set is the speculative association between events; the edge set is obtained through multi-dimensional similarity matching.
[0216] Causal graph module, which constructs a new set of directed edges based on the behavior graph. For any two nodes, each edge represents that the event of node one is a possible cause of the event of node two, and quantifies its causal strength through edge weights; establishes a causal graph; performs main cause node identification through calculation of the causal activation degree index; the causal activation degree index calculates the behavior risk score of nodes, which is statically mapped from its action type; the main cause node set is composed of nodes with the highest causal activation degree index.
[0217] Path analysis module, which calculates the risk score of an attack path, where the attack path is a corresponding attack path structure composed of an ordered set of event nodes; the risk score is calculated based on the weights and path lengths of the edges of the attack path in the causal graph.
[0218] Strategy generation module, which maps the attack path to stage behavior labels, constructs a response score matrix according to the attack path structure and the corresponding label sequence, and the elements of the response score matrix represent the adaptability to different response strategies in the attack path; synthesizes the path risk score and the strategy adaptability to generate a final response intensity vector; the response strategy intensity vector represents the type of strategy recommended to be executed on the attack path and its priority.
[0219] As described above, it is only the preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution of the present invention and its inventive concept, makes equivalent substitutions or changes, and should be covered by the protection scope of the present invention.
Claims
1. A distributed network threat intelligent monitoring method based on artificial intelligence, characterized in that, Including: S1: Input the first row of feature vectors and the second row of feature vectors; Calculate the behavior mutation intensity of nodes within a time window based on the first row of feature vectors and the second row of feature vectors; Calculate the behavior focus value of nodes in combination with the complexity entropy of behavior distribution; S2: Establish a piecewise mapping function to map the behavior focus value to the sampling level; Output the sampling level, and obtain a set of structured sampling data packets based on the determined granularity after the sampling level; S3: Perform a normalization mapping on the set of structured sampling data packets to obtain a standard event representation vector; Incorporate the standard event representation vectors of all nodes in all time windows into a unified graph structure to obtain a behavior graph. The node set of the behavior graph is the set of standard event representation vectors, and the edge set is the speculated association between events; the edge set is obtained through multi-dimensional similarity matching; S4: Construct a set of new directional edges based on the behavior graph. For any two nodes, each edge represents that the event of node one is a possible cause of the event of node two, and quantify its causal strength through edge weights; establish a causal graph; Perform main cause node identification through calculation of the causal activation degree index; the causal activation degree index calculates the behavior risk score of a node, which is statically mapped from its action type; The set of nodes with the highest causal activation degree index forms the main cause node set; S5: Calculate the risk score of the attack path. The attack path is a corresponding attack path structure composed of a set of ordered event nodes; the risk score is calculated based on the weights and path lengths of the edges of the attack path in the causal graph; S6: Map the attack path to stage behavior labels, and construct a response score matrix according to the attack path structure and the corresponding label sequence. The elements of the response score matrix represent the adaptability to different response strategies in the attack path; Integrate the path risk score and the strategy adaptability to generate a final response intensity vector; The response strategy intensity vector represents the types of strategies recommended to be executed on the attack path and their priorities.
2. The method for intelligent monitoring of distributed network threats based on artificial intelligence according to claim 1, wherein The first row of feature vectors represents the statistical results of a certain period, which are generated in real time by the local network behavior collection component on the edge node; The second row of feature vectors is the statistical results of the previous period of the first row of feature vectors, which are saved in the local cache of the edge node.
3. The distributed network threat intelligent monitoring method based on artificial intelligence according to claim 1, characterized in that The complexity entropy of the behavior distribution is estimated through a protocol frequency histogram and is used to represent structural diversity.
4. The method for intelligent monitoring of distributed network threats based on artificial intelligence according to claim 1, wherein, A non-linear reinforcement term is introduced in the piecewise mapping function to amplify the granularity response under high focus values. The piecewise mapping function balances the granularity consistency between nodes through the granularity difference value between a node and its neighboring nodes in its subnet.
5. The method for intelligent monitoring of distributed network threats based on artificial intelligence according to claim 1, characterized in that, The value range of the sampling level is {0, 1, 2}, corresponding to low, medium, and high granularity respectively.
6. The method for intelligent monitoring of distributed network threats based on artificial intelligence according to claim 1, wherein The main cause node is a node whose number of edges with high causal weights exceeds a preset threshold number, and the number of high-risk behavior nodes cumulatively triggered in its subsequent path is higher than the preset threshold.
7. The method for intelligent monitoring of distributed network threats based on artificial intelligence according to claim 1, wherein The response score matrix constructs a set of recommended response action sets to be executed for each path.
8. An artificial intelligence-based distributed network threat intelligent monitoring system, characterized in that, Including: Node evaluation module, which takes the first row of feature vectors and the second row of feature vectors as input; calculates the behavior mutation intensity of nodes within a time window based on the first row of feature vectors and the second row of feature vectors; calculates the behavior focus value of nodes in combination with the complexity entropy of behavior distribution; Granularity control module, which establishes a segmented mapping function to map the behavior focus value to the sampling level; Outputs the sampling level, and obtains a set of structured sampling data packets after determining the granularity based on the sampling level; Behavior graph module, which performs a normalization mapping on the set of structured sampling data packets to obtain a standard event representation vector; incorporates the standard event representation vectors of all nodes in all time windows into a unified graph structure to obtain a behavior graph, where the node set of the behavior graph is the set of standard event representation vectors, and the edge set is the speculative association between events; the edge set is obtained through multi-dimensional similarity matching; Causal graph module, which constructs a new set of directed edges based on the behavior graph. For any two nodes, each edge represents that the event of node one is a possible cause of the event of node two, and quantifies its causal strength through edge weights; establishes a causal graph; performs main cause node identification through the calculation of the causal activation degree index; the causal activation degree index calculates the behavior risk score of nodes, which is statically mapped from their action types; the main cause node set is composed of nodes with the highest causal activation degree index; Path analysis module, which calculates the risk score of an attack path, where the attack path is a corresponding attack path structure composed of an ordered set of event nodes; the risk score is calculated based on the weights of the edges and the path length of the attack path in the causal graph; Policy generation module, which maps the attack path to stage behavior labels, constructs a response score matrix according to the attack path structure and the corresponding label sequence, where the elements of the response score matrix represent the adaptability to different response policies in the attack path; synthesizes the path risk score and the policy adaptability to generate a final response intensity vector; the response policy intensity vector represents the types of policies recommended to be executed on the attack path and their priorities.