AI-based cybersecurity system trained with multimodal large models

The AI-powered cybersecurity system, trained using a multimodal large model and combined with multidimensional data analysis, addresses shortcomings in hardware fault diagnosis, network attack detection, endpoint security monitoring, and key management. It achieves more accurate fault identification, attack detection, and threat assessment, thereby enhancing the system's security adaptability and situational awareness.

CN120281550BActive Publication Date: 2026-05-26SHENZHEN JINCHAO CLOUD CONTROL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHENZHEN JINCHAO CLOUD CONTROL TECH CO LTD
Filing Date
2025-04-23
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing technologies do not fully consider the correlation of multi-dimensional data in hardware fault diagnosis, resulting in delayed fault identification; network attack detection has difficulty in quickly identifying new attack patterns, leading to a high risk of misjudgment; endpoint security monitoring has limited ability to identify dynamic behavior and weak attack tracing capabilities; key management mechanisms have poor adaptability and are unable to cope with security challenges in complex environments; and overall threat assessment lacks multi-level data comprehensive analysis, resulting in insufficient threat perception.

Method used

The AI-powered cybersecurity system, trained on a multimodal large model, utilizes a server fault diagnosis module, a network attack detection module, an endpoint security monitoring module, and a key management optimization module. By combining multidimensional data analysis, it identifies abnormal behavior, dynamically adjusts security strategies, and improves the accuracy of threat assessment and response speed.

Benefits of technology

It improves the accuracy of fault prediction, reduces the risk of business interruption caused by hardware failure, enhances the accuracy of attack detection and tracing capabilities, dynamically adjusts key policies, improves security adaptability and threat assessment precision, and enhances global security situation awareness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281550B_ABST
    Figure CN120281550B_ABST
Patent Text Reader

Abstract

This invention relates to the field of intelligent security operation and maintenance technology, specifically to an artificial intelligence network security system based on multimodal large model training. The system includes a server fault diagnosis module, a network attack detection module, an endpoint security monitoring module, a key management optimization module, and a threat analysis feedback module. In this invention, multidimensional data analysis improves the accuracy of fault prediction, reducing business interruptions caused by sudden hardware failures. Based on server anomaly assessment, network access frequency, source, and command characteristics are evaluated to improve attack detection accuracy and reduce the risk of false positives. Endpoint device execution behavior, resource calls, and behavior sequences are extracted to achieve fine-grained security monitoring, enhancing attack tracing capabilities. Key policies are dynamically adjusted to improve security adaptability and reduce policy lag risks. Multi-level data is integrated to calculate the fit between threat behavior and attack, enhancing the precision and response speed of threat assessment and improving overall security situation awareness.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of intelligent security operation and maintenance technology, and in particular to an artificial intelligence network security system based on multimodal large model training. Background Technology

[0002] The field of intelligent security operations and maintenance technology encompasses multiple aspects, including data center operations and maintenance management, network security protection, and system resource optimization. The core of this technology involves using artificial intelligence and automation to monitor, analyze, and optimize hardware devices, network traffic, and application systems within the data center in real time, thereby improving operational efficiency and security. This technology includes hardware fault diagnosis techniques based on log analysis, network attack identification techniques combined with security threat intelligence, resource scheduling techniques for load balancing, and multi-level security policy enforcement techniques. Overall, this technology enhances the stability and security of data centers in complex environments through data collection, modeling analysis, and policy optimization.

[0003] Among them, the AI-based cybersecurity system trained on a multimodal large model refers to a system that utilizes multimodal data such as natural language, images, logs, and traffic, combined with deep learning models, to identify and manage cybersecurity risks. For hardware device fault identification, this system extracts time-series features from server operation logs and sensor data, and uses historical anomaly pattern comparison analysis for prediction. For network attack detection, it establishes an attack chain model using the MITREATT&CK knowledge base and matches attack behavior patterns through traffic feature decomposition. For resource scheduling optimization, it dynamically adjusts server load and storage allocation based on reinforcement learning strategies. The system also includes a security policy execution mechanism, using digital signature technology to verify the integrity of iptables rules and performing rule parsing and distributed execution through DPU devices. Furthermore, the system employs a threshold signature method to construct a multi-administrator approval mechanism, performing joint signature authentication for critical security configuration changes to ensure the credibility of policy execution.

[0004] Current technologies for hardware fault diagnosis primarily rely on log analysis for anomaly detection, but they fail to fully consider the correlation of multi-dimensional data, leading to a lag in the identification of potential faults and difficulty in timely detection of abnormal trends. In network attack detection, methods based on attack chain models and matching traffic characteristics are limited by the update speed of the rule base, making it difficult to quickly identify new attack patterns. Furthermore, the judgment of abnormal access frequency is relatively coarse, posing a risk of misjudgment. In endpoint security monitoring, current technologies focus more on static security policies, with limited ability to identify the dynamic behavior of endpoint devices, making it difficult to accurately trace attack paths and resulting in weak attack attribution capabilities. Key management mechanisms mainly rely on preset policies, exhibiting poor adaptive adjustment capabilities to changes in key access behavior, making it difficult to effectively address security challenges in complex environments. In addition, the lack of comprehensive analysis capabilities for multi-level data in the overall threat assessment process leads to insufficient comprehensiveness of threat perception, hindering the achievement of end-to-end tracking and accurate response to attack behavior. Summary of the Invention

[0005] The purpose of this invention is to address the shortcomings of existing technologies by proposing an artificial intelligence network security system based on multimodal large model training.

[0006] To achieve the above objectives, the present invention adopts the following technical solution: an artificial intelligence network security system based on multimodal large model training includes:

[0007] The server fault diagnosis module obtains logs and fault codes, and analyzes the time dependence of logs in conjunction with hardware performance, task scheduling, and load balancing. It also assesses operational deviations by combining fault cases and equipment status to determine the degree of server anomaly.

[0008] Based on the server's anomaly level, the network attack detection module collects network data packet addresses, protocol types, data packet sizes, and timestamps, analyzes access behavior trends, identifies abnormal access paths, determines the likelihood of an attack, parses data packet content, matches suspicious instruction features, marks suspicious sources, calculates attack activity, and analyzes and obtains the attack's impact range.

[0009] Based on the attack impact range, the endpoint security monitoring module monitors the execution behavior of endpoint devices, extracts the operating environment, resource calls and behavior sequences, calculates the matching degree between behavior patterns and attack samples, identifies abnormal behavior chains and analyzes the impact range, and generates the endpoint threat level.

[0010] Based on the endpoint threat level, the key management optimization module sets the key lifecycle and records usage and access sources, analyzes key call stability, adjusts encryption strength, triggers permission re-verification, analyzes key access behavior changes, and obtains the key security change rate.

[0011] As a further aspect of the present invention, the server anomaly degree includes log sequence time correlation, server temperature, server voltage, device operating stability, and the degree of deviation between the current state and the fault sample; the network attack activity degree includes network sources with abnormal access counts, the degree of matching between instruction characteristics and attack patterns, suspicious network sources, and the scope of attack impact; the endpoint threat degree includes the execution behavior of endpoint devices, operating environment, resource calls, the degree of matching between behavior patterns and attack samples, abnormal behavior chains, and the scope of abnormal impact; and the key security change rate includes key lifecycle, key usage, access source, call stability, encryption strength, permission re-verification, and changes in access behavior.

[0012] As a further aspect of the present invention, the server fault diagnosis module includes:

[0013] The log acquisition submodule acquires server operation logs, extracts time records, fault codes, processor load, memory usage and disk read / write speed, filters log sequences in abnormal time periods, calculates time interval distribution, analyzes change characteristics, and obtains log time interval feature values.

[0014] Based on the log time interval feature value, the fault analysis submodule extracts the task scheduling, load distribution, and hardware operating status of the corresponding time period, calculates the scheduling change rate, load offset degree, and hardware fluctuation amplitude, and compares it with the fault case library to obtain the fault matching parameter deviation value.

[0015] The stability calculation submodule calculates the offset trend of the operating parameters based on the fault matching parameter deviation value and the current operating status of the server, determines the offset magnitude of the operating status, calculates the deviation between the server's operating stability and the stability benchmark value in the fault case library, and obtains the degree of server abnormality.

[0016] As a further aspect of the present invention, the specific calculation formula for the offset trend of the calculated operating parameters is as follows:

[0017] ;

[0018] Calculate the trend of runtime parameter offset Based on the current operating status of the server, the deviation of the operating status is calculated, and the deviation between the server's operating stability and the stability benchmark value in the fault case library is calculated to obtain the degree of server abnormality.

[0019] in, Represents the trend of operating parameter offset. Represents the current number of servers The runtime parameter values ​​for a given time period. This represents the baseline value of the parameter under normal server operating conditions. Represents the total number of sampling time periods. Representing the server number The operating weight coefficient of each device Representing the server number The degree of deviation in the current operating status of each device. This represents the total number of server devices.

[0020] As a further aspect of the present invention, the network attack detection module includes:

[0021] The network traffic analysis submodule, in conjunction with the server anomaly level, collects the source address, destination address, protocol type, packet size, and timestamp of network data packets, calculates the number of requests and total traffic at the source address, analyzes the protocol type distribution, extracts the request distribution trend, calculates the request density and protocol balance, compares the changes over time, and obtains the traffic distribution offset.

[0022] Based on the traffic distribution offset, the abnormal access identification submodule extracts high-frequency access addresses and request numbers, calculates the access path jump amplitude, analyzes path change trends, filters abnormal access paths, parses data packet instruction types, matches suspicious instruction feature library, and obtains suspicious path identification degree.

[0023] The attack activity assessment submodule calculates the frequency and duration of suspicious source requests based on the suspicious path identification, analyzes the request fluctuation trend, assesses the persistence of attack behavior, calculates the change in the access frequency of the attack target and the abnormal traffic ratio, and obtains the scope of attack impact.

[0024] As a further aspect of the present invention, the endpoint security monitoring module includes:

[0025] The behavior extraction submodule monitors the execution behavior of endpoint devices based on the scope of the attack, obtains the operating environment information, resource call sequence and behavior sequence of the monitored endpoint devices, filters the inter-process interaction and file access operation items in the behavior sequence, analyzes the correlation of resource call sequence, and generates resource call correlation degree.

[0026] The anomaly identification submodule analyzes the offset trend of the current behavior sequence based on the resource call correlation and the execution behavior data of the endpoint device, calculates the offset magnitude of the behavior sequence, determines the scope of the anomaly's impact, and generates the anomaly behavior offset.

[0027] The threat assessment submodule calculates the coverage and impact intensity of the abnormal behavior chain based on the abnormal behavior offset, extracts the endpoint resource call characteristics within the impact range, calculates the distribution of affected resources, and analyzes the endpoint threat level based on the distribution of affected resources.

[0028] As a further aspect of the present invention, the key management optimization module includes:

[0029] The key lifecycle setting submodule obtains the initial usage time, number of calls and access source of the key based on the endpoint threat level, calculates the remaining lifecycle and call stability of the key, compares the call frequency of the key with the set lifecycle range, determines whether the key lifecycle needs to be adjusted, and if the call stability deviation exceeds the lifecycle range, modifies the key time and records the adjustment result to obtain the key lifecycle parameters.

[0030] The key call analysis submodule analyzes the access source, call count and access device information in the key usage record according to the key lifecycle parameters, calculates the stability change value of key call, compares the change value with the normal key call state, and if it exceeds the normal range, adjusts the encryption strength and marks the key risk level, and obtains the key call stability change value.

[0031] The key access behavior adjustment submodule combines the key call stability change value to analyze the change trend of key access behavior, calculate the change rate and range of access behavior, determine whether the change magnitude of access behavior is abnormal, and if it exceeds the set range, trigger permission re-verification, adjust the key permission level according to the access source, and obtain the key security change rate.

[0032] As a further aspect of the present invention, the specific calculation formula for the rate and range of change of the access behavior is as follows: ;

[0033] Calculate the rate of change of access behavior, determine whether the magnitude of the change of access behavior is abnormal, if it exceeds the set range, trigger permission re-verification, adjust the key permission level according to the access source, and obtain the key security change rate.

[0034] in, This represents the rate of change in access behavior. This represents the number of visits within the statistical time window. Representing the The time interval between visits This represents the average access interval of the key within a historical time window. Representing the The time interval between visits within the corresponding history window This represents the cumulative calculation of all access behavior data. This represents taking the absolute value. This represents the square root operation.

[0035] As a further aspect of the present invention, the system also includes a threat analysis feedback module:

[0036] Based on the key security change rate, the threat analysis and feedback module integrates server logs, network traffic, endpoint behavior, and key lifecycle data to calculate the fit between current threat behavior and attack, correlate suspicious access sources, and generate a network security threat assessment result.

[0037] The network security threat assessment results include server logs, network traffic, endpoint behavior, key lifecycle data, current threat behavior and attack fit, and suspicious access sources.

[0038] As a further aspect of the present invention, the threat analysis feedback module includes:

[0039] The key change analysis submodule obtains the key security change rate, extracts time series information from server logs, key lifecycle data and endpoint device key operation records, calculates the change frequency of key creation, modification and deletion, compares it with the key security benchmark frequency, and determines the abnormal change rate.

[0040] Based on the abnormal change rate, the access behavior association submodule extracts network traffic data for the corresponding time period, calculates the distribution characteristics of access source address, request path, and user identity information, compares the access time pattern in the server log, detects abnormal changes in access request density, and obtains the suspicious access source ratio.

[0041] The threat matching calculation submodule matches attack events based on the ratio of suspicious access sources, extracts access frequency, key operation type, endpoint interaction pattern features, compares the degree of matching between the current behavior pattern and the attack record, and generates a network security threat assessment result.

[0042] Compared with the prior art, the advantages and positive effects of the present invention are as follows:

[0043] In this invention, multi-dimensional data analysis is used to improve the accuracy of fault prediction and reduce business interruptions caused by sudden hardware failures. Based on server anomaly assessment, network access frequency, source, and command characteristics are evaluated to improve the accuracy of attack detection and reduce the risk of misjudgment. Endpoint device execution behavior, resource calls, and behavior sequences are extracted to achieve fine-grained security monitoring and enhance attack tracing capabilities. Key policies are dynamically adjusted to improve security adaptability and reduce the risk of policy lag. Multi-level data is integrated to calculate the fit between threat behavior and attack, enhancing the precision of threat assessment and response speed, and improving the overall security situation awareness capability. Attached Figure Description

[0044] Figure 1 This is a system flowchart of the present invention;

[0045] Figure 2 This is a flowchart of the sub-steps of the present invention. Detailed Implementation

[0046] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0047] In the description of this invention, it should be understood that the terms "length," "width," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," and "outer," etc., indicating orientation or positional relationships, are based on the orientation or positional relationships shown in the accompanying drawings and are only for the convenience of describing the invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the invention. Furthermore, in the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.

[0048] Please see Figure 1 Artificial intelligence cybersecurity systems based on multimodal large-scale model training include:

[0049] The server fault diagnosis module obtains server logs and fault codes, and analyzes the time dependency of log sequences in conjunction with hardware performance, task scheduling, and load balancing. It also calculates operational stability deviations and determines the degree of server anomaly by combining fault cases with equipment operating status.

[0050] The network attack detection module collects the address, protocol, size, and timestamp of network data packets based on the server's anomaly level, analyzes access behavior trends, calculates request anomaly level, compares with normal traffic patterns, identifies abnormal access paths, judges the possibility of an attack by combining traffic mutation trends, parses data packet content, matches suspicious instruction characteristics, marks suspicious sources, calculates attack activity, and analyzes and obtains the attack's impact range.

[0051] The endpoint security monitoring module monitors the execution behavior of endpoint devices based on the attack impact range, extracts the operating environment, resource calls, and behavior sequences, calculates the matching degree between behavior patterns and attack samples, identifies abnormal behavior chains and analyzes the abnormal impact range, and generates the endpoint threat level.

[0052] The key management optimization module sets the key lifecycle based on the endpoint threat level, records key usage and access sources, evaluates call stability, adjusts encryption strength, triggers permission re-verification, analyzes changes in access behavior, and determines the key security change rate.

[0053] The threat analysis feedback module integrates server logs, network traffic, endpoint behavior, and key lifecycle data based on key security change rate, calculates the fit between current threat behavior and attack, associates suspicious access sources, and generates network security threat assessment results.

[0054] Server anomaly level includes log sequence time correlation, server temperature, server voltage, device operational stability, and the degree of deviation between the current state and fault samples. Network attack activity level includes network sources of abnormal access counts, the degree of matching between command characteristics and attack patterns, suspicious network sources, and the scope of attack impact. Endpoint threat level includes endpoint device execution behavior, operating environment, resource calls, the degree of matching between behavior patterns and attack samples, abnormal behavior chains, and the scope of abnormal impact. Key security change rate includes key lifecycle, key usage, access sources, call stability, encryption strength, permission re-verification, and changes in access behavior. Network security threat assessment results include server logs, network traffic, endpoint behavior, key lifecycle data, the degree of fit between current threat behavior and attacks, and suspicious access sources.

[0055] Please see Figure 2 The server fault diagnosis module includes:

[0056] The log acquisition submodule acquires server operation logs, extracts time records, fault codes, processor load, memory usage and disk read / write speed, filters log sequences in abnormal time periods, calculates time interval distribution, analyzes change characteristics, and obtains log time interval feature values.

[0057] To obtain server operation logs, a monitoring system must first be established to monitor the server's operating status in real time, including processor load, memory usage, and disk read / write speed. This data is recorded in real time and stored in log format. For example, the server's CPU load, memory usage, and disk I / O operations per minute can be recorded in a CSV file. To extract log sequences from abnormal time periods, the system can set thresholds, such as CPU load exceeding 80%, memory usage exceeding 90%, or a sudden increase in disk read / write speed of more than double. These thresholds can be set based on past performance monitoring data. Once any indicator exceeds these thresholds, the relevant logs will be marked as abnormal. Next, the system needs to perform time interval analysis on these marked abnormal logs. The specific analysis method can use descriptive analysis in statistics to calculate the time difference between log records. For example, if the recording time intervals are mainly concentrated within a few seconds over a period of time, it can be determined that the system may have encountered a brief period of high load or failure. Finally, through the statistical distribution of these time intervals, characteristic values ​​of the log time intervals can be obtained, such as the average time interval, median time interval, and standard deviation of the time interval. These characteristic values ​​help to further analyze abnormal patterns in the log data and obtain log time interval characteristic values.

[0058] The fault analysis submodule extracts task scheduling, load distribution, and hardware operating status for the corresponding time period based on log time interval feature values, calculates scheduling change rate, load offset degree, and hardware fluctuation amplitude, and compares with the fault case library to obtain fault matching parameter deviation values.

[0059] The fault analysis submodule begins by extracting task scheduling, load distribution, and hardware operating status for the corresponding time period. This data can be obtained by querying the server's system logs and task scheduler records. For example, the operating system's API can be used to obtain information on all currently running tasks and their CPU and memory usage. The rate of change in task scheduling can be estimated by comparing the task queue lengths at different time points. If the task queue length increases rapidly in a short period, it indicates a high rate of change in scheduling. The load offset can be calculated using standard deviation and coefficient of variation to measure load fluctuations over different time periods. Hardware operating status analysis requires checking data recorded by hardware performance monitoring tools, such as CPU temperature and fan speed. Abnormal fluctuations in these indicators may indicate hardware failures. These calculated parameters are compared with data in the fault case library. Methods such as cosine similarity and Euclidean distance can be used to calculate the deviation between parameters. These deviations are used to assess the similarity between the current system state and known fault cases, ultimately yielding the fault matching parameter deviation value.

[0060] The stability calculation submodule calculates the offset trend of the operating parameters based on the fault matching parameter deviation value and the current operating status of the server, determines the offset magnitude of the operating status, calculates the deviation between the server's operating stability and the stability benchmark value in the fault case library, and obtains the degree of server abnormality.

[0061] The specific formula for calculating the offset trend of the operating parameters is as follows: ;

[0062] Calculate the trend of runtime parameter offset Based on the current operating status of the server, the deviation of the operating status is calculated, and the deviation between the server's operating stability and the stability benchmark value in the fault case library is calculated to obtain the degree of server abnormality.

[0063] in, Represents the trend of operating parameter offset. Represents the current number of servers The runtime parameter values ​​for a given time period. This represents the baseline value of the parameter under normal server operating conditions. Represents the total number of sampling time periods. Representing the server number The operating weight coefficient of each device Representing the server number The degree of deviation in the current operating status of each device. Represents the total number of server devices.

[0064] Calculate the trend of runtime parameter offset

[0065] Collect operational parameter data: Use server performance monitoring tools (such as Zabbix, Nagios, etc.) to collect key operational parameter values ​​of the server in real time at different time periods, such as CPU utilization and memory utilization. Assume that within five time periods ( The collected CPU utilization data is as follows: ;

[0066] Determine the benchmark value Based on historical data or industry standards, set a baseline value for the server's CPU utilization under normal operating conditions. Assume the baseline value is 50%.

[0067] Calculate the deviation value for each time period: ;

[0068] ;

[0069] ;

[0070] ;

[0071] ;

[0072] Calculate the average deviation:

[0073] ;

[0074] Calculate the influence coefficient of equipment operating status

[0075] Determine the total number of server devices Assume the server contains 4 key devices ( ): CPU, memory, disk, and network interface.

[0076] Set equipment weight coefficient : Assign weighting coefficients based on the impact of each device on server performance. These weighting coefficients are determined by the importance of each device to overall performance and may be adjusted according to workload changes. Assume the weighting coefficients are as follows: ;

[0077] ;

[0078] ;

[0079] ;

[0080] Quantify the degree of deviation in equipment operating status The current operating status of each device is obtained through monitoring tools and compared with its normal operating status, quantifying the degree of deviation. Assume the degree of deviation for each device is as follows: ;

[0081] ;

[0082] ;

[0083] ;

[0084] Calculate the weighted sum of squared deviations: ;

[0085] Calculate the trend of runtime parameter offset

[0086] Substitute into the formula: ;

[0087] calculate: ;

[0088] ;

[0089] Interpretation of results: Calculated trend of operating parameter offset This indicates that the server's current CPU utilization has deviated by 1.76% from the baseline. This result suggests that the server's operating state deviates somewhat from the expected stable state, requiring further analysis and adjustments to maintain server stability and performance.

[0090] Please see Figure 2 The network attack detection module includes:

[0091] The network traffic analysis submodule combines the server anomaly level to collect the source address, destination address, protocol type, packet size, and timestamp of network data packets. It calculates the number of requests and total traffic at the source address, analyzes the protocol type distribution, extracts the request distribution trend, calculates the request density and protocol balance, compares the changes over time, and obtains the traffic distribution offset.

[0092] During data acquisition, traffic capture tools (such as Wireshark or Tcpdump) are first used to monitor the server's inbound and outbound traffic in real time. The IP header information in the data packets is parsed to extract the source and destination addresses. Simultaneously, TCP / UDP headers are parsed to identify the protocol type, and the packet size is obtained by reading the packet payload. Timestamp information is obtained from the server's system time synchronization mechanism. Next, all source addresses are counted to determine the number of requests for each source address, and the packet size corresponding to that source address is accumulated to calculate the total traffic. The distribution of protocol types is analyzed by classifying and statistically analyzing the traffic share of different protocols. For example, within a specific time period, the traffic share of HTTP, TCP, and UDP protocols is calculated, and the protocol distribution is observed. Based on the traffic changes between different time periods, a fixed time window (e.g., 5 minutes or 1 hour) is set. Within each time window, the number of requests and packet size for all source addresses are calculated and compared with the values ​​of the previous window to obtain the trend of request distribution. For request density calculation, the density is calculated based on the number of requests per unit time, and trend analysis is performed using data from consecutive time windows. Protocol balance is used to measure whether traffic of different protocol types is evenly distributed. A high balance means that the traffic sources are relatively even, while a low balance indicates that the traffic is biased. Furthermore, by comparing the changes in protocol traffic ratio, total request volume, and traffic size in different time periods, the offset of traffic distribution is calculated. If the offset is large, there may be abnormal traffic surges or decreases.

[0093] The abnormal access identification submodule extracts high-frequency access addresses and request numbers based on traffic distribution offset, calculates access path jump amplitude, analyzes path change trends, filters abnormal access paths, parses data packet instruction types, matches suspicious instruction feature library, and obtains suspicious path identification degree.

[0094] First, establish criteria for determining high-frequency access. This can be done by calculating the average and fluctuation range of all IP requests based on historical server access data. A threshold is set for values ​​exceeding this average by a certain multiple. If a value exceeds this threshold, it is considered a high-frequency access address. After obtaining the high-frequency access address, analyze its access path jump range, extract the IP's access records, and count the number of different URL paths accessed. Simultaneously, calculate the range of path changes. If the IP frequently jumps between multiple different pages, it indicates a large path jump range. Then, calculate the path changes of the same source address within adjacent time periods, observe the path change trend, and assess whether abnormal access behavior exists. For abnormal path identification, further analyze the request type of the data packets, such as GET, POST, PUT, etc., and compare them with known suspicious instruction characteristics, such as SQL injection statements and XSS script code commonly used in web attacks. If the request content contains suspicious instructions, determine the abnormality level of the access path and calculate its suspicious path identification score. Paths with a high identification score may be malicious access.

[0095] The attack activity assessment submodule calculates the frequency and duration of requests from suspicious sources based on the identification of suspicious paths, analyzes the trend of request fluctuations, assesses the persistence of attack behavior, calculates the changes in the access frequency of the attack target and the ratio of abnormal traffic, and obtains the scope of the attack's impact.

[0096] First, the number of visits to suspicious paths is counted, and the access frequency per unit time is calculated. The access duration is calculated based on the time interval between the first and last access. Then, the fluctuation trend of suspicious requests is analyzed. A fixed time window is set, and the change in the number of requests within adjacent time periods is calculated. If the request fluctuation is large, it indicates that the attack behavior may be active. The persistence of the attack behavior is further assessed by calculating the average access interval of a suspicious IP. If the access interval is small, it indicates that the attack has strong continuity. Then, the access frequency change of the attack target is calculated, that is, the number of times a target is accessed per unit time, and its change range is analyzed. At the same time, the proportion of abnormal traffic is calculated, the total traffic of suspicious requests is counted, and it is compared with the total traffic of the server to calculate the ratio of abnormal traffic. Finally, the scope of the attack impact is obtained, including the number of affected target IPs, the types of services involved, and the duration of the attack.

[0097] Please see Figure 2 The endpoint security monitoring module includes:

[0098] The behavior extraction submodule monitors the execution behavior of endpoint devices based on the scope of the attack, obtains the operating environment information, resource call sequence and behavior sequence of the monitored endpoint devices, filters the inter-process interaction and file access operation items in the behavior sequence, analyzes the correlation of resource call sequence, and generates resource call correlation degree;

[0099] First, obtain the endpoint device's runtime environment information, including hardware status, operating system version, process list, and resource usage such as CPU load, memory usage, and disk I / O rate. Then, use system call monitoring tools (such as Sysmon or Auditd) to capture the endpoint device's resource call sequences in real time, including process API calls, file access, and network communication. Filter the behavior sequences, focusing on inter-process interactions and file access operations. During process interaction recording, obtain the interacting process ID, target process ID, call time, and call method. For example, if a process sends data to another process via shared memory, the data transfer rate and data length should be recorded. In the process of file access monitoring, the focus is on extracting access methods (read, write, execute), access paths, access times, and file modification information. For example, if a process repeatedly modifies critical system configuration files or accesses abnormal directories, it is marked as high-risk. Subsequently, correlation analysis is performed on resource call sequences to identify high-frequency access patterns and abnormal access behaviors. The correlation between processes is calculated by combining historical call data, such as whether multiple processes frequently access the same files or call the same APIs. Finally, a resource call correlation degree is formed. If a process frequently calls high-privilege APIs or modifies multiple critical files multiple times in a short period of time, its correlation degree may be high. Finally, the resource call patterns of endpoint devices are determined, forming a complete data correlation result.

[0100] The anomaly identification submodule analyzes the offset trend of the current behavior sequence based on the resource call correlation and the execution behavior data of the endpoint device, calculates the offset magnitude of the behavior sequence, determines the scope of the anomaly's impact, and generates the anomaly behavior offset.

[0101] First, a baseline of behavior under normal operating conditions is constructed, including the normal API call sequence, file access path, and access frequency of each process. Historical data is statistically analyzed, such as recording when a process typically calls which APIs and whether the file access pattern is stable. Then, a sliding window mechanism is used to monitor the current behavior sequence and compare it with historical baseline data to identify abnormal offset trends. When calculating the offset magnitude, the focus is on changes in resource calls. For example, if a process typically calls an API 10 times per minute, but the number of calls increases to 50 times in the current minute, it is considered to have a significant offset. In addition, the duration and trend of abnormal behavior are analyzed by comparing behavior sequences in different time periods, such as whether it is a short-term abnormal fluctuation or a long-term abnormal pattern. Then, the scope of the abnormal impact is determined by analyzing the number of processes involved, file modification status, and network communication status. For example, if an abnormal behavior causes multiple critical system processes to terminate abnormally or multiple files to be tampered with, the scope of impact is large. Finally, the offset magnitude of the abnormal behavior is calculated, and the abnormal offset result is output.

[0102] The threat assessment submodule calculates the coverage and impact intensity of the abnormal behavior chain based on the abnormal behavior offset, extracts the endpoint resource call characteristics within the impact range, calculates the distribution of affected resources, and analyzes the endpoint threat level based on the distribution of affected resources.

[0103] First, the characteristics of endpoint resource calls involved are extracted, including the type, frequency, and associated processes of abnormal API calls. For example, whether an API called by a process involves privilege escalation, process injection, or system tampering. Then, the resource distribution involved in the abnormal behavior chain is analyzed. For example, if an abnormal behavior involves access to a large number of critical system files, it may indicate a high threat level. When calculating the distribution of affected resources, the abnormal situations of different types of resources are statistically analyzed, such as the proportion of API access, file modification, and process creation. Historical data is then combined to determine the threat level of the current abnormal behavior. For example, if the current abnormal behavior is highly similar to the behavior pattern of known malware, the threat level may be high. Finally, based on the distribution characteristics and coverage of abnormal behavior, the threat level of endpoint devices is assessed, and a complete threat assessment result is generated.

[0104] Please see Figure 2 The key management optimization module includes:

[0105] The key lifecycle setting submodule obtains the initial usage time, number of calls, and access source of the key based on the endpoint threat level, calculates the remaining lifecycle and call stability of the key, compares the call frequency of the key with the set lifecycle range, determines whether the key lifecycle needs to be adjusted, and if the call stability deviation exceeds the lifecycle range, modifies the key time and records the adjustment result to obtain the key lifecycle parameters.

[0106] The key lifecycle setting submodule first obtains the initial usage time, number of calls, and access source of the key. The initial usage time can be obtained from database records, and the system adds a timestamp each time a key is generated. The number of calls can be counted from API access records in the server logs. The access source needs to be combined with parameters such as IP address, device ID, and MAC address, and parsed using a geolocation database and device fingerprint analysis tools to determine whether the access behavior meets expectations. After obtaining this data, it is necessary to calculate the remaining lifecycle and call stability of the key. The remaining lifecycle can be obtained by subtracting the current usage time from the initial set duration. Call stability is analyzed by the change in the number of key calls over a period of time. A sliding window method is used to calculate the historical average, and the current number of calls is compared with the average. If the change in the current number of calls exceeds a set threshold, such as the average of a certain key over the past week, the system will take action. If the daily call count is 100, but suddenly increases to 500 within the last 24 hours, the magnitude of the change is calculated. If it exceeds the set range, the call stability deviation is considered significant. The calculated call stability deviation value is then compared with the key's set lifespan range. If the key call frequency remains high but the lifespan is set too short, or the call frequency is low but the lifespan is set too long, the key's lifespan needs to be adjusted. The adjustment can be done using a dynamic adjustment mechanism, that is, the lifespan is appropriately extended or shortened according to the magnitude of the call stability deviation. For example, if the call stability deviation exceeds 30%, the lifespan can be increased by 5%-10% from the original lifespan. If the call stability deviation is small, the original lifespan remains unchanged. The adjusted key lifespan will be recorded and stored in the database and used for subsequent key management strategy optimization, ultimately yielding the key lifespan parameters.

[0107] The key call analysis submodule analyzes the access source, call count and access device information in the key usage record based on the key lifecycle parameters, calculates the stability change value of key call, compares the change value with the normal key call state, and if it exceeds the normal range, adjusts the encryption strength and marks the key risk level, and obtains the key call stability change value.

[0108] The key usage analysis submodule first analyzes key usage records based on key lifecycle parameters, including access source, number of calls, and access device information. Access source analysis needs to consider geographical location, IP reputation, and historical access records. If a particular IP address is found to have low historical call stability—for example, an IP with an average of 50 calls per day over the past month, but a sudden increase to 200 calls in the last 5 days—its call change is calculated. If the change exceeds a set range, the IP's access behavior is considered potentially abnormal. Further analysis is then performed using access device information. If the device fingerprint information of the access source does not match historical records, there may be a risk of key sharing or abuse, requiring the behavior to be flagged. Simultaneously, the key usage analysis submodule also needs to compare the current call change value with the normal key usage status. The difference in key usage status can be determined through historical data statistics. A baseline range is set; if the current usage change exceeds this range, the key usage is considered abnormal. In this case, the encryption strength of the key needs to be adjusted. Adjustment methods include increasing the complexity of the encryption algorithm, such as upgrading SHA-256 to SHA-512, or increasing the iteration count of PBKDF2, thus enhancing key security. Simultaneously, to further manage key security, the risk level of the key needs to be marked. The risk level can be divided according to the magnitude of the change in usage stability. For example, if the change is less than 20%, the risk level is low; if the change is between 20% and 50%, the risk level is medium; and if it exceeds 50%, the risk level is high. Finally, the key usage stability change value is obtained.

[0109] The key access behavior adjustment submodule combines the key call stability change value to analyze the change trend of key access behavior, calculate the change rate and range of access behavior, determine whether the change magnitude of access behavior is abnormal, and if it exceeds the set range, trigger permission re-verification, adjust the key permission level according to the access source, and obtain the key security change rate.

[0110] The specific formula for calculating the rate and range of change in access behavior is as follows: ;

[0111] Calculate the rate of change of access behavior, determine whether the magnitude of the change of access behavior is abnormal, if it exceeds the set range, trigger permission re-verification, adjust the key permission level according to the access source, and obtain the key security change rate.

[0112] in, This represents the rate of change in access behavior. This represents the number of visits within the statistical time window. Representing the The time interval between visits This represents the average access interval of the key within a historical time window. Representing the The time interval between visits within the corresponding history window This represents the cumulative calculation of all access behavior data. This represents taking the absolute value. Represents the square root operation.

[0113] This formula is used to calculate the rate of change in access behavior. This is calculated by monitoring and collecting changes in time intervals of actual data. Specifically, the time interval for each access... Obtained through access logs, where This represents the access event number within a specific time window. In the actual example, it is assumed that within a certain monitoring period, [number of events was recorded]. The actual interval time (in minutes) between each visit was 30, 45, 30, 35, and 50 minutes.

[0114] Average access time interval within the historical time window This is derived from the average of the same number of past access records and is set as follows: Minutes. Time interval between each history visit. This was also determined through log records, assuming the historical records were 35, 40, 42, 37, and 45 minutes.

[0115] The calculation process using the formula is as follows:

[0116] Calculate the sum of the absolute values ​​of the differences between each access and the average time interval: ;

[0117] Calculate the sum of squares of the differences between each current visit and each previous visit: ;

[0118] Calculate the sum of the absolute values ​​of the differences between the current access and the previous access for each visit: ;

[0119] Calculate the rate of change : ;

[0120] The result indicates that, considering changes in historical and current data, the rate of change in access behavior is 0.87, meaning that current access behavior changes significantly compared to historical behavior. This numerical result suggests the need for further analysis of the anomalies in access behavior and may require triggering permission re-verification, further adjusting key permission levels based on the source of access, thereby ensuring system security.

[0121] Please see Figure 2 The threat analysis feedback module includes:

[0122] The key change analysis submodule obtains the key security change rate, extracts time series information from server logs, key lifecycle data and endpoint device key operation records, calculates the change frequency of key creation, modification and deletion, compares it with the key security benchmark frequency, and determines the abnormal change rate.

[0123] First, server logs, key lifecycle data, and endpoint device key operation records are extracted. Server logs include timestamps, operation types (create, modify, delete), and user IDs. Key lifecycle data covers key generation time, activation time, and expiration time. Endpoint device key operation records contain key usage records from different terminals and their corresponding operation times. By performing time series analysis on this data, a time distribution curve of key changes is generated. For example, on a certain day, the key creation operation times are {10:05, 12:15, 16:30}, the modification operation times are {11:20, 14:45, 18:00}, and the deletion operation times are {9:00, 17:20}. Then, the key creation... The frequency of key changes (creation, modification, deletion) is measured using a sliding window method, with each window spanning one hour. The number of key changes in each time period is counted. For example, in the time period from 10:00 to 11:00, a key is created once, modified once, and deleted zero times. The time series change curve is then obtained and compared with the key security baseline frequency. The baseline frequency can be calculated using historical data, such as the average key change frequency of the same time period over the past 30 days. If the change frequency in the current time period exceeds twice the baseline frequency, it is considered an abnormal change rate. Assuming the baseline change frequency is 1 time / hour and the actual observed change frequency is 3 times / hour, the abnormal change rate is calculated as (3-1) / 1 = 200%. Finally, the time distribution data of the abnormal change rate is obtained.

[0124] The access behavior association submodule extracts network traffic data for the corresponding time period based on the abnormal change rate, calculates the distribution characteristics of access source address, request path, and user identity information, compares the access time patterns in the server logs, detects abnormal changes in access request density, and obtains the ratio of suspicious access sources.

[0125] This includes access source IP address, request path, user identity information, access time, etc. Distribution characteristics are calculated for this data. First, the number of accesses from different source IPs is counted. Assuming that during the abnormal fluctuation period, IP address A accessed the server 15 times, IP address B accessed it 20 times, and IP address C accessed it 5 times, while the historical average for normal periods is IP address A: 5 times, IP address B: 6 times, IP address C: 3 times, then the access growth rate for each IP is calculated as (15-5) / 5=200%, (20-6) / 6=233.3%, and (5-3) / 3=66.7%, respectively. Next, the access frequency distribution of user identity information is calculated, and the concentration of request paths is extracted. Assuming request path X... If a request was accessed 30 times during this period, while the historical average is 10 times, then the access growth rate of the request path is (30-10) / 10=200%. Then, the access time pattern in the server logs is used as a comparison benchmark. For example, under normal circumstances, the average distribution of access requests per hour is 100 times, while the access requests in the abnormal period reach 250 times. Then, the abnormal change rate of access request density is calculated as (250-100) / 100=150%. Finally, the suspicious access source ratio is calculated, and IP addresses with access growth rates exceeding the benchmark are marked as suspicious sources. Assuming that the total number of accessing IPs is 50, and the access growth rate of 15 IPs exceeds 200%, then the suspicious access source ratio is 15 / 50=30%.

[0126] The threat matching calculation submodule matches attack events based on the ratio of suspicious access sources, extracts access frequency, key operation type, endpoint interaction pattern features, compares the degree of matching between the current behavior pattern and the attack record, and generates network security threat assessment results.

[0127] First, based on the suspicious access source ratio, a list of suspicious IP addresses is filtered out, and the access frequency of these IPs is calculated. For example, if an IP address accesses the server 60 times in one hour, while the average access frequency of normal users is 20 times, then the abnormal access frequency ratio of this IP is calculated to be 60 / 20 = 3.0, which exceeds the benchmark by more than 3 times. Next, the key operation types are analyzed, and the key operation categories involved by the suspicious IP addresses are counted. For example, if a suspicious IP address performs 3 key creation, 5 modification, and 2 deletion operations in a short period of time, while the historical benchmark averages are 1, 2, and 1 respectively, then the abnormal key operation ratios are calculated to be 3 / 1 = 3.0, 5 / 2 = 2.5, and 2 / 1 = 2.0 respectively. Further analysis of endpoint interaction patterns... The system identifies suspicious IP addresses by analyzing their endpoint device types and interaction patterns. For example, if an IP address is found to be logging in simultaneously on terminal devices in different geographical locations, or switching between multiple devices for key operations within a short period, it is marked as an abnormal interaction pattern. Finally, these features are matched against behavioral patterns in historical attack records. For instance, in past attack events, if the frequency of abnormal access exceeds 2.5 times and the ratio of abnormal key operations exceeds 2.0 times, 80% of the events are confirmed as attack events. Therefore, the matching degree of the current behavioral pattern can be calculated as (3.0+2.5+2.0) / 3=2.5. If the score exceeds the threshold of 2.0, the current event is determined to be a suspected network security threat, and a network security threat assessment result is generated.

[0128] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention in any other way. Any person skilled in the art may make changes or modifications to the above-disclosed technical content to create equivalent embodiments that can be applied to other fields. However, any simple modifications, equivalent changes, and modifications made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the protection scope of the present invention.

Claims

1. An artificial intelligence network security system based on multimodal large model training, characterized in that: The system includes: The server fault diagnosis module is used to obtain logs and fault codes, and combine them with hardware performance, task scheduling, and load balancing to analyze log time dependencies, assess operational deviations by combining fault cases and equipment status, and determine the degree of server anomaly. The network attack detection module is used to collect network data packet addresses, protocol types, data packet sizes and timestamps based on the server's anomaly level, analyze access behavior trends, identify abnormal access paths, determine the possibility of attacks, parse data packet content, match suspicious instruction features, mark suspicious sources, calculate attack activity, and analyze and obtain the attack's impact range. The endpoint security monitoring module is used to monitor the execution behavior of endpoint devices based on the attack impact range, extract the operating environment, resource calls and behavior sequences, calculate the matching degree between behavior patterns and attack samples, identify abnormal behavior chains and analyze the impact range, and generate the endpoint threat level. The key management optimization module is used to set the key lifecycle and record usage and access sources based on the endpoint threat level, analyze key call stability, adjust encryption strength, trigger permission re-verification, analyze key access behavior changes, and obtain key security change rate. The threat analysis feedback module is used to integrate server logs, network traffic, endpoint behavior, and key lifecycle data based on the key security change rate, calculate the fit between the current threat behavior and the attack, associate suspicious access sources, and generate network security threat assessment results. The threat analysis feedback module includes: The key change analysis submodule is used to obtain the key security change rate, extract time series information from server logs, key lifecycle data and endpoint device key operation records, calculate the change frequency of key creation, modification and deletion, compare with the key security benchmark frequency, and determine the abnormal change rate. The access behavior association submodule is used to extract network traffic data for the corresponding time period based on the abnormal change rate, calculate the distribution characteristics of access source address, request path, and user identity information, compare the access time pattern in the server log, detect abnormal changes in access request density, and obtain the suspicious access source ratio. The threat matching calculation submodule is used to match attack events based on the ratio of suspicious access sources, extract access frequency, key operation type, endpoint interaction mode features, compare the degree of matching between the current behavior pattern and the attack record, and generate network security threat assessment results. The network security threat assessment results include server logs, network traffic, endpoint behavior, key lifecycle data, current threat behavior and attack fit, and suspicious access sources.

2. The artificial intelligence network security system based on multimodal large model training according to claim 1, characterized in that: The server fault diagnosis module includes: The log acquisition submodule is used to acquire server operation logs, extract time records, fault codes, processor load, memory usage and disk read / write rate, filter log sequences in abnormal time periods, calculate time interval distribution, analyze change characteristics, and obtain log time interval feature values. The fault analysis submodule is used to extract the task scheduling, load allocation, and hardware operating status of the corresponding time period based on the log time interval feature value, calculate the scheduling change rate, load offset degree, and hardware fluctuation amplitude, and compare it with the fault case library to obtain the fault matching parameter deviation value. The stability calculation submodule is used to calculate the offset trend of the operating parameters based on the fault matching parameter deviation value and the current operating status of the server, determine the offset magnitude of the operating status, calculate the deviation between the server's operating stability and the stability benchmark value in the fault case library, and obtain the degree of server abnormality.

3. The artificial intelligence network security system based on multimodal large model training according to claim 1, characterized in that: The network attack detection module includes: The network traffic analysis submodule is used to collect the source address, destination address, protocol type, packet size and timestamp of network data packets in combination with the server anomaly level, calculate the number of requests and total traffic at the source address, analyze the protocol type distribution, extract the request distribution change trend, calculate the request density and protocol balance, compare the changes over time, and obtain the traffic distribution offset. The abnormal access identification submodule is used to extract high-frequency access addresses and request numbers based on the traffic distribution offset, calculate the access path jump amplitude, analyze the path change trend, filter abnormal access paths, parse data packet instruction types, match suspicious instruction feature library, and obtain suspicious path identification degree. The attack activity assessment submodule is used to calculate the frequency and duration of suspicious source requests based on the suspicious path identification degree, analyze the request fluctuation trend, assess the persistence of attack behavior, calculate the change in the access frequency of the attack target and the abnormal traffic ratio, and obtain the scope of attack impact.