Standardized processing system and method for multi-modal data acquisition and fusion of network transaction platform
Through a standardized processing system of multimodal data acquisition and fusion, the shortcomings of the online trading platform in data acquisition, fusion, threat detection and response are solved, efficient and accurate data processing and security response are achieved, and the security and stability of the online trading platform are improved.
Patent Information
- Application Number
- CN202510424680.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-07
- Publication Date
- 2025-07-18
AI Technical Summary
The existing online trading platforms have many shortcomings in multimodal data acquisition, fusion, threat detection and response, which are difficult to meet the growing security needs of online trading platforms, especially in areas such as incomplete data acquisition, difficulty in data processing and fusion, inaccurate threat detection, inflexible response and insufficient data privacy protection.
The multimodal data acquisition module, preprocessing module, multimodal fusion module, threat detection module and response strategy generation module are adopted, and combined with automatic encoder, natural language processing model, large model and differential privacy technology, real-time acquisition, cleaning, fusion, threat detection and flexible response of multimodal data are achieved, adaptive defense strategies are generated and data privacy is guaranteed.
It realizes efficient and accurate multimodal data fusion and threat detection, improves the security and stability of the online trading platform, reduces false alarm rates, improves response speed and data privacy protection capabilities, and ensures the flexibility and reliability of the system.
Smart Images

Figure CN120336713A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network transaction data collection. More specifically, the present invention relates to a standardized processing system and method for multi-modal data collection and fusion in a network transaction platform. Background Art
[0002] With the rapid development of Internet technology, network transactions have become an important mode of modern business activities, and their scale and complexity are increasing day by day. While providing convenient services for people, network transaction platforms are also facing severe security challenges. Endless network attack means emerge, from traditional malware intrusion and phishing to new types of distributed denial of service (DDoS) attacks and advanced persistent threats (APT), etc., bringing huge pressure to the safe operation of the platform.
[0003] In terms of data collection, the data generated by network transaction platforms presents multi-modal characteristics, covering structured data (such as transaction records and data in user information databases), unstructured data (such as text logs and user comments on transaction platforms), and semi-structured data (such as configuration files in XML format and partial interface data in JSON format). These data come from multiple channels such as network traffic monitoring systems, log management systems, malware libraries, and threat intelligence platforms. However, existing data collection technologies often can only collect data of a single type or from some sources, and cannot achieve comprehensive and real-time collection of multi-modal data, resulting in a large amount of valuable security-related information being missed.
[0004] In the aspect of data processing and fusion, due to the significant differences in the formats, structures, and semantics of data from different sources, traditional methods are difficult to effectively clean, normalize, and fuse them. For example, there are huge differences in the processing methods between numerical data such as traffic bytes and request frequencies in network traffic data and unstructured information in log texts. If these multi-modal data cannot be fused into unified and valuable information, it will not be able to provide strong support for subsequent security analysis. When dealing with multi-modal data fusion, existing technologies often only simply splice or conduct shallow correlation analysis, unable to deeply explore the potential relationships and features between data, seriously affecting the ability to identify and judge network security threats.
[0005] In the threat detection phase, traditional rule - based detection methods rely on pre - set rules to identify attack behaviors. However, in the face of ever - changing network attack methods, new attack patterns may not be covered by existing rules, leading to frequent false negatives; at the same time, due to the limitations of the rules, for some behaviors that seem abnormal but are not real attacks, false positives are likely to occur, interfering with the judgment of security personnel and increasing the cost of security operation and maintenance. Moreover, most of these traditional methods are based on static analysis and are difficult to cope with the dynamically changing network environment, unable to track and analyze the changing trends of network traffic, system status, etc. in real - time, and unable to detect potential security threats in a timely manner.
[0006] In terms of response strategies, when a security threat is detected, the response mechanisms of traditional systems are often not flexible and efficient enough. Manual intervention in response operations takes a long time and cannot meet the timeliness requirements for dealing with emergency security incidents; while automated scripts can improve the response speed, but they have deficiencies in the pertinence and adaptability of strategies and are difficult to formulate the optimal defense strategy according to different types of threats and complex network environments. In addition, there is a lack of an effective linkage mechanism between different security devices and systems, resulting in the inability of each link in the response process to work together and reducing the overall defense effect.
[0007] With the increasing awareness of data privacy protection and the introduction of relevant laws and regulations, online trading platforms have higher and higher requirements for data privacy protection. However, in the process of data processing by existing network security technologies, the protection measures for sensitive data are relatively weak, easily leading to the leakage of sensitive information such as user information and transaction data, causing huge losses to users and platforms. During data transmission, there are also risks of being stolen and tampered with, unable to fully guarantee the security and integrity of data. In summary, there are many deficiencies in the existing online trading platform security technologies in aspects such as multi - modal data acquisition, fusion, threat detection, and response, and it is difficult to meet the growing security needs of online trading platforms. There is an urgent need for a more efficient, intelligent, and secure standardized processing system and method for multi - modal data acquisition and fusion of online trading platforms. Summary of the Invention
[0008] In order to overcome the above - mentioned defects of the prior art, the present invention provides a standardized processing system and method for multi - modal data acquisition and fusion of an online trading platform to solve the problems raised in the above - mentioned background technology.
[0009] To achieve the above object, the present invention provides the following technical solutions: A standardized processing system for multi - modal data acquisition and fusion of an online trading platform, comprising:
[0010] A data acquisition module for real-time acquisition of multimodal data from the network traffic monitoring system, log management system, malicious code library, and threat intelligence platform of the network trading platform, including structured data, unstructured data, and semi-structured data;
[0011] A preprocessing module configured to clean, normalize, denoise, and label the acquired data to generate a standardized data set;
[0012] A multimodal fusion module that uses an autoencoder and a natural language processing model to perform feature dimensionality reduction and semantic analysis on network traffic data, system logs, malicious code samples, and threat intelligence data to generate a unified multimodal feature vector;
[0013] A threat detection module that performs real-time analysis on the fused feature vectors based on a pre-trained large model, identifies abnormal behaviors, and generates alarms;
[0014] A response strategy generation module that automatically generates defense strategies based on the alarm results and executes response operations through automated scripts or manual intervention.
[0015] Preferably, the preprocessing module further includes:
[0016] A data cleaning unit that uses the Pandas library to remove redundant data and invalid records;
[0017] A normalization unit that unifies and standardizes the data through Scikit-learn;
[0018] A labeling unit that classifies and labels malicious code samples and threat intelligence data based on LabelEncoder.
[0019] Preferably, the multimodal fusion module specifically includes:
[0020] A network traffic feature extraction unit that uses an autoencoder to reduce the dimensionality of network traffic data and extract time series features and statistical features;
[0021] A log semantic analysis unit that parses the context information in the system logs based on the BERT model and extracts key entities and event sequences;
[0022] A dynamic behavior analysis unit that monitors the execution behavior of malicious code and binary files through a sandbox environment to generate dynamic behavior features.
[0023] Preferably, the threat detection module uses a large model based on the Transformer architecture, combines the LSTM network to process time series data, and integrates an expert knowledge base to perform secondary verification on the alarms, with a false alarm rate more than 30% lower than that of traditional rule engines.
[0024] Preferably, the response strategy generation module includes:
[0025] Call the Ansible script according to the threat type to automatically isolate the infected host;
[0026] Update the firewall rules and traffic cleaning policies in real time through the SIEM platform;
[0027] Generate a visual attack path graph and notify the security team through multiple channels.
[0028] Preferably, it further includes:
[0029] A privacy protection unit that desensitizes sensitive data using differential privacy technology and ensures data transmission security through the AES encryption algorithm;
[0030] An adversarial defense unit that generates adversarial samples using the Adversarial Robustness Toolbox to enhance the robustness of the large model.
[0031] A method for a standardized processing system of multimodal data acquisition and fusion of the above-mentioned online trading platform, including the following steps:
[0032] Step 1: Collect multi-source heterogeneous data through Snort, ELKStack, and VirusTotal;
[0033] Step 2: Clean, normalize, and annotate the data to generate a standardized data set;
[0034] Step 3: Perform multimodal feature fusion using an autoencoder and a BERT model;
[0035] Step 4: Perform real-time threat detection based on the ResNet-50 model with transfer learning;
[0036] Step 5: Automatically generate a response strategy based on the detection result and execute it.
[0037] Preferably, the multimodal feature fusion step further includes:
[0038] Extract time series features and statistical features from network traffic data;
[0039] Perform entity recognition and sentiment analysis on system logs to extract semantic features;
[0040] Mine the association rules between malicious code samples and threat intelligence through the FP-Growth algorithm.
[0041] Preferably, it further includes:
[0042] Deploy the trained large model to the online trading platform through Docker containerization;
[0043] Use Metasploit to simulate attacks to verify the detection ability of the system, and conduct stress tests through JMeter;
[0044] Build a visual cockpit to display the threat situation and processing progress in real time.
[0045] Preferably, the specific steps of step five include:
[0046] Automatically start the traffic cleaning device for DDoS attacks;
[0047] Trigger the host isolation and backup recovery mechanism for the spread behavior of ransomware;
[0048] Share threat intelligence to the MISP platform through the API interface.
[0049] The technical effects and advantages of the present invention:
[0050] 1. The data acquisition module collects multi-modal data from multiple sources. The preprocessing module uses tools such as the Pandas library and Scikit-learn to clean, normalize, and annotate the data, and can obtain a high-quality standardized data set, providing a reliable basis for subsequent analysis. Compared with traditional methods, the data quality is higher, and the processing is more efficient and standardized.
[0051] 2. The multi-modal fusion module uses autoencoders and natural language processing models, such as BERT, to extract key features from network traffic, logs, malicious code, and threat intelligence data, and generates a unified multi-modal feature vector, effectively integrating multi-source data information and improving the accuracy of threat detection.
[0052] 3. The threat detection module processes time series data based on the large model of the Transformer architecture combined with the LSTM network, and integrates the expert knowledge base for secondary verification and warning. The false alarm rate is more than 30% lower than that of the traditional rule engine, realizing more accurate automated threat detection and reducing the burden of manual analysis.
[0053] 4. The response strategy is timely and effective: the response strategy generation module can automatically generate defense strategies according to the warnings, and execute response operations through Ansible scripts, SIEM platforms, etc., such as isolating hosts and updating firewall rules, improving the response speed and accuracy, and effectively coping with security threats.
[0054] 5. The privacy protection unit uses differential privacy technology and AES encryption algorithm to ensure data privacy and transmission security. The adversarial defense unit enhances the robustness of the large model by generating adversarial samples, improving the overall security and stability of the system.
[0055] 6. Elastic scaling is achieved by containerizing the large model in Docker. System performance is ensured to be reliable through simulated attacks and stress tests. A visual cockpit is built to display the threat situation and processing progress in real time, facilitating monitoring and decision-making by the security team. Description of the Drawings
[0056] Figure 1 It is a flowchart of the method for the standardized processing system of multi-modal data collection and fusion of the network trading platform of the present invention. Detailed Implementation Modes
[0057] Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0058] As shown in the appended Figure 1 The standardized processing system for multi-modal data collection and fusion of the network trading platform adopts a hierarchical design, including a data collection layer, a preprocessing layer, a fusion analysis layer, a detection and response layer, and a visualization layer. Each module realizes loose-coupling communication with the message queue (Apache Kafka) through an API interface, including:
[0059] A data collection module, configured to collect multi-modal data in real time from the network traffic monitoring system, log management system, malicious code library, and threat intelligence platform of the network trading platform, including structured data, unstructured data, and semi-structured data;
[0060] A preprocessing module, configured to perform cleaning, normalization, denoising, and annotation processing on the collected data to generate a standardized data set;
[0061] Specifically, when implemented, the data collection module deploys Snort or Suricata as a traffic monitoring tool to capture protocol traffic such as HTTP / HTTPS, DNS, and FTP in real time, and transmits the data stream to the preprocessing module through Kafka. The ELK Stack (Elasticsearch, Logstash, Kibana) is used to collect access logs, operation logs, and exception logs of the trading platform. The log format is unified as JSON. Then, the latest malware samples (such as ransomware and trojans) are regularly crawled from the VirusTotal platform, and their types, behavior characteristics, and hazard levels are marked. The CVE vulnerability library and CIRCL malicious IP blacklist of the MISP platform are integrated, and data real-time synchronization is achieved through the RESTful API.
[0062] The preprocessing module uses the Pandas library to remove duplicate records (such as duplicate HTTP requests), invalid data (such as empty fields), and noisy data (such as non-business-related traffic). It standardizes numerical data (such as traffic bytes and request frequency) using StandardScaler from Scikit-learn; tokenizes and stems the log text, converts it into TF-IDF vectors, and labels malicious code samples as categories such as "virus" and "trojan" based on LabelEncoder; labels threat intelligence data with levels such as "high risk", "medium risk", and "low risk".
[0063] Specifically, a large amount of high-quality data is collected from the network traffic monitoring system, log management system, malicious code library, and threat intelligence platform through the data collection module and preprocessing module, including data cleaning, normalization, annotation, etc. Pandas is used for data cleaning to remove invalid or duplicate data, Scikit-learn is used for data standardization to unify the data format, and LabelEncoder is used for data annotation to add labels to the data. Specifically, HTTP / HTTPS requests and DNS query data are collected from the Snort intrusion detection system, cleaned and normalized through Pandas, and then labeled using LabelEncoder.
[0064] At the same time, deep learning frameworks (TensorFlow, PyTorch) are used to train large models, optimize model parameters, and improve the generalization ability of the models. TensorFlow or PyTorch is used for model training, and KerasTuner is used for hyperparameter optimization. The transfer learning strategy is adopted, and the pre-trained model (ResNet-50 on ImageNet) is used for initialization, and then fine-tuned on the local dataset. Hyperparameters such as the learning rate and regularization parameters are optimized through grid search or random search methods. Specifically, a deep neural network model based on ResNet-50 is constructed using TensorFlow, the convergence process is accelerated through transfer learning, and the learning rate and regularization parameters are optimized using KerasTuner. At the same time, TensorFlowLite or ONNXRuntime is used for model compression and acceleration, and techniques such as model pruning, quantization, and knowledge distillation are used to reduce the model size and improve the inference speed. Finally, the trained large model is quantized through TensorFlowLite to reduce the model volume and improve the inference speed, ensuring the efficient operation of the model in practical applications.
[0065] The multimodal fusion module uses autoencoders and natural language processing models to perform feature dimensionality reduction and semantic analysis on network traffic data, system logs, malicious code samples, and threat intelligence data, generating unified multimodal feature vectors.
[0066] In specific implementation, an autoencoder is constructed using TensorFlow (input layer dimension = 1000, hidden layer dimension = 256) to reduce the dimension of traffic data, extract time series features (such as traffic fluctuation period) and statistical features (such as standard deviation of request volume), and based on a pre-trained BERT model (fine-tuning the corpus in the field of network security), parse key entities (such as IP addresses, user names) and event sequences (such as "login failure → abnormal file download") in the log to generate semantic vectors. Finally, run the malicious code sample in CuckooSandbox, monitor its process creation, file modification and network connection behaviors, and generate a dynamic behavior feature matrix.
[0067] Specifically, use Pandas for data merging and NumPy for data processing to fuse data from different sources, namely network traffic data, system logs, malicious code samples and threat intelligence data, and integrate them into a unified data set to form a multi-modal data set. As the network traffic data is reduced in dimension and features are extracted using the Autoencoder, and at the same time the BERT is used to perform semantic analysis on the system logs to extract key events and context information, key features are extracted from the multi-modal data using large model technology to improve the accuracy of threat detection.
[0068] The specific fusion process of the multi-modal fusion module is as follows:
[0069] Input: Network traffic matrix X flow , log semantic vector X log , dynamic behavior feature X behav ;
[0070] Output: Fusion feature vector F fused .
[0071] Specific steps:
[0072] Apply the autoencoder to X flow to extract low-dimensional feature X flow ;
[0073] Apply the BERT model to X log and input semantic embedding X log ;
[0074] Perform PCA dimensionality reduction on X behav to obtain X behav ;
[0075] Use the attention mechanism for weighted fusion:
[0076] F fused = α·X flow + β·X log+γ·X behav
[0077] Among them, the weights α, β, and β are dynamically optimized through model training.
[0078] The threat detection module performs real-time analysis on the fused feature vectors based on a pre-trained large model, identifies abnormal behaviors, and generates alarms.
[0079] In specific implementation, the PyTorch framework is used to construct a hybrid model. Based on ResNet-50 as the basic architecture, the pre-trained weights of ImageNet are migrated. LSTM is combined to process time series data. Multimodal feature vectors are input, and threat probability values are output. An expert knowledge base (the rule base covers the OWASP Top 10 attack patterns) is integrated to perform secondary verification on the alarms preliminarily screened by the model. For example, when the model detects an "SQL injection attempt", the knowledge base verifies whether it conforms to the attack characteristics.
[0080] Specifically, automated threat detection is achieved through large model technology, reducing the dependence on manual analysis. A real-time detection model based on LSTM is deployed to receive network traffic data in real time through Apache Kafka, automatically identify and classify potential security threats.
[0081] The response strategy generation module automatically generates defense strategies according to the alarm results and executes response operations through automated scripts or manual intervention.
[0082] In specific implementation, for DDoS attacks, the Ansible script is called to trigger the cloud traffic cleaning device (AWS Shield); for ransomware, the host isolation command is executed to block the infected IP, and the firewall rules are updated in real time through Splunk ES (Security Information and Event Management Platform) to block malicious IPs, and alarms are pushed to Slack or Enterprise WeChat.
[0083] Specifically, large model technology is used to automatically generate response strategies, improving the response speed and accuracy. Automated scripts are written using Ansible or Puppet, and the SIEM platform (Splunk) is used for real-time monitoring and response. When a DDoS attack is detected, the system automatically generates and executes corresponding response strategies, such as starting the traffic cleaning device, automatically updating the firewall rules, and isolating the infected host through the Ansible script.
[0084] Finally, an interactive panel is designed based on Grafana to dynamically display the real-time threat heat map, the attack path topology map (i.e., the path of "attack source → jump server → database"), and the processing progress. The system modules are packaged as Docker images, and elastic scaling is achieved through the Kubernetes cluster to ensure stability in high-concurrency scenarios.
[0085] The preprocessing module further includes:
[0086] A data cleaning unit that uses the Pandas library to remove redundant data and invalid records;
[0087] A normalization unit that unifies and standardizes the data through Scikit-learn;
[0088] A labeling unit that classifies and labels malicious code samples and threat intelligence data based on LabelEncoder.
[0089] In specific implementation, raw data is collected from a network traffic monitoring system, a log management system, a malicious code library, and a threat intelligence platform. Intrusion detection systems such as Snort and Suricata are used to collect network traffic data; the ELK Stack (Elasticsearch, Logstash, Kibana) is used to collect and manage log data; platforms such as VirusTotal are used to collect malicious code samples; and the MISP (Malware Information Sharing Platform) is used to collect threat intelligence data. Then, the collected data is cleaned, labeled, and formatted. Invalid or duplicate data records are removed through Pandas, the data is normalized using Scikit-learn, and labels are added to the data using LabelEncoder to generate a high-quality dataset suitable for large model training.
[0090] Then, the initial model is trained. Using the preprocessed dataset, a deep neural network model based on ResNet-50 is constructed using TensorFlow. The convergence process is accelerated through transfer learning strategies, and the learning rate and regularization parameters are optimized using KerasTuner. The large model architecture is designed and implemented for initial training. Subsequently, the model is optimized by fine-tuning the model using TensorFlow or PyTorch and performing transfer learning using the HuggingFace Transformers library. The pre-trained BERT model is fine-tuned on the local dataset to adapt to specific tasks in the field of network security, such as log analysis and threat detection, to optimize the model performance and improve the detection accuracy.
[0091] The multimodal fusion module specifically includes:
[0092] A network traffic feature extraction unit that uses an autoencoder to reduce the dimensionality of network traffic data and extract time series features and statistical features;
[0093] A log semantic analysis unit that parses the context information in system logs based on the BERT model and extracts key entities and event sequences;
[0094] The dynamic behavior analysis unit monitors the execution behaviors of malicious codes and binary files through a sandbox environment, and generates dynamic behavior features.
[0095] In specific implementation, network traffic data, system logs, malicious code samples, and threat intelligence data from different sources are merged using Pandas, processed using NumPy, integrated into a unified dataset to form a multi-modal dataset. Then, key features are extracted from the multi-modal data using large model technologies. The Autoencoder is used for dimensionality reduction and feature extraction of network traffic data, and at the same time, BERT is used for semantic analysis of system logs to extract key events and context information, and construct feature vectors.
[0096] The threat detection module adopts a large model based on the Transformer architecture, combines the LSTM network to process time series data, and integrates an expert knowledge base to conduct secondary verification on alarms. The false alarm rate is more than 30% lower than that of traditional rule engines.
[0097] The response strategy generation module includes:
[0098] Automatically isolate the infected host by calling the Ansible script according to the threat type;
[0099] Real-time update firewall rules and traffic cleaning strategies through the SIEM platform;
[0100] Generate a visual attack path map and notify the security team through multiple channels.
[0101] In specific implementation, a real-time detection model is built using TensorFlow or PyTorch, Apache Kafka is used for real-time data stream processing to identify abnormal behaviors. According to the identification results, response strategies are automatically generated, and response operations are executed through automated tools. The system can immediately generate alarms and notify the security team through channels such as emails, text messages, and instant messaging tools. The automatically generated response strategies include automated response scripts and manual suggestion plans, and support instant updates to cope with the ever-changing security situation.
[0102] It also includes:
[0103] The privacy protection unit desensitizes sensitive data using differential privacy technology, and ensures data transmission security through the AES encryption algorithm;
[0104] The adversarial defense unit uses the AdversarialRobustnessToolbox to generate adversarial samples to enhance the robustness of the large model.
[0105] In specific implementation, Adversarial Robustness Toolbox (ART) is used for adversarial sample defense. Adversarial samples are generated through ART to test the robustness of the model, and the defense ability of the model is enhanced through adversarial training. At the same time, during data collection and model training, sensitive data is desensitized, the Differential Privacy technology is used to protect data privacy, and the encryption algorithm (AES) is used to protect data transmission security.
[0106] A method for a standardized processing system of multi-modal data collection and fusion of the above-mentioned network trading platform includes the following steps:
[0107] Step 1: Collect multi-source heterogeneous data through Snort, ELKStack, and VirusTotal;
[0108] Step 2: Clean, normalize, and annotate the data to generate a standardized data set;
[0109] Step 3: Use an autoencoder and a BERT model for multi-modal feature fusion, including:
[0110] Extract time series features and statistical features from network traffic data;
[0111] Perform entity recognition and sentiment analysis on system logs to extract semantic features;
[0112] Mine the association rules between malicious code samples and threat intelligence through the FP-Growth algorithm;
[0113] Step 4: Perform real-time threat detection based on the ResNet-50 model with transfer learning;
[0114] Step 5: Automatically generate and execute response strategies according to the detection results, including:
[0115] Automatically start the traffic cleaning device for DDoS attacks;
[0116] Trigger the host isolation and backup recovery mechanism for the spreading behavior of ransomware;
[0117] Share threat intelligence to the MISP platform through the API interface.
[0118] It also includes:
[0119] Deploy the trained large model to the network trading platform through Docker containerization;
[0120] Use Metasploit to simulate attacks to verify the detection ability of the system, and conduct stress tests through JMeter;
[0121] Build a visual cockpit to display the threat situation and processing progress in real time.
[0122] During specific implementation, the trained large model is deployed into the existing network security protection system through Docker containerization to ensure seamless integration of the system and achieve end-to-end threat detection and response. Multiple types of network attacks are simulated through Metasploit to verify the detection ability and response speed of the system; JMeter is used for stress testing to ensure the stability and reliability of the system under high load, verify the performance and reliability of the system, and conduct optimization and adjustment.
[0123] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A standardized processing system for multi-modal data acquisition and fusion in an online trading platform, characterized in that, Including: A data acquisition module for real-time collecting multimodal data from the network traffic monitoring system, log management system, malicious code library and threat intelligence platform of the network trading platform, including structured data, unstructured data and semi-structured data; A preprocessing module configured to clean, normalize, denoise and label the collected data to generate a standardized data set; A multimodal fusion module that uses an autoencoder and a natural language processing model to perform feature dimensionality reduction and semantic analysis on network traffic data, system logs, malicious code samples and threat intelligence data to generate a unified multimodal feature vector; A threat detection module that performs real-time analysis on the fused feature vectors based on a pre-trained large model, identifies abnormal behaviors and generates alarms; A response strategy generation module that automatically generates defense strategies according to the alarm results and executes response operations through automated scripts or manual intervention.
2. The standardized processing system for multi-modal data collection and fusion of an online trading platform according to claim 1, wherein The preprocessing module further includes: A data cleaning unit that uses the Pandas library to remove redundant data and invalid records; A normalization unit that unifies and standardizes the data through Scikit-learn; A labeling unit that classifies and labels malicious code samples and threat intelligence data based on LabelEncoder.
3. The standardized processing system for multi-modal data collection and fusion of the online trading platform according to claim 1, characterized in that, The multimodal fusion module specifically includes: A network traffic feature extraction unit that uses an autoencoder to reduce the dimensionality of network traffic data and extract time series features and statistical features; A log semantic analysis unit that parses the context information in the system logs based on the BERT model and extracts key entities and event sequences; A dynamic behavior analysis unit that monitors the execution behaviors of malicious code and binary files through a sandbox environment to generate dynamic behavior features.
4. The standardized processing system for multi-modal data collection and fusion of an online trading platform according to claim 1, wherein The threat detection module uses a large model based on the Transformer architecture, combines the LSTM network to process time series data, and integrates an expert knowledge base to perform secondary verification on the alarms.
5. The standardized processing system for multi-modal data collection and fusion of an online trading platform according to claim 1, characterized in that, The response strategy generation module includes: Automatically isolating the infected host by calling the Ansible script according to the threat type; Real-time updating the firewall rules and traffic cleaning strategies through the SIEM platform; Generating a visual attack path graph and notifying the security team through multiple channels.
6. The standardized processing system for multi-modal data acquisition and fusion of an online trading platform according to claim 1, wherein Also including: A privacy protection unit that desensitizes sensitive data using differential privacy technology and ensures data transmission security through the AES encryption algorithm; An adversarial defense unit that uses the AdversarialRobustnessToolbox to generate adversarial samples to enhance the robustness of the large model.
7. A method for the standardized processing system of multi-modal data acquisition and fusion of a network trading platform according to any one of claims 1-6, characterized in that, Including the following steps: Step 1: Collecting multi-source heterogeneous data through Snort, ELKStack and VirusTotal; Step 2: Cleaning, normalizing and labeling the data to generate a standardized data set; Step 3: Performing multimodal feature fusion using an autoencoder and the BERT model; Step 4: Performing real-time threat detection based on the ResNet-50 model of transfer learning; Step 5: Automatically generating response strategies according to the detection results and executing them.
8. The standardized processing method for multi-modal data acquisition and fusion of a network trading platform according to claim 7, characterized in that, The multimodal feature fusion step further includes: Extracting time series features and statistical features from network traffic data; Perform entity recognition and sentiment analysis on system logs to extract semantic features; Mining the association rules between malicious code samples and threat intelligence through the FP-Growth algorithm.
9. The standardized processing method for multi-modal data acquisition and fusion of an online trading platform according to claim 7, wherein, It also includes: Deploy the trained large model to the network trading platform through Docker containerization; Use Metasploit to simulate attacks to verify the system's detection capabilities and conduct stress tests through JMeter; Build a visual cockpit to display the threat situation and processing progress in real time.
10. The standardized processing method for multi-modal data collection and fusion of an online trading platform according to claim 7, characterized in that, The specific steps of generating the response strategy include: Automatically start the traffic cleaning device for DDoS attacks; Trigger the host isolation and backup recovery mechanism for the spread behavior of ransomware; Share threat intelligence to the MISP platform through the API interface.
Citation Information
Cited By
Flow collection system, threat analysis method and strategy generation method
CN120785652A
A traffic collection system, threat analysis method, and policy generation method
CN120785652B
Phishing attack interception method and device based on sandbox and multi-modal fusion analysis and computer equipment
CN120856448A
Network security risk prediction and prevention method and system based on big data
CN121396539A
Industrial network firewall rule generation method based on deep neural network
CN122437721A