Intelligent security comprehensive management and control system

Through the intelligent comprehensive security management and control system, a dynamic priority topology network is built using monitoring layer data collection, regional decision-making layer dynamic calculation and cloud analysis layer correction, which solves the resource allocation and defense blind spots of existing security systems in real-time risk diffusion scenarios, and achieves efficient and accurate threat identification and resource scheduling.

CN120263545AActive Publication Date: 2025-07-04FUJIAN YUNSU INFORMATION TECH CO LTD

Patent Information

Application Number
CN202510732774.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-04
Publication Date
2025-07-04
Estimated Expiration
2045-06-04

AI Technical Summary

Technical Problem

It is difficult for existing security systems to adjust resource allocation in a timely manner in real-time risk diffusion scenarios. Information sharing between devices is limited in partition independent management and control mode, and monitoring strategies cannot be dynamically optimized, resulting in defense blind spots and resource redundancy, making it difficult to balance security efficiency and operation and maintenance costs.

Method used

Through real-time data acquisition of the monitoring layer, dynamic risk calculation of the regional decision-making layer and global correction of the cloud analysis layer, a dynamic priority topology network is built, and mobile monitoring equipment is dispatched to focus on high-threat areas, deploy interception strategies and optimize equipment resources, and ensure system stability with the full-stack self-test protocol.

Benefits of technology

Real-time dynamic response and efficient resource scheduling in complex threat scenarios are achieved, high-threat areas are accurately identified, defense blind spots and resource redundancy are reduced, and the active defense level of the security system is improved.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention provides an intelligent security comprehensive management and control system, and relates to the field of intelligent security management and control. Comprising a monitoring layer, a regional decision-making layer, a cloud analysis layer and an execution control layer, the monitoring layer collects data through fixed-point monitoring equipment, mobile monitoring equipment and a simulation management node; the regional decision-making layer calculates a local risk index based on the data and generates a local service topology sub-graph, and triggers a simulation management node to generate an abnormal operation record; the cloud analysis layer integrates the local service topology sub-graphs, corrects risk index errors, constructs a dynamic priority service topology network and generates a risk gradient; and the execution control layer schedules the mobile monitoring equipment according to the risk gradient, closes a redundancy process, deploys an interception strategy and an optimization means, and verifies the running state of the equipment through a full-stack self-check protocol.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of intelligent security control, and specifically to an intelligent security comprehensive control system. Background Art

[0002] With the rapid development of Internet of Things and artificial intelligence technologies, the application demand of intelligent security systems in fields such as public security and industrial monitoring is increasing day by day; traditional security relies on manual patrols and the linkage of fixed devices, making it difficult to cope with complex and changeable abnormal behaviors; the current industry urgently needs to achieve comprehensive control capabilities of real-time dynamic response, accurate threat recognition, and efficient resource scheduling to enhance the active defense level of security systems.

[0003] The security solutions commonly adopted in the current industry mainly include the following two categories: one is the centralized control architecture, which receives front-end sensor data through a central server and triggers response actions based on preset rules; the other is the partition-independent control mode, which divides the monitoring area into independent sub-units, and each unit executes a standardized operation process through a local controller; although such solutions can cope with conventional security threats, their management logic is fixed and cannot adapt to dynamically changing threat scenarios.

[0004] The existing solutions have the following deficiencies: the centralized architecture relies on the central server to process massive amounts of data, and it is difficult to adjust resource allocation in a timely manner in the case of risk diffusion scenarios, resulting in a lag in the defense of key areas; in the partition-independent control mode, the information sharing between devices is limited, and it is impossible to dynamically optimize the monitoring strategy according to the global threat situation, forming a defense blind spot; the device scheduling driven by static rules is likely to cause resource redundancy in low-risk areas, while the protection of high-value targets is insufficient, making it difficult to balance security effectiveness and operation and maintenance costs. Summary of the Invention

[0005] (I) Technical Problems to be Solved In view of the deficiencies of the prior art, the present invention provides an intelligent security comprehensive control system to solve the problems in the above background art, that is, in the case of real-time risk diffusion scenarios, the existing system is difficult to adjust resource allocation in a timely manner due to the centralized architecture; in the partition-independent control mode, the information sharing between devices is limited, and it is impossible to dynamically optimize the monitoring strategy according to the global threat situation, forming a defense blind spot; the device scheduling driven by static rules is likely to cause resource redundancy in low-risk areas, while the protection of high-value targets is insufficient, making it difficult to balance security effectiveness and operation and maintenance costs.

[0006] (II) Technical Solutions To achieve the above objectives, the present invention is realized through the following technical solutions: An intelligent security comprehensive management and control system includes that the monitoring layer monitors real-time service data streams, process states, and environmental parameters through fixed-point monitoring devices, supplements monitoring blind spots through mobile monitoring devices, and simulates normal business processes through simulation management nodes to identify abnormal operations. The monitoring layer transmits the collected data to the regional decision-making layer; the monitoring layer also includes historical operation abnormal frequencies, real-time process deviation degrees, and equipment efficiency indexes, which are used for calculating risk indicators of the regional decision-making layer; Based on the data of the monitoring layer, the regional decision-making layer calculates local risk indicators through a dynamic weight formula and generates a local business topology sub-graph. At the same time, according to the growth of the risk indicators, it triggers the simulation management node to generate and record abnormal operations. The parameters of the simulation management node are adjusted according to a dynamic equation, and at the same time, the local business topology sub-graph and the recorded abnormal operations are uploaded to the cloud analysis layer; The cloud analysis layer integrates all local business topology sub-graphs, corrects risk indicator errors through a conflict resolution algorithm, constructs a dynamic priority business topology network, generates a risk gradient, marks high-threat areas based on a risk gradient diffusion model, and issues updated weight parameters to the regional decision-making layer; The execution control layer schedules mobile monitoring devices to focus on high-threat areas according to the risk gradient of the dynamic priority business topology network, suspends redundant processes in low-risk areas, deploys interception strategies and optimization means on abnormal operation paths according to abnormal characteristics, and generates self-check instructions through a full-stack self-check protocol for periodically verifying the operating status of devices.

[0007] Preferably, the monitoring layer collects service data streams, process status, and environmental parameters in real time through the fixed-point monitoring devices. The fixed-point monitoring devices include high-precision sensors, process status recorders, and environmental parameter collection devices deployed at fixed nodes, which are used to monitor temperature, humidity, energy consumption, people flow, light, vibration, and electromagnetic interference intensity data in real time. The mobile monitoring devices include drones equipped with multi-spectral sensors and inspection robots equipped with environmental scanners. The drones cover the monitoring blind spots of the fixed-point monitoring devices through preset flight paths, and the inspection robots scan the ground blind spots along the dynamically planned trajectories and transmit the scanned data to the regional decision-making layer in real time. The simulation management node consists of a virtual management node and a physical management node. The virtual management node simulates the protocol logic and operation characteristics of normal service processes based on process simulation technology. The physical management node is a low-power real device that periodically sends heartbeat signals and is associated with the virtual management node through a random mapping rule. The heartbeat signal is a simplified timing signal that is only used to indicate the online status and does not transmit actual monitoring data. The monitoring layer transmits the collected data to the regional decision-making layer, including the historical operation exception frequency, real-time process deviation degree, and device efficiency index, for the regional decision-making layer to calculate risk indicators. The device efficiency index is periodically verified through the full-stack self-checking protocol of the fixed-point monitoring devices and mobile monitoring devices.

[0008] Preferably, the regional decision-making layer divides the service area monitored by the monitoring layer into equal-area grid units, and each grid is defined as a service node. Based on the historical operation exception frequency, real-time process deviation degree, device efficiency index, and anti-fragility gain factor collected by the monitoring layer, the real-time risk indicators of each node are calculated through a dynamic weight formula. The historical operation exception frequency is the number of exception events per minute statistically recorded in the exception event log stored by the monitoring layer. The real-time process deviation degree is obtained by calculating the standard deviation deviation degree between the monitoring data and the preset reference value. The preset reference value is the average value of the historical monitoring data of the environmental sensor and the infrared thermal imaging sensor in the normal state. The standard deviation is a quantitative index of the dispersion degree of the historical data distribution, which is used to measure the fluctuation range of data in the normal state. The deviation degree is the degree of difference between the real-time monitoring data and the preset reference value, which is quantified by calculating the standard deviation multiple or absolute value difference between the real-time data and the reference value. Specifically, when the real-time data exceeds the ±2 standard deviation range of the reference value, it is determined as an abnormality and the calculation of the real-time risk indicator is triggered. The higher the deviation degree, the greater the abnormal risk of the sensor data, and the system dynamically adjusts the monitoring resource allocation strategy accordingly. The device efficiency index is generated by periodically verifying the full-stack self-checking protocol of the fixed-point monitoring devices and mobile monitoring devices. The real-time risk indicator formula is: , where, H f is the historical number of exceptions statistically recorded by the monitoring layer, S eFor the deviation degree D of the monitored data from the reference value h For the equipment operation status score A g Calculated through the logarithmic relationship between the historical number of anomalies and the simulation node trigger rate; the weight values of α, β, γ, and δ are dynamically adjusted by the cloud analysis layer according to the environmental light intensity and the pedestrian flow density. The anti-fragile gain factor A g Has a logarithmic relationship with the historical number of anomalies and the simulation node trigger rate, and is calculated through where N a Is the historical number of anomalies, and R d Is the simulation node trigger rate; when the real-time risk indicator of the service node exceeds the preset threshold, it is marked as a high-threat node, otherwise it is a low-threat node. The preset threshold Tv is 80, and the value range is 0 - 100; the risk indicator of the high-threat node is transmitted to adjacent nodes according to the exponential decay rule through the risk gradient diffusion model; the adjacent nodes receive the attenuated risk indicator and superimpose it on their own risk indicator to form a dynamic risk diffusion link. The formula of the risk gradient diffusion model is , where k is the diffusion coefficient and d is the distance between nodes. A new global topology is generated every 5 seconds, and the link with the maximum risk gradient is marked, such as the shortest path from the entrance to the core computer room; the regional decision layer also deploys a lightweight prediction model based on time series analysis. The input parameters include historical risk indicators, temperature, humidity, and electromagnetic interference intensity data, and the output is the adjustment direction of the weight parameters within the next 5 seconds, and the prediction result is uploaded to the cloud analysis layer for global correction.

[0009] Preferably, the weight values of α, β, γ, and δ are dynamically adjusted by the cloud analysis layer according to the environmental light intensity and the pedestrian flow density. Specifically, it is collected in real time through the environmental sensors of the monitoring layer, and the data unit is lux (Lux), and the sampling frequency is 1 time per second; the multi-spectral sensor of the fixed-point monitoring device captures the video stream, combines with the deep learning model to count the number of people in the area in real time, and calculates the pedestrian flow density (unit: person / m 2 ), and normalizes the light intensity L and the pedestrian flow density D to the interval of 0, 1. The formula is: ; where full darkness L min Is 0 Lux, strong light L max Is 1000 Lux, D min Is 0 person / m 2 , Dmax is 5 person / m 2 ; The cloud analysis layer dynamically calculates the weight value based on the following rules: Rule 1 is the influence of the light intensity on the weight α of the real-time process deviation degree. When Lnorm <0.3, it is low light: due to the improvement of the sensitivity of the monitoring device, increase the weight α to amplify the anomaly detection sensitivity; when Lnorm When it is 0.7, it is high light intensity: due to the interference of visible light, the accuracy of the sensor may be reduced, and the weight should be appropriately reduced; the adjustment formula is as follows: Rule 2 is the influence of the pedestrian flow density on the weight β of the historical operation anomaly frequency. When D norm > 0.6, it is high pedestrian flow density: due to the complex activities of people, it is easy to cover up real attacks, so the weight is reduced to reduce the dependence on historical data; when D norm > 0.4, it is low pedestrian flow density: increase the weight to strengthen the matching of historical attack patterns; the adjustment formula is as follows: ; Rule 3 is to ensure the stability of the weight γ of the equipment efficiency index, that is, regardless of how the environmental parameters change, the weight γ remains at the basic value of 0.2. Only when the equipment efficiency index is lower than the safety threshold, the weight γ is increased proportionally to switch to the standby equipment.

[0010] Rule 4 is the dynamic balance of the weight δ of the anti-fragile gain factor. When a new type of abnormal feature is detected, the weight δ is increased through the anti-fragile strategy library. The adjustment formula is as follows: .

[0011] Preferably, when the regional decision layer detects that the local risk index continues to increase and exceeds the preset threshold of 80, it triggers the generation mechanism of the simulation management node; the simulation management node simulates the process signals and protocol characteristics of the fixed-point monitoring device, and its signal strength and response delay parameters are adjusted according to the dynamic equation. The simulation management node records the abnormal access, illegal operations or resource abuse behaviors of the attacker, extracts the operation type, frequency, interaction protocol and path characteristics, generates an abnormal feature vector and stores it in the anti-fragile strategy library of the cloud analysis layer; the anti-fragile strategy library dynamically adjusts the weight of the risk index formula according to the abnormal feature vector, and simulates the composite scenarios of protocol violations, resource abuse and process interference through a generative adversarial network, generates an optimized strategy and verifies it through a virtualized sandbox environment, and finally issues it to the regional decision layer and the execution control layer. The generative adversarial network formula is as follows: Among them, the generator G inputs the noise vector z and generates a simulated abnormal feature vector G(z); the discriminator D distinguishes the real abnormal data x from the generated data G(z) and outputs the discrimination probability D(x) ∈ [0, 1]; p data is the probability distribution of the real abnormal feature vector; p z is the probability distribution of the noise vector.

[0012] Preferably, the cloud analysis layer receives the local business topology subgraphs uploaded by all regional decision layers, corrects the differences in risk indicators in the conflict areas through the weighted voting algorithm, and the weighted voting weight is positively correlated with the credibility of the historical data of the adjacent nodes. The credibility of the historical data is calculated from the risk indicator prediction error rate. The weighted voting algorithm formula is ; where V 校正 is the calibrated risk indicator; w k is the voting weight of the k-th adjacent node, which is positively correlated with the historical data credibility C k , that is, w k =C k ; Vk is the original risk indicator reported by the k-th adjacent node; n is the total number of adjacent nodes participating in the voting. The historical data credibility is calculated as Ck = 1 - E k / total ; where E k is the risk indicator error rate of the k-th adjacent node, calculated as the deviation between the predicted result of the historical risk indicator and the actual occurrence frequency of abnormal events; E total is the benchmark value of the total system error rate; Based on the calibrated risk indicator data, the cloud analysis layer constructs a dynamic priority service topology network through a risk gradient diffusion model. The model dynamically assigns service priorities according to the distance between nodes and the risk indicator differences and generates a risk gradient; The cloud analysis layer sends the updated weight parameters to the regional decision layer for real-time adjustment of the dynamic weight formula, and at the same time dynamically adjusts the mapping rules of the simulation management nodes according to the abnormal feature matching results, so that the functional mapping between virtual management and physical devices changes randomly.

[0013] Preferably, the execution control layer schedules mobile monitoring devices according to the risk gradient of the dynamic priority service topology network. The drone swarm dynamically adjusts the density of the focused area through a distributed task allocation algorithm. The specific implementation is as follows: After receiving the risk gradient data sent by the cloud analysis layer, the drone cluster assigns each drone to the area around high-threat nodes based on the auction algorithm. The auction algorithm dynamically bids for the target area according to the current position of the drone, the remaining flight time, and the task priority. The winning drones automatically adjust their flight altitude and speed to form multiple layers of focused areas. The inner-layer drones approach high-threat nodes along a spiral trajectory, and the outer-layer drones cruise along an elliptical path to block potential abnormal paths. The density of the focused area is adjusted in real time according to the risk gradient. When the risk gradient increases by 10%, the distance between drones decreases by 15%; The inspection robot optimizes its moving trajectory through a path planning algorithm. After receiving the risk gradient data in real time, it preferentially moves along the direction of increasing risk gradient while avoiding obstacles and low-threat areas, and updates the path every 5 seconds to ensure full-dimensional coverage of high-threat areas; When suspending the fixed-point monitoring devices in the area where the risk indicator is lower than the preset threshold, the shutdown ratio is dynamically calculated according to the risk indicator as 1 - real-time risk indicator / preset threshold. The shutdown operation is carried out in stages. First, the devices farthest from the high-threat area are shut down, followed by redundant cameras, and finally environmental sensors. The released CPU and memory resources are allocated by the resource pool management module to the interception strategy in the high-threat area. Preferably, the interception strategy is deployed by using software-defined network technology to dynamically redirect attack traffic to the virtual management node; resource restriction devices and process blocking mechanisms are deployed on the abnormal operation path. The resource restriction devices include a directional permission controller and a process lock, which dynamically adjust the restriction intensity and scope of action according to the real-time location, operation speed, and behavior characteristics of the operator. Moreover, the startup timing of the resource restriction device is dynamically adjusted with the operation speed of the operator, and the interval time between the two is inversely proportional; the execution control layer checks the device operation status every 30 seconds through the full-stack self-checking protocol. The hardware layer detects the camera focusing accuracy, motor wear rate, and battery voltage. The software layer verifies the consistency of the firmware signature and communication protocol version. The coordination layer measures the instruction response delay between the drone and the robot. When the device efficiency index is lower than the safety threshold of 60, the system automatically marks the faulty device, cuts off its network connection, and activates the standby device. After the standby device starts up, it synchronizes the latest risk gradient data and takes over the tasks of the original device, and at the same time reallocates the network bandwidth.

[0014] Preferably, the area decision layer exchanges local risk index data with adjacent nodes through a consensus mechanism based on the Byzantine fault tolerance algorithm, generates a local service topology subgraph, and marks the conflict area; the consensus mechanism of the Byzantine fault tolerance algorithm is that each adjacent node acts as a consensus participant and broadcasts its calculated local risk index and the corresponding spatio-temporal label within each synchronization period. The default synchronization period is 1 second; after all nodes receive the data, they execute a three-phase protocol, namely pre-preparation, preparation, and submission, and verify the data validity through the majority voting principle. If more than 2 / 3 of the nodes reach an agreement, a local service topology subgraph is generated, and the area where the difference in risk indicators exceeds the preset threshold, where the area with an absolute difference of 30% is the conflict area; for malicious nodes or data-abnormal nodes, they are excluded from the consensus network through the dynamic reputation value mechanism; if the difference in risk indicators between the area decision layer and the cloud analysis layer exceeds the preset threshold, a self-checking instruction for the monitoring layer device is triggered, including camera focal length calibration, abnormal network port restart, and sensor data verification; after the self-check is completed, the local risk index is recalculated, and the updated data is uploaded to the cloud analysis layer for global correction to ensure the data consistency of the risk gradient diffusion model.

[0015] (III) Beneficial Effects The present invention provides an intelligent security comprehensive management and control system. It has the following beneficial effects: 1. Through the multi-source data fusion of the monitoring layer and the dynamic weight formula of the area decision layer, the calculation accuracy of local risk indicators is improved; the cloud analysis layer integrates the global topology subgraph and corrects errors, constructs a dynamic priority network to accurately mark high-threat areas; the simulation management node adjusts according to the dynamic equation and combines with the generative adversarial network to enhance the ability to trap covert attacks and reduce the risk of being identified.

[0016] 2. The risk gradient diffusion model is adopted to drive the mobile monitoring device to dynamically focus on high-threat areas, and redundant processes are synchronously shut down to release resources; the interception strategy and the acousto-optic interference device are adaptively deployed according to abnormal characteristics to block abnormal paths; the full-stack self-checking protocol periodically checks the operating status of the device and automatically switches to standby nodes to ensure the continuous and stable operation of the system and the efficient allocation of resources. Detailed implementation manners

[0017] The technical solutions in the embodiments of the present invention will be clearly and completely described below. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0018] The embodiments of the present invention provide an intelligent security comprehensive management and control system. The monitoring layer collects data on temperature, humidity, energy consumption, number of people, light, vibration, and electromagnetic interference intensity in real time through high-precision sensors deployed on fixed nodes, and at the same time monitors the business data flow and process status using a process status recorder; the multi-spectral sensor drones in the mobile monitoring device cover the monitoring blind spots of fixed-point devices according to a preset flight path, and the patrol robots scan the ground blind spots through dynamic trajectory planning and transmit data to the regional decision-making layer in real time; the simulation management node consists of virtual nodes and physical nodes. The virtual nodes generate simulation task execution signals and dynamic process identifiers based on process simulation technology, and the physical nodes, as low-power devices, periodically send heartbeat signals and are associated with virtual nodes through a random mapping rule; the monitoring layer transmits the collected real-time data, historical operation anomaly frequency, real-time process deviation degree, and device efficiency index to the regional decision-making layer, where the device efficiency index checks the hardware function and software integrity every 30 seconds through the full-stack self-checking protocol.

[0019] The regional decision-making layer divides the monitoring area into grid units of equal area, and each grid is used as an independent business node; based on the historical operation anomaly frequency, real-time process deviation degree, device efficiency index, and anti-fragility gain factor, the real-time risk index of the node is calculated through a dynamic weight formula, where the real-time process deviation degree is obtained by comparing the standard deviation deviation of the monitoring data with the preset reference value, and when the deviation exceeds ±2 times the standard deviation, the risk index calculation is triggered; the anti-fragility gain factor is dynamically adjusted according to the logarithmic relationship between the historical number of anomalies and the simulation node trigger rate; when the node risk index exceeds the threshold of 80, it is marked as a high-threat node, and the risk index is transmitted to adjacent nodes according to the exponential decay rule through the risk gradient diffusion model to form a dynamic risk diffusion link; the lightweight prediction model deployed by the regional decision-making layer inputs the historical risk index and environmental parameters, predicts the adjustment direction of the weight parameters within the next 5 seconds, and uploads the prediction result to the cloud analysis layer for global correction.

[0020] The cloud analysis layer receives the local business topology subgraphs uploaded by the regional decision-making layers, and uses a weighted voting algorithm to correct the differences in risk indicators in the conflict areas. The voting weight is positively correlated with the credibility of the historical data of adjacent nodes. Based on the corrected data, a dynamic priority business topology network is constructed, and business priorities are assigned and risk gradients are generated according to the distance between nodes and the differences in risk indicators. The cloud analysis layer dynamically adjusts the weight parameters according to the light intensity and the density of people flow. The light intensity is collected in real time by environmental sensors and normalized to the range of 0-1, and the density of people flow is calculated by counting the number of people through a deep learning model. When the light intensity is lower than 0.3, the weight of the real-time process deviation degree is increased to improve the sensitivity of anomaly detection. When the density of people flow is higher than 0.6, the weight of the historical operation anomaly frequency is reduced to reduce misjudgment. The updated weight parameters are sent to the regional decision-making layers. At the same time, the anti-fragile strategy library adjusts the weights of the risk formula according to the anomaly feature vectors, and generates optimization strategies by simulating compound anomaly scenarios through a generative adversarial network. After being verified by a virtualized sandbox, the strategies are sent to the execution control layer.

[0021] The execution control layer schedules the drone swarm and inspection robots according to the risk gradient to focus on high-threat areas. The drone cluster bids for the target area through an auction algorithm. The winning drones approach high-threat nodes in a spiral trajectory, and the outer drones cruise along an elliptical path to block abnormal paths. For every 10% increase in the risk gradient, the distance between drones is reduced by 15%. The inspection robots use an algorithm to plan the path, and preferentially move along the direction of the rising risk gradient and avoid obstacles. The fixed-point monitoring devices in low-risk areas release resources in stages according to the shutdown ratio of 1 - real-time risk indicator / 80, and preferentially turn off the farthest devices and redundant cameras. Directional permission controllers and process locks are deployed on abnormal paths, and the restriction intensity is dynamically adjusted according to the operator's position and speed. The startup time is inversely proportional to the operating speed. The full-stack self-checking protocol checks the device status every 30 seconds. The hardware layer detects the focusing accuracy of the camera and the battery voltage, and the software layer verifies the firmware signature. When the device efficiency index is lower than 60, the backup device is switched and the network bandwidth is reallocated.

[0022] The regional decision-making layers exchange risk indicator data with adjacent nodes through the Byzantine fault tolerance algorithm, broadcast the data once every 1 second, and execute a three-phase consensus protocol. The areas where the differences in risk indicators exceed 30% are marked as conflict areas. If the data difference from the cloud analysis layer exceeds the threshold, a self-checking instruction for the monitoring layer is triggered, the sensors are calibrated, and the abnormal ports are restarted. After the self-checking is completed, the data is uploaded again. The parameters of the simulated management nodes are adjusted according to the dynamic equation, and the survival period is positively correlated with the local risk indicators. At the same time, the interaction logic and energy consumption mode of the protocol stack are modified in real time through an adaptive learning mechanism to increase the difficulty of attacker identification. Finally, the system forms a closed-loop control from data collection, risk calculation, global correction to resource scheduling, achieving precise defense and resource optimization in high-threat areas.

[0023] Although embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. An intelligent security comprehensive management and control system, characterized in that, Including: The monitoring layer monitors real-time service data streams, process status, and environmental parameters through fixed-point monitoring devices, supplements monitoring blind spots through mobile monitoring devices, and simulates normal business processes through simulated management nodes to identify abnormal operations. The monitoring layer transmits the collected data to the regional decision-making layer; the monitoring layer also includes historical operation anomaly frequencies, real-time process deviation degrees, and equipment efficiency indexes for calculating risk indicators in the regional decision-making layer; Based on the data of the monitoring layer, the regional decision-making layer calculates local risk indicators through a dynamic weight formula and generates a local business topology sub-graph. At the same time, according to the growth of risk indicators, it triggers the simulated management node to generate and record abnormal operations. The parameters of the simulated management node are adjusted according to a dynamic equation, and at the same time, the local business topology sub-graph and the recorded abnormal operations are uploaded to the cloud analysis layer; The cloud analysis layer integrates all local business topology sub-graphs, corrects risk indicator errors through a conflict resolution algorithm, constructs a dynamic priority business topology network, generates a risk gradient, marks high-threat areas based on a risk gradient diffusion model, and issues updated weight parameters to the regional decision-making layer; The execution control layer, according to the risk gradient of the dynamic priority business topology network, schedules mobile monitoring devices to focus on high-threat areas, suspends redundant processes in low-risk areas, deploys interception strategies and optimization means on abnormal operation paths according to abnormal characteristics, and generates self-check instructions through a full-stack self-check protocol for periodically verifying the operating status of devices.

2. The intelligent security comprehensive management and control system according to claim 1, wherein: The monitoring layer includes: (a) Fixed-point monitoring devices, including high-precision sensors supporting multi-dimensional data collection, process status recorders, and environmental parameter collection devices deployed on fixed nodes. The environmental parameter collection devices collect data on temperature, humidity, energy consumption, human flow, light, vibration, and electromagnetic interference intensity in real time; (b) Mobile monitoring devices, including unmanned aerial vehicles equipped with multi-spectral sensors and inspection robots equipped with environmental scanners, used to dynamically cover the monitoring blind spots of the fixed-point monitoring devices and transmit scanned data in real time; (c) Simulated management nodes, consisting of virtual management nodes and physical management nodes. The virtual management nodes are generated based on process simulation technology and simulate the protocol logic and operation characteristics of normal business processes, including simulated task execution signals and dynamically changing process identifiers; the physical management nodes are low-power real devices that only send heartbeat signals and are randomly mapped to virtual management nodes. The heartbeat signal is a simple periodic signal regularly sent by the physical management node to indicate its online status but does not transmit actual business data.

3. An intelligent security comprehensive management and control system according to claim 1, characterized in that: The risk indicator calculation method of the regional decision-making layer includes: Dividing the business area monitored by the monitoring layer into unit grids, and each grid is defined as a business node; Based on the historical operation anomaly frequencies, real-time process deviation degrees, equipment efficiency indexes, and anti-fragility gain factors collected by the monitoring layer, calculating the real-time risk indicators of each business node through a dynamic weight formula; the anti-fragility gain factor has a logarithmic relationship with the number of historical anomalies and the simulation node trigger rate, and the initial value is 1; When it is detected that the node risk index exceeds the preset threshold, it is marked as a high-threat node. The risk index of the high-threat node is transmitted to the adjacent nodes according to the exponential decay rule through the risk gradient diffusion model. After the adjacent nodes receive the risk index, it is added to their own risk index to form a dynamic risk diffusion link. The regional decision-making layer also deploys a lightweight prediction model based on time series analysis, predicts the direction of weight parameter adjustment within the next 5 seconds based on historical risk indicators and environmental parameters, and uploads the prediction results to the cloud analysis layer for global correction to reduce the risk indicator calculation deviation caused by network delays.

4. An intelligent security comprehensive management and control system according to claim 2, characterized in that: When the regional decision-making layer detects that the local risk index continues to grow and exceeds a preset threshold, a simulation management node is generated; The simulation management node simulates the process signal and protocol characteristics of the fixed-point monitoring device in the monitoring layer; the parameter strength and response delay parameters of the simulation management node are adjusted according to the dynamic equation, and the interaction mode of the normal business process is dynamically simulated; And record the attacker's abnormal access to the simulated management node, illegal operations or resource abuse behaviors, extract the operation type, frequency, interaction protocol and path characteristics, generate abnormal feature vectors and store them in the anti-fragile strategy library of the cloud analysis layer; the anti-fragile strategy library dynamically adjusts the risk indicator formula weight of the dynamic priority business topology network to improve the sensitivity to similar anomalies; and simulates unknown abnormal features through a generative adversarial network, dynamically generates optimization strategies and sends them to the regional decision-making layer; the generative adversarial network supports cross-protocol violation, resource abuse and process interference composite scenario simulation; The optimization strategy includes modifying the dynamic adjustment parameters of the simulation management node and adjusting the risk diffusion coefficient of the dynamic priority service topology network, and optimizing the linkage rules between resource allocation and process blocking; the optimization strategy is verified in the virtualized sandbox environment and then sent to the regional decision-making layer and the execution control layer; The survival period of the simulated management node is positively correlated with the local risk index, and the higher the risk index, the longer the virtual management survival time; The cloud analysis layer dynamically adjusts the node mapping rules according to the abnormal feature matching results, so that the function mapping between the virtual management node and the physical device changes randomly, preventing attackers from identifying the simulated management node through long-term observation; The simulation management node also integrates an adaptive learning mechanism to adjust the simulation characteristics and response strategies in real time according to the attacker's behavior patterns, including dynamically modifying the network protocol stack interaction logic, adjusting parameter intensity cycles and counterfeit device energy consumption patterns, so as to increase the operator's identification difficulty and violation costs.

5. An intelligent security comprehensive management and control system according to claim 1, characterized in that: Integrate the local business topology sub-maps uploaded by all regional decision-making layers, and correct the risk indicator errors in the local business topology sub-maps through the conflict resolution algorithm, including: Receive local risk indicator data from decision-makers in different regions; The weighted voting algorithm is used to correct the differences in risk indicators in the conflict area. The weights of the weighted voting are positively correlated with the credibility of the historical data of adjacent nodes. The credibility of the historical data is calculated by the cloud analysis layer according to the risk indicator error rate of the regional decision layer. The risk indicator error rate is the deviation between the historical risk indicator prediction result and the actual occurrence frequency of abnormal events. Based on the corrected risk indicator data, a dynamic priority service topology network is constructed through a risk gradient diffusion model. The risk gradient diffusion model dynamically assigns service priorities according to the correlation between nodes and the differences in risk indicators, and generates a risk gradient. The cloud analysis layer dynamically calculates the updated weight parameters according to the risk gradient value and the credibility of historical data, and sends the updated weight parameters to the regional decision layer for real-time adjustment of the dynamic weight formula.

6. An intelligent security comprehensive management and control system according to claim 5, characterized in that: The collaborative verification method between the regional decision layer and the cloud analysis layer includes: The regional decision layer exchanges the local risk indicator data with adjacent nodes through a consensus mechanism based on the Byzantine fault tolerance algorithm, generates a local service topology subgraph and marks the conflict area. The conflict area is the area where the difference in risk indicators between adjacent nodes exceeds a preset difference threshold. If the difference in risk indicators between the regional decision layer and the cloud analysis layer exceeds the preset threshold, a self-check instruction for the monitoring layer device is triggered, including sensor calibration, restart of abnormal network ports, and data verification. After the self-check is completed, the local risk indicators are recalculated, and the updated local risk indicators are uploaded to the cloud analysis layer for global correction.

7. An intelligent security comprehensive management and control system according to claim 1, characterized in that: The resource scheduling method of the execution control layer includes: The scheduling of the mobile monitoring device further adopts the drone swarm cooperation technology and the robot cooperation mechanism. The drones and the inspection robots share the risk gradient information of the dynamic priority service topology network through a distributed communication protocol, and dynamically adjust the focusing density and the moving trajectory. Based on the high-threat nodes marked in the regional decision layer, a monitoring focusing area centered on the set of high-threat nodes is formed. The drone swarm approaches the high-threat nodes along a spiral trajectory, and the inspection robots move along the direction of the rising risk gradient to achieve full-dimensional spatial coverage of the high-threat area. Suspend a dynamically proportional number of fixed-point monitoring devices in the area where the risk indicators are lower than the preset threshold to release computing resources, and preferentially allocate them to the interception strategies in the high-threat area. Deploy resource restriction devices and process blocking mechanisms on the abnormal operation path to block the illegal operation route. The resource restriction devices include a directional permission controller and a process lock, which dynamically adjust the restriction intensity and the scope of action according to the real-time position, operation speed, and behavior characteristics of the operator. The startup timing of the resource restriction device is dynamically adjusted according to the operation speed of the operator, and the operation speed is inversely proportional to the interval time of the startup timing. The execution control layer monitors the device operation status in real time, periodically verifies the hardware functions, software integrity, and collaborative working latency through the full-stack self-checking protocol, and triggers the adjustment of the resource allocation strategy when anomalies are detected, including allocating the released computing resources to high-threat areas according to the risk gradient weights, and automatically switching to a standby device and reallocating the network bandwidth when the device efficiency index is lower than the safety threshold.

Citation Information

Patent Citations

  • A mobile management system and method based on IPv6 heterogeneous converged network

    CN102291746A

  • Method for transmitting and sharing threat information based on dynamic attack surface

    CN111683057A

  • Dynamic monitoring method and system for realizing intelligent security

    CN120071238A

  • Method and device for managing security in a computer network

    US20160330219A1

Cited By

  • Intelligent security management system and method based on big data

    CN120875587A

  • Industrial internet-of-things monitoring system for normal slag heat exchange process of inferior oil device

    CN121028722A

  • TBM remote monitoring method based on multi-level collaborative management architecture

    CN121262216A

  • TBM remote monitoring method based on multi-level collaborative management architecture

    CN121262216B

  • Internet of Things monitoring data processing method and system

    CN121396873A