An intelligent security integrated management and control system

Through the intelligent security integrated management and control system, real-time monitoring, dynamic calculation and global correction, and dynamic resource scheduling, the problems of resource allocation lag and defense blind spots in the existing security system in risk diffusion scenarios are solved, and efficient risk identification and resource optimization are achieved.

CN120263545BActive Publication Date: 2025-09-19FUJIAN YUNSU INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510732774.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-04
Publication Date
2025-09-19
Estimated Expiration
2045-06-04

AI Technical Summary

Technical Problem

Existing security systems have difficulty adjusting resource allocation in a timely manner in real-time risk diffusion scenarios. Information sharing between devices is limited in the partitioned independent control mode, resulting in defense blind spots. Static rule-driven equipment scheduling leads to redundant resources in low-risk areas and insufficient protection for high-value targets, making it difficult to balance security effectiveness and operation and maintenance costs.

Method used

The monitoring layer collects multi-source data in real time, the regional decision-making layer dynamically calculates risk indicators, the cloud analysis layer integrates global topology subgraphs and corrects errors, simulates management nodes to adjust strategies, and the execution control layer dynamically schedules resources. The risk gradient diffusion model and generative adversarial network are used to enhance defense capabilities.

Benefits of technology

It achieves accurate risk identification and resource optimization in dynamic threat scenarios, dynamically focuses on high-threat areas, shuts down redundant processes, deploys interception strategies, and ensures stable system operation and efficient resource allocation.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The present invention provides an intelligent security integrated management and control system, which relates to the field of intelligent security management and control; it comprises: a monitoring layer, a regional decision-making layer, a cloud analysis layer and an execution control layer; the monitoring layer collects data through fixed-point monitoring equipment, mobile monitoring equipment and simulation management nodes; the regional decision-making layer calculates local risk indicators based on the data and generates local business topology subgraphs, and at the same time triggers simulation management nodes to generate and record abnormal operations; the cloud analysis layer integrates local business topology subgraphs, corrects risk indicator errors, constructs a dynamic priority business topology network and generates a risk gradient; the execution control layer dispatches mobile monitoring equipment according to the risk gradient, shuts down redundant processes, and deploys interception strategies and optimization means, and at the same time verifies the equipment operation status through a full-stack self-check protocol.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of intelligent security management and control, and in particular to an intelligent security integrated management and control system. Background Art

[0002] With the rapid development of the Internet of Things and artificial intelligence technologies, the demand for the application of intelligent security systems in public safety, industrial monitoring and other fields is growing. Traditional security relies on manual inspections and the linkage of fixed equipment, which makes it difficult to cope with complex and changeable abnormal behaviors. The current industry urgently needs to achieve comprehensive management and control capabilities such as real-time dynamic response, accurate threat identification and efficient resource scheduling to enhance the active defense level of the security system.

[0003] The security solutions currently commonly used in the industry mainly include the following two categories: the first is a centralized management and control architecture, which receives front-end sensor data through a central server and triggers response actions based on preset rules; the second is a partitioned independent management mode, which divides the monitoring area into independent sub-units, and each unit executes standardized operating procedures through a local controller. Although this type of solution can deal with conventional security threats, its management logic is rigid and cannot adapt to dynamically changing threat scenarios.

[0004] The existing solutions have the following shortcomings: the centralized architecture relies on central servers to process massive amounts of data, making it difficult to adjust resource allocation in a timely manner in risk diffusion scenarios, resulting in lagging defense in key areas; under the partitioned independent management mode, information sharing between devices is limited, and monitoring strategies cannot be dynamically optimized according to the global threat situation, resulting in defense blind spots; static rule-driven equipment scheduling can easily lead to resource redundancy in low-risk areas, while high-value targets are insufficiently protected, making it difficult to balance security effectiveness and operation and maintenance costs. Summary of the Invention

[0005] (1) Technical problems solved

[0006] In response to the shortcomings of the existing technology, the present invention provides an intelligent security integrated management and control system to solve the problems raised in the above background technology. In the real-time risk diffusion scenario, the existing system is difficult to adjust resource allocation in a timely manner due to its centralized architecture; in the partitioned independent management mode, information sharing between devices is limited, and it is impossible to dynamically optimize the monitoring strategy according to the global threat situation, forming a defense blind spot; static rule-driven equipment scheduling is prone to cause resource redundancy in low-risk areas, while high-value targets are insufficiently protected, making it difficult to balance the risks of security effectiveness and operation and maintenance costs.

[0007] (2) Technical solution

[0008] To achieve the above objectives, the present invention is implemented through the following technical solutions: an intelligent security integrated management and control system, including: a monitoring layer that uses fixed-point monitoring equipment to monitor real-time business data streams, process status, and environmental parameters, uses mobile monitoring equipment to supplement monitoring blind spots, and uses simulation management nodes to simulate normal business processes to identify abnormal operations. The monitoring layer transmits the collected data to the regional decision-making layer; the monitoring layer also includes historical operation abnormality frequencies, real-time process deviations, and equipment efficiency indexes, which are used by the regional decision-making layer to calculate risk indicators;

[0009] Based on the data from the monitoring layer, the regional decision-making layer calculates local risk indicators through a dynamic weight formula and generates a local business topology subgraph. At the same time, according to the growth of the risk indicator, the simulation management node is triggered to generate and record abnormal operations. The parameters of the simulation management node are adjusted according to the dynamic equation. At the same time, the local business topology subgraph and the recorded abnormal operations are uploaded to the cloud analysis layer.

[0010] The cloud analysis layer integrates all local business topology subgraphs, corrects risk indicator errors through conflict resolution algorithms, builds a dynamic priority business topology network, generates risk gradients, and marks high-threat areas based on the risk gradient diffusion model, and sends updated weight parameters to the regional decision-making layer;

[0011] The execution control layer dispatches mobile monitoring equipment to focus on high-threat areas and suspends redundant processes in low-risk areas according to the risk gradient of the dynamic priority business topology network, and deploys interception strategies and optimization measures on abnormal operation paths according to abnormal characteristics, and generates self-test instructions through the full-stack self-test protocol for periodic verification of the equipment operation status.

[0012] Preferably, the monitoring layer collects business data flow, process status and environmental parameters in real time through the fixed-point monitoring equipment, wherein the fixed-point monitoring equipment includes high-precision sensors, process status recorders and environmental parameter collection equipment deployed at fixed nodes for real-time monitoring of temperature, humidity, energy consumption, human flow, light, vibration and electromagnetic interference intensity data; the mobile monitoring equipment includes a drone equipped with a multi-spectral sensor and a patrol robot equipped with an environmental scanner, the drone covers the monitoring blind spot of the fixed-point monitoring equipment through a preset flight path, the patrol robot scans the ground blind spot along a dynamically planned trajectory and transmits the scanning data back to the regional decision-making layer in real time; the simulation management node The point consists of a virtual management node and a physical management node. The virtual management node simulates the protocol logic and operation characteristics of the normal business process based on process simulation technology; the physical management node is a low-power real device that regularly sends heartbeat signals and is associated with the virtual management node through random mapping rules. The heartbeat signal is a simple timing signal that is only used to indicate the online status without transmitting actual monitoring data; the monitoring layer transmits the collected data to the regional decision-making layer, which also includes the historical operation abnormality frequency, real-time process deviation and equipment efficiency index, so that the regional decision-making layer can calculate the risk indicator; the equipment efficiency index is periodically verified through the full-stack self-test protocol of the fixed-point monitoring device and the mobile monitoring device.

[0013] Preferably, the regional decision layer divides the business area monitored by the monitoring layer into equal-area grid units, and each grid is defined as a business node; based on the historical operation abnormality frequency, real-time process deviation, equipment efficiency index and anti-fragility gain factor collected by the monitoring layer, the real-time risk index of each node is calculated by a dynamic weight formula, wherein the historical operation abnormality frequency is the number of abnormal events per minute counted by the abnormal event log stored in the monitoring layer, and the real-time process deviation is obtained by calculating the standard deviation deviation of the monitoring data from the preset benchmark value, and the preset benchmark value is the mean of the historical monitoring data of the environmental sensor and the infrared thermal imaging sensor in a normal state, and the standard deviation is the average of the historical monitoring data of the environmental sensor and the infrared thermal imaging sensor in a normal state. The difference is a quantitative indicator of the degree of dispersion of the historical data distribution, which is used to measure the fluctuation range of data under normal conditions; the deviation is the degree of difference between the real-time monitoring data and the preset baseline value, which is quantified by calculating the standard deviation multiple or absolute value difference between the real-time data and the baseline value. Specifically, when the real-time data exceeds the range of ±2 times the standard deviation of the baseline value, it is judged as abnormal and triggers the calculation of the real-time risk index; the higher the deviation, the greater the risk of sensor data abnormality, and the system dynamically adjusts the monitoring resource allocation strategy accordingly; the equipment effectiveness index is generated by periodic verification of the full-stack self-test protocol of the fixed-point monitoring equipment and the mobile monitoring equipment; the real-time risk index formula is: , where H f is the number of historical anomalies counted by the monitoring layer, S eD is the deviation between the monitoring data and the benchmark value. h Score the equipment operation status, A g Calculated by the logarithmic relationship between the number of historical anomalies and the trigger rate of the simulated node; the weight values ​​of α, β, γ, and δ are dynamically adjusted by the cloud analysis layer according to the ambient light intensity and crowd density, and the anti-fragile gain factor A g It is logarithmically related to the number of historical anomalies and the trigger rate of simulated nodes. Calculate, where N a is the number of historical anomalies, R d To simulate the node trigger rate; when the real-time risk index of a business node exceeds the preset threshold, it is marked as a high-threat node, otherwise it is marked as a low-threat node. The preset threshold Tv is 80, and the value range is 0-100; the risk index of the high-threat node is transmitted to the adjacent nodes according to the exponential decay rule through the risk gradient diffusion model; the adjacent nodes receive the attenuated risk index and add it to their own risk index to form a dynamic risk diffusion link. The formula of the risk gradient diffusion model is: , where k is the diffusion coefficient and d is the distance between nodes. A new global topology is generated every 5 seconds, marking the link with the largest risk gradient, such as the shortest path from the entrance to the core computer room. The regional decision-making layer also deploys a lightweight prediction model based on time series analysis. The input parameters include historical risk indicators, temperature, humidity, and electromagnetic interference intensity data. The model outputs the weight parameter adjustment direction within the next 5 seconds and uploads the prediction results to the cloud analysis layer for global correction.

[0014] Preferably, the weight values ​​of α, β, γ, and δ are dynamically adjusted by the cloud analysis layer according to the ambient light intensity and the crowd density. Specifically, the environmental sensor of the monitoring layer collects data in real time, the data unit is Lux, and the sampling frequency is 1 time per second; the multispectral sensor of the fixed-point monitoring equipment captures the video stream, and the number of people in the area is counted in real time in combination with the deep learning model to calculate the crowd density (unit: people / m 2 ), and normalize the light intensity L and crowd density D to the range of 0,1, the formula is: ;

[0015] Among them, all dark L min 0Lux, strong light L max 1000 Lux, D min 0 people / m 2 , Dmax is 5 people / m 2 The cloud analysis layer dynamically calculates weight values ​​based on the following rules:

[0016] Rule 1 is the influence of light intensity on the real-time process deviation weight α. Lnorm<0.3 indicates low light: due to the increased sensitivity of the monitoring equipment, the weight α is increased to amplify the sensitivity of abnormal detection; when L norm When <0.7, it is high illumination: Since visible light interference may reduce sensor accuracy, the weight is appropriately reduced; the adjustment formula is: Rule 2 is the influence of traffic density on the weight β of historical operation abnormal frequency. norm When it is >0.6, it is a high crowd density: because the complex activities of people can easily mask the real attack, the weight is reduced to reduce the dependence on historical data; when D norm When the value is >0.4, it indicates low crowd density: the weight is increased to strengthen the matching of historical attack patterns. The adjustment formula is: ;

[0017] Rule 3 ensures the stability of the equipment performance index weight γ. That is, regardless of how the environmental parameters change, the weight γ maintains a base value of 0.2. Only when the equipment performance index falls below the safety threshold, the weight γ is increased proportionally to switch to the backup equipment.

[0018] Rule 4 is the dynamic balance of the anti-fragility gain factor weight δ. When a new abnormal feature is detected, the weight δ is increased through the anti-fragility strategy library. The adjustment formula is: .

[0019] Preferably, when the regional decision-making layer detects that the local risk index continues to grow and exceeds a preset threshold of 80, the simulation management node generation mechanism is triggered; the simulation management node simulates the process signal and protocol characteristics of the fixed-point monitoring device, and its signal strength and response delay parameters are adjusted according to the dynamic equation. The simulation management node records the attacker's abnormal access, illegal operation or resource abuse behavior, extracts the operation type, frequency, interaction protocol and path characteristics, generates an abnormal feature vector and stores it in the anti-fragile strategy library of the cloud analysis layer; the anti-fragile strategy library dynamically adjusts the risk indicator formula weight according to the abnormal feature vector, and simulates a composite scenario of protocol violation, resource abuse and process interference through a generative adversarial network, generates an optimization strategy and verifies it in a virtualized sandbox environment, and finally sends it to the regional decision-making layer and the execution control layer, wherein the generative adversarial network formula is: The generator G inputs the noise vector z and generates the simulated abnormal feature vector G(z); the discriminator D distinguishes the real abnormal data x from the generated data G(z) and outputs the discrimination probability D(x)∈[0,1]; p data is the probability distribution of the true abnormal feature vector; p z is the probability distribution of the noise vector.

[0020] Preferably, the cloud analysis layer receives the local business topology subgraphs uploaded by all regional decision layers, and corrects the risk indicator differences of the conflicting areas through a weighted voting algorithm. The weighted voting weight is positively correlated with the credibility of the historical data of the adjacent nodes, and the credibility of the historical data is calculated by the risk indicator prediction error rate. The weighted voting algorithm formula is: ; Where V 校正 is the adjusted risk index; w k is the voting weight of the kth neighboring node, and the historical data credibility C k Positive correlation, that is, w k =C k ; Vk is the original risk index reported by the kth neighboring node; n is the total number of neighboring nodes participating in the vote, and the credibility of the historical data is calculated as Ck=1-E k / total ; Among them E k is the risk indicator error rate of the kth adjacent node, calculated as the deviation between the historical risk indicator prediction result and the actual frequency of abnormal events; E total is the benchmark value of the system's total error rate; based on the corrected risk indicator data, the cloud-based analysis layer constructs a dynamic priority business topology network through a risk gradient diffusion model. The model dynamically allocates business priorities and generates risk gradients based on the distance between nodes and the difference in risk indicators; the cloud-based analysis layer sends the updated weight parameters to the regional decision-making layer for real-time adjustment of the dynamic weight formula, and at the same time dynamically adjusts the mapping rules of the simulated management nodes based on the abnormal feature matching results, so that the functional mapping between virtual management and physical devices changes randomly.

[0021] Preferably, the execution control layer dispatches mobile monitoring equipment according to the risk gradient of the dynamic priority business topology network, and the drone swarm dynamically adjusts the focus area density through a distributed task allocation algorithm, which is specifically implemented as follows: after the drone cluster receives the risk gradient data sent by the cloud analysis layer, it allocates each drone to the surrounding area of ​​the high-threat node based on the auction algorithm. The auction algorithm dynamically bids for the target area according to the current position of the drone, the remaining flight time and the task priority. The winning drone automatically adjusts the flight altitude and speed to form a multi-layer focus area. The inner drone approaches the high-threat node in a spiral trajectory, and the outer drone cruises along an elliptical path to block potential abnormal paths. The focus area density is adjusted in real time according to the risk gradient. For every 10% increase in the risk gradient, the distance between drones is reduced by 15%; the inspection robot passes through The path planning algorithm optimizes the movement trajectory. After receiving risk gradient data in real time, it preferentially moves in the direction of increasing risk gradient while avoiding obstacles and low-threat areas. The path is updated every 5 seconds to ensure full-dimensional space coverage of high-threat areas. When suspending fixed-point monitoring equipment in an area where the risk index is lower than the preset threshold, the shutdown ratio is dynamically calculated based on the risk index as 1-real-time risk index / preset threshold. The shutdown operation is performed in stages, first shutting down the device farthest from the high-threat area, then shutting down redundant cameras, and finally shutting down environmental sensors. The released CPU and memory resources are allocated to the interception strategy in the high-threat area through the resource pool management module.

[0022] Preferably, the interception strategy deployment uses software-defined network technology to dynamically redirect attack traffic to the virtual management node; resource restriction devices and process blocking mechanisms are deployed on abnormal operation paths, and the resource restriction devices contain directional permission controllers and process locks. The restriction strength and scope of action are dynamically adjusted according to the operator's real-time location, operation speed and behavioral characteristics, and the startup timing of the resource restriction device is dynamically adjusted with the operator's operation speed, and the interval between the two is inversely proportional; the execution control layer verifies the device operation status every 30 seconds through the full-stack self-check protocol, the hardware layer detects the camera focus accuracy, motor wear rate and battery voltage, the software layer verifies the consistency of the firmware signature and communication protocol version, and the collaborative layer measures the command response delay between the drone and the robot. When the device performance index is lower than the safety threshold of 60, the system automatically marks the faulty device, cuts off its network connection and activates the backup device. After the backup device is started, it synchronizes the latest risk gradient data and takes over the original device's tasks, while reallocating the network bandwidth.

[0023] Preferably, the regional decision-making layer exchanges local risk indicator data with adjacent nodes through a consensus mechanism based on the Byzantine fault-tolerant algorithm, generates a local business topology subgraph, and marks the conflict area. The consensus mechanism of the Byzantine fault-tolerant algorithm is that each adjacent node acts as a consensus participant, broadcasts its own calculated local risk indicator and corresponding spatiotemporal label in each synchronization cycle, and the synchronization cycle defaults to 1 second. After receiving the data, all nodes execute a three-stage protocol, namely, pre-preparation, preparation, and submission, and verify the validity of the data through the majority voting principle. If more than 2 / 3 of the nodes reach a consensus, a local business topology subgraph is generated, and the risk indicator difference exceeds a preset threshold, where the area with an absolute difference of 30% is the conflict area. Malicious nodes or data abnormal nodes are excluded from the consensus network through a dynamic reputation value mechanism. If the risk indicator difference between the regional decision-making layer and the cloud analysis layer exceeds a preset threshold, the self-test instruction of the monitoring layer device is triggered, including camera focus calibration, abnormal network port restart, and sensor data verification. After the self-test is completed, the local risk indicator is recalculated, and the updated data is uploaded to the cloud analysis layer for global correction to ensure the data consistency of the risk gradient diffusion model.

[0024] (3) Beneficial effects

[0025] The present invention provides an intelligent security integrated management and control system. It has the following beneficial effects:

[0026] 1. The accuracy of local risk indicator calculations is improved through the fusion of multi-source data at the monitoring layer and the dynamic weight formula at the regional decision-making layer. The cloud-based analysis layer integrates global topology subgraphs and corrects errors, building a dynamic priority network to accurately mark high-threat areas. Simulation management nodes are adjusted according to dynamic equations and combined with generative adversarial networks to enhance the ability to trap covert attacks and reduce the risk of being identified.

[0027] 2. A risk gradient diffusion model is used to drive mobile monitoring equipment to dynamically focus on high-threat areas, while simultaneously shutting down redundant processes to release resources. Interception strategies and sound and light jamming equipment are adaptively deployed based on abnormal characteristics to block abnormal paths. A full-stack self-checking protocol periodically verifies the operating status of equipment and automatically switches to backup nodes to ensure continuous and stable system operation and efficient resource allocation. DETAILED DESCRIPTION

[0028] The following is a clear and complete description of the technical solutions in the embodiments of the present invention. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of the present invention.

[0029] An embodiment of the present invention provides an intelligent security integrated management and control system, in which the monitoring layer collects temperature, humidity, energy consumption, pedestrian flow, light, vibration and electromagnetic interference intensity data in real time through high-precision sensors deployed at fixed nodes, and uses process status recorders to monitor business data flow and process status; the multispectral sensor drone in the mobile monitoring equipment covers the monitoring blind spots of the fixed equipment according to a preset flight path, and the inspection robot scans the ground blind spots through dynamic trajectory planning and transmits data back to the regional decision-making layer in real time; the simulation management node is composed of virtual nodes and physical nodes, and the virtual node generates simulation task execution signals and dynamic process identifiers based on process simulation technology. The physical node, as a low-power device, periodically sends heartbeat signals and associates the virtual node through random mapping rules; the monitoring layer transmits the collected real-time data, historical operation abnormality frequency, real-time process deviation and equipment efficiency index to the regional decision-making layer, wherein the equipment efficiency index verifies the hardware function and software integrity every 30 seconds through a full-stack self-test protocol.

[0030] The regional decision-making layer divides the monitoring area into grid units of equal area, with each grid serving as an independent business node. The dynamic weight formula is used to calculate the node's real-time risk index based on the historical frequency of operational anomalies, real-time process deviation, equipment efficiency index, and anti-fragility gain factor. The real-time process deviation is obtained by comparing the standard deviation of the monitoring data with the preset benchmark value. When the deviation exceeds ±2 times the standard deviation, the risk index calculation is triggered. The anti-fragility gain factor is dynamically adjusted based on the logarithmic relationship between the number of historical anomalies and the simulated node trigger rate. When the node risk index exceeds the threshold of 80, it is marked as a high-threat node, and the risk index is transferred to adjacent nodes according to the exponential decay rule through the risk gradient diffusion model, forming a dynamic risk diffusion link. The lightweight prediction model deployed by the regional decision-making layer inputs historical risk indicators and environmental parameters, predicts the direction of weight parameter adjustment within the next 5 seconds, and uploads the prediction results to the cloud analysis layer for global correction.

[0031] The cloud-based analysis layer receives local business topology subgraphs uploaded by each regional decision-making layer and uses a weighted voting algorithm to correct the risk indicator differences in the conflicting areas. The voting weight is positively correlated with the credibility of the historical data of adjacent nodes. A dynamic priority business topology network is constructed based on the corrected data. Business priorities are assigned and risk gradients are generated based on the distance between nodes and the difference in risk indicators. The cloud-based analysis layer dynamically adjusts weight parameters based on light intensity and crowd density. Light intensity is collected in real time by environmental sensors and normalized to the range of 0-1, while crowd density is calculated by counting the number of people using a deep learning model. When the light intensity is lower than 0.3, the weight of the real-time process deviation is increased to improve the sensitivity of anomaly detection. When the crowd density is higher than 0.6, the weight of the historical operation anomaly frequency is reduced to reduce misjudgments. The updated weight parameters are sent to the regional decision-making layer. At the same time, the anti-fragile strategy library adjusts the risk formula weight based on the anomaly feature vector and generates optimization strategies by simulating complex anomaly scenarios through a generative adversarial network. After verification in the virtualized sandbox, the strategy is sent to the execution control layer.

[0032] The execution control layer dispatches drone swarms and inspection robots to focus on high-threat areas based on the risk gradient; drone swarms bid for target areas through an auction algorithm, and the winning drone approaches the high-threat node in a spiral trajectory, while the outer drones cruise along an elliptical path to block abnormal paths. For every 10% increase in the risk gradient, the distance between drones decreases by 15%; the inspection robots use The algorithm plans paths, prioritizing movement along the increasing risk gradient and avoiding obstacles. Fixed-point monitoring equipment in low-risk areas releases resources in phases based on a shutdown ratio of 1 minus the real-time risk index / 80, prioritizing the furthest devices and redundant cameras. Directional permission controllers and process locks are deployed on abnormal paths, dynamically adjusting restriction strength based on the operator's location and speed, with activation timing inversely proportional to operation speed. A full-stack self-check protocol verifies device status every 30 seconds. The hardware layer checks camera focus accuracy and battery voltage, and the software layer verifies firmware signatures. When the device performance index falls below 60, it switches to a backup device and reallocates network bandwidth.

[0033] The regional decision-making layer exchanges risk indicator data with adjacent nodes through the Byzantine fault-tolerant algorithm, broadcasts data once every 1 second and executes a three-stage consensus protocol, marking areas where the risk indicator difference exceeds 30% as conflict areas; if the data difference with the cloud analysis layer exceeds the threshold, the monitoring layer self-test instruction is triggered, the sensor is calibrated and the abnormal port is restarted, and the data is uploaded again after the self-test is completed; the simulation management node parameters are adjusted according to the dynamic equation, and the survival cycle is positively correlated with the local risk indicator. At the same time, the protocol stack interaction logic and energy consumption mode are modified in real time through the adaptive learning mechanism, increasing the difficulty of attacker identification; ultimately, the system forms a closed-loop control from data collection, risk calculation, global correction to resource scheduling, realizing precise defense and resource optimization in high-threat areas.

[0034] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. An intelligent security integrated management and control system, characterized in that: include: The monitoring layer uses fixed-point monitoring equipment to monitor real-time business data flows, process status, and environmental parameters. It also uses mobile monitoring equipment to supplement monitoring blind spots. It also simulates normal business processes through simulated management nodes to identify abnormal operations. The monitoring layer transmits the collected data to the regional decision-making layer. The monitoring layer also includes historical operational abnormality frequencies, real-time process deviations, and equipment efficiency indices, which are used by the regional decision-making layer to calculate risk indicators. Based on the data from the monitoring layer, the regional decision-making layer calculates local risk indicators using a dynamic weight formula and generates a local business topology subgraph. Simultaneously, based on the growth of the risk indicators, it triggers the generation of a simulation management node and records abnormal operations. The parameters of the simulation management node are adjusted according to the dynamic equation, and the local business topology subgraph and the recorded abnormal operations are uploaded to the cloud analysis layer. The cloud analysis layer integrates all local business topology subgraphs, corrects risk indicator errors through conflict resolution algorithms, builds a dynamic priority business topology network, generates risk gradients, and marks high-threat areas based on the risk gradient diffusion model, and sends updated weight parameters to the regional decision-making layer; The execution control layer dispatches mobile monitoring devices to focus on high-threat areas based on the risk gradient of the dynamic priority service topology network, suspends redundant processes in low-risk areas, and deploys interception strategies and optimization measures on abnormal operation paths based on abnormal characteristics. It also generates self-test instructions through the full-stack self-test protocol for periodic verification of device operation status. Among them, the simulation management node adjusts its parameter strength and response delay parameters according to the dynamic equation, and dynamically simulates the interaction mode of the normal business process, while recording the attacker's abnormal access, illegal operation or resource abuse behavior, extracting the operation type, frequency, interaction protocol and path characteristics to generate abnormal feature vectors, and storing them in the anti-fragile strategy library; the anti-fragile strategy library simulates the composite scenario of protocol violation, resource abuse and process interference through the generative adversarial network, generates optimization strategies, verifies them in the virtualized sandbox environment, and sends them to the regional decision-making layer and the execution control layer; the generative adversarial network supports the simulation of composite scenarios of cross-protocol violation, resource abuse and process interference, and the optimization strategy includes modifying the dynamic adjustment parameters of the simulation management node and adjusting the risk diffusion coefficient of the dynamic priority business topology network, and optimizing the linkage rules of resource allocation and process blocking.

2. The intelligent security integrated management and control system according to claim 1, characterized in that: The monitoring layer includes: (a) Fixed-point monitoring equipment, including high-precision sensors that support multi-dimensional data collection, process status recorders, and environmental parameter collection equipment deployed at fixed nodes. The environmental parameter collection equipment collects real-time data on temperature, humidity, energy consumption, human traffic, light, vibration, and electromagnetic interference intensity; (b) mobile monitoring equipment, including drones equipped with multispectral sensors and patrol robots equipped with environmental scanners, used to dynamically cover the monitoring blind spots of the fixed-point monitoring equipment and transmit scanning data in real time; (c) Simulated management nodes, consisting of virtual management nodes and physical management nodes, wherein the virtual management nodes are generated based on process simulation technology, simulating the protocol logic and operational characteristics of normal business processes, including simulated task execution signals and dynamically changing process identifiers; the physical management nodes are low-power real devices that only send heartbeat signals and are randomly mapped to virtual management nodes. The heartbeat signals are simple timing signals sent periodically by the physical management nodes to indicate their online status, but do not transmit actual business data.

3. The intelligent security integrated management and control system according to claim 1, characterized in that: The risk indicator calculation method of the regional decision-making layer includes: Divide the business area monitored by the monitoring layer into unit grids, each grid being defined as a business node; Based on the historical operation abnormality frequency, real-time process deviation, equipment efficiency index and anti-fragility gain factor collected by the monitoring layer, the real-time risk index of each business node is calculated using a dynamic weight formula; the anti-fragility gain factor is logarithmically related to the historical abnormality number and the simulation node trigger rate, and the initial value is 1; When a node's risk index exceeds a preset threshold, it is marked as a high-threat node. The risk index of the high-threat node is transferred to adjacent nodes according to the exponential decay rule through the risk gradient diffusion model. After receiving the risk index, the adjacent nodes add it to their own risk index, forming a dynamic risk diffusion link. The regional decision-making layer also deploys a lightweight prediction model based on time series analysis, predicts the direction of weight parameter adjustment within the next 5 seconds based on historical risk indicators and environmental parameters, and uploads the prediction results to the cloud analysis layer for global correction to reduce the risk indicator calculation deviation caused by network delay.

4. The intelligent security integrated management and control system according to claim 2, characterized in that: When the regional decision-making layer detects that the local risk indicator continues to grow and exceeds a preset threshold, a simulation management node is generated; The simulation management node simulates the process signals and protocol characteristics of the fixed-point monitoring equipment in the monitoring layer; After generating the abnormal feature vector, the anti-fragility strategy library of the cloud analysis layer is stored; the anti-fragility strategy library dynamically adjusts the risk indicator formula weight of the dynamic priority service topology network to improve the sensitivity to similar abnormalities; Generative adversarial networks are used to simulate unknown anomaly features, dynamically generate optimization strategies, and distribute them to regional decision-makers. These networks support simulations of complex scenarios such as cross-protocol violations, resource abuse, and process interference. The optimization strategy includes modifying the dynamic adjustment parameters of the simulated management node and adjusting the risk diffusion coefficient of the dynamic priority service topology network, and optimizing the linkage rules between resource allocation and process blocking. The optimization strategy is verified in a virtualized sandbox environment and then issued to the regional decision-making layer and the execution control layer. The survival period of the simulated management node is positively correlated with the local risk index. The higher the risk index, the longer the virtual management survival time. The cloud analysis layer dynamically adjusts the node mapping rules based on the abnormal feature matching results, so that the functional mapping between the virtual management node and the physical device changes randomly, preventing attackers from identifying the simulated management node through long-term observation; The simulation management node also integrates an adaptive learning mechanism to adjust the simulation characteristics and response strategies in real time according to the attacker's behavior patterns, including dynamically modifying the network protocol stack interaction logic, adjusting the parameter intensity cycle and the energy consumption mode of the counterfeit device, so as to increase the operator's identification difficulty and the cost of violation.

5. The intelligent security integrated management and control system according to claim 1, characterized in that: Integrate the local business topology subgraphs uploaded by all regional decision-making layers and correct the risk indicator errors in the local business topology subgraphs through the conflict resolution algorithm, including: Receive local risk indicator data from decision-makers in different regions; A weighted voting algorithm is used to correct the difference in risk indicators in conflicting areas. The weight of the weighted voting is positively correlated with the credibility of the historical data of the adjacent nodes. The credibility of the historical data is calculated by the cloud analysis layer based on the risk indicator error rate of the regional decision-making layer. The risk indicator error rate is the deviation between the historical risk indicator prediction results and the actual frequency of abnormal events. Based on the corrected risk indicator data, a dynamic priority business topology network is constructed through a risk gradient diffusion model. The risk gradient diffusion model dynamically assigns business priorities based on the correlation between nodes and the difference in risk indicators, and generates a risk gradient. The cloud analysis layer dynamically calculates updated weight parameters based on the risk gradient value and the credibility of historical data, and sends the updated weight parameters to the regional decision-making layer for real-time adjustment of the dynamic weight formula.

6. The intelligent security integrated management and control system according to claim 5, characterized in that: The collaborative verification method between the regional decision-making layer and the cloud analysis layer includes: The regional decision-making layer exchanges the local risk indicator data with adjacent nodes through a consensus mechanism based on the Byzantine fault tolerance algorithm, generates a local business topology subgraph, and marks the conflicting area; the conflicting area is an area where the difference in risk indicators of adjacent nodes exceeds a preset difference threshold; If the difference in risk indicators between the regional decision-making layer and the cloud analysis layer exceeds a preset threshold, the self-test instructions of the monitoring layer equipment are triggered, including sensor calibration, restart of abnormal network ports and data verification. After the self-test is completed, the local risk indicators are recalculated and the updated local risk indicators are uploaded to the cloud analysis layer for global correction.

7. The intelligent security integrated management and control system according to claim 1, characterized in that: The resource scheduling method of the execution control layer includes: The scheduling of the mobile monitoring equipment further adopts drone swarm collaboration technology and robot collaboration mechanism. The drones and inspection robots share the risk gradient information of the dynamic priority service topology network through a distributed communication protocol, and dynamically adjust the focus density and movement trajectory. Based on the high-threat nodes marked in the regional decision layer, a monitoring focus area centered on the high-threat node set is formed. The drone swarm approaches the high-threat node in a spiral trajectory, and the inspection robot moves in the direction of the rising risk gradient, achieving full-dimensional spatial coverage of the high-threat area. Suspending a dynamic proportion of fixed-point monitoring devices in areas where risk indicators fall below a preset threshold frees up computing resources, prioritizing them for interception strategies in high-threat areas; Deploy resource restriction devices and process blocking mechanisms on the abnormal operation path to block illegal operation routes. The resource restriction device includes a directional permission controller and a process lock, which dynamically adjusts the restriction intensity and scope based on the operator's real-time location, operation speed, and behavioral characteristics. The activation timing of the resource restriction device is dynamically adjusted with the operator's operation speed, and the operation speed is inversely proportional to the interval between the activation timings. The execution control layer monitors the operating status of the equipment in real time, and periodically checks the hardware functions, software integrity and collaborative work delays through the full-stack self-check protocol. When an anomaly is found, it triggers the adjustment of the resource allocation strategy, including allocating the released computing resources to high-threat areas according to the risk gradient weight, and automatically switching to backup equipment and reallocating network bandwidth when the equipment performance index is lower than the safety threshold.

Citation Information

Patent Citations

  • Dynamic monitoring method and system for realizing intelligent security

    CN120071238A