Complex network anomaly detection method and device driven by time-space factors and medium

By building a network security industry chain network, using time decay function and spatial neighborhood feature encoding to generate spatiotemporal factors, combined with time-sequence sliding windows and comparison learning, the problems of spatial and temporal feature fusion and dynamic behavior capture in the industrial chain network are solved, and abnormal detection with high accuracy and timeliness are achieved.

CN120342685AActive Publication Date: 2025-07-18TIANJIN UNIV

Patent Information

Application Number
CN202510479525.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-07-18
Estimated Expiration
2045-04-17

AI Technical Summary

Technical Problem

It is difficult for the existing technology to effectively integrate spatiotemporal characteristics, handle multimodal relationship heterogeneity and capture dynamic behavior patterns in the abnormal detection of industrial chain networks, resulting in insufficient timeliness of misjudgment and early warning.

Method used

Build a network security industry chain network, generate spatiotemporal factors through time decay function and spatial neighborhood feature encoding, calculate dynamic relationship weights, combine time-sequence sliding windows and comparison learning, calculate node-level feature deviations and structural evolution rates, and set dynamic scoring thresholds to identify abnormal behaviors.

Benefits of technology

Accurately detect abnormalities in the life cycle of enterprise relationships, quantify the contribution of abnormalities of different types of edges, and improve the accuracy and timeliness of abnormal detection in complex networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342685A_ABST
    Figure CN120342685A_ABST
Patent Text Reader

Abstract

The invention discloses a time-space factor driven complex network anomaly detection method and device and a medium, and relates to the technical field of complex network analysis and network security. The method comprises the following steps: constructing a network security industry chain network, coding time features and spatial neighborhood features based on a time decay function to obtain a time-space factor, calculating a dynamic relation weight according to the time-space factor, obtaining a feature vector of each node based on time sequence sliding window sampling and contrast window learning, and obtaining a feature vector of each node; determining the node-level characteristic deviation of each node based on the characteristic vector of each node, and calculating the score of each node based on the node-level characteristic deviation, the structure evolution rate and the cross-network alignment anomaly of each node; and based on a dynamically set score threshold, if the score of the node exceeds the set score threshold, determining that the node has an abnormal behavior. According to the invention, the accuracy of complex network anomaly detection can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of complex network analysis and network security, and more specifically, to a method, device, and medium for detecting complex network anomalies driven by spatio-temporal factors. Background Art

[0002] With the rapid development of the digital economy, the complexity and dynamics of industrial chain networks have increased exponentially. Traditional graph-structure-based anomaly detection techniques have significant technical bottlenecks when dealing with modern industrial chain networks: First, in terms of spatio-temporal feature modeling, existing methods are mostly based on static topological structure analysis and fail to effectively integrate the time evolution law and spatial distribution characteristics of industrial chain networks, resulting in a risk of misjudgment when identifying spatio-temporal coupling anomalies such as cross-regional industrial transfer and sudden supply chain breaks; Second, in the dimension of network relationship processing, current network alignment techniques mostly adopt a homogeneous edge weight processing mechanism and are difficult to accurately represent the heterogeneous characteristics of multi-modal relationships such as competition, cooperation, and supply between enterprises, resulting in semantic distortion during cross-industrial chain knowledge migration; Third, at the level of dynamic behavior capture, mainstream static network analysis methods can only capture the instantaneous state of enterprise nodes and lack the ability to continuously track the dynamic evolution of node behavior patterns (such as the reconstruction of cooperation relationships caused by strategic transformation and demand changes caused by market fluctuations), resulting in insufficient timeliness of early warning of potential risks. The above technical defects seriously restrict the intelligent upgrade of the industrial chain risk prevention and control system. Summary of the Invention

[0003] To solve the above technical problems, the present invention provides a method, device, and medium for detecting complex network anomalies driven by spatio-temporal factors, which improve the accuracy of complex network anomaly detection by considering the spatio-temporal evolution characteristics of industrial chain networks, dealing with the heterogeneity of multi-dimensional relationships (competition / cooperation / supply), and capturing the dynamic behavior patterns of enterprise nodes.

[0004] In a first aspect, the present invention provides a method for detecting complex network anomalies driven by spatio-temporal factors, the method comprising:

[0005] Constructing a network security industrial chain network; wherein, the network security industrial chain network is represented as G=(V, E T , A S ), where V is a set of nodes, including multiple nodes, each node respectively representing an entity in the industrial chain, and E T is a set of temporal edges for describing the dynamic interaction relationships between nodes, and E T ={E supply , E compete , E coop}×T, and E supply , E compete , E cooprespectively represent the supply relationship, competition relationship and collaboration relationship, T represents the set of timestamps, A S is the spatio-temporal attribute matrix, A S =(X t , S k ), X t ∈R n×d , representing the time feature, n and d represent dimensions, R represents the real number space, S k =A k ·X, representing the k-order spatial neighborhood feature, A represents the adjacency matrix, k represents the order, X represents the node feature, A k represents performing k times of graph convolution operations. The time feature is used to record the dynamic behavior metrics of each node, the spatial neighborhood feature is used to capture the topological associations of the industrial chain network, and the weights of the supply relationship, competition relationship and collaboration relationship are determined by the adjacency matrix;

[0006] Encode the time feature and the spatial neighborhood feature based on the time decay function to obtain the spatio-temporal factor, and calculate the dynamic relationship weight according to the spatio-temporal factor. The dynamic relationship weight is used to quantify the abnormal contribution degree of different types of temporal edges;

[0007] Based on the time-series sliding window sampling, extract the network state containing τ time steps from the network security industrial chain network;

[0008] Based on the network state containing τ time steps, extract the feature vectors of the same nodes in different time windows as positive samples, and the feature vectors of different nodes in the same time window as negative samples. The feature vectors are the dynamic relationship weights. Based on the contrast loss function, perform contrast learning on the positive samples and negative samples to obtain the characteristic vectors of each node;

[0009] Determine the node-level feature deviation of each node based on the characteristic vectors of each node, and calculate the score of each node based on the node-level feature deviation, structural evolution rate and cross-network alignment anomaly degree of each node;

[0010] Based on the dynamically set score threshold, if the score of a node exceeds the set score threshold, it is determined that the node has abnormal behavior.

[0011] Further, encode the time feature and the spatial neighborhood feature based on the time decay function through the following formula to obtain the spatio-temporal factor:

[0012] Z = σ([X t ||S k ·W z +b z )

[0013] In the formula, Z represents the spatio-temporal factor, || represents feature concatenation, Wz represents the weight matrix, b z represents the bias term, and σ represents the time decay function.

[0014] Furthermore, the time decay function is expressed as:

[0015] σ(t) = e -λΔt

[0016] where e represents the natural constant, Δt represents the time interval, and λ represents the decay coefficient.

[0017] Furthermore, according to the spatio-temporal factor, the dynamic relationship weight is calculated through the following formula:

[0018] α ij = softmax(LeakyReLu(a T [Z i ||Z j ))

[0019] where α ij represents the dynamic relationship weight between the i-th node and the j-th node, softmax represents the normalization operation, LeakyReLu represents the activation function, Z i and Z j represent the spatio-temporal factors of the i-th node and the j-th node respectively, and || represents feature concatenation.

[0020] Furthermore, based on the time-series sliding window sampling, the network state containing τ time steps extracted from the network security industrial chain network is represented as W t = [G t-τ , G t-τ+1 , …, G t , where G t-τ , G t-τ+1 and G t represent the network states at time steps t - τ, -τ + 1, and t respectively.

[0021] Furthermore, the contrastive loss function is expressed as:

[0022]

[0023] where L c represents the contrastive loss, e represents the natural constant, represents the negative sample, represents the positive sample, sim represents the similarity, τ is the sliding window length, m is the serial number of the negative sample, M is the number of negative samples, and c i is the feature vector of the i-th node.

[0024] Further, based on the node-level feature deviation, structure evolution rate, and cross-network alignment anomaly degree of each node, calculate the score of each node through the following formula:

[0025] Score(v i )=α·||c i -μ W ||+β·ΔD(v i )+γ·Φ(v i )

[0026] In the formula, Score(v i ) represents the score of node v i . α, β, and γ respectively represent the weights of node-level feature deviation, structure evolution rate, and cross-network alignment anomaly degree. ||c i -μ W || represents the node-level feature deviation, μ W represents the sliding window feature mean, ΔD(v i ) represents the temporal change rate of node degree centrality, and Φ(v i ) represents the cross-network alignment anomaly degree.

[0027] Further, set the scoring threshold dynamically according to the average score and standard deviation of the nodes.

[0028] In the second aspect, the present invention provides a spatio-temporal factor-driven complex network anomaly detection device, and the device includes:

[0029] A network construction module, configured to construct a network security industrial chain network; wherein, the network security industrial chain network is represented as G=(V, E T , A S ), where V is a set of nodes, including multiple nodes, and each node represents an entity in the industrial chain. E T is a set of temporal edges, used to describe the dynamic interaction relationship between nodes. E T ={E supply , E compete , E coop}×T, and E supply , E compete , E coop respectively represent supply relationship, competition relationship, and cooperation relationship, and T represents a set of timestamps. A S is a spatio-temporal attribute matrix, A S =(X t , S k ), X t ∈R n×d , represents time feature, n and d represent dimensions, R represents the real number space, and S k =A k·X represents the k - order spatial neighborhood feature, A represents the adjacency matrix, k represents the order, X represents the node feature, A k represents performing k - times graph convolution operations. The time feature is used to record the dynamic behavior metrics of each node, and the spatial neighborhood feature is used to capture the topological associations of the industrial chain network. The weights of the supply relationship, competition relationship, and collaboration relationship are determined by the adjacency matrix;

[0030] The dynamic relationship weight calculation module is configured to encode the time feature and the spatial neighborhood feature based on a time decay function to obtain a spatio - temporal factor, and calculate the dynamic relationship weight according to the spatio - temporal factor. The dynamic relationship weight is used to quantify the abnormal contribution degree of different types of temporal edges;

[0031] The time - series sampling module is configured to extract a network state containing τ time steps from the network security industrial chain network based on time - series sliding window sampling;

[0032] The contrast learning module is configured to, based on the network state containing τ time steps, extract the feature vectors of the same node in different time windows as positive samples, and the feature vectors of different nodes in the same time window as negative samples. The feature vectors are the dynamic relationship weights, and perform contrast learning on the positive samples and negative samples based on a contrast loss function to obtain the characteristic vectors of each node;

[0033] The score calculation module is configured to determine the node - level feature deviation of each node based on the characteristic vectors of each node, and calculate the score of each node based on the node - level feature deviation, structural evolution rate, and cross - network alignment anomaly degree of each node;

[0034] The anomaly recognition module is configured to, based on a dynamically set score threshold, if the score of a node exceeds the set score threshold, determine that the node has abnormal behavior.

[0035] In a third aspect, the present invention provides a readable storage medium storing one or more programs, and the one or more programs can be executed by one or more processors to implement the method as described above.

[0036] The present invention has at least the following beneficial effects:

[0037] 1) In terms of modeling, through the timestamp mechanism of the temporal edge set, the life cycle of enterprise relationships can be accurately characterized, and abnormal behaviors such as a certain enterprise suddenly terminating a long-term supply contract (a sharp drop in edge weight) and turning to a competitor for procurement (creating a new competitive edge) can be detected. The spatio-temporal attribute matrix combines the individual business indicators of enterprises (time dimension) with the topological influence of the industrial chain (space dimension). When there is an abnormal increase in the number of patents at a certain node, the model can simultaneously evaluate whether it triggers a technological synergy effect among upstream and downstream enterprises (positive spatial propagation) or a surge in malicious lawsuits from competitors (negative spatial propagation).

[0038] 2) The temporal decay factor λ and the spatial propagation order k are introduced to calculate the spatio-temporal factor, and the dynamic relationship weight is calculated based on the spatio-temporal factor. The abnormal contribution degrees of different types of edges (supply / competition / collaboration) are quantified through the dynamic relationship weight.

[0039] 3) The triple criteria of node-level feature deviation, structure evolution rate, and cross-network alignment anomaly degree are integrated to calculate the score, and the accuracy of complex network anomaly detection is improved by setting a dynamic scoring threshold. Brief Description of the Drawings

[0040] Figure 1 The flowchart of a spatio-temporal factor-driven complex network anomaly detection method according to an embodiment of the present invention is shown.

[0041] Figure 2 The structural diagram of the network security industrial chain network according to an embodiment of the present invention is shown;

[0042] Figure 3 The abnormal determination flowchart according to an embodiment of the present invention is shown;

[0043] Figure 4 The structural diagram of a spatio-temporal factor-driven complex network anomaly detection device according to an embodiment of the present invention is shown. Detailed Embodiments

[0044] To enable those skilled in the art to better understand the technical solutions of the present invention, the present invention will be described in detail below in conjunction with the drawings and specific embodiments. The embodiments of the present invention will be further described in detail below in conjunction with the drawings and specific examples, but shall not be construed as a limitation to the present invention. For the various steps described herein, if there is no necessity for a sequential relationship between them, the order in which they are described as examples herein shall not be regarded as a limitation, and those skilled in the art should know that they can be adjusted in order as long as the logic between them is not destroyed and the entire process cannot be realized.

[0045] Figure 1The flowchart of a complex network anomaly detection method driven by spatio-temporal factors according to an embodiment of the present invention is shown. An embodiment of the present invention provides a complex network anomaly detection method driven by spatio-temporal factors, as Figure 1 shown, the method includes the following steps S10 - S70.

[0046] S10: Construct a network security industrial chain network.

[0047] In this embodiment, the network security industrial chain network is represented as G=(V, E T , A S ), where V is the node set, including multiple nodes, and each node represents an entity in the industrial chain. E T is the temporal edge set, used to describe the dynamic interaction relationship between nodes. E T ={E supply , E compete , E coop}×T, E supply , E compete , E coop respectively represent the supply relationship, competition relationship, and cooperation relationship, T represents the timestamp set, and A S is the spatio-temporal attribute matrix, A S =(X t , S k ), X t ∈R n×d , represents the time feature, n and d represent dimensions, R represents the real number space, and S k =A k ·X, represents the k-order spatial neighborhood feature, A represents the adjacency matrix, k represents the order, X represents the node feature, and A k represents performing k times of graph convolution operations. The time feature is used to record the dynamic behavior indicators of each node, and the spatial neighborhood feature is used to capture the topological correlation of the industrial chain network. The weights of the supply relationship, competition relationship, and cooperation relationship are determined by the adjacency matrix.

[0048] The node set represents entities such as enterprises and institutions in the industrial chain, which can be represented as V=(v1...v i ...v g ), v i represents any node in the node set, i = 1, 2...g, v g represents the last node, representing that the node set V contains g nodes, and each node v iCorresponds to an independent market entity. For example, nodes can be enterprises or institutions included in the network security industry chain network. Each node also has node attributes, which include static characteristics (such as enterprise scale, business field) and dynamic characteristics (such as quarterly business data). For example, the 500 member enterprises in a certain network security industry alliance form a node set, and each node records basic information such as the registered capital of the enterprise and the classification of the main business.

[0049] The temporal edge set is used to describe the dynamic interaction relationships between nodes and includes three types of core relationship edges:

[0050] Supply relationship E supply : Represents the product / service supply chain between enterprises, such as the procurement of firewall devices and the outsourcing of security services. Each edge is attached with a timestamp t, which is recorded in the timestamp set T and is used to mark the effective period of the business relationship. For example, the edge formed when enterprise A purchases an intrusion detection system from enterprise B in the first quarter of 2023 is denoted as E 2023Q1 supply (A, B).

[0051] Competition relationship E compete : Reflects adversarial interactions such as market share competition and patent litigation. The edge weight is quantified by the number of intellectual property dispute cases in the judicial database, and the timestamp records the quarter when the litigation occurs.

[0052] Cooperation relationship E coop : Includes cooperation behaviors such as joint research and development and technical standard formulation, and dynamic weights are assigned according to the amount of the cooperation agreement and the execution period.

[0053] Spatio-temporal attribute matrix A S , A feature expression system that integrates the time and space dimensions, consists of two parts:

[0054] Time feature X t ∈R n×d , Records the dynamic behavior indicators of each node. For example, dimension n represents the specific time, and dimension d includes the quarterly revenue growth rate (calculation method: (current value - previous value) / previous value), the number of patent authorizations (cumulative count in the time window), the proportion of supply chain order amount, etc.

[0055] k-order spatial neighborhood feature S k =A k ·X, Achieves feature propagation through the k-th power operation of the adjacency matrix A to capture the topological associations of the industrial chain network. For example, S3 = A 3 ·X represents aggregating the technical indicators of the third-order neighborhood (i.e., the upstream and downstream of the upstream and downstream of the supply chain) to evaluate the risk conduction effect. The upstream and downstream of the upstream and downstream of the supply chain refer to the upstream and downstream of the upstream of the supply chain and the upstream and downstream of the downstream of the supply chain.

[0056] Adjacency matrix A: Initially defined as a binary matrix A ∈ {0, 1} n×n , if node v i and v j have any type of relational edge, then A ij = 1. In practical applications, it can be extended to a weighted matrix, and the weight values are set differently according to the relationship type:

[0057] Supply relationship weight w supply : Calculated by normalizing according to the order amount;

[0058] Competition relationship weight w compete : The amount and frequency involved in related litigation cases;

[0059] Cooperation relationship weight w coop : Assigned values by grading according to the technical content of the cooperation agreement.

[0060] k - order spatial propagation: Achieve multi - hop neighborhood feature aggregation through matrix power operation A k . Technically, A k ·X is equivalent to performing k graph convolution operations, propagating node features layer by layer. For example: when k = 1, capture the features of direct suppliers / customers; when k = 2, extend to secondary suppliers or partners of competitors; when k > 3, identify systemic risks in the industrial chain.

[0061] Exemplarily, Figure 2 shows the structural diagram of the network security industrial chain network according to an embodiment of the present invention. As Figure 2 shown, nine nodes are exemplified in this network security industrial chain network, namely v1, v2, v3, v4, v5, v6, v7, v8, v9; among them, the connected nodes indicate that the two nodes have a connection relationship, and the connection relationship is at least one of supply relationship, competition relationship, and cooperation relationship. The unconnected nodes indicate that these two nodes have not yet generated at least one of supply relationship, competition relationship, and cooperation relationship in this network security industrial chain network. In this embodiment, E Tij is used to represent the temporal edge between node v i and node v j . For example, the temporal edge between node v1 and v2 is represented by E T12 , and the temporal edge between node v2 and v3 is represented by E T13 , and so on. The spatio - temporal attribute matrix A S is a feature expression system, so it is not shown in the figure. Figure 2The relationships between various nodes can be at least one of a supply relationship, a competition relationship, and a collaboration relationship. For example, the relationships between node v1 and v2 and between node v1 and v8 are both supply relationships. In the supply relationship between node v1 and v2, node v1 is the supplier, and in the supply relationship between node v1 and v8, node v8 is the supplier. Node v1 has selected two suppliers, namely node v2 and v3, for the same product. At this time, the relationship between node v2 and v3 is a competition relationship. Nodes v2, v4, and v5 have reached a tripartite cooperation agreement with each other. In this relationship, a collaboration relationship is formed between any two of nodes v2, v4, and v5. For example, three enterprises or institutions jointly develop a certain type of product and reach a cooperation development agreement. There may also be multiple relationships between two nodes. For example, there are both a supply relationship and a collaboration relationship between node v3 and v6. Node v6 provides products for node v3, but node v3 and v6 also cooperate to develop a certain technology at the same time. For some large comprehensive enterprises, there may be three relationships between two enterprises at the same time. For example, there are supply, competition, and collaboration relationships between node v3 and v7 at the same time. At least one business of node v3 is provided by node v7, but there is at least one business of node v3 that conflicts with the business of node v7, thus forming a competition relationship. Moreover, in some cross-businesses or the same business, node v3 and v7 have reached a cooperation development agreement, thus forming E T37 Simultaneously including E supply ,E compete ,E coop cases.

[0062] In some embodiments, based on the constructed network security industry chain network, network anomaly detection can also be initially realized. Its implementation principle is achieved through dynamic relationship perception, spatio-temporal coupling analysis, and multi-relationship heterogeneity processing. Among them, spatio-temporal coupling analysis is achieved based on the characteristics of the spatio-temporal attribute matrix, and dynamic relationship perception and multi-relationship heterogeneity processing are achieved based on the temporal edge set.

[0063] Specifically:

[0064] Dynamic relationship perception: Through the timestamp mechanism of the temporal edge set E T , accurately characterize the life cycle of enterprise relationships. For example, it can detect abnormal behaviors such as an enterprise suddenly terminating a long-term supply contract (the edge weight drops sharply) and turning to a competitor for procurement (creating a new competition edge).

[0065] Spatio-temporal coupling analysis: The spatio-temporal attribute matrix A S combines the individual business indicators of enterprises (time dimension) with the topological impact of the industry chain (space dimension). When there is an abnormal increase in the number of patents of a certain node, the model can simultaneously evaluate whether it triggers the technological synergy effect of upstream and downstream enterprises (positive spatial propagation) or a sharp increase in malicious lawsuits from competitors (negative spatial propagation).

[0066] Handling multi-relationship heterogeneity: Designing differentiated detection strategies for different abnormal patterns of three types of relationships, namely supply, competition, and collaboration:

[0067] Abnormality in supply relationship: The quarterly-on-quarter decline in order volume exceeds 30% and the order volume of competitors surges by 50%;

[0068] Abnormality in competition relationship: The frequency of patent litigation exceeds 3 standard deviations of the historical mean;

[0069] Abnormality in collaboration relationship: The ratio of joint R & D investment to patent output deviates from the industry benchmark value by 40%.

[0070] Exemplarily, taking the data of a certain network security industry alliance (including 427 enterprises) as an example, quarterly data for the past 3 years are extracted, including 12-dimensional features such as the enterprise revenue growth rate (dimension 1), the number of vulnerability disclosures (dimension 2), and the proportion of R & D investment (dimension 3) (d = 12). Set k = 3-order neighborhood propagation and calculate the third-order supply chain technical indicators for each enterprise. For example, the third-order features of a certain firewall manufacturer include the network security level protection certification status of its customers (first order), the system integrators of its customers (second order), and the government agencies served by the integrators (third order). 4 abnormal enterprises are identified through the network security industry chain network. Among them, the abnormal performance of the collaboration relationship of a cloud service provider is that although the quarterly R & D investment has increased by 120%, the patent output of the joint laboratory it participates in is 0, and the R & D efficiency of partners within the third-order neighborhood has decreased by 35% synchronously, triggering the abnormal scoring threshold.

[0071] S20: Encoding the time feature and the spatial neighborhood feature based on a time decay function to obtain a spatio-temporal factor, and calculating a dynamic relationship weight according to the spatio-temporal factor, where the dynamic relationship weight is used to quantify the abnormal contribution degree of different types of temporal edges.

[0072] In some embodiments, the time feature and the spatial neighborhood feature are encoded based on a time decay function through the following formula to obtain a spatio-temporal factor:

[0073] Z = σ([X t ||S k ·W z +b z )

[0074] In the formula, Z represents the spatio-temporal factor, || represents feature concatenation, W z represents the weight matrix, b z represents the bias term, and σ represents the time decay function.

[0075] Among them, the time decay function is expressed as:

[0076] σ(t) = e -λΔt

[0077] In the formula, e represents the natural constant, Δt represents the time interval, and λ represents the decay coefficient.

[0078] In this embodiment, during the calculation of the spatio-temporal factor, the time feature matrix X t (such as historical time series data) and the spatial neighborhood feature S k are tensor concatenated [X t ||S k to fuse spatio-temporal information. Then, based on the concatenated feature that fuses spatio-temporal information, linear transformation and time decay are performed: a linear mapping of the concatenated feature is generated through the learnable parameter matrix W z and the bias term b z . Subsequently, a time decay function is applied to dynamically weight the feature according to the time interval Δt. This time decay function is used to control the decay rate of the contribution of historical data, and the decay coefficient λ is recommended to take values in the range of 0.05 - 0.2. For example, when λ = 0.1, the influence weight of the supply chain contract in 2020 decays to 30% of the initial value in 2023 (calculation: e -0.1×3 ≈0.74 decays annually).

[0079] In some embodiments, according to the spatio-temporal factor, the dynamic relationship weight is calculated through the following formula:

[0080] α ij = softmax(LeakyReLu(a T [Z i ||Z j ))

[0081] In the formula, α ij represents the dynamic relationship weight between the i-th node and the j-th node, softmax represents the normalization operation, LeakyReLu represents the activation function, Z i and Z j respectively represent the spatio-temporal factors of the i-th node and the j-th node, and || represents feature concatenation.

[0082] The α ij calculated through the attention mechanism can quantify the abnormal contribution degrees of different types of edges (supply / competition / collaboration).

[0083] Therefore, in step S20, through the time decay function, the model can balance the contributions of historical and recent data, avoid long-term noise interference, and retain key long-term patterns (such as seasonal trends). The attention mechanism dynamically adjusts the connection weights between nodes, replacing the fixed adjacency matrix of traditional graph networks, and is more suitable for non-uniform and time-varying spatio-temporal relationships (such as sudden collaborations in the supply chain). The concatenation operation and the non-linear transformation (LeakyReLU) enhance the interaction of spatio-temporal features, enabling the resulting feature vectors to capture complex spatio-temporal coupling phenomena.

[0084] S30: Based on time-series sliding window sampling, extract the network state containing τ time steps from the network security industrial chain network.

[0085] In some embodiments, the network state containing τ time steps extracted from the network security industrial chain network based on time-series sliding window sampling is denoted as W t =[G t-τ , G t-τ+1 , …, G t , where G t-τ , G t-τ+1 and G t represent the network states at time steps t - τ, -τ + 1, and t respectively. Through the above sliding window sampling method, the continuous network state is discretized into local time-series segments, balancing timeliness and context information.

[0086] S40: Based on the network state containing τ time steps, extract the feature vectors of the same node in different time windows as positive samples, and the feature vectors of different nodes in the same time window as negative samples. The feature vectors are dynamic relationship weights, and contrastive learning is performed on the positive and negative samples based on the contrastive loss function to obtain the characteristic vectors of each node.

[0087] In this embodiment, based on the network state containing τ time steps, the method for extracting the feature vectors of the same node in different time windows and the feature vectors of different nodes in the same time window is the same, and it can be calculated in the manner described in step 30, which will not be repeated here. Based on the constructed positive and negative samples, cross-window contrastive learning is used to perform contrastive learning on the positive and negative samples, aiming to learn the discriminability of node representations, so that normal nodes remain consistent in time, and abnormal nodes deviate from the normal state, thereby obtaining the characteristic vectors of each node.

[0088] In some embodiments, the contrastive loss function is expressed as:

[0089]

[0090] In the formula, L c represents the contrastive loss, e represents the natural constant, Indicates a negative sample, Indicates a positive sample, sim represents similarity, τ is the sliding window length, m is the serial number of the negative sample, M is the number of negative samples, c i Is the feature vector of the i-th node.

[0091] S50: Determine the node-level feature deviation of each node based on the feature vectors of each node, and calculate the score of each node based on the node-level feature deviation, structure evolution rate, and cross-network alignment anomaly degree of each node.

[0092] In some embodiments, based on the node-level feature deviation, structure evolution rate, and cross-network alignment anomaly degree of each node, calculate the score of each node through the following formula:

[0093] Score(v i ) = α·||c i - μ W || + β·ΔD(v i ) + γ·Φ(v i )

[0094] In the formula, Score(v i ) represents the score of node v i , α, β, and γ respectively represent the weights of the node-level feature deviation, structure evolution rate, and cross-network alignment anomaly degree, ||c i - μ W || represents the node-level feature deviation, μ W represents the sliding window feature mean, ΔD(v i ) represents the temporal change rate of node degree centrality, Φ(v i ) represents the cross-network alignment anomaly degree.

[0095] S60: Based on a dynamically set score threshold, if the score of a node exceeds the set score threshold, determine that the node has abnormal behavior.

[0096] In some embodiments, the score threshold is dynamically set according to the average score and standard deviation of the nodes.

[0097] Exemplarily, Figure 3 Shows the abnormal determination flowchart according to an embodiment of the present invention. When performing abnormal determination, the following steps are included:

[0098] S61: Calculate the score Score(v i ) of node v i .

[0099] S62: Dynamically set the score threshold: S L = μ + 3σ i (μ is the average score, σi (where the standard deviation is).

[0100] S63: Determine if Score(v i ) > S L . If so, execute S64; if not, execute S66.

[0101] S64: Conduct a traceability analysis on the nodes exceeding the threshold.

[0102] This step is used to examine the historical behaviors, associated nodes, and feature contribution degrees of the nodes exceeding the threshold.

[0103] S65: Examine the spatio-temporal feature contribution degree max(α,β,γ).

[0104] This step is used to determine the dominant factors (i.e., node-level feature deviation, structure evolution rate, and cross-network alignment anomaly degree) leading to the anomalies of the nodes exceeding the threshold, and to judge which one of the node-level feature deviation, structure evolution rate, and cross-network alignment anomaly degree causes the anomalies.

[0105] S66: End.

[0106] An embodiment of the present invention also provides a spatio-temporal factor-driven complex network anomaly detection device, as Figure 4 shown. This device includes:

[0107] A network construction module 401, configured to construct a network security industrial chain network; wherein, the network security industrial chain network is represented as G=(V,E T ,A S ), where V is a set of nodes, including multiple nodes, each node respectively represents an entity in the industrial chain, and E T is a set of temporal edges, used to describe the dynamic interaction relationships between nodes, and E T ={E supply ,E compete ,E coop}×T, E supply ,E compete ,E coop respectively represent supply relationships, competition relationships, and collaboration relationships, T represents a set of timestamps, and A S is a spatio-temporal attribute matrix, and A S =(X t ,S k ), X t ∈R n×d , represents time features, n and d represent dimensions, R represents the real number space, and S k =A k ·X, represents the k-order spatial neighborhood features, A represents the adjacency matrix, k represents the order, and X represents the node features, A kIt represents performing k graph convolution operations. The temporal features are used to record the dynamic behavior metrics of each node, and the spatial neighborhood features are used to capture the topological associations of the industrial chain network. The weights of the supply relationship, competition relationship, and collaboration relationship are determined by the adjacency matrix;

[0108] The dynamic relationship weight calculation module 402 is configured to encode the temporal features and spatial neighborhood features based on a time decay function to obtain a spatio-temporal factor, and calculate the dynamic relationship weight according to the spatio-temporal factor. The dynamic relationship weight is used to quantify the abnormal contribution degree of different types of temporal edges;

[0109] The time series sampling module 403 is configured to extract the network state containing τ time steps from the network security industrial chain network based on time series sliding window sampling;

[0110] The contrastive learning module 404 is configured to, based on the network state containing τ time steps, extract the feature vectors of the same node in different time windows as positive samples, and the feature vectors of different nodes in the same time window as negative samples. The feature vectors are dynamic relationship weights, and perform contrastive learning on the positive samples and negative samples based on a contrastive loss function to obtain the characteristic vectors of each node;

[0111] The score calculation module 405 is configured to determine the node-level feature deviation of each node based on the characteristic vectors of each node, and calculate the score of each node based on the node-level feature deviation, structure evolution rate, and cross-network alignment anomaly degree of each node;

[0112] The anomaly recognition module 406 is configured to, based on a dynamically set score threshold, if the score of a node exceeds the set score threshold, determine that the node has abnormal behavior.

[0113] In some embodiments, the dynamic relationship weight calculation module is further configured to encode the temporal features and spatial neighborhood features based on a time decay function through the following formula to obtain a spatio-temporal factor:

[0114] Z = σ([X t || S k · W z + b z )

[0115] In the formula, Z represents the spatio-temporal factor, || represents feature concatenation, W z represents the weight matrix, b z represents the bias term, and σ represents the time decay function.

[0116] In some embodiments, the time decay function is expressed as:

[0117] σ(t) = e-λΔt

[0118] In the formula, e represents the natural constant, Δt represents the time interval, and λ represents the attenuation coefficient.

[0119] In some embodiments, the dynamic relationship weight calculation module is further configured to calculate the dynamic relationship weight according to the spatio-temporal factor through the following formula:

[0120] α ij = softmax(LeakyReLu(a T [Z i ||Z j ))

[0121] In the formula, α ij represents the dynamic relationship weight between the i-th node and the j-th node, softmax represents the normalization operation, LeakyRelu represents the activation function, Z i and Z j respectively represent the spatio-temporal factors of the i-th node and the j-th node, and || represents feature concatenation.

[0122] In some embodiments, based on the time-series sliding window sampling, the network state containing τ time steps extracted from the network security industrial chain network is represented as W t = [G t-τ , G t-τ+1 , …, G t , where G t-τ , G t-τ+1 and G t respectively represent the network states at time steps t - τ, -τ + 1, and t.

[0123] In some embodiments, the contrast loss function is expressed as:

[0124]

[0125] In the formula, L c represents the contrast loss, e represents the natural constant, represents the negative sample, represents the positive sample, sim represents the similarity, τ is the sliding window length, m is the serial number of the negative sample, M is the number of negative samples, and c i is the feature vector of the i-th node.

[0126] In some embodiments, the scoring calculation module is further configured to calculate the score of each node based on the node-level feature deviation, structure evolution rate, and cross-network alignment anomaly degree of each node through the following formula:

[0127] Score(v i) = α·||c i - μ W || + β·ΔD(v i ) + γ·Φ(v i )

[0128] where Score(v i ) represents the score of node v i , α, β, and γ respectively represent the weights of node - level feature deviation, structure evolution rate, and cross - network alignment anomaly degree, ||c i - μ W || represents the node - level feature deviation, μ W represents the sliding - window feature mean, ΔD(v i ) represents the temporal change rate of node degree centrality, Φ(v i ) represents the cross - network alignment anomaly degree.

[0129] In some embodiments, the anomaly recognition module is further configured to dynamically set a scoring threshold according to the average score and standard deviation of nodes.

[0130] It should be noted that the structure of the complex network anomaly detection device driven by various spatio - temporal factors described in this embodiment belongs to the same technical concept as the spatio - temporal factor - driven complex network anomaly detection method described above, and achieves the same beneficial effects through the same principle, which will not be elaborated here.

[0131] The embodiment of the present invention also provides a readable storage medium, where the readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the method described in any of the above embodiments.

[0132] The above - mentioned embodiments are only used to illustrate the present invention, rather than to limit the present invention. Those of ordinary skill in the relevant technical fields can also make various changes and modifications without departing from the spirit and scope of the present invention. Therefore, all equivalent technical solutions also belong to the scope of the present invention, and the patent protection scope of the present invention should be defined by the claims.

Claims

1. A complex network anomaly detection method driven by spatio-temporal factors, characterized in that, The method includes: Construct a network security industry chain network; among them, the network security industry chain network is represented as G=(V,E T ,A S ), where V is a set of nodes, including multiple nodes, and each node represents an entity in the industry chain. E T is a set of temporal edges, used to describe the dynamic interaction relationships between nodes. E T ={E supply ,E compete ,E coop}×T, E supply ,E compete ,E coop represent supply relationship, competition relationship and collaboration relationship respectively. T represents a set of timestamps. A S is a spatio-temporal attribute matrix. A S =(X t ,S k ), X t ∈R n ×d , represents time characteristics, n and d represent dimensions, R represents the real number space. S k =A k ·X, represents the k-order spatial neighborhood characteristics. A represents the adjacency matrix, k represents the order, X represents the node characteristics. A k represents performing k times of graph convolution operations. The time characteristics are used to record the dynamic behavior indicators of each node. The spatial neighborhood characteristics are used to capture the topological associations of the industry chain network. The weights of the supply relationship, competition relationship and collaboration relationship are determined by the adjacency matrix; Encoding the time feature and the spatial neighborhood feature based on a time decay function to obtain a spatio-temporal factor, and calculating a dynamic relationship weight according to the spatio-temporal factor, where the dynamic relationship weight is used to quantify the abnormal contribution degree of different types of temporal edges; Sampling based on a time-series sliding window, and extracting a network state including τ time steps from the network security industrial chain network; Based on the network state including τ time steps, extracting the feature vectors of the same node in different time windows as positive samples, and the feature vectors of different nodes in the same time window as negative samples. The feature vectors are dynamic relationship weights, and performing contrast learning on the positive samples and the negative samples based on a contrast loss function to obtain the characteristic vectors of each node; Determining the node-level feature deviation of each node based on the characteristic vectors of each node, and calculating the score of each node based on the node-level feature deviation, the structure evolution rate, and the cross-network alignment abnormality degree of each node; Based on a dynamically set score threshold, if the score of a node exceeds the set score threshold, it is determined that the node has an abnormal behavior.

2. The complex network anomaly detection method driven by spatio-temporal factors according to claim 1, characterized in that, Encoding the time feature and the spatial neighborhood feature based on a time decay function through the following formula to obtain a spatio-temporal factor: Z = σ([X t ||S k ·W z +b z ) where Z represents the spatio-temporal factor, || represents feature concatenation, and W z represents the weight matrix, and b z represents the bias term, and σ represents the time decay function.

3. The complex network anomaly detection method driven by spatio-temporal factors according to claim 2, wherein The time decay function is expressed as: σ(t) = e -λΔt In the formula, e represents the natural constant, Δt represents the time interval, and λ represents the decay coefficient.

4. The complex network anomaly detection method driven by spatio-temporal factors according to claim 1, characterized in that Calculating the dynamic relationship weight through the following formula according to the spatio-temporal factor: α ij = softmax(LeakyReLu(a T [Z i ||Z j )) where α ij represents the dynamic relationship weight between the i-th node and the j-th node, softmax represents the normalization operation, LeakyReLu represents the activation function, Z i and Z j respectively represent the spatio-temporal factors of the i-th node and the j-th node, and || represents feature concatenation.

5. The complex network anomaly detection method driven by spatio-temporal factors according to claim 1, characterized in that The network state containing τ time steps extracted from the network security industry chain network based on time-series sliding window sampling is denoted as W t =[G t-τ , G t-τ+1 , …, G t , where G t-τ , G t-τ+1 and G t respectively represent the network states at time steps t - τ, -τ + 1, and t 6. The complex network anomaly detection method driven by spatio-temporal factors according to claim 1, wherein, The contrast loss function is expressed as: where L c represents the contrastive loss, e represents the natural constant, represents the negative sample, represents the positive sample, sim represents the similarity, τ is the sliding window length, m is the serial number of the negative sample, M is the number of negative samples, and c i is the feature vector of the i-th node.

7. The complex network anomaly detection method driven by spatio-temporal factors according to claim 6, characterized in that Calculating the score of each node through the following formula based on the node-level feature deviation, the structure evolution rate, and the cross-network alignment abnormality degree of each node: Score(v i ) = α·||c i -μ W || + β·ΔD(v i ) + γ·Φ(v i ) where Score(v i ) represents the score of node v i , α, β, and γ represent the weights of the node-level feature deviation, the structure evolution rate, and the cross-network alignment anomaly degree respectively, ||c i -μ W || represents the node-level feature deviation, μ W represents the sliding window feature mean, ΔD(v i ) represents the temporal change rate of the node degree centrality, and φ(v i ) represents the cross-network alignment anomaly degree.

8. The complex network anomaly detection method driven by spatio-temporal factors according to claim 1, wherein The score threshold is dynamically set according to the average score and the standard deviation of the nodes.

9. A complex network anomaly detection device driven by spatio-temporal factors, characterized in that, The apparatus includes: A network construction module, configured to construct a network security industrial chain network; wherein, the network security industrial chain network is represented as G=(V, E T , A S ), where V is a set of nodes, including multiple nodes, each node respectively represents an entity in the industrial chain, and E T is a set of temporal edges, used to describe the dynamic interaction relationships between nodes, and E T = {E supply , E compete , E coop}×T, where E supply , E compete , E coop respectively represent supply relationships, competition relationships, and cooperation relationships, T represents a set of timestamps, and A S is a spatio-temporal attribute matrix, and A S = (X t , S k ), where X t ∈ R n×d , represents time characteristics, n and d represent dimensions, R represents the real number space, and S k = A k ·X, represents the k-order spatial neighborhood characteristics, A represents the adjacency matrix, k represents the order, X represents the node characteristics, and A k represents performing k times of graph convolution operations. The time characteristics are used to record the dynamic behavior indicators of each node, the spatial neighborhood characteristics are used to capture the topological associations of the industrial chain network, and the weights of the supply relationships, competition relationships, and cooperation relationships are determined by the adjacency matrix; A dynamic relationship weight calculation module, configured to encode the time feature and the spatial neighborhood feature based on a time decay function to obtain a spatio-temporal factor, and calculate a dynamic relationship weight according to the spatio-temporal factor, where the dynamic relationship weight is used to quantify the abnormal contribution degree of different types of temporal edges; A time-series sampling module, configured to sample based on a time-series sliding window and extract a network state including τ time steps from the network security industrial chain network; A contrast learning module, configured to, based on the network state including τ time steps, extract the feature vectors of the same node in different time windows as positive samples, and the feature vectors of different nodes in the same time window as negative samples. The feature vectors are dynamic relationship weights, and perform contrast learning on the positive samples and the negative samples based on a contrast loss function to obtain the characteristic vectors of each node; A score calculation module, configured to determine the node-level feature deviation of each node based on the characteristic vectors of each node, and calculate the score of each node based on the node-level feature deviation, the structure evolution rate, and the cross-network alignment abnormality degree of each node; An abnormality recognition module, configured to, based on a dynamically set score threshold, if the score of a node exceeds the set score threshold, determine that the node has an abnormal behavior.

10. A non-transitory computer-readable storage medium storing instructions, characterized in that, When the instruction is executed by a processor, execute the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Industrial Internet of Things anomaly detection method based on time-space gated map attention network

    CN118018258A

  • Regional electromagnetic inspection method and system based on vehicle-mounted electromagnetic detection equipment

    CN119717034A

Cited By

  • Economic database construction method for algae industry

    CN121935414A