Network crime prevention and control method based on multi-dimensional data fusion and dynamic model

Through multi-dimensional data fusion and dynamic models, a dynamic model of the number of cybercrimes was constructed, and the number of cybercrimes was divided into five changing periods. Targeted policy adjustment plans were proposed, which solved the problem of lack of scientificity in cybercrime prevention and control measures, and achieved more efficient prevention and control effects.

CN120373899APending Publication Date: 2025-07-25HUNAN NORMAL UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510470266.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The lack of effective theoretical support in the existing technology has led to the lack of scientificity and accuracy of cybercrime prevention and control measures around the world, making it difficult to deal with the multi-dimensional changes in cybercrime.

Method used

Through multi-dimensional data fusion and dynamic model, a dynamic model of the number of cybercrimes is constructed, the cohort change relationship between the number of parties, victims and potential victims of cybercrimes is analyzed, and the cohort change relationship is divided into five periods of change, and a targeted policy adjustment plan is proposed.

Benefits of technology

It has improved the scientificity and accuracy of cybercrime prevention and control, optimized prevention and control measures, and improved the ability to predict and respond to cybercrimes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120373899A_ABST
    Figure CN120373899A_ABST
Patent Text Reader

Abstract

The invention provides a network crime prevention and control method based on multi-dimensional data fusion and a dynamic model, and belongs to the technical field of crime prediction, prevention and control. The method comprises the steps of 1, extracting original index parameter data of all countries from a target data source, and obtaining network crime indexes of all countries; 2, analyzing tuning parameters of national network security measure indexes and network crime indexes based on a regression model, and analyzing to obtain an index with the strongest negative correlation as the number of network crimes; 3, constructing a dynamic model of the number of network crimes, solving a queue change relation of the number of parties, victims and potential victims generating the network crimes, and dividing the number of the network crimes into five change periods; 4, introducing a multi-dimensional index to construct a multi-dimensional network crime model; 5, the multidimensional network crime model is combined with five change periods, and an optimal policy adjustment scheme of each period is provided. Through multi-dimensional data fusion and a dynamic model, network crimes are accurately predicted, and prevention and control policies are optimized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of crime prediction and prevention and control, and particularly to a method for preventing and controlling cybercrime based on multi-dimensional data fusion and dynamic models. Background Art

[0002] With the rapid development of the Internet and information and communication technologies, the interconnection of the global cyberspace has reached an unprecedented level. However, the openness and anonymity of the cyberspace have also given rise to a new form of crime - cybercrime. Many countries lack theoretical support for formulating cybersecurity policies and laws, which has had different impacts on preventing and controlling cybercrime.

[0003] Therefore, the present invention proposes a method for preventing and controlling cybercrime based on multi-dimensional data fusion and dynamic models. Summary of the Invention

[0004] The present invention provides a method for preventing and controlling cybercrime based on multi-dimensional data fusion and dynamic models, which is used to analyze cybercrime through multi-dimensional data fusion and dynamic models, extract global indicator data, establish a regression model to optimize prevention and control measures, and propose targeted policy adjustment plans based on five change periods to improve the efficiency and accuracy of cybercrime prevention and control.

[0005] On the one hand, the present invention provides a method for preventing and controlling cybercrime based on multi-dimensional data fusion and dynamic models, including:

[0006] Step 1: Extract the original indicator parameter data of all countries from the target data source, preprocess the original indicator parameter data of all countries to obtain standard indicator parameter data, and obtain the cybercrime indicators of all countries;

[0007] Step 2: Obtain the cybersecurity measure indicators of any country, analyze the tuning parameters of the cybersecurity measure indicators and cybercrime indicators of the country based on the regression model, and analyze that the indicator with the strongest negative correlation is the number of cybercrimes;

[0008] Step 3: Construct a dynamic model of the number of cybercrimes, solve to generate the queue change relationship of the number of parties, victims, and potential victims of cybercrimes, and divide the number of cybercrimes into five change periods;

[0009] Step 4: Introduce multi-dimensional indicators to construct a multi-dimensional cybercrime model;

[0010] Step 5: The multi-dimensional cybercrime model combines the five change periods to propose the best policy adjustment plan for each period.

[0011] On the other hand, extracting the original indicator parameter data of all countries from the target data source includes:

[0012] Determine the country for target analysis. Using all country names as query conditions, collect the original data of cybersecurity measures indicators from the ITU website, obtain the original data of cyberattack indicators from research institutions, and collect the original data of human operation indicators of all countries from the official data sources of the United Nations;

[0013] The original data of cybersecurity measures indicators, the original data of cyberattack indicators, and the original data of human operation indicators constitute the original indicator parameter data of all countries.

[0014] On the other hand, after preprocessing the original indicator parameter data of all countries, obtain the standard indicator parameter data, and obtain the cybercrime indicators of all countries, including:

[0015] Fill in the missing values of the original indicator parameter data of all countries using polynomial interpolation, and exclude and screen the outliers using statistical methods to generate the standard indicator parameter data;

[0016] Obtain the standard cyberattack data of any country, and the success rate of cybercrime in the country is: Where SR represents the success rate of cybercrime, S represents the number of successful cybercrimes in the country, and W represents the total number of cyberattacks in the country;

[0017] The frustration rate is: Where FR represents the frustration rate of cybercrime, and F represents the number of failed cybercrimes in the country;

[0018] The cyber litigation rate is: Where L represents the total number of litigated cybercrimes in the country, and Q represents the total number of cybercrimes in the country;

[0019] Obtain the cybercrime indicators of the country: success rate, frustration rate, number of cybercrimes, prosecution rate.

[0020] On the other hand, obtain the cybersecurity measure indicators of any country, analyze the tuning parameters of the country's cybersecurity measure indicators and cybercrime indicators based on the regression model, and analyze that the indicator with the strongest negative correlation is the number of cybercrimes, including:

[0021] For the cybercrime indicators, the corresponding cybersecurity measure indicators are proposed as: legal measures, technical measures, organizational measures, capacity development measures, cooperation measures;

[0022] Use the Lasso regression function to analyze the tuning parameters of the cybersecurity measure indicators and the corresponding cybercrime indicators. The Lasso regression function is:

[0023] Where, y i is the predicted variable, x ijis the response variable, β j is the dynamic regression coefficient, β0 is the intercept, λ is the tuning parameter for controlling the penalty intensity, n means there are n predictor variables, and p means there are p response variables;

[0024] Taking the network security measures index as the response variable and the cyber crime index as the predictor variable, the Lasso regression function is used to obtain the λ and Lambda curves, and the relationship coefficient between the number of cyber crimes and the capacity development measures index is -0.622. It can be obtained that the indicator with the strongest negative correlation is the number of cyber crimes.

[0025] On the other hand, it also includes:

[0026] Cybersecurity measures policies were hierarchically clustered according to the EU climate distance, and countries were divided into three role modeling categories. Variance analysis was performed on cybercrime indicators and cybersecurity measures policies. The F value of all cybercrime indicators was greater than 1, and the P value was 0, indicating that the differences between different role modeling categories were significant in all cases. The F value represents the ratio of between-group variation to within-group variation, and the P value represents the probability of observing the current F value under the assumption that the null hypothesis is valid. The policy investment in cybersecurity measures policies is significantly related to the decline in the number of cybercrime indicators.

[0027] Moreover, policy investment in cybersecurity measures policies is significantly correlated with a decrease in the number of cybercrime indicators.

[0028] On the other hand, a dynamic model of cybercrime quantity is constructed, including:

[0029] The factors that influence the indicators are proposed to be: criminal parties, victims, and potential victims;

[0030] The dynamic model of cybercrime quantity based on the factors affecting the indicators is:

[0031] Among them, C represents the number of criminals, S represents the number of potential victims, I represents the number of victims, R represents the number of law enforcement agencies, τ represents the efficiency coefficient of law enforcement agencies against criminals, a represents the rate coefficient of non-victims becoming criminals, b represents the probability of non-victims becoming victims after contacting criminals, represents the dynamic model of the number of offenders and time, μ represents the recovery rate of victims to non-victims, A dynamic model representing the number of victims and time, A dynamic model representing the number and timing of potential victims.

[0032] On the other hand, the cohort change relationship of the number of parties, victims, and potential victims of cybercrime is solved, and the number of cybercrimes is divided into five change periods, including:

[0033] For the solution of the dynamic model of the number of cybercrimes, the differential equations for determining the factors are specifically as follows:

[0034] For the solution of the dynamic model of the number of cybercrimes, the differential equations for determining the factors are specifically as follows:

[0035] R = p1*LEG + p2*ORG + p3*cd; where cd represents the capacity development parameter, p1 represents the preset coefficient of law enforcement agencies, p2 represents the preset coefficient of laws, p3 represents the preset coefficient of capacity development, LEG represents the law enforcement intensity of law enforcement agencies, and ORG represents the legal supervision intensity;

[0036] where r1 represents the first converted victim coefficient, r2 represents the second converted victim coefficient, and r3 represents the third converted victim coefficient;

[0037] τ = ln(q1*TEC + q2*co + 1); where ln() represents the logarithmic function, TEC represents the technical parameter, co represents the cooperation parameter, q1 represents the preset coefficient of technology, and q2 represents the preset coefficient of cooperation;

[0038] where d1 represents the preset recovery coefficient of capacity development, d2 represents the preset recovery coefficient of cooperation, and d3 represents the recovery constant;

[0039] where f1 represents the preset crime coefficient of laws and f2 represents the preset crime constant;

[0040] Perform non-linear fitting on the differential equations of the above factors, and substitute the fitting results into the dynamic model of the number of cybercrimes to obtain the queue change table of cybercrime parties - victims - potential victims;

[0041] Based on the queue change table of cybercrime parties - victims - potential victims, divide the number of cybercriminals into five periods: rapid growth period, slow growth period, stable period, slow decline period, and rapid decline period.

[0042] On the other hand, introduce multi-dimensional indicators to construct a multi-dimensional cybercrime model, including:

[0043] Perform correlation analysis on all indicators of population indicators, network security measure indicators, and network attack indicators, and obtain that there is a correlation greater than the preset threshold between human operation indicators and network security indicators;

[0044] As derived above, the original variables affecting network security do not change, but human operation indicators include: GDP, education type, and Internet penetration will increase the impact on the number of cybercrimes. Then, according to the fitting of the differential equations of the factors, adjust the fitting to obtain a new fitting result as:

[0045] Among them, EDU represents the education type parameter;

[0046] a = e -0.046*LEG+0.1374*RE+2.1203 ; among them, RE represents the annual income parameter;

[0047] Among them, Int represents the Internet penetration parameter;

[0048] Substitute the newly fitted result into the dynamic model of the number of cybercrimes to generate multi-dimensional indicators and construct a multi-dimensional cybercrime model.

[0049] On the other hand, the multi-dimensional cybercrime model combines five change periods and proposes the best policy adjustment plan for each period, including:

[0050] According to the characteristics of the cyber-attack index types in the five change periods, input the multi-dimensional cybercrime model to output cyber security measure indicators and human operation indicators;

[0051] Based on the numerical fluctuations of the cyber security measure indicators and human operation indicators, combine with national policies to formulate and propose the best policy adjustment plan for the corresponding period.

[0052] Compared with the prior art, the beneficial effects of the present invention are:

[0053] The present invention provides a cybercrime prevention and control method based on multi-dimensional data fusion and dynamic models, which is used to analyze cybercrimes through multi-dimensional data fusion and dynamic models, extract global indicator data, establish a regression model to optimize prevention and control measures, and propose targeted policy adjustment plans based on five change periods to improve the efficiency and accuracy of cybercrime prevention and control. Brief Description of the Drawings

[0054] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0055] Figure 1 It is a flowchart of the cybercrime prevention and control method based on multi-dimensional data fusion and dynamic models provided by the embodiments of the present invention;

[0056] Figure 2 It is a diagram of λ and correlation coefficients of the comprehensive cyber security parameter;

[0057] Figure 3 It is an analysis of variance diagram of cybercrime indicators and cyber security measure policies;

[0058] Figure 4 It is the result of Lasso regression. Detailed implementation manners

[0059] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without making creative efforts based on the embodiments in the present invention belong to the scope of protection of the present invention.

[0060] Embodiment 1:

[0061] As Figure 1 shown, the network crime prevention and control method based on multi-dimensional data fusion and dynamic model provided by the embodiment of the present invention includes:

[0062] Step 1: Extract the original index parameter data of all countries from the target data source, preprocess the original index parameter data of all countries to obtain the standard index parameter data, and obtain the network crime indexes of all countries;

[0063] Step 2: Obtain the network security measure indexes of any country, analyze the tuning parameters of the network security measure indexes and network crime indexes of the country based on the regression model, and analyze that the index with the strongest negative correlation is the number of network crimes;

[0064] Step 3: Construct a dynamic model of the number of network crimes, solve the queue change relationship of the number of parties, victims and potential victims of network crimes generated, and divide the number of network crimes into five change periods;

[0065] Step 4: Introduce multi-dimensional indexes to construct a multi-dimensional network crime model;

[0066] Step 5: Combine the multi-dimensional network crime model with the five change periods, and propose the best policy adjustment plan for each period.

[0067] In this embodiment, the target data source refers to the data source for extraction, analysis and modeling, including: World Bank, International Telecommunication Union, United Nations Library, Kaspersky Cyber Map, etc.

[0068] In this embodiment, the original index parameter data refers to the preliminary data directly collected from the data source without being processed.

[0069] In this embodiment, the preprocessing performs operations such as cleaning, converting and standardizing the original data, and the purpose is to convert the original data into a consistent and easy-to-analyze form.

[0070] In this embodiment, the standard index parameter data refers to the data that has been preprocessed and subjected to unified standardization or normalization processing.

[0071] In this embodiment, the cybercrime index is a quantitative standard for measuring the occurrence of cybercrime activities, including: the number of cybercrimes, the success rate of crimes, the frustration rate, the litigation rate, etc.

[0072] In this embodiment, the cyber security measure index includes: legal measures, technical measures, organizational measures, capacity development measures, and cooperation measures.

[0073] In this embodiment, the regression model is a statistical analysis method used to study the relationship between one or more independent variables and a dependent variable.

[0074] In this embodiment, the tuning parameter refers to the parameter used to adjust the regression model or other mathematical models to optimize the prediction performance of the model or enable the model to more accurately describe the relationship between the independent variable and the dependent variable.

[0075] In this embodiment, negative correlation refers to the relationship between two variables, where when one variable increases, the other variable decreases.

[0076] In this embodiment, the number of cybercrimes refers to the total number of cybercrime incidents that occurred in a specific region or country within a specific time period.

[0077] In this embodiment, the dynamic model of the number of cybercrimes is a mathematical model used to describe and predict the changing pattern of the number of cybercrimes over time.

[0078] In this embodiment, the queue change relationship refers to the change in the number of different groups of cybercrimes over time.

[0079] In this embodiment, the five change periods include: the rapid growth period, the slow growth period, the stable period, the slow decline period, and the rapid decline period.

[0080] In this embodiment, the multi-dimensional index includes: the technical dimension, the legal dimension, the economic dimension, the social dimension, the educational dimension, etc.

[0081] In this embodiment, the multi-dimensional cybercrime model is a model that comprehensively considers multiple dimensions (factors) to analyze and predict cybercrime behavior and its changes.

[0082] In this embodiment, the best policy adjustment plan is a targeted adjustment for different stages of cybercrime situations. By dynamically monitoring and analyzing the change periods of cybercrimes, appropriate strategies and measures can be formulated for each stage to minimize the occurrence of cybercrimes and improve the prevention ability to the greatest extent.

[0083] The working principle and beneficial effects of the above technical solution are as follows: By means of multi-dimensional data analysis and regression models, a dynamic cybercrime model is constructed to predict the changing trends of crimes and propose targeted policy adjustments, effectively enhancing the scientificity and accuracy of cybercrime prevention and control.

[0084] Example 2:

[0085] Based on the above Example 1, the original indicator parameter data of all countries are extracted from the target data source, including:

[0086] Determine the country for target analysis. Using the names of all countries as query conditions, the original data of cybersecurity measures indicators are collected from the ITU website, the original data of cyberattack indicators are obtained from research institutions, and the original data of human operation indicators of all countries are collected from the official data sources of the United Nations;

[0087] The original data of cybersecurity measures indicators, the original data of cyberattack indicators, and the original data of human operation indicators constitute the original indicator parameter data of all countries.

[0088] In this example, the original data of cybersecurity measures indicators refer to the detailed data on the measures, strategies, and actions taken by countries in the field of cybersecurity collected through various international organizations, government agencies, or relevant research institutions, including: data on cybersecurity laws, talent cultivation, international cooperation, etc.

[0089] In this example, the original data of cyberattack indicators refer to the specific data collected, recorded, evaluated, and analyzed by various countries in the face of cyberattacks, including: the number of attacks, victims, recovery time, etc.

[0090] In this example, the original data of human operation indicators are a series of statistical indicators measuring human well-being and development levels, including: data such as GDP, education level, income level, etc.

[0091] The working principle and beneficial effects of the above technical solution are as follows: By integrating the data sources of the ITU, research institutions, and the United Nations, collecting the cybersecurity, cyberattack, and human development indicators of various countries, a comprehensive original dataset is formed, which helps to analyze from multiple dimensions and optimize cybercrime prevention and control strategies, improving data accuracy and decision-making support.

[0092] Example 3:

[0093] Based on the above Example 2, after preprocessing the original indicator parameter data of all countries, standard indicator parameter data are obtained, and the cybercrime indicators of all countries are obtained, including:

[0094] Fill in the missing values of the original indicator parameter data of all countries using polynomial interpolation, and exclude and screen the outliers using statistical methods to generate standard indicator parameter data;

[0095] Obtain the standard data of cyber attacks in any country, and the success rate of cybercrime in that country is obtained as follows: Where SR represents the success rate of cybercrime, S represents the number of successful cybercrimes in that country, and W represents the total number of cyber attacks in that country;

[0096] The frustration rate is: Where FR represents the frustration rate of cybercrime, and F represents the number of failed cybercrimes in that country;

[0097] The cyber litigation rate is: Where L represents the total number of cybercrimes subject to litigation in that country, and Q represents the total number of cybercrimes in that country;

[0098] Obtain the cybercrime indicators of that country: success rate, frustration rate, number of cybercrimes, prosecution rate.

[0099] In this embodiment, polynomial interpolation constructs a polynomial through existing data points, so that this polynomial passes through all known data points and can estimate the data values of missing points.

[0100] In this embodiment, the statistical method calculates the Z value of the data point, and the Z value represents the degree of deviation of the data point from the mean. If the Z value of the data point is greater than a certain threshold (usually set to 3), then the data point is considered an outlier.

[0101] In this embodiment, for the number of cybercrimes, considering the existence of small, numerous, and strong attacks, it is too one-sided to only focus on the quantity. Therefore, we consider using the WCI score as an indicator of the frequency of cybercrime attacks.

[0102] The working principle and beneficial effects of the above technical solution are: filling in missing values through polynomial interpolation and screening out outliers through statistical methods to generate standard indicator parameter data. By calculating the success rate, frustration rate, and cyber litigation rate of cybercrimes, constructing national cybercrime indicators helps to accurately assess cybercrime risks and optimize prevention and control strategies.

[0103] Example 4:

[0104] On the basis of the above Example 1, obtain the cyber security measure indicators of any country, analyze the tuning parameters of the cyber security measure indicators and cybercrime indicators of that country based on the regression model, and the indicator with the strongest negative correlation is found to be the number of cybercrimes, including:

[0105] For the cybercrime indicators, the corresponding cyber security measure indicators are proposed as: legal measures, technical measures, organizational measures, capacity development measures, cooperation measures;

[0106] Use the Lasso regression function to analyze the tuning parameters of network security measure indicators and corresponding cybercrime indicators. The Lasso regression function is as follows:

[0107] Among them, y i is the predicted variable, x ij is the response variable, β j is the dynamic regression coefficient, β0 is the intercept, λ is the tuning parameter that controls the penalty intensity, n represents there are n predicted variables in total, and p represents there are p response variables in total;

[0108] Taking the network security measure indicators as the response variables and the cybercrime indicators as the predicted variables, through the Lasso regression function, λ and the Lambda curve are obtained. The correlation coefficient between the number of cybercrimes and the capacity development measure indicators is -0.622, and it can be obtained that the indicator with the strongest negative correlation is the number of cybercrimes.

[0109] In this embodiment, the Lasso regression function is a technique for regression analysis. It introduces an L1 regularization term on the basis of ordinary least squares regression to prevent overfitting and perform feature selection.

[0110] In this embodiment, the predicted variable refers to the independent variable used to predict or explain the change of the response variable (i.e., the dependent variable).

[0111] In this embodiment, the response variable is the network security measure indicator.

[0112] In this embodiment, the intercept is the constant term in the regression equation, indicating the value of the response variable when all the predicted variables are zero.

[0113] In this embodiment, the Lambda curve is used to show how each regression coefficient (including the intercept) in the model changes as the tuning parameter (i.e., λ) changes.

[0114] In this embodiment, the λ and correlation coefficients of the network security comprehensive parameters are as Figure 2 shown.

[0115] The working principle and beneficial effects of the above technical solution are: By using Lasso regression to analyze the relationship between network security measures and cybercrime indicators, it is determined that the negative correlation between the capacity development measures and the number of cybercrimes is the strongest, which helps to identify the most effective network security measures, optimize the prevention and control strategies, and improve network security management.

[0116] Example 5:

[0117] Based on the above Example 4, it further includes:

[0118] Stratify and cluster network security measure policies according to the climate distance of the European Union, classify countries into three categories of role modeling categories, and analyze the cybercrime indicators and network security measure policies through variance analysis. The F-value of all cybercrime indicators is greater than 1, and the P-value is 0, indicating that the differences among different role modeling categories are significant in all cases. Among them, the F-value represents the ratio of the variation between groups to the variation within groups, and the P-value represents the probability of observing the current F-value under the assumption that the null hypothesis holds. And there is a significant relationship between the policy investment in the network security measure policy and the decrease in the cybercrime quantity indicator;

[0119] And there is a significant relationship between the policy investment in the network security measure policy and the decrease in the cybercrime quantity indicator.

[0120] In this embodiment, the climate distance of the European Union is a distance metric based on climate-related indicators.

[0121] In this embodiment, hierarchical clustering is the process of gradually merging data points into different hierarchical structures.

[0122] In this embodiment, the role modeling categories are based on hierarchical clustering to divide all countries into three categories. Most countries in the world belong to the third category, that is, most countries attach more importance to network security.

[0123] In this embodiment, the F-value is a measure of the ratio of the variability between different groups to the variability within groups. The F-value is greater than 1 and the P-value is 0, indicating that the differences between different role modeling categories are significant.

[0124] In this embodiment, the P-value is a statistic for measuring the significance of differences between different groups. The smaller the P-value, the more significant the difference between groups.

[0125] In this embodiment, the variation between groups represents the differences between different groups.

[0126] In this embodiment, the variation within groups represents the random error between individuals within a group.

[0127] In this embodiment, the variance analysis of the cybercrime indicators and network security measure policies is as Figure 3 shown.

[0128] The working principle and beneficial effects of the above technical solution are as follows: Stratify and cluster network security measure policies through the climate distance of the European Union, classify countries into three roles, use variance analysis to reveal the significant differences in cybercrime indicators among different roles, and prove that there is a significant relationship between policy investment and the decrease in the number of cybercrimes, which helps to optimize network security policies.

[0129] Example 6:

[0130] Based on the above Example 1, construct a dynamic model of the number of cybercrimes, including:

[0131] The factors determining the impact indicators are: the criminal parties, the victims, and the potential victims;

[0132] Based on the factors of the impact indicators, a dynamic model of the number of cybercrimes is constructed as follows:

[0133] Among them, C represents the number of criminals, S represents the number of potential victims, I represents the number of victims, R represents the number of law enforcement agencies, τ represents the efficiency coefficient of law enforcement agencies against criminals, a represents the rate coefficient of non-victims becoming criminals, b represents the probability of non-victims becoming victims after contacting criminals, represents the dynamic model of the number of criminals and time, and μ represents the recovery rate of victims returning to non-victims. represents the dynamic model of the number of victims and time. represents the dynamic model of the number of potential victims and time.

[0134] In this embodiment, the dynamic model is a model that describes how the number of cybercrimes changes over time and how the factors interact with each other.

[0135] The working principle and beneficial effects of the above technical solution are: by constructing a dynamic model based on the parties, victims, and potential victims, analyzing the interaction relationship among criminals, victims, and law enforcement agencies, revealing the law of the change of the number of cybercrimes over time, helping to optimize crime prevention and law enforcement strategies, and improving the efficiency of cybercrime prevention and control.

[0136] Example 7:

[0137] Based on the above Example 6, solve the queue change relationship of the number of parties, victims, and potential victims of cybercrimes, and divide the number of cybercrimes into five change periods, including:

[0138] For the solution of the dynamic model of the number of cybercrimes, determine the differential equations of the factors, specifically:

[0139] R = p1 * LEG + p2 * ORG + p3 * cd; where cd represents the capacity development parameter, p1 represents the preset coefficient of law enforcement agencies, p2 represents the legal preset coefficient, p3 represents the capacity development preset coefficient, LEG represents the law enforcement intensity of law enforcement agencies, and ORG represents the legal supervision intensity;

[0140] Among them, r1 represents the first conversion victim coefficient, r2 represents the second conversion victim coefficient, and r3 represents the third conversion victim coefficient;

[0141] τ = ln(q1 * TEC + q2 * co + 1); where, ln() represents the logarithmic function, TEC represents the technical parameter, co represents the cooperation parameter, q1 represents the technical preset coefficient, and q2 represents the cooperation preset coefficient;

[0142] Where, d1 represents the preset recovery coefficient of ability development, d2 represents the preset recovery coefficient of cooperation, and d3 represents the recovery constant;

[0143] Where, f1 represents the legal preset crime coefficient, and f2 represents the preset crime constant;

[0144] Perform non - linear fitting on the differential equation of the above factors, and substitute the fitting result into the dynamic model of the number of cybercrimes to obtain the queue change table of cybercrime parties - victims - potential victims;

[0145] Based on the queue change table of cybercrime parties - victims - potential victims, divide the number of cybercriminals into five periods: rapid growth period, slow growth period, stable period, slow decline period, and rapid decline period.

[0146] In this embodiment, the law enforcement agency preset coefficient refers to a parameter used to describe the preset ability or influence of the law enforcement agency in combating cybercrimes.

[0147] In this embodiment, the legal preset coefficient represents the influence of factors related to laws and policies on criminal activities.

[0148] In this embodiment, the ability development preset coefficient is a parameter that measures the influence of factors related to ability development on cybercrime behavior.

[0149] In this embodiment, the first converted victim coefficient, the second converted victim coefficient, and the third converted victim coefficient are parameters that affect the speed at which potential victims turn into actual victims.

[0150] In this embodiment, the technical preset coefficient is a parameter used to describe the influence of technical factors.

[0151] In this embodiment, the ability development preset recovery coefficient is a parameter used to describe the speed of ability recovery during the process of victims recovering to non - victims.

[0152] In this embodiment, the legal preset crime coefficient refers to a parameter in the dynamic model of the number of cybercrimes that reflects the expected influence of laws on criminal behavior.

[0153] In this embodiment, the preset crime constant refers to a constant term related to the occurrence of crimes.

[0154] In this embodiment, the recovery constant is used to describe the rate of the recovery process, which refers to the degree to which the victim returns to a non-victim state under controlled or intervention measures.

[0155] In this embodiment, the purpose of non-linear fitting is to find a non-linear function that can as accurately as possible describe the trend and changes of actual data. In non-linear fitting, the form of the function is usually not linear, but contains parameters with non-linear relationships, and the values of these parameters are estimated through numerical optimization methods.

[0156] In this embodiment, the network crime perpetrator-victim-potential victim cohort change table is a mathematical model tool for describing the dynamic changes of network crime activities and their different stages. It helps analyze the quantitative changes of the three main groups in network crime (perpetrators, victims, potential victims) at different time nodes, and further reveals the evolution process of network crime activities.

[0157] The working principle and beneficial effects of the above technical solution are as follows: By solving the differential equation of the network crime quantity dynamic model and performing non-linear fitting, a cohort change table of network crime perpetrators, victims, and potential victims is constructed. Dividing the crime quantity into five periods helps accurately predict and respond to network crime changes and optimize prevention measures.

[0158] Example 8:

[0159] Based on the above Example 7, a multi-dimensional network crime model is constructed by introducing multi-dimensional indicators, including:

[0160] Performing a correlation analysis on all indicators of population indicators, network security measure indicators, and network attack indicators, and obtaining that there is a correlation greater than the preset threshold between human operation indicators and network security indicators;

[0161] As obtained above, the original variables affecting network security do not change, but human operation indicators include: GDP, education type, and Internet penetration, which will increase the impact on the quantity of network crimes. Then, according to the fitting of the differential equation of the factor, the fitting is adjusted to obtain a new fitting result:

[0162] Among them, EDU represents the education type parameter;

[0163] a = e -0.046*LEG+0.1374*RE+2.1203 ; among them, RE represents the annual income parameter;

[0164] Among them, Int represents the Internet penetration parameter;

[0165] Substitute the new fitting result into the network crime quantity dynamic model to generate a multi-dimensional network crime model constructed by multi-dimensional indicators.

[0166] In this embodiment, the Lasso regression results are as Figure 4 shown.

[0167] In this embodiment, the purpose of the correlation analysis is to evaluate whether there is a certain degree of association between these variables and how strong this association is.

[0168] In this embodiment, the preset threshold is a criterion for judging the strength of the relationship between variables.

[0169] In this embodiment, based on Figure 4 , demographic data and cybersecurity performance indicators generally have a high correlation. Among them, GDP has a high negative correlation with the number of cybercrimes, and education also has a high negative correlation with the success rate of cybercrimes.

[0170] In this embodiment, the original variables refer to the basic indicators that have been collected before data analysis.

[0171] In this embodiment, the education type parameter is a parameter used to measure the impact of the education type on the number of cybercrimes.

[0172] In this embodiment, the annual income parameter refers to the parameter related to the annual income level of the national human group.

[0173] In this embodiment, the Internet penetration parameter refers to the popularity or penetration rate of the Internet in a country.

[0174] The working principle and beneficial effects of the above technical solution are: through correlation analysis, significant associations between human operation indicators (GDP, education type, Internet penetration) and cybersecurity indicators are found, and differential equation fitting is adjusted to generate a multi-dimensional cybercrime model, which helps to deeply analyze the impact of human activities on cybercrimes and optimize prevention strategies.

[0175] Embodiment 9:

[0176] Based on the above Embodiment 1, the multi-dimensional cybercrime model combines five change periods and proposes the best policy adjustment plan for each period, including:

[0177] According to the characteristics of the cyber attack indicator types in the five change periods, input the multi-dimensional cybercrime model to output cybersecurity measure indicators and human operation indicators;

[0178] Based on the numerical fluctuations of the cybersecurity measure indicators and human operation indicators, combined with national policies, propose the best policy adjustment plan for the corresponding period.

[0179] In this embodiment, the characteristics include: success rate, frustration rate, attack method, attack target, etc.

[0180] The working principle and beneficial effects of the above technical solution are as follows: By analyzing the network attack characteristics in five changing periods through a multi-dimensional cybercrime model, network security measures and human operation indicators are output. Combining numerical fluctuations with national policies to formulate the best policy adjustment plan helps to optimize network security strategies at different stages and reduce the risk of cybercrime.

[0181] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A network crime prevention and control method based on multi-dimensional data fusion and dynamic model, characterized in that, Including: Step 1: Extract the original indicator parameter data of all countries from the target data source. After preprocessing the original indicator parameter data of all countries, obtain the standard indicator parameter data and the cybercrime indicators of all countries; Step 2: Obtain the cybersecurity measure indicators of any country. Based on the regression model, analyze the tuning parameters of the cybersecurity measure indicators and cybercrime indicators of the country, and analyze that the indicator with the strongest negative correlation is the number of cybercrimes; Step 3: Construct a dynamic model of the number of cybercrimes, solve to generate the queue change relationship of the number of parties, victims and potential victims of cybercrimes, and divide the number of cybercrimes into five change periods; Step 4: Introduce multi-dimensional indicators to construct a multi-dimensional cybercrime model; Step 5: Combine the multi-dimensional cybercrime model with the five change periods, and propose the best policy adjustment plan for each period.

2. The network crime prevention and control method based on multi-dimensional data fusion and dynamic model according to claim 1, characterized in that Extract the original indicator parameter data of all countries from the target data source, including: Determine the country for target analysis. Using the names of all countries as query conditions, collect the original data of cybersecurity measure indicators from the ITU website, obtain the original data of cyberattack indicators from research institutions, and collect the original data of human operation indicators of all countries from the official data source of the United Nations; The original data of cybersecurity measure indicators, the original data of cyberattack indicators and the original data of human operation indicators constitute the original indicator parameter data of all countries.

3. The network crime prevention and control method based on multi-dimensional data fusion and dynamic model according to claim 2, characterized in that, After preprocessing the original indicator parameter data of all countries, obtain the standard indicator parameter data and the cybercrime indicators of all countries, including: Fill in the missing values of the original indicator parameter data of all countries using polynomial interpolation, and exclude and screen the outliers using statistical methods to generate the standard indicator parameter data; Obtain the standard data of cyberattacks in any country, and the success rate of cybercrimes in that country is obtained as follows: Among them, SR represents the success rate of cybercrimes, S represents the number of successful cybercrimes in that country, and W represents the total number of cyberattacks in that country; The frustration rate is: Wherein, FR represents the frustration rate of cybercrime, and F represents the number of cybercrime failures in the country; The online litigation rate is: where L represents the total number of online crimes in litigation in the country, and Q represents the total number of online crimes in the country; Obtain the cybercrime indicators of the country: success rate, frustration rate, number of cybercrimes, prosecution rate.

4. The network crime prevention and control method based on multi-dimensional data fusion and dynamic model according to claim 1, characterized in that Obtain the cybersecurity measure indicators of any country. Based on the regression model, analyze the tuning parameters of the cybersecurity measure indicators and cybercrime indicators of the country, and analyze that the indicator with the strongest negative correlation is the number of cybercrimes, including: For the cybercrime indicators, the corresponding cybersecurity measure indicators are proposed as: legal measures, technical measures, organizational measures, capacity development measures, cooperation measures; Use the Lasso regression function to analyze the tuning parameters of the cybersecurity measure indicators and the corresponding cybercrime indicators. The Lasso regression function is: Among them, y i is the predictor variable, x ij is the response variable, β j is the dynamic regression coefficient, β0 is the intercept, λ is the tuning parameter that controls the penalty intensity, n represents there are a total of n predictor variables, and p represents there are a total of p response variables; Taking the cybersecurity measure indicators as the response variable and the cybercrime indicators as the predictive variables, obtain λ and the Lambda curve through the Lasso regression function. The correlation coefficient between the number of cybercrimes and the capacity development measure indicators is -0.622, and it can be obtained that the indicator with the strongest negative correlation is the number of cybercrimes.

5. The network crime prevention and control method based on multi-dimensional data fusion and dynamic model according to claim 4, characterized in that, Also including: Stratify and cluster the cybersecurity measure policies according to the climate distance of the European Union, divide the countries into three types of role modeling categories, and analyze the cybercrime indicators and cybersecurity measure policies through variance analysis. The F values of all cybercrime indicators are greater than 1, and the P value is 0, indicating that the differences between different role modeling categories are significant in all cases. Among them, the F value represents the ratio of between-group variation to within-group variation, and the P value represents the probability of observing the current F value under the assumption that the null hypothesis holds; Moreover, there is a significant relationship between the policy investment in the network security measures policy and the decline in the number of cybercrimes.

6. The network crime prevention and control method based on multi-dimensional data fusion and dynamic model according to claim 1, characterized in that, Construct a dynamic model of the number of cybercrimes, including: The factors determined to affect the indicators are: the offender, the victim, and the potential victim; Based on the factors affecting the indicators, the dynamic model of the number of cybercrimes is constructed as: Among them, C represents the number of criminals, S represents the number of potential victims, I represents the number of victims, R represents the number of law enforcement agencies, τ represents the efficiency coefficient of law enforcement agencies against criminals, a represents the rate coefficient of non-victims becoming criminals, and b represents the probability that non-victims become victims after contacting criminals. It represents the dynamic model of the number of criminals and time, and μ represents the recovery rate of victims returning to non-victims. It represents the dynamic model of the number of victims and time. bCS + μI + τCR represents the dynamic model of the number of potential victims and time.

7. The network crime prevention and control method based on multi-dimensional data fusion and dynamic model according to claim 6, characterized in that, Solve to generate the queue change relationship of the number of offenders, victims, and potential victims of cybercrimes, and divide the number of cybercrimes into five change periods, including: For the solution of the dynamic model of the number of cybercrimes, determine the differential equations of the factors, specifically: R = p1 * LEG + p2 * ORG + p3 * cd; where cd represents the capacity development parameter, p1 represents the preset coefficient of the law enforcement agency, p2 represents the preset coefficient of the law, p3 represents the preset coefficient of capacity development; LEG represents the law enforcement intensity of the law enforcement agency, and ORG represents the legal supervision intensity; Among them, r1 represents the first conversion victim coefficient, r2 represents the second conversion victim coefficient, and r3 represents the third conversion victim coefficient; Among them, r1 represents the first conversion coefficient, r2 represents the second conversion coefficient, and r3 represents the third conversion coefficient; τ = ln(q1 * TEC + q2 * co + 1); where ln() represents the logarithmic function, TEC represents the technical parameter, co represents the cooperation parameter, q1 represents the preset coefficient of technology, and q2 represents the preset coefficient of cooperation; Wherein, d1 represents the preset recovery coefficient of ability development, d2 represents the preset recovery coefficient of cooperation, and d3 represents the recovery constant; Among them, f1 represents the legally preset crime coefficient, and f2 represents the preset crime constant; Perform non-linear fitting on the differential equations of the above factors, and substitute the fitting results into the dynamic model of the number of cybercrimes to obtain the queue change table of cybercrime offenders-victims-potential victims; Based on the queue change table of cybercrime offenders-victims-potential victims, divide the number of cybercriminals into five periods: rapid growth period, slow growth period, stable period, slow decline period, and rapid decline period.

8. The network crime prevention and control method based on multi-dimensional data fusion and dynamic model according to claim 7, characterized in that, Introduce multi-dimensional indicators to construct a multi-dimensional cybercrime model, including: Conduct a correlation analysis on all indicators of the population indicator, network security measure indicator, and network attack indicator, and obtain that there is a correlation greater than the preset threshold between the human operation indicator and the network security indicator; As derived above, the original variables affecting network security do not change, but the human operation indicators include: GDP, education type, and Internet penetration, which will increase the impact on the number of cybercrimes. Then, according to the fitting of the differential equations of the factors, adjust the fitting to obtain a new fitting result as: Among them, EDU represents the education type parameter; a = e -0.046*LEG+0.1374*RE+2.1203 ; wherein, RE represents the annual income parameter; Among them, Int represents the Internet penetration parameter; Substitute the new fitting result into the dynamic model of the number of cybercrimes to generate a multi-dimensional indicator to construct a multi-dimensional cybercrime model.

9. The network crime prevention and control method based on multi-dimensional data fusion and dynamic model according to claim 1, characterized in that The multi-dimensional cybercrime model combines the five change periods and proposes the best policy adjustment plan for each period, including: According to the characteristics of the network attack indicator types in the five change periods, input the multi-dimensional cybercrime model to output the network security measure indicator and the human operation indicator; Based on the numerical fluctuations of the network security measure indicator and the human operation indicator, combine with the national policy to propose the best policy adjustment plan for the corresponding period.