Network security early warning method and system based on artificial intelligence

Through multi-dimensional traffic analysis of quantum-enhanced deep packet detection and deep reinforcement learning, combined with hidden channel coding and dynamic knowledge graph of graph neural networks, camouflage strategies and lightweight encryption are optimized, which solves the problems of low detection efficiency and transparency of existing network security early warning systems in the face of new attacks, and achieves efficient and hidden network security defense.

CN120342671APending Publication Date: 2025-07-18JIANGMEN LINGZHI TECH CO LTD

Patent Information

Application Number
CN202510437539.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

When existing cybersecurity early warning systems face new attacks or highly camouflaged intrusions, their detection efficiency is low and their system transparency increases, resulting in an intensified risk of exposure to defense strategies and unable to effectively deal with complex and concealed cyber attacks.

Method used

Quantum enhanced deep packet detection combined with deep reinforcement learning is used to perform multi-dimensional traffic analysis, generate dynamic camouflage instructions and embed communication messages through hidden channel encoding technology, and build dynamic knowledge graphs with graph neural networks. Use reinforcement learning to optimize camouflage strategies, and use lightweight encryption and distributed execution nodes for efficient defense.

Benefits of technology

It realizes accurate identification and prediction of new attacks and advanced threats, improves the real-time and automation level of security responses, ensures the concealment and efficiency of defense systems, and minimizes the impact of cyber attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342671A_ABST
    Figure CN120342671A_ABST
Patent Text Reader

Abstract

The invention discloses a network security early warning method and system based on artificial intelligence, and relates to the technical field of network security early warning and defense. According to the method, multi-dimensional intelligent analysis of network traffic and accurate identification of abnormal traffic modes are realized, the defense concealment is enhanced through a concealed channel coding technology, detection of attackers is avoided, internal association and evolution paths of attack modes are mined by using a dynamic knowledge graph and an attention mechanism, and the attack modes are accurately identified. The method improves the recognition and prediction capability of novel attacks and advanced threats, optimizes a camouflage strategy, combines a lightweight encryption algorithm and distributed execution nodes, efficiently deploys defense actions, evaluates the attack mitigation effect in real time through a support vector machine, dynamically adjusts a defense strategy, achieves the quick recovery of a network state, and achieves the stable operation. And the real-time performance and the automation level of safety response are obviously improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security warning and defense, and in particular to a network security warning method and system based on artificial intelligence. Background Art

[0002] The application of artificial intelligence in the field of network security has become the cornerstone of maintaining the order of the digital world, and its importance is self-evident. With the increasing complexity and concealment of network attack means, as the outpost of the defense system, the warning mechanism must be efficient and concealed to cope with the emerging threats. However, most current network security warning systems still face significant limitations in actual deployment. Existing solutions mostly rely on static rule matching or explicit feature recognition. Although they can detect known threats to a certain extent, they are often powerless against new types of attacks or highly disguised intrusion behaviors. This passive defense mode is easy to be recognized and bypassed by attackers, resulting in the warning system being in vain. In addition, when traditional methods improve the detection efficiency, the transparency of the system often increases, which further exacerbates the risk of exposing the defense strategy. Summary of the Invention

[0003] The present invention provides a network security warning method and system based on artificial intelligence to solve the above-mentioned existing technical problems.

[0004] The technical solution of the present invention is realized as follows:

[0005] A network security warning method based on artificial intelligence includes the following steps:

[0006] S100. Obtain traffic data through quantum-enhanced deep packet detection, extract features and dynamically adjust weights in combination with deep reinforcement learning, introduce time series analysis and spatial correlation mining, and obtain a real-time traffic pattern description with spatio-temporal correlation;

[0007] S200. Generate a dynamic camouflage instruction sequence according to the real-time traffic pattern description, use a generative adversarial network to adjust the parameters of the camouflage instructions to match the traffic features, obtain a set of camouflage instructions, integrate the set of camouflage instructions into the network traffic data, and use a covert channel coding technology to embed the instruction sequence into a normal communication message to obtain the fused traffic data;

[0008] S300. Analyze the traffic behavior of the traffic data through an anomaly detection algorithm. When an abnormal pattern deviating from a preset value is detected, trigger a complex attack recognition module to judge the potential attack type;

[0009] S400. Based on the potential attack type, in combination with the historical attack sample database and real-time traffic behavior characteristics, an association analysis method based on graph neural network is adopted to construct a dynamic knowledge graph of attack patterns. Then, through node embedding and edge relation reasoning of the graph neural network, the internal associations and evolution paths of attack patterns are mined, and the attention mechanism is used to dynamically adjust the feature weights, and the probability distribution of attack patterns is updated in real time to obtain the dynamic prediction results of current attack patterns;

[0010] S500. According to the dynamic prediction results, adjust the parameters for generating the camouflage strategy, use the reinforcement learning algorithm to optimize the strategy generation direction, obtain a more adaptable set of camouflage strategies, optimize the instruction transmission process according to the set of camouflage strategies, and use a lightweight encryption algorithm to compress the data volume of the camouflage instructions to obtain an instruction sequence for efficient transmission;

[0011] S600. By analyzing the network status of the instruction sequence and obtaining monitoring data, determine whether the monitoring data exceeds the preset response value. When it exceeds, activate the response mechanism, determine the defense action sequence, and according to the defense action sequence, deploy the action sequence to the network environment through distributed execution nodes, and use time synchronization technology to coordinate the execution of each node to obtain the network status data after the attack is mitigated.

[0012] Furthermore, obtain a real-time traffic pattern description with spatio-temporal correlation, specifically including:

[0013] S110. Obtain network traffic data, use quantum-enhanced deep packet detection technology to perform multi-dimensional analysis on the traffic, extract traffic features, and then use an adaptive feature extraction algorithm driven by deep reinforcement learning to process the extracted traffic features, and dynamically adjust the weights and parameters of feature extraction;

[0014] S120. Introduce time series analysis through the adjusted feature weights and parameters, analyze the change trend of the traffic pattern in the time series to obtain preliminary change trend data;

[0015] S130. Extract the association patterns between different network nodes from the network traffic through spatial association mining to obtain node pattern data. When the preliminary change trend data exceeds the preset threshold, adjust the parameters of the time series analysis in combination with the node pattern data to obtain updated change trend data;

[0016] S140. According to the updated change trend data and node pattern data, generate a real-time traffic pattern description data with spatio-temporal correlation, and use the real-time traffic pattern description data to compare with the original traffic features to judge the abnormal state of the traffic pattern and obtain the pattern analysis result.

[0017] Furthermore, obtain the fused traffic data, specifically including:

[0018] Generate an initial camouflage instruction based on traffic characteristics, construct an instruction sequence through a dynamic generation method to obtain a preliminary instruction set, use a generative adversarial network to adjust the parameters of the preliminary instruction set, obtain matching information from the traffic characteristics, and get an optimized camouflage instruction set;

[0019] Analyze the communication message structure through steganography techniques, determine the embedding point location, obtain available message carriers, and use coding techniques to embed the optimized camouflage instruction set into the communication message. When the capacity of the embedding point is insufficient, adjust the coding density to obtain the encoded message data;

[0020] Use a traffic injection tool to integrate the encoded message data into the real-time traffic to obtain fusion data, and verify according to the pattern difference between the fusion data and the original traffic. When the difference exceeds the preset threshold, readjust the camouflage instruction parameters to obtain the final fusion traffic data.

[0021] Furthermore, judge the potential attack types, specifically including:

[0022] Analyze the traffic behavior through the fused traffic data by running an anomaly detection algorithm to obtain an abnormal pattern deviating from the preset value. According to the abnormal pattern, use statistical methods to calculate the deviation degree from the preset threshold to determine the existence of a significant deviation. When a significant deviation exists, trigger a complex attack recognition module through the deviation data to obtain potential attack characteristics; through the potential attack characteristics, use a classification algorithm to analyze the feature distribution to obtain a preliminary attack type judgment result. According to the preliminary judgment result, obtain historical traffic data for pattern comparison to determine the accuracy of the attack type; through the accuracy data, use a rule matching method to process the attack characteristics, judge the final attack classification, and generate corresponding behavior analysis records according to the final attack classification to obtain a structured attack log.

[0023] Furthermore, obtain the dynamic prediction result of the current attack mode, specifically including:

[0024] Obtain the historical attack sample database and real-time traffic behavior feature data, and preliminarily process the data through a graph neural network to generate an attack mode knowledge graph;

[0025] Analyze the feature representation of each node in the knowledge graph through node embedding technology to obtain the correlation analysis result between nodes, and use edge relation reasoning technology to mine the evolution path of the correlation analysis result between nodes to obtain the potential change trend of the attack mode;

[0026] Dynamically adjust the feature weights using the attention mechanism, update the feature weight values of each node according to the change trend, calculate the probability distribution through the updated feature weight values, and obtain the real-time probability distribution data of the attack pattern; when the probability distribution data exceeds the preset threshold, combine the historical samples and real-time traffic characteristics, determine it as a high-risk attack pattern, and generate the corresponding dynamic prediction result;

[0027] Update the knowledge graph according to the dynamic prediction result, and perform iterative analysis on the new data through the graph neural network to obtain more accurate attack pattern feature data.

[0028] Furthermore, obtain a more adaptable set of camouflage strategies, specifically including:

[0029] Take the real-time state information in the network environment as the initial state and input it into the reinforcement learning model to construct the state space; and set a reward mechanism in the reinforcement learning algorithm. When the camouflage strategy successfully avoids attacks and reduces the risk of the system being detected, a positive reward is given, otherwise a negative reward is given; continuously explore and try in the state space, and adjust the strategy generation direction according to the reward feedback; in each iteration, use the policy gradient method to update the policy parameters to generate a more adaptable set of camouflage strategies.

[0030] Furthermore, adopt a lightweight encryption algorithm to compress the data volume of the camouflage instructions to obtain an instruction sequence for efficient transmission, specifically including:

[0031] Adjust the strategy set through the preset adaptive camouflage rules to generate the initial camouflage strategy, extract the instruction transmission characteristics according to the initial camouflage strategy, determine the transmission optimization direction, use the lightweight encryption algorithm to process the transmission optimization direction to obtain the encrypted instruction set, perform data compression operations on the encrypted instruction set to generate compressed data packets. When the compressed data packets meet the preset threshold, send them through the efficient transmission channel to obtain the transmission sequence, and then obtain the feedback information of the transmission sequence, judge whether to adjust the camouflage strategy and generate an updated sequence, and replace the original instruction sequence with the updated sequence to obtain the final efficient transmission result.

[0032] Furthermore, determine the defense action sequence, specifically including:

[0033] Use the time series analysis method to analyze the network state of the instruction sequence, then obtain the monitoring data, judge whether the monitoring data exceeds the preset response value, then determine the exceeding degree through the threshold judgment process. When it exceeds, activate the response mechanism using the preset rules, determine the defense action configuration, obtain the action sequence content according to the defense action configuration, use the scheduling algorithm to obtain the execution order, and then process the action sequence content through the transmission protocol to obtain the defense action implementation result.

[0034] Furthermore, obtain the network state data after the attack is mitigated, specifically including:

[0035] Obtain a defense action sequence, deploy the action sequence to the network environment through distributed execution nodes to obtain preliminary deployment data, and use time synchronization technology to coordinate the execution of each node in the preliminary deployment data to obtain synchronous timestamps;

[0036] Analyze the execution status of nodes based on the synchronous timestamps. If it is determined that the time deviation exceeds a preset threshold, adjust the execution rhythm to obtain a coordination result. Calculate the attack mitigation degree based on the coordination result, and use the support vector machine algorithm to determine the network state after mitigation to obtain state indicators;

[0037] Obtain the state indicators and compare them with the first sequence of data. If the indicators are abnormal, update the defense action sequence to obtain the second sequence of data, redeploy the second sequence of data to the network environment, and use data acquisition technology to extract the final state data to obtain the final state data.

[0038] A network security early warning system based on artificial intelligence for implementing a network security early warning method based on artificial intelligence, including:

[0039] A traffic pattern analysis module that obtains network traffic data through quantum-enhanced deep packet detection technology, performs multi-dimensional analysis on the traffic and extracts features, dynamically adjusts the weights and parameters of feature extraction using deep reinforcement learning, and at the same time introduces time series analysis and spatial correlation mining to obtain real-time traffic pattern description data with spatio-temporal correlation;

[0040] A dynamic camouflage and traffic fusion module that generates a dynamic camouflage instruction sequence according to the real-time traffic pattern description, uses a generative adversarial network to adjust the parameters of the camouflage instructions to match the traffic characteristics to obtain a set of camouflage instructions, and then embeds the instruction sequence into normal communication messages using covert channel coding technology;

[0041] An anomaly detection and attack recognition module that analyzes the traffic behavior of traffic data through an anomaly detection algorithm. When an abnormal pattern deviating from a preset value is detected, it triggers a complex attack recognition module to determine the potential attack type;

[0042] An attack pattern prediction module that, according to the potential attack type, combines the historical attack sample database and real-time traffic behavior characteristics, uses an association analysis method based on graph neural networks to construct a dynamic knowledge graph of attack patterns, mines the internal associations and evolution paths of attack patterns through node embedding and edge relationship reasoning of graph neural networks, and uses an attention mechanism to dynamically adjust feature weights to update the probability distribution of attack patterns in real time to obtain the current dynamic prediction result of attack patterns;

[0043] The camouflage strategy optimization module adjusts the parameters for generating the camouflage strategy according to the dynamic prediction results, optimizes the strategy generation direction using the reinforcement learning algorithm, generates a more adaptable set of camouflage strategies, and at the same time compresses the data volume of the camouflage instructions using a lightweight encryption algorithm to obtain an instruction sequence for efficient transmission;

[0044] The response and defense execution module analyzes the network state of the instruction sequence and obtains monitoring data, determines whether the monitoring data exceeds the preset response value. When the monitoring data exceeds the preset response threshold, it activates the response mechanism, determines the defense action sequence, and then deploys the action sequence to the network environment through distributed execution nodes, and uses time synchronization technology to coordinate the execution of each node to obtain the network state data after the attack is mitigated.

[0045] Advantages of the present invention:

[0046] Through the combination of quantum-enhanced deep packet inspection and deep reinforcement learning, the present invention realizes multi-dimensional intelligent analysis of network traffic, can dynamically adjust feature weights, combines time series analysis and spatial correlation mining to accurately identify abnormal traffic patterns with spatio-temporal correlation. At the same time, it uses a generative adversarial network (GAN) to dynamically adjust camouflage instructions, and embeds the instructions into normal communication packets through covert channel coding technology, making the defense system highly concealed and effectively avoiding detection and evasion by attackers;

[0047] Construct a dynamic knowledge graph of attack patterns using graph neural networks, dynamically adjust feature weights in combination with the attention mechanism, and mine the internal associations and evolution paths of attack patterns. Through the fusion analysis of the historical attack sample database and real-time traffic behavior characteristics, the system can accurately predict potential attack types and update the probability distribution of attack patterns in real time. Compared with traditional static rule matching methods, this solution significantly improves the detection ability of new attacks and advanced persistent threats;

[0048] Using the reinforcement learning algorithm to optimize the camouflage strategy generation direction can adaptively adjust the defense strategy. At the same time, it uses a lightweight encryption algorithm to compress the data volume of camouflage instructions, combines distributed execution nodes and time synchronization technology to ensure the efficient deployment and coordinated execution of defense actions, and evaluates the attack mitigation effect in real time through algorithms such as support vector machines and dynamically adjusts the defense strategy. Finally, it realizes the rapid recovery and stable operation of the network state, greatly improving the real-time and automation level of security response while ensuring the detection accuracy. This efficient attack prediction and defense response mechanism enables the system to take effective defense measures before or at the initial stage of an attack, minimizing the impact of the attack on the network system. Brief Description of the Drawings

[0049] Figure 1Schematic flowchart of a network security warning method based on artificial intelligence provided in the first embodiment of this application;

[0050] Figure 2 Schematic flowchart of obtaining a real-time traffic pattern description with spatio-temporal correlation by a network security warning method based on artificial intelligence provided in the first embodiment of this application;

[0051] Figure 3 Schematic flowchart of obtaining fused traffic data by a network security warning method based on artificial intelligence provided in the first embodiment of this application;

[0052] Figure 4 Schematic diagram of the structure of a network security warning system based on artificial intelligence provided in the second embodiment of this application. Detailed implementation manners

[0053] To make the objectives, features, and advantages of the present invention more obvious and understandable, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the embodiments described below are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0054] Embodiment 1

[0055] As Figures 1-3 shown, this embodiment provides a network security warning method based on artificial intelligence, including the following steps:

[0056] S100. Obtain traffic data through quantum-enhanced deep packet detection, extract features, dynamically adjust weights by combining deep reinforcement learning, introduce time series analysis and spatial correlation mining, and obtain a real-time traffic pattern description with spatio-temporal correlation;

[0057] Further, in S100, obtaining a real-time traffic pattern description with spatio-temporal correlation specifically includes:

[0058] S110. Obtain network traffic data, perform multi-dimensional analysis on the traffic using quantum-enhanced deep packet detection technology, extract traffic features, and then process the extracted traffic features using an adaptive feature extraction algorithm driven by deep reinforcement learning to dynamically adjust the weights and parameters of feature extraction;

[0059] S120. Introduce time series analysis through the adjusted feature weights and parameters, analyze the change trend of the traffic pattern in the time series, and obtain preliminary change trend data;

[0060] S130. Extract the association patterns between different network nodes from network traffic through spatial association mining to obtain node pattern data. When the preliminary change trend data exceeds the preset threshold, adjust the parameters of time series analysis in combination with the node pattern data to obtain the updated change trend data.

[0061] S140. Generate real-time traffic pattern description data with spatio-temporal correlation according to the updated change trend data and node pattern data. Compare the real-time traffic pattern description data with the original traffic characteristics to judge the abnormal state of the traffic pattern and obtain the pattern analysis result.

[0062] Among them, obtain historical samples and real-time traffic, process the pattern analysis result through a graph neural network to generate an initial knowledge graph, and analyze the feature representation of each node in the knowledge graph through node embedding to obtain the preliminary association analysis result between nodes.

[0063] Specifically, it can be described as follows. Obtain network traffic data, optimize the deep packet detection algorithm through quantum computing, parse the packet header and payload information, and extract features such as source address, destination address, and protocol type; then use the Deep Q-Network (DQN) algorithm to dynamically adjust the weights according to the importance of traffic features, and adjust the source address weight from 0.3 to 0.5.

[0064] Introduce time series analysis with the adjusted feature weights and parameters to analyze the change trend of the traffic pattern in the time series to obtain the preliminary change trend data. For example, use the ARIMA model to analyze the traffic data and predict the traffic change trend within the next 5 minutes. Extract the association patterns between different network nodes from network traffic through spatial association mining to obtain node pattern data. For example, use the K-means clustering algorithm to classify the node traffic and identify the distribution patterns of high-traffic nodes and low-traffic nodes. If the preliminary change trend data exceeds the preset threshold, adjust the parameters of time series analysis in combination with the node pattern data to obtain the updated change trend data. For example, when the traffic change trend exceeds 10%, adjust the parameters of the ARIMA model and recalculate the change trend.

[0065] Generate real-time traffic pattern description data with spatio-temporal correlation based on the updated trend data and node pattern data. For example, fuse time series data and node clustering results to generate a feature matrix describing the spatio-temporal distribution of traffic. Compare the real-time traffic pattern description data with the original traffic characteristics to judge the abnormal state of the traffic pattern and obtain the pattern analysis result. For example, calculate the difference between the real-time feature matrix and the historical feature matrix using the Euclidean distance to judge whether there is abnormal traffic. Obtain historical samples and real-time traffic, and process the pattern analysis result through a graph neural network to generate an initial knowledge graph. For example, use GAT (Graph Attention Network) to model nodes and edges to construct a knowledge graph of network traffic;

[0066] Analyze the feature representations of each node in the knowledge graph through node embedding to obtain a preliminary correlation analysis result between nodes. For example, use the Node2Vec algorithm to embed nodes, calculate the similarity between nodes, and identify potential attack paths.

[0067] S200. Generate a dynamic camouflage instruction sequence according to the real-time traffic pattern description. Use a generative adversarial network to adjust the parameters of the camouflage instructions to match the traffic characteristics to obtain a set of camouflage instructions. Incorporate the set of camouflage instructions into the network traffic data, and use steganographic channel coding technology to embed the instruction sequence into normal communication messages to obtain the fused traffic data;

[0068] Among them, in the network security early warning system, obtaining network traffic data is the basis of the entire process. Multidimensionally analyze and extract features of the traffic through technologies such as quantum-enhanced deep packet inspection, and use deep reinforcement learning to dynamically adjust weights and introduce time series and spatial correlation mining to obtain a real-time traffic pattern description with spatio-temporal correlation. This step aims to comprehensively and accurately understand the real-time operating state of the network, master the characteristics and change laws of normal and abnormal traffic, and generating a dynamic camouflage instruction sequence is based on a deep understanding of network traffic to prepare for subsequent early warning and defense work.

[0069] It should be noted that network attackers usually try to detect and identify the characteristics and patterns of defense systems in order to launch targeted attacks. They generate dynamic camouflage instruction sequences that match the characteristics of network traffic and integrate them into network traffic data, which can effectively confuse the attackers' judgment. When attackers attempt to analyze network traffic, the camouflage instruction sequences can interfere with their recognition of the real traffic patterns and defense strategies, making the defense system more concealed and reducing the risk of being attacked. For example, if attackers judge the existence of a security defense mechanism based on specific traffic patterns, the dynamic camouflage instruction sequences can change the external manifestation of the traffic, making it difficult for them to easily identify the existence of the defense system, thus buying more time and opportunities for subsequent anomaly detection and attack defense. Therefore, generating dynamic camouflage instruction sequences after obtaining network traffic data is a crucial step in building an active, efficient, and concealed network security early warning system. The two are closely linked and jointly serve the goal of enhancing network security.

[0070] Furthermore, in S200, the obtained fused traffic data specifically includes:

[0071] S210. Generate initial camouflage instructions according to traffic characteristics, construct an instruction sequence through a dynamic generation method to obtain a preliminary instruction set, and use a generative adversarial network to adjust the parameters for the preliminary instruction set, obtain matching information from the traffic characteristics, and get an optimized camouflage instruction set;

[0072] S220. Analyze the communication message structure through covert channel technology to determine the embedding point location, obtain available message carriers, and use coding technology to embed the optimized camouflage instruction set into the communication message. When the capacity of the embedding point is insufficient, adjust the coding density to obtain the coded message data;

[0073] S230. Use a traffic injection tool to integrate the coded message data into the real-time traffic to obtain fused data, and verify according to the pattern difference between the fused data and the original traffic. When the difference exceeds the preset threshold, readjust the camouflage instruction parameters to obtain the final fused traffic data.

[0074] Among them, the final fused traffic data is parsed through quantum-enhanced deep packet detection technology to extract the adjusted traffic characteristics, and spatial correlation analysis is used to extract the association patterns of different network nodes from the adjusted traffic characteristics to obtain node pattern data.

[0075] Specifically, it can be described as follows. Network traffic is captured by a real-time traffic collection device at a rate of 1000 packets per second. Pattern analysis technology based on the hidden Markov model is used to extract traffic characteristics, and characteristic parameters with an average packet interval time of 12.3 ms and a standard deviation of payload size of 45.6 bytes are calculated. According to the extracted traffic characteristics, an initial camouflage instruction sequence is generated using an LSTM neural network, the dynamic range of the instruction length is set to 64 - 128 bytes, and a preliminary instruction set containing 32 instructions is generated. A Wasserstein generative adversarial network is used to optimize the preliminary instruction set. The discriminator uses the KL divergence of the traffic characteristics as the loss function. After 50 iterations of training, an optimized instruction set with a matching error between the instruction parameters and the traffic characteristics lower than 5% is obtained. By analyzing the optional field structure of the HTTP header, the last 20 bytes of the User-Agent field are determined as the embedding point, and packets with a payload greater than 200 bytes are selected as carriers. The LSB encoding technology is used to embed instructions by replacing the last 2 bits of each byte. When the carrier capacity is insufficient, it is switched to DCT coefficient encoding, and the encoding density is increased from 1 bit / coefficient to 2 bit / coefficient. The Scapy traffic injection tool is used to send the encoded packets at the same Poisson distribution time interval as the original traffic, and the injection rate is controlled within the range of 800 - 1200 pps. The dynamic time warping algorithm is used to calculate the pattern difference between the fused traffic and the original traffic. When the DTW distance exceeds 0.15, the instruction parameters are adjusted within the range of ±3% by the generative adversarial network for re-optimization. Quantum annealing algorithm-enhanced deep packet detection is applied to the final traffic, and a 128-dimensional feature vector space is used for parsing to extract the updated traffic statistical characteristics. Based on the improved Granger causality analysis algorithm, the traffic correlation coefficient between network nodes is calculated, an association matrix including delay jitter and packet loss rate is established, and the cross-node traffic pattern is analyzed.

[0076] S300. Analyze the traffic behavior of traffic data through an anomaly detection algorithm. When an abnormal pattern deviating from a preset value is detected, trigger the complex attack recognition module to determine the potential attack type.

[0077] Furthermore, in S300, determining the potential attack type specifically includes:

[0078] Based on the fused traffic data, run an anomaly detection algorithm to analyze traffic behavior, obtain anomaly patterns that deviate from the preset values. According to the anomaly patterns, use statistical methods to calculate the deviation degree from the preset threshold, and determine the existence of significant deviation. When significant deviation exists, trigger the complex attack recognition module through the deviation data to obtain potential attack features; through the potential attack features, use a classification algorithm to analyze the feature distribution to obtain a preliminary judgment result of the attack type. According to the preliminary judgment result, obtain historical traffic data for pattern comparison to determine the accuracy of the attack type; through the accuracy data, use a rule matching method to process the attack features, judge the final attack classification, and generate corresponding behavior analysis records according to the final attack classification to obtain structured attack logs.

[0079] Among them, through the structured attack logs, use a graph neural network to process real-time traffic data to generate an initial knowledge graph. According to the initial knowledge graph, use node embedding technology to analyze the feature representations of each node to obtain a preliminary correlation analysis result between nodes.

[0080] Specifically, it can be described as follows: Based on the fused traffic data, run an isolation forest-based anomaly detection algorithm to analyze traffic behavior and calculate the deviation degree of data points from the normal behavior pattern; use standard deviation and mean statistical methods to calculate the deviation degree from the preset threshold. If the deviation value exceeds 2 times the preset standard deviation, determine the existence of significant deviation; if significant deviation exists, trigger the complex attack recognition module through the deviation data and use a deep learning-based feature extraction method to obtain potential attack features; through the potential attack features, use a support vector machine classification algorithm to analyze the feature distribution, calculate the similarity between the feature vector and the known attack categories, and obtain a preliminary judgment result of the attack type. According to the preliminary judgment result, obtain historical traffic data and use the dynamic time warping algorithm for pattern comparison to calculate the similarity score and determine the accuracy of the attack type; through the accuracy data, use a rule-based matching method to process the attack features. If the feature matching degree exceeds 90%, then judge the final attack classification.

[0081] S400. According to the potential attack type, combined with the historical attack sample database and real-time traffic behavior characteristics, use a graph neural network-based association analysis method to construct a dynamic knowledge graph of the attack pattern, and then through the node embedding and edge relationship reasoning of the graph neural network, mine the internal association and evolution path of the attack pattern, and use the attention mechanism to dynamically adjust the feature weights, and update the probability distribution of the attack pattern in real time to obtain the current dynamic prediction result of the attack pattern;

[0082] Furthermore, in S400, obtaining the current dynamic prediction result of the attack pattern specifically includes:

[0083] Obtain the historical attack sample database and real-time traffic behavior feature data, and preliminarily process the data through a graph neural network to generate an attack pattern knowledge graph;

[0084] Analyze the feature representations of each node in the knowledge graph through node embedding technology to obtain the correlation analysis results between nodes. Use edge relationship reasoning technology to mine the evolution path of the correlation analysis results between nodes to obtain the potential change trend of the attack pattern;

[0085] Use the attention mechanism to dynamically adjust the feature weights, update the feature weight values of each node according to the change trend, calculate the probability distribution through the updated feature weight values, and obtain the real-time probability distribution data of the attack pattern; When the probability distribution data exceeds the preset threshold, combine the historical samples and real-time traffic characteristics to determine it as a high-risk attack pattern and generate the corresponding dynamic prediction result;

[0086] Update the knowledge graph according to the dynamic prediction result, and perform iterative analysis on the new data through the graph neural network to obtain more accurate attack pattern feature data.

[0087] Among them, use the quantum-enhanced deep packet detection technology to parse the network traffic, extract the traffic features related to the attack pattern to obtain the real-time description data, and compare and analyze the real-time description data with the attack pattern feature data to judge the abnormal state of the traffic pattern and obtain the final attack pattern prediction result.

[0088] Specifically, it can be described as follows. Obtain the malicious IPs, attack payloads, and vulnerability exploitation records in the historical attack sample database, combine the TCP / UDP session characteristics in the real-time traffic, and use the GraphSAGE graph neural network to aggregate the features of the data to generate an initial knowledge graph containing three types of nodes: attackers, targets, and attack methods; Embed the knowledge graph nodes into 128-dimensional vectors through the Node2Vec algorithm, calculate the node pairs with a cosine similarity greater than 0.85 as the preliminary associations, use the GAT graph attention network for edge relationship reasoning, analyze the evolution sequences with no more than 3 node hops in the attack path, and identify the trend of the evolution from DDoS attacks to APT attacks. Use the multi-head attention mechanism to dynamically adjust the feature weights. When the frequency of a certain type of attack feature exceeds 100 times within 1 hour, increase its weight from 0.3 to 0.7;

[0089] Based on the updated weight values, calculate the probability distribution of each attack pattern through the Softmax function, and trigger an alarm when the probability of SQL injection attack exceeds the 0.9 threshold;

[0090] Add the early warning result as a new node to the knowledge graph, use the GIN network for iterative training, output a 128-dimensional new vector containing zero-day attack features, use a DPI engine enhanced by a quantum random number generator to parse traffic, and extract 23 features such as anomalies in cipher suites in the TLS handshake protocol;

[0091] Detect feature mutations through LSTM time series analysis. When the feature fluctuation exceeds 3 standard deviations within 5 minutes, adjust the LSTM window size in combination with the node pattern in the knowledge graph;

[0092] Finally, calculate the Euclidean distance between the real-time traffic features and the knowledge graph vector. When the distance value is greater than 1.5, it is determined as an abnormal attack mode.

[0093] S500. According to the dynamic prediction result, adjust the parameters for generating the camouflage strategy, use the reinforcement learning algorithm to optimize the strategy generation direction, obtain a more adaptable set of camouflage strategies, optimize the instruction transmission process according to the set of camouflage strategies, and use a lightweight encryption algorithm to compress the data volume of the camouflage instructions to obtain an instruction sequence for efficient transmission;

[0094] Furthermore, in S500, to obtain a more adaptable set of camouflage strategies, specifically including:

[0095] Take the real-time state information in the network environment, such as traffic fluctuation conditions, attack type and intensity changes, etc., as the initial state and input it into the reinforcement learning model to construct the state space;

[0096] And set a reward mechanism in the reinforcement learning algorithm. When the camouflage strategy successfully avoids attacks and reduces the risk of the system being detected, a positive reward is given, otherwise a negative reward is given;

[0097] By continuously exploring and trying in the state space, adjust the strategy generation direction according to the reward feedback; in each iteration, use the policy gradient method to update the policy parameters to generate a strategy that is more adaptable to the complex and changeable network attack environment. After multiple rounds of learning and optimization, finally converge to form a more adaptable set of camouflage strategies.

[0098] Furthermore, in S500, use a lightweight encryption algorithm to compress the data volume of the camouflage instructions to obtain an instruction sequence for efficient transmission, specifically including:

[0099] Adjust the policy set through the preset adaptive camouflage rules to generate an initial camouflage policy. Extract the instruction transmission features according to the initial camouflage policy, determine the transmission optimization direction, and use a lightweight encryption algorithm to process the transmission optimization direction to obtain the encrypted instruction set. Perform data compression operations on the encrypted instruction set to generate compressed data packets. When the compressed data packets meet the preset threshold, send them through an efficient transmission channel to obtain a transmission sequence. Then, obtain the feedback information of the transmission sequence, determine whether to adjust the camouflage policy and generate an updated sequence, and replace the original instruction sequence with the updated sequence to obtain the final efficient transmission result.

[0100] Run the real-time monitoring module for the final efficient transmission result to analyze the network status and obtain monitoring data. If the monitoring data exceeds the preset response threshold, activate the response mechanism to determine the defense action sequence.

[0101] Specifically, it can be described as follows: Generate an initial camouflage policy. For example, use a rule selection algorithm based on dynamic weights to dynamically adjust the camouflage policy weights according to the network traffic characteristics. Analyze the delay, packet loss rate, and bandwidth utilization rate of instruction transmission through a feature extraction algorithm, and determine that the optimization direction is to reduce the delay. Use a lightweight encryption algorithm to process the transmission optimization direction to obtain the encrypted instruction set. For example, use the AES-128 algorithm to encrypt the instructions to ensure data security. Perform data compression operations on the encrypted instruction set to generate compressed data packets. For example, use the LZ77 algorithm to compress the encrypted instructions to 70% of the original data. If the compressed data packets meet the preset threshold, send them through an efficient transmission channel to obtain a transmission sequence. For example, set the compressed data packet size threshold to 1MB and send it through a dedicated transmission channel.

[0102] Obtain the feedback information of the transmission sequence. For example, analyze the transmission success rate through the feedback information. If it is lower than 95%, adjust the camouflage policy, replace the original instruction sequence with the updated sequence, and obtain the final efficient transmission result. For example, apply the updated instruction sequence to the next transmission.

[0103] S600: Analyze the network status of the instruction sequence and obtain monitoring data. Determine whether the monitoring data exceeds the preset response value. When it exceeds, activate the response mechanism to determine the defense action sequence. According to the defense action sequence, deploy the action sequence to the network environment through distributed execution nodes and use time synchronization technology to coordinate the execution of each node to obtain the network status data after the attack is mitigated.

[0104] Furthermore, in S600, determining the defense action sequence specifically includes:

[0105] Analyze the network status of the instruction sequence using time series analysis method, then obtain the monitoring data, determine whether the monitoring data exceeds the preset response value, and determine the degree of excess through the threshold judgment process. When it exceeds, activate the response mechanism using the preset rules, determine the defense action configuration, obtain the action sequence content according to the defense action configuration, obtain the execution order using the scheduling algorithm, and then process the action sequence content through the transmission protocol to obtain the implementation result of the defense action.

[0106] Specifically, it can be described as follows. Collect network status information through sensors, including indicators such as traffic rate, packet loss rate, and latency, and analyze the network status of the instruction sequence using time series analysis method to obtain the status analysis result;

[0107] Based on the status analysis result, obtain the monitoring data. Determine that if the traffic rate exceeds the preset threshold of 100 Mbps, then determine the degree of excess as 20% through the threshold judgment process;

[0108] According to the degree of excess, activate the response mechanism using the preset rules, and determine the defense action configuration as the traffic limiting strategy;

[0109] Through the defense action configuration, obtain the action sequence content, obtain the execution order using the priority scheduling algorithm, give priority to processing high-priority traffic, and use the execution order to process the action sequence content through the TCP transmission protocol to obtain the implementation result of the defense action, and limit the traffic rate to 80 Mbps.

[0110] Furthermore, obtain the network status data after attack mitigation, specifically including:

[0111] Obtain the defense action sequence, deploy the action sequence to the network environment through distributed execution nodes to obtain the preliminary deployment data, and use time synchronization technology to coordinate the execution of each node in the preliminary deployment data to obtain the synchronization timestamp;

[0112] Analyze the execution status of the nodes for the synchronization timestamp. Determine that if the time deviation exceeds the preset threshold, then adjust the execution rhythm to obtain the coordination result. Calculate the degree of attack mitigation through the coordination result, and use the support vector machine algorithm to determine the network status after mitigation to obtain the status indicators;

[0113] Obtain the status indicators and compare them with the first sequence data. Determine that if the indicators are abnormal, then update the defense action sequence to obtain the second sequence data, redeploy the second sequence data to the network environment, and use the data acquisition technology to extract the final status data to obtain the final status data;

[0114] Process the data through a graph neural network to generate an initial knowledge graph. Analyze the feature representations of each node in the knowledge graph through node embedding, and use edge relation reasoning technology to mine the evolution path to obtain the potential change trend of the attack pattern. Update the feature weight values of each node according to the change trend, and calculate the probability distribution through the updated feature weight values to obtain the real-time probability distribution data of the attack pattern.

[0115] Specifically, it can be described as follows. Obtain the defense action sequence, and use a policy network based on deep reinforcement learning to generate a sequence of actions including firewall rule updates, traffic redirection, honeypot deployment, etc. The number of actions is controlled within the range of 5 - 10. Deploy the action sequence to the network environment through distributed execution nodes. Each node uses Kubernetes container orchestration technology to manage the deployment task and generate preliminary deployment data including node ID, deployment time, and execution status. Use the PTP precise time protocol to synchronize the execution process of each node in the preliminary deployment data with a precision reaching the microsecond level, and generate a synchronized timestamp including the time deviation value.

[0116] Analyze the node execution status based on the synchronized timestamp. If it is detected that the time deviation of a certain node exceeds the 50ms threshold, use the NTP protocol to dynamically adjust the clock frequency of this node to obtain a coordination result including adjustment parameters. Calculate the attack mitigation degree through the coordination result, use the SVM algorithm to classify the network traffic characteristics, select the RBF kernel function, and the classification accuracy rate reaches more than 92%, and output the status indicators including packet loss rate, latency, and throughput.

[0117] Obtain the status indicators and compare them with the first sequence of data. If it is detected that the packet loss rate increases by more than 15% or the latency increases by more than 20ms, use the genetic algorithm to re-optimize the action sequence, and set the mutation probability to 0.1 to obtain the second sequence of data including new weight parameters.

[0118] Redeploy the second sequence of data to the network environment, use the NetFlow protocol to collect traffic data, set the sampling interval to 1 minute, and extract the final state data including 500 feature dimensions.

[0119] Obtain the final state data, use the GAT graph attention network to construct a knowledge graph, set the number of attention heads to 8, and the hidden layer dimension to 256 to generate an initial knowledge graph including node types and connection relationships.

[0120] Analyze the knowledge graph features through node embedding, use the Node2Vec algorithm to learn 128-dimensional vector representations, and combine with the TransE model to infer edge relations to mine the evolution trend of attack paths within 3 hops.

[0121] Update the feature weights according to the changing trend, calculate the probability distribution using the Softmax function, set the temperature coefficient to 0.5, and output real-time data containing 20 types of attack patterns and their occurrence probabilities.

[0122] Embodiment 2

[0123] As Figure 3 shown, this embodiment provides an artificial intelligence-based network security warning system for implementing an artificial intelligence-based network security warning method, including:

[0124] A traffic pattern analysis module that obtains network traffic data through quantum-enhanced deep packet detection technology, performs multi-dimensional analysis on the traffic and extracts features, dynamically adjusts the weights and parameters of feature extraction using deep reinforcement learning, and at the same time introduces time series analysis and spatial correlation mining to analyze the changing trend of traffic patterns in the time series and the spatial correlation patterns between different network nodes, obtains real-time traffic pattern description data with spatio-temporal correlation, and compares it with the original traffic features to judge the abnormal state of the traffic pattern, obtains the pattern analysis result, and provides basic data support for subsequent attack detection and warning;

[0125] A dynamic camouflage and traffic fusion module that generates a dynamic camouflage instruction sequence according to the real-time traffic pattern description, uses a generative adversarial network to adjust the parameters of the camouflage instructions to match the traffic features, obtains a set of camouflage instructions, then uses covert channel coding technology to embed the instruction sequence into normal communication messages, and integrates the encoded message data into the real-time traffic through a traffic injection tool to obtain the fused traffic data, and verifies according to the pattern difference between the fused data and the original traffic, and finally obtains traffic data that is highly fused with the original traffic and difficult to be detected by attackers, enhancing the security and concealment of network traffic;

[0126] An anomaly detection and attack recognition module that analyzes the traffic behavior of traffic data through an anomaly detection algorithm. When an abnormal pattern deviating from a preset value is detected, it triggers a complex attack recognition module to judge the potential attack type; calculates the deviation degree between the abnormal pattern and the preset threshold through a statistical method to determine the existence of a significant deviation, and then obtains potential attack features, analyzes the feature distribution using a classification algorithm to obtain a preliminary attack type judgment result, and combines historical traffic data for pattern comparison to determine the accuracy of the attack type, and finally generates a structured attack log to provide accurate attack information for subsequent attack pattern analysis and warning;

[0127] The attack mode prediction module, according to the potential attack types, combines the historical attack sample database and real-time traffic behavior characteristics, and uses the correlation analysis method based on graph neural network to construct a dynamic knowledge graph of attack modes. Through the node embedding and edge relationship reasoning of the graph neural network, it mines the internal correlations and evolution paths of attack modes, and uses the attention mechanism to dynamically adjust the feature weights, and updates the probability distribution of attack modes in real time, obtaining the dynamic prediction results of current attack modes, so as to predict possible attack behaviors and development trends in advance, providing forward-looking guidance for network security defense;

[0128] The camouflage strategy optimization module, according to the dynamic prediction results, adjusts the parameters for generating camouflage strategies, uses the reinforcement learning algorithm to optimize the strategy generation direction, generates a more adaptable set of camouflage strategies, and at the same time uses a lightweight encryption algorithm to compress the data volume of camouflage instructions, obtaining an instruction sequence for efficient transmission, ensuring that the camouflage strategy can be executed quickly and safely in a complex network environment, further enhancing the security and defense capabilities of the network.

[0129] The response and defense execution module, by analyzing the network status of the instruction sequence and obtaining monitoring data, determines whether the monitoring data exceeds the preset response value. When the monitoring data exceeds the preset response threshold, it activates the response mechanism, determines the defense action sequence, and then deploys the action sequence to the network environment through distributed execution nodes, and uses time synchronization technology to coordinate the execution of each node, obtaining the network status data after the attack is mitigated, so as to effectively defend against and mitigate network attacks, ensuring the normal operation and security and stability of the network.

[0130] The specific embodiments of the invention have been described in detail above, but they are only examples, and the invention is not limited to the specific embodiments described above. Those skilled in the art should understand that the above embodiments and the descriptions in the specification only illustrate the principles of the invention. Without departing from the spirit and scope of the invention, the invention will have various changes and improvements, and these changes and improvements all fall within the scope of the invention claimed. The scope of the invention claimed is defined by the appended claims and their equivalents.

Claims

1. A network security warning method based on artificial intelligence, characterized in that: It includes the following steps: Obtain traffic data through quantum-enhanced deep packet detection, extract features and dynamically adjust weights by combining deep reinforcement learning, introduce time series analysis and spatial correlation mining to obtain a real-time traffic pattern description with spatio-temporal correlation; Generate a dynamic camouflage instruction sequence according to the real-time traffic pattern description, use a generative adversarial network to adjust the parameters of the camouflage instructions to match the traffic characteristics, obtain a set of camouflage instructions, integrate the set of camouflage instructions into the network traffic data, and use steganographic channel coding technology to embed the instruction sequence into normal communication messages to obtain the fused traffic data; Analyze the traffic behavior of the traffic data through an anomaly detection algorithm. When an abnormal pattern deviating from a preset value is detected, trigger a complex attack recognition module to determine the potential attack type; According to the potential attack type, combine the historical attack sample database and the real-time traffic behavior characteristics, adopt an association analysis method based on a graph neural network to construct a dynamic knowledge graph of the attack pattern, and then through the node embedding and edge relationship reasoning of the graph neural network, mine the internal association and evolution path of the attack pattern, and use the attention mechanism to dynamically adjust the feature weights, and update the probability distribution of the attack pattern in real time to obtain the current dynamic prediction result of the attack pattern; According to the dynamic prediction result, adjust the parameters for generating the camouflage strategy, use a reinforcement learning algorithm to optimize the strategy generation direction, obtain a more adaptable set of camouflage strategies, optimize the instruction transmission process according to the set of camouflage strategies, and use a lightweight encryption algorithm to compress the data volume of the camouflage instructions to obtain an instruction sequence for efficient transmission; By analyzing the network state of the instruction sequence and obtaining monitoring data, judge whether the monitoring data exceeds a preset response value. When it exceeds, activate the response mechanism, determine the defense action sequence, and deploy the action sequence to the network environment through distributed execution nodes according to the defense action sequence, and use time synchronization technology to coordinate the execution of each node to obtain the network state data after the attack is mitigated.

2. The network security early warning method based on artificial intelligence according to claim 1, characterized in that: The obtaining of the real-time traffic pattern description with spatio-temporal correlation specifically includes: Obtain network traffic data, use quantum-enhanced deep packet detection technology to perform multi-dimensional analysis on the traffic, extract traffic features, and then use an adaptive feature extraction algorithm driven by deep reinforcement learning to process the extracted traffic features, and dynamically adjust the weights and parameters of feature extraction; Introduce time series analysis through the adjusted feature weights and parameters, analyze the change trend of the traffic pattern in the time series to obtain preliminary change trend data; Extract the association pattern between different network nodes from the network traffic through spatial correlation mining to obtain node pattern data. When the preliminary change trend data exceeds a preset threshold, combine the node pattern data to adjust the parameters of the time series analysis to obtain updated change trend data; Generate a real-time traffic pattern description data with spatio-temporal correlation according to the updated change trend data and node pattern data, compare the real-time traffic pattern description data with the original traffic features, judge the abnormal state of the traffic pattern, and obtain the pattern analysis result.

3. A network security early warning method based on artificial intelligence according to claim 1, characterized in that: The obtaining of the fused traffic data specifically includes: Generate an initial camouflage instruction according to the traffic characteristics, construct an instruction sequence through a dynamic generation method to obtain a preliminary instruction set, and use a generative adversarial network to adjust the parameters of the preliminary instruction set, obtain matching information from the traffic characteristics, and obtain an optimized camouflage instruction set; Analyze the communication message structure through steganography channel technology, determine the embedding point position, obtain available message carriers, and use coding technology to embed the optimized camouflage instruction set into the communication message. When the capacity of the embedding point is insufficient, adjust the coding density to obtain the coded message data; Integrate the coded message data into the real-time traffic through a traffic injection tool to obtain integrated data, and verify according to the pattern difference between the integrated data and the original traffic. When the difference exceeds the preset threshold, readjust the camouflage instruction parameters to obtain the final integrated traffic data.

4. A network security early warning method based on artificial intelligence according to claim 1, characterized in that: The judgment of potential attack types specifically includes: Through the integrated traffic data, run an anomaly detection algorithm to analyze the traffic behavior, obtain an abnormal pattern that deviates from the preset value, and according to the abnormal pattern, use a statistical method to calculate the deviation degree from the preset threshold to determine the existence of a significant deviation. When a significant deviation exists, trigger a complex attack recognition module through the deviation data to obtain potential attack characteristics; Through the potential attack characteristics, use a classification algorithm to analyze the feature distribution to obtain a preliminary attack type judgment result, and according to the preliminary judgment result, obtain historical traffic data for pattern comparison to determine the accuracy of the attack type; Through the accuracy data, use a rule matching method to process the attack characteristics, judge the final attack classification, and generate corresponding behavior analysis records according to the final attack classification to obtain a structured attack log.

5. A network security warning method based on artificial intelligence according to claim 1, characterized in that: The obtaining of the dynamic prediction result of the current attack mode specifically includes: Obtain a historical attack sample database and real-time traffic behavior feature data, and preliminarily process the data through a graph neural network to generate an attack mode knowledge graph; Analyze the feature representation of each node in the knowledge graph through node embedding technology to obtain the correlation analysis result between nodes, and use edge relationship reasoning technology to mine the evolution path of the correlation analysis result between nodes to obtain the potential change trend of the attack mode; Use the attention mechanism to dynamically adjust the feature weights, update the feature weight values of each node according to the change trend, calculate the probability distribution through the updated feature weight values to obtain the real-time probability distribution data of the attack mode; when the probability distribution data exceeds the preset threshold, combine the historical samples and real-time traffic characteristics to judge as a high-risk attack mode and generate the corresponding dynamic prediction result; Update the knowledge graph according to the dynamic prediction result, and perform iterative analysis on the new data through a graph neural network to obtain more accurate attack mode feature data.

6. The network security early warning method based on artificial intelligence according to claim 1, characterized in that: The obtaining of a more adaptable camouflage strategy set specifically includes: Input the real-time status information in the network environment as the initial state into the reinforcement learning model to construct the state space; and set a reward mechanism in the reinforcement learning algorithm. When the camouflage strategy successfully evades attacks and reduces the risk of the system being detected, a positive reward is given, otherwise a negative reward is given; continuously explore and try in the state space, and adjust the policy generation direction according to the reward feedback; in each iteration, use the policy gradient method to update the policy parameters to generate a more adaptable set of camouflage strategies.

7. A network security early warning method based on artificial intelligence according to claim 1, characterized in that: The method of using a lightweight encryption algorithm to compress the data volume of the camouflage instructions to obtain an instruction sequence for efficient transmission specifically includes: Adjust the policy set through a preset adaptive camouflage rule to generate an initial camouflage policy, extract instruction transmission features according to the initial camouflage policy, determine the transmission optimization direction, process the transmission optimization direction using a lightweight encryption algorithm to obtain an encrypted instruction set, perform a data compression operation on the encrypted instruction set to generate a compressed data packet. When the compressed data packet meets the preset threshold, it is sent through an efficient transmission channel to obtain a transmission sequence, and then obtain the feedback information of the transmission sequence, determine whether to adjust the camouflage policy and generate an updated sequence, and replace the original instruction sequence with the updated sequence to obtain the final efficient transmission result.

8. An artificial intelligence-based network security warning method according to claim 1, wherein: The determination of the defense action sequence specifically includes: Use a time series analysis method to analyze the network state of the instruction sequence, then obtain monitoring data, determine whether the monitoring data exceeds the preset response value, and then determine the degree of exceeding through a threshold judgment process. When it exceeds, activate the response mechanism using a preset rule to determine the defense action configuration, obtain the content of the action sequence according to the defense action configuration, use a scheduling algorithm to obtain the execution order, and then process the content of the action sequence through a transmission protocol to obtain the result of the implementation of the defense action.

9. The network security early warning method based on artificial intelligence according to claim 1, characterized in that: The method of obtaining the network state data after attack mitigation specifically includes: Obtain the defense action sequence, deploy the action sequence to the network environment through distributed execution nodes to obtain preliminary deployment data, and use time synchronization technology to coordinate the execution of each node in the preliminary deployment data to obtain a synchronous timestamp; Analyze the execution status of the nodes according to the synchronous timestamp, determine whether the time deviation exceeds the preset threshold, and if so, adjust the execution rhythm to obtain a coordinated result. Calculate the degree of attack mitigation based on the coordinated result, and use a support vector machine algorithm to determine the network state after mitigation to obtain state indicators; Obtain the state indicators and compare them with the first sequence of data. If the indicators are abnormal, update the defense action sequence to obtain the second sequence of data, redeploy the second sequence of data to the network environment, and use data acquisition technology to extract the final state data to obtain the final state data.

10. A network security early warning system based on artificial intelligence, which is used to implement a network security early warning method based on artificial intelligence as described in any one of claims 1-9, characterized in that: It includes: A traffic pattern analysis module that obtains network traffic data through quantum-enhanced deep packet detection technology, performs multi-dimensional analysis on the traffic and extracts features, dynamically adjusts the weights and parameters of feature extraction using deep reinforcement learning, and at the same time introduces time series analysis and spatial correlation mining to obtain real-time traffic pattern description data with spatio-temporal correlation; The dynamic camouflage and traffic fusion module generates a sequence of dynamic camouflage instructions according to the real-time traffic pattern description, uses a generative adversarial network to adjust the parameters of the camouflage instructions to match the traffic characteristics, obtains a set of camouflage instructions, and then embeds the instruction sequence into the normal communication message by using steganographic coding technology; The anomaly detection and attack recognition module analyzes the traffic behavior of traffic data through an anomaly detection algorithm. When an abnormal pattern deviating from the preset value is detected, it triggers the complex attack recognition module to determine the potential attack type; The attack pattern prediction module constructs a dynamic knowledge graph of attack patterns by using an association analysis method based on graph neural networks according to the potential attack type, combined with the historical attack sample database and real-time traffic behavior characteristics. Through the node embedding and edge relationship reasoning of the graph neural network, it mines the internal association and evolution path of the attack pattern, and uses the attention mechanism to dynamically adjust the feature weights, and updates the probability distribution of the attack pattern in real time to obtain the current dynamic prediction result of the attack pattern; The camouflage strategy optimization module adjusts the parameters of the camouflage strategy generation according to the dynamic prediction result, uses a reinforcement learning algorithm to optimize the strategy generation direction, generates a more adaptable set of camouflage strategies, and at the same time compresses the data volume of the camouflage instructions by using a lightweight encryption algorithm to obtain an instruction sequence for efficient transmission; The response and defense execution module analyzes the network state of the instruction sequence and obtains monitoring data, and judges whether the monitoring data exceeds the preset response value. When the monitoring data exceeds the preset response threshold, it activates the response mechanism, determines the defense action sequence, and then deploys the action sequence to the network environment through distributed execution nodes, and uses time synchronization technology to coordinate the execution of each node to obtain the network state data after the attack is mitigated.

Citation Information

Patent Citations

  • Encrypted malicious flow identification method and device based on spatial-temporal characteristics and attention mechanism

    CN116094792A

  • Network security detection method and system based on quantum computing

    CN118337431A

  • APT covert channel identification method and system based on multi-mode anomaly detection

    CN119066464A

  • Dynamic attack surface transformation active defense system for production system

    CN119728240A

  • Network security dynamic early warning method and system based on knowledge graph

    CN119788344A

Cited By

  • Intelligent potential safety hazard identification and early warning system based on Internet of Things

    CN120639469A

  • Network threat detection and blocking system based on multi-dimensional behavior analysis

    CN120639524A

  • Platform security information integration situation early warning method

    CN120675888A

  • Platform security information integration situational early warning method

    CN120675888B

  • Intrusion detection alarm noise reduction and priority dynamic sorting method

    CN120880869A