Dynamic security method and system based on big data

Through big data dynamic security methods, using dynamic spatiotemporal baseline models and risk knowledge graphs, potential threats are identified and predicted, solving the high false alarm rate and recognition lag problems of existing security systems, and achieving efficient and accurate security decision support.

CN120493137BActive Publication Date: 2025-09-12SHANGHAI ZHISHENG INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510983890.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-17
Publication Date
2025-09-12
Estimated Expiration
2045-07-17

Smart Images

  • Figure CN120493137B_ABST
    Figure CN120493137B_ABST
Patent Text Reader

Abstract

The present invention provides a dynamic security method and system based on big data, which belongs to the field of security technology. The dynamic security method based on big data of the present invention constructs an abnormal event chain based on the identified initial abnormal event, predicts the high-level risk event that the real abnormal event chain evolves into, and determines the response measures for the high-level risk event. The dynamic security method based on big data of the present invention can identify historical standardized events from multiple isolated and weak abnormal signals after identifying the initial abnormal event through a dynamic spatiotemporal baseline model, and then connect these events into a candidate abnormal event chain. It can accurately discover potential threats from hidden event information in advance, obtain more accurate security identification results, and achieve a fundamental transformation from post-event response to pre-event warning, providing a valuable early intervention window for security decision-making, and then taking targeted preventive measures to reduce security risks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of security technology, and in particular to a dynamic security method and system based on big data. Background Art

[0002] Traditional security systems rely heavily on manual real-time video monitoring or post-event video review. This approach is not only labor-intensive but also suffers from inefficient response times and significant lags. While recent advances in artificial intelligence have led to widespread adoption of intelligent security systems, existing solutions still face significant bottlenecks and limitations.

[0003] Current mainstream intelligent security systems often rely on rigid event detection rules, such as preset rules for "area intrusion" and "person loitering." Existing technologies generally lack deep contextual awareness of the monitored scene. Unable to dynamically learn and understand a scene's "normal state" at different times and in different environments, the system struggles to distinguish between real threats and normal activities or environmental disturbances. This leads to either high false alarm rates due to oversensitivity, significantly consuming security resources, or failure to accurately and promptly identify potential threats.

[0004] Therefore, how to analyze security data based on big data to obtain accurate security identification results is still a problem that needs to be solved urgently. Summary of the Invention

[0005] The present invention provides a dynamic security method and system based on big data, which is used to solve the defect in the prior art that it is difficult to identify truly threatening events for security protection, and achieve the effect of obtaining accurate security identification results.

[0006] The present invention provides a dynamic security method based on big data, comprising:

[0007] Inputting the unprocessed security data collected at the target location into a dynamic spatiotemporal baseline model to identify initial abnormal events that deviate from the normal state; the dynamic spatiotemporal baseline model is trained based on historical time series of different data sources at the target location;

[0008] Using the initial abnormal event as an index, querying for associated event data from other data sources within the associated spatiotemporal range corresponding to the initial abnormal event;

[0009] According to a preset spatiotemporal association rule, historical standardized events associated with the initial abnormal event in the temporal and spatial dimensions are identified from the associated event data, and the initial abnormal event and the historical standardized events are combined into a candidate abnormal event chain;

[0010] The candidate abnormal event chain is confirmed, and for the confirmed abnormal event chain, based on the preset risk knowledge graph, the high-level risk event that the abnormal event chain evolves into is predicted, and the response measures for the high-level risk event are determined.

[0011] According to a big data-based dynamic security method provided by the present invention, the abnormal event chain includes events associated with a target object. Before confirming the candidate abnormal event chain, the method further includes:

[0012] Determining a pre-calibrated visual surveillance fuzzy area in the target location;

[0013] Based on the associated event data corresponding to the target object, determining a potential activity area of ​​the target object from the visual monitoring fuzzy area, and determining a potential activity trajectory of the target object;

[0014] A supplementary event is determined based on the potential activity trajectory of the target object and inserted into the candidate abnormal event chain.

[0015] According to a dynamic security method based on big data provided by the present invention, the associated event data corresponding to the target object includes:

[0016] At least one of access control data of the target place, infrared data including the target object, surveillance video data including at least part of the target object, and preset rule data including the target object.

[0017] According to a big data-based dynamic security method provided by the present invention, confirming the candidate abnormal event chain includes:

[0018] Based on at least one key event in the candidate abnormal event chain, determining an event verification rule corresponding to the at least one key event from preset event verification rules;

[0019] The candidate abnormal event chain is confirmed based on the event verification rule corresponding to the at least one key event; the event verification rule includes at least one of a physical logic verification rule, an authority verification rule and a state consistency verification rule.

[0020] According to a big data-based dynamic security method provided by the present invention, the candidate abnormal event chain is encapsulated as confirmation task information and sent to the administrator, and feedback information from the administrator is received; the confirmation task information also includes event data corresponding to each task in the candidate abnormal event chain.

[0021] According to a big data-based dynamic security method provided by the present invention, the step of determining response measures for the high-level risk event includes:

[0022] Based on the spatiotemporal trajectory of the high-level risk event and the event types involved, corresponding response measures are matched from a preset emergency plan library. The response measures include at least one of optimizing the inspection route of security personnel, prioritizing the review of monitoring screen lists, controlling the operation of warning lights or alarm devices, and controlling the locking of automatic doors.

[0023] According to a big data-based dynamic security method provided by the present invention, the data source includes at least one of a surveillance camera, a thermal imager, an access control system, a network traffic monitor, an audio acquisition device, and a license plate acquisition system.

[0024] The present invention also provides a dynamic security system based on big data, comprising:

[0025] A first processing module is configured to input the security data to be processed collected at the target location into a dynamic spatiotemporal baseline model to identify initial abnormal events that deviate from a normal state; the dynamic spatiotemporal baseline model is trained based on historical time series of different data sources at the target location;

[0026] A second processing module is configured to use the initial abnormal event as an index to query associated event data from other data sources within an associated spatiotemporal range corresponding to the initial abnormal event;

[0027] a third processing module, configured to identify, from the associated event data, historical standardized events associated with the initial abnormal event in terms of time and space dimensions according to a preset spatiotemporal association rule, and to form a candidate abnormal event chain with the initial abnormal event and the historical standardized events;

[0028] The fourth processing module is used to confirm the candidate abnormal event chain, predict the high-level risk event that the confirmed abnormal event chain will evolve into based on the preset risk knowledge graph, and determine the response measures for the high-level risk event.

[0029] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the dynamic security method based on big data as described above is implemented.

[0030] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the above-described dynamic security methods based on big data.

[0031] The present invention also provides a computer program product, comprising a computer program, which, when executed by a processor, implements any of the above-described dynamic security methods based on big data.

[0032] The big data-based dynamic security method and system provided by the present invention can identify the initial abnormal event through a dynamic spatiotemporal baseline model, and then identify historical standardized events from multiple isolated and weak abnormal signals, and then connect these events into a candidate abnormal event chain. It can accurately discover potential threats from hidden event information in advance, obtain more accurate security identification results, and realize a fundamental transformation from post-event response to pre-event warning, providing a valuable early intervention window for security decision-making, and then taking targeted preventive measures to reduce security risks. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0034] Figure 1 This is one of the flow charts of the dynamic security method based on big data provided by the present invention;

[0035] Figure 2 This is the second flow chart of the dynamic security method based on big data provided by the present invention;

[0036] Figure 3 It is a structural diagram of the dynamic security system based on big data provided by the present invention;

[0037] FIG4 is a schematic structural diagram of an electronic device provided by the present invention. DETAILED DESCRIPTION

[0038] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0039] The following combination Figure 1 - Figure 4 describes the big data-based dynamic security method and system of the present invention.

[0040] As shown in FIG1 , an embodiment of the present invention provides a dynamic security method based on big data, which can be executed by a corresponding dynamic security system based on big data. The method mainly includes steps 110 , 120 , 130 and 140 .

[0041] In step 110 , the security data to be processed collected at the target location is input into the dynamic spatiotemporal baseline model to identify initial abnormal events that deviate from the normal state.

[0042] The dynamic spatiotemporal baseline model is trained based on the historical time series of different data sources of the target field.

[0043] The dynamic spatiotemporal baseline model is the "brain" of the system's environmental perception. It's not a static model, but rather a dynamic model describing the "normal state" by continuously learning from historical data from various sensors (such as cameras and access control systems) within target locations (such as warehouses and campuses). This "normal" state is spatially and temporally defined. For example, an office building is typically bustling with people during the day on weekdays, but should be static late at night or on weekends.

[0044] An initial anomaly event is any single event captured in real time that significantly deviates from the "normal" state defined by the dynamic spatiotemporal baseline model. For example, if a thermal imager suddenly detects a moving heat source within a warehouse perimeter, which should be static in "night mode," this event is labeled an "initial anomaly event."

[0045] It continuously collects data from various sensors and extracts features, such as the number of people and vehicles and their movement trajectories from videos, and card swipe events from access control logs. Simultaneously, it compares these real-time features with an internal time-aware autoencoder network. If the reconstruction error of the real-time data exceeds the threshold set during training on the normal dataset, the system determines a deviation, generates an initial anomaly event, and records and stores metadata such as time, location, and type.

[0046] It's understandable that the dynamic spatiotemporal baseline model enables automated and intelligent detection of anomalies. It proactively identifies truly concerning "signals" from massive amounts of background data, replacing the traditional model where security personnel constantly stare at their screens. This significantly improves the efficiency and accuracy of early warnings, adapts to gradual environmental changes, and reduces false alarm rates.

[0047] Step 120 , using the initial abnormal event as an index, querying for associated event data from other data sources within the associated spatiotemporal range corresponding to the initial abnormal event.

[0048] The associated spatiotemporal range is a query window defined with the time and location of the initial abnormal event as the center point. For example, the area within 15 minutes before and after the initial event and within a spatial radius of 500 meters.

[0049] In some embodiments, the data source includes at least one of a surveillance camera, a thermal imager, an access control system, a network traffic monitor, an audio acquisition device, and a license plate acquisition system.

[0050] Surveillance cameras are devices used to capture video images. Thermal imagers are devices used to capture thermal imaging data and can be used to detect the presence and movement of people or objects. Access control systems are systems used to control access. Network traffic monitors are devices used to monitor network traffic and detect abnormal behavior. Audio capture devices are devices used to capture sound data and detect unusual sound events. License plate capture systems are systems used to identify vehicle license plates.

[0051] The system accesses multiple data sources, including video surveillance, access control, perimeter protection, and network security logs, through standard protocols (such as RTSP and ONVIF) or APIs. The system cleans, converts, and integrates this data into a unified format for subsequent analysis.

[0052] By integrating multiple data sources, the system can obtain more comprehensive and accurate security information, improve the detection rate of abnormal events and the accuracy of risk assessment.

[0053] Step 130 , according to the preset spatiotemporal association rules, confirm from the associated event data the historical standardized events associated with the initial abnormal event in the time dimension and the space dimension, and form the initial abnormal event and the historical standardized events into a candidate abnormal event chain.

[0054] As can be understood, by using pre-set spatiotemporal association rules, all retrieved related events are treated as nodes, and weighted edges are established between nodes based on spatiotemporal association rules, such as coordinated attack rules and reconnaissance and intrusion rules. In this way, multiple isolated and weak abnormal signals can be linked together to form one or more candidate abnormal event chains.

[0055] Spatiotemporal association rules can be a logical rule base constructed from security expert knowledge and historical data mining, used to define the strength of associations between different events. For example, the rule "Event A (network scan) and Event B (physical proximity to the computer room) have a strong logical association if they occur within 5 minutes of each other" can be used.

[0056] A candidate abnormal event chain is a logically connected sequence of events consisting of an initial abnormal event and multiple other events found within the associated spatiotemporal range and connected by spatiotemporal association rules. A candidate abnormal event chain is a potential threat storyline that needs to be verified and confirmed.

[0057] After receiving the initial abnormal event, using it as a clue, all other data sources can be queried based on the event, location, and type of the initial abnormal event within a set time and space range.

[0058] The system receives an initial abnormal event containing metadata such as time, location, and type. For example, in the "Potential Intrusion Risk Prediction for Unmanned Warehouses" scenario, this initial abnormal event might be "At 02:05 AM, a vehicle not on the whitelist was observed loitering at a low speed in the area of ​​the P1 perimeter camera."

[0059] Based on this, you can query all historical standardized events within the associated spatiotemporal range. You can use the time (02:05 AM) and space (P1 camera area) of the initial anomalous event as the center, and query the system's spatiotemporal database within a preset spatiotemporal range, for example, 5 minutes before and after the time, with a spatial radius of 50 meters. This query will retrieve event data from all sources and all types within this range, regardless of whether they are marked as anomalous.

[0060] Furthermore, spatiotemporal association rules can be applied to construct an event association graph. An event association graph is a network diagram in which each "node" represents an independent event (such as a wandering vehicle, abnormal access control, or abnormal sound), and the "directed edges" between nodes represent the associations between them.

[0061] Spatiotemporal association rules are the basis for connecting nodes. They are a logical rule base containing expert knowledge and are used to determine whether there is an association between two events and the strength of the association.

[0062] We can traverse all the events collected in the previous step and establish connections (i.e., edges in the graph) between them based on pre-defined "spatiotemporal association rules." These rules are mainly divided into two categories: general spatiotemporal proximity rules and specific logical rules based on expert knowledge.

[0063] The general spatiotemporal proximity rule is the most basic rule, which states that events occurring at similar times and locations are potentially related. For example, in a campus scenario, the "01:32 AM surveillance evasion behavior" and the "01:35 AM access control card swipe failure" are only three minutes apart and physically close to each other, so a strong correlation edge is established between them.

[0064] Specific logic rules based on expert knowledge are more advanced and intelligent rules that define the inherent logic of a specific type of event combination.

[0065] For example, specific logic rules based on expert knowledge can be set according to actual monitoring scenarios.

[0066] For example, for server rooms, you can set up coordinated attack rules. Specifically, a coordinated attack rule might be: If event A (type = network scan, target = server X) and event B (type = physical proximity, location = the room where server X is located) occur within a time window T (e.g., 5 minutes), then a "strong logical association" edge is established between events A and B, with a weight of w = 0.9.

[0067] For example, for areas with access control, you can set up reconnaissance and intrusion rules. Specifically, the reconnaissance and intrusion rules might be: If event A (Type = Suspicious Loitering, Area = Perimeter Z) is followed by event B (Type = Perimeter Sensor Trigger, Area = Perimeter Z) within a time window T' (e.g., 10 minutes), then a "medium logical association" edge is established between events A and B, with a weight of w = 0.7.

[0068] In the above embodiment, the chaotic event points can be organized into a structured logic line that can be understood by a computer through meaningful logical rules, revealing the potential intentions and patterns that cannot be reflected by a single event.

[0069] It can be understood that in this embodiment, isolated, potentially ignored, low-priority abnormal events or events that are not identified as abnormal events in traditional security systems can be intelligently synthesized into a threat event chain with strong logical associations and high confidence, greatly improving the ability to understand complex or non-obvious abnormal behaviors.

[0070] Step 140: Confirm the candidate abnormal event chains, and for the confirmed abnormal event chains, predict the high-level risk events that the abnormal event chains may evolve into based on the preset risk knowledge graph, and determine the response measures for the high-level risk events.

[0071] The risk knowledge graph is a structured knowledge base used to describe various security risks and their evolutionary paths. Nodes in the graph represent various events, assets, and consequences, while edges represent the causal or logical relationships between them.

[0072] A high-level risk event refers to a more serious security event that may evolve from the current event chain, as predicted by the risk knowledge graph, such as evolving from "suspicious wandering" to "burglary."

[0073] For high-level risk events, the system recommends actions to be taken, such as dispatching patrols, locking down target areas, etc.

[0074] After receiving a real-world abnormal event chain, the system uses its built-in risk knowledge graph or sequence prediction model to perform logical deductions. It predicts the most likely high-level risk event that the event chain will evolve into in the future and quantifies the risk type, probability of occurrence, possible time window, and recommended intervention measures. The final warning information is then output to the security control center or automated response system.

[0075] According to the big data-based dynamic security method provided by the embodiment of the present invention, after the initial abnormal event is identified through the dynamic spatiotemporal baseline model, historical standardized events can be identified from multiple isolated and weak abnormal signals, and then these events can be connected into a candidate abnormal event chain. It can accurately discover potential threats from hidden event information in advance, obtain more accurate security identification results, and realize the fundamental transformation from post-event response to pre-event warning, providing a valuable early intervention window for security decision-making, and then taking targeted preventive measures to reduce security risks.

[0076] In some embodiments, the abnormal event chain includes events associated with the target object. Before confirming the candidate abnormal event chain, the big data-based dynamic security method further includes steps 210, 220, and 230.

[0077] Step 210, determining a pre-calibrated visual monitoring fuzzy area in the target location;

[0078] Step 220 , based on the associated event data corresponding to the target object, determining the potential activity area of ​​the target object from the visual monitoring fuzzy area, and determining the potential activity trajectory of the target object;

[0079] Step 230 : Determine a supplementary event based on the potential activity trajectory of the target object and insert it into the candidate abnormal event chain.

[0080] Visual surveillance blur areas are areas that cannot be clearly covered by surveillance cameras due to occlusion, angle, equipment failure, etc., such as corners of buildings, areas blocked by trees, etc.

[0081] The target object is a person or object that requires special attention, such as high-value assets, personnel, etc.

[0082] Security personnel can manually mark blind spots based on on-site inspections and historical data analysis. The system regularly checks camera status and automatically marks areas corresponding to faulty or offline cameras as blind spots. This approach compensates for blind spots in the surveillance system and ensures comprehensive monitoring of the target location.

[0083] The associated event data corresponding to the target object may include data from access control systems, infrared sensors, surveillance videos, etc., including the identity and location information of the target object.

[0084] The potential activity area is the area where the target object is likely to appear, based on its historical behavior patterns and current environment information. The potential activity trajectory is the movement path of the target object, based on the potential activity area and time information.

[0085] After receiving an initial abnormal event, the system uses this event as a central point to query data from other heterogeneous data sources within a pre-defined spatiotemporal neighborhood. For example, if a target object was last seen on surveillance footage moving toward a blind spot, the system will use its historical speed and direction to predict its likely path within the blind spot. These predicted trajectories are added as new "events" to the event chain, influencing subsequent risk assessments. Even within blind spots, the system can infer the target object's behavior, improving the detection rate of abnormal events.

[0086] In some embodiments, the associated event data corresponding to the target object includes at least one of: access control data of the target location, infrared data including the target object, surveillance video data including at least part of the target object, and preset rule data including the target object.

[0087] Access control data is access control system data that records the time and location of people entering and exiting. Infrared data is thermal imaging data collected by infrared sensors, which can be used to detect the presence and movement of people or objects. Surveillance video data is video images captured by surveillance cameras. Preset rule data is manually set rules that describe the normal behavior patterns of target objects, such as "a certain employee can only enter the office during working hours."

[0088] In the scenario of an area with access control, the above steps are automatically triggered when the system tracks the intruder's video trajectory at 01:32 AM and is interrupted at the edge of the "visual surveillance blur area #08".

[0089] In this case, the system can immediately query the spatiotemporal database for associated event data, centered around 01:32 AM and "Blurred Area #08." Access control data, infrared data, and other surveillance video data can be simultaneously queried. The system discovered that at 01:35 AM, the "warehouse" access control reader, located on the other side of "Blurred Area #08," recorded a failed swipe attempt with an invalid card. If a thermal imager or passive infrared detector is installed at the warehouse entrance, the system will also query for any abnormal heat source movement signals at similar times. Furthermore, the system can retrieve the target object's last image and movement direction as captured by the C5 camera before entering the blind spot.

[0090] In this case, the system acquires two key, high-confidence spatiotemporal anchors.

[0091] Anchor point A: 01:32 AM, the target is at the end of the C5 camera's field of view, at the entrance to the obscured area. Anchor point B: 01:35 AM, the target is at the warehouse entrance (where the access control card reader is located). The system draws an inferred path between these two anchor points, generating a potential trajectory for the target. This trajectory clearly shows that after entering the blind spot, the target did not leave, but instead crossed the area and headed straight for the warehouse entrance.

[0092] In this embodiment, a disappeared target can be relocated, and its true intention is revealed to be not random movement, but approaching a high-value target with a clear purpose. The certainty of non-video data (access control records) is utilized to make up for the lack of video data and reconstruct a complete chain of behavioral evidence.

[0093] In some embodiments, confirming a candidate abnormal event chain includes: based on at least one key event in the candidate abnormal event chain, determining an event verification rule corresponding to at least one key event from preset event verification rules; confirming the candidate abnormal event chain based on the event verification rule corresponding to at least one key event; the event verification rule includes at least one of a physical logic verification rule, an authority verification rule, and a state consistency verification rule.

[0094] A key event refers to an event in the event chain that has a significant impact on risk assessment, such as "illegal break-in" or "attempt to crack passwords."

[0095] Physical logic verification rules are used to check whether the behaviors in the event chain conform to physical laws and logic, such as "it is impossible for a person to move from point A to point B, which is a long distance away, in a short time."

[0096] Permission verification rules are used to check whether the behavior in the event chain complies with the rules set by the permission, such as "unauthorized personnel cannot enter the computer room."

[0097] State consistency check rules are used to check whether the states of entities involved in an event chain are consistent, for example, "a laptop taken out of the company must be in a borrowed state."

[0098] The system pre-establishes an event verification rule library, which contains various physical logic verification rules, permission verification rules and status consistency verification rules.

[0099] The system analyzes each event in the event chain and determines the corresponding verification rules. For example, if the event chain includes the event "people move across floors in a short period of time", the "physical logic verification rules" will be applied for verification.

[0100] In this embodiment, illogical or unauthorized event chains can be identified or filtered out, thereby improving recognition capabilities or reducing false positives, thereby improving the accuracy of risk assessment.

[0101] In some embodiments, confirming the candidate abnormal event chain includes: packaging the candidate abnormal event chain into confirmation task information, sending it to the administrator, and receiving feedback information from the administrator; the confirmation task information also includes event data corresponding to each task in the candidate abnormal event chain.

[0102] The manual review process needs to first confirm the confirmation task information, which includes a comprehensive information package of event chain description, relevant data (such as video screenshots, sensor data) and preliminary risk assessment.

[0103] The administrator is the security personnel or person in charge of security monitoring and incident response. Feedback information is the administrator's judgment (confirmation / denial) of the event chain and his or her handling opinions.

[0104] If the system cannot automatically confirm an event chain (for example, due to low confidence), the event chain can be packaged as a "confirmation task" and sent to the administrator via the mobile app or security control center. Alternatively, the event chain can be packaged as a "confirmation task" and sent to the administrator via the mobile app or security control center when the administrator is online, thereby ensuring the accuracy of task chain identification.

[0105] Administrators can review task information and analyze relevant data to determine whether the chain of events constitutes a real threat. Administrators provide feedback to the system, leveraging human experience and judgment to handle complex or ambiguous events, avoiding overreactions or underreporting due to automation errors.

[0106] In some embodiments, determining response measures for high-level risk events includes: matching corresponding response measures from a preset emergency plan library based on the spatiotemporal trajectory of the high-level risk event and the event types involved, the response measures including at least one of optimizing patrol routes for security personnel, prioritizing review of surveillance screen lists, controlling the operation of warning lights or alarm devices, and controlling the locking of automatic doors.

[0107] The emergency plan library is a knowledge base that contains various security risks and their corresponding response measures.

[0108] For example, patrol routes can be optimized, planning optimal patrol routes for security personnel based on the location and time of risk events. Prioritized surveillance footage lists can also be used, recommending a list of key surveillance cameras to security personnel based on the type and location of risk events.

[0109] An emergency plan library can be pre-built in the system, containing various risk events and their corresponding response measures. When the system predicts a high-level risk event, it matches the most appropriate response measures in the emergency plan library based on its spatiotemporal trajectory and event type.

[0110] For example, if the system predicts the risk of intrusion or theft, it will recommend measures such as "dispatching a patrol to the target area" or "locking all access control points in the target building." The system pushes these measures to security personnel, assisting them in decision-making and enabling them to quickly and accurately formulate response measures to minimize security risks.

[0111] The following example illustrates the discovery of an abnormal event chain using the possibility that high-value items may be stolen from a warehouse.

[0112] 02:05 AM: The system detected an anomaly in the video data from camera P1. Feature extraction revealed a vehicle not on the whitelist was loitering at a low speed on the road behind the warehouse, significantly deviating from the Night Mode baseline. The system generated an "Initial Anomaly: Suspicious Loitering Vehicle" report.

[0113] 02:10 AM: After receiving the anomaly, the system queries the associated data and discovers that the network firewall logs indicate a port scan activity at 02:09 AM from an unknown IP address, targeting the warehouse's inventory management server.

[0114] 02:15AM: The system further correlated that the T1 thermal imaging sensor located near the fence behind the warehouse captured a short, moving, weak heat signal at 02:14AM, the morphology of which did not match the known small animal heat signature pattern.

[0115] The system can construct a candidate abnormal event chain: [02:05, P1, vehicle wandering], [02:09, network, port scan], [02:14, T1, abnormal heat source]. This chain is closely connected in time and highly logically related (external reconnaissance, network detection, physical proximity), confirming it as an abnormal event chain.

[0116] The system identified the above chain of events, and its built-in risk knowledge graph contained a path: [Reconnaissance], [Network Probe], [Perimeter Approach], [Physical Intrusion], [Theft of High-Value Items]. This chain of events perfectly matched the first three steps of this path. Based on this, the system deduced that the next step was highly likely to be a "physical intrusion," ultimately leading to "theft of high-value items."

[0117] The system immediately generates a top-priority alert and pushes it to the security center's large screen, displaying recommended actions: immediately dispatch security personnel to the rear of the supervised area; remotely lock all warehouse doors within the supervised area; and alert security personnel to immediately conduct patrols.

[0118] The following describes the dynamic security system based on big data provided by the present invention. The dynamic security system based on big data described below and the dynamic security method based on big data described above can refer to each other.

[0119] like Figure 3 As shown, the big data-based dynamic security system provided by the embodiment of the present invention mainly includes a first processing module 310 , a second processing module 320 and a third processing module 330 .

[0120] The first processing module 310 is used to input the security data to be processed collected at the target location into a dynamic spatiotemporal baseline model to identify initial abnormal events that deviate from the normal state; the dynamic spatiotemporal baseline model is trained based on historical time series of different data sources at the target location;

[0121] The second processing module 320 is configured to use the initial abnormal event as an index and query associated event data from other data sources within the associated spatiotemporal range corresponding to the initial abnormal event;

[0122] The third processing module 330 is used to identify historical standardized events associated with the initial abnormal event in the time dimension and space dimension from the associated event data according to the preset spatiotemporal association rules, and to form a candidate abnormal event chain with the initial abnormal event and the historical standardized events;

[0123] The fourth processing module 340 is used to confirm the candidate abnormal event chain, predict the high-level risk event that the confirmed abnormal event chain will evolve into based on the preset risk knowledge graph, and determine the response measures for the high-level risk event.

[0124] According to the big data-based dynamic security system of the embodiment of the present invention, after identifying the initial abnormal event through the dynamic spatiotemporal baseline model, it can identify historical standardized events from multiple isolated and weak abnormal signals, and then connect these events into a candidate abnormal event chain. It can accurately discover potential threats from hidden event information in advance, obtain more accurate security identification results, and realize the fundamental transformation from post-event response to pre-event warning, providing a valuable early intervention window for security decision-making, and then can take targeted preventive measures to reduce security risks.

[0125] Figure 4 An example of a physical structure diagram of an electronic device is shown below. Figure 4As shown, the electronic device may include: a processor 410, a communication interface 420, a memory 430, and a communication bus 440, wherein the processor 410, the communication interface 420, and the memory 430 communicate with each other via the communication bus 440. The processor 410 may call logic instructions in the memory 430 to execute a dynamic security method based on big data, which includes: inputting security data to be processed collected at a target location into a dynamic spatiotemporal baseline model to identify initial abnormal events that deviate from a normal state; the dynamic spatiotemporal baseline model is trained based on historical time series from different data sources of the target location; using the initial abnormal event as an index, querying associated event data from other data sources within the associated spatiotemporal range corresponding to the initial abnormal event; identifying historical standardized events associated with the initial abnormal event in time and space dimensions from the associated event data based on preset spatiotemporal association rules, and forming a candidate abnormal event chain with the initial abnormal event and the historical standardized events; confirming the candidate abnormal event chain, and predicting the high-level risk event that the actual abnormal event chain will evolve into based on a preset risk knowledge graph for the confirmed abnormal event chain, and determining response measures for the high-level risk event.

[0126] Furthermore, the logic instructions in the aforementioned memory 430 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product, stored in a storage medium, includes instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0127] On the other hand, the present invention also provides a computer program product, which includes a computer program, which can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the dynamic security method based on big data provided by the above methods, the method including: inputting the security data to be processed collected at the target location into a dynamic spatiotemporal baseline model to identify initial abnormal events that deviate from the normal state; the dynamic spatiotemporal baseline model is obtained by training the historical time series of different data sources of the target field; using the initial abnormal event as an index, querying the associated event data from other data sources within the associated spatiotemporal range corresponding to the initial abnormal event; according to the preset spatiotemporal association rules, confirming the historical standardized events associated with the initial abnormal event in the time dimension and the spatial dimension from the associated event data, and forming the initial abnormal event and the historical standardized events into a candidate abnormal event chain; confirming the candidate abnormal event chain, and for the confirmed abnormal event chain, predicting the high-level risk event evolved from the real abnormal event chain based on the preset risk knowledge graph, and determining the response measures for the high-level risk event.

[0128] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the big data-based dynamic security method provided by the above-mentioned methods, the method comprising: inputting the security data to be processed collected at the target location into a dynamic spatiotemporal baseline model to identify initial abnormal events that deviate from the normal state; the dynamic spatiotemporal baseline model is obtained by training based on the historical time series of different data sources of the target field; using the initial abnormal event as an index, querying the associated event data from other data sources within the associated spatiotemporal range corresponding to the initial abnormal event; according to preset spatiotemporal association rules, confirming the historical standardized events associated with the initial abnormal event in the time dimension and the spatial dimension from the associated event data, and forming the initial abnormal event and the historical standardized events into a candidate abnormal event chain; confirming the candidate abnormal event chain, and for the confirmed abnormal event chain, predicting the high-level risk event evolved from the real abnormal event chain based on the preset risk knowledge graph, and determining the response measures for the high-level risk event.

[0129] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units. That is, they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0130] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods of each embodiment or certain portions of the embodiments.

[0131] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A dynamic security method based on big data, characterized in that: include: Input the security data collected at the target location into the dynamic spatiotemporal baseline model to identify initial abnormal events that deviate from the normal state; The dynamic spatiotemporal baseline model is obtained by training based on historical time series of different data sources of the target field; Using the initial abnormal event as an index, querying for associated event data from other data sources within the associated spatiotemporal range corresponding to the initial abnormal event; According to a preset spatiotemporal association rule, historical standardized events associated with the initial abnormal event in the temporal and spatial dimensions are identified from the associated event data, and the initial abnormal event and the historical standardized events are combined into a candidate abnormal event chain; Confirm the candidate abnormal event chain, and for the confirmed abnormal event chain, predict the high-level risk event that the abnormal event chain may evolve into based on the preset risk knowledge graph, and determine the response measures for the high-level risk event; The abnormal event chain includes events associated with the target object. Before confirming the candidate abnormal event chain, the method further includes: Determining a pre-calibrated visual surveillance fuzzy area in the target location; Based on the associated event data corresponding to the target object, determining a potential activity area of ​​the target object from the visual monitoring fuzzy area, and determining a potential activity trajectory of the target object; A supplementary event is determined based on the potential activity trajectory of the target object and inserted into the candidate abnormal event chain.

2. The dynamic security method based on big data according to claim 1, characterized in that: The associated event data corresponding to the target object includes: At least one of the access control data of the target place, the infrared data of the target object, the monitoring video data of at least part of the target object, and the preset rule data of the target object.

3. The big data-based dynamic security method according to claim 1 or 2, characterized in that: The confirming of the candidate abnormal event chain includes: Based on at least one key event in the candidate abnormal event chain, determining an event verification rule corresponding to the at least one key event from preset event verification rules; The candidate abnormal event chain is confirmed based on the event verification rule corresponding to the at least one key event; the event verification rule includes at least one of a physical logic verification rule, an authority verification rule and a state consistency verification rule.

4. The big data-based dynamic security method according to claim 1 or 2, characterized in that: The confirming of the candidate abnormal event chain includes: The candidate abnormal event chain is encapsulated as confirmation task information and sent to an administrator, and feedback information from the administrator is received; the task information also includes event data corresponding to each task in the candidate abnormal event chain.

5. The dynamic security method based on big data according to claim 1, characterized in that: Determining the response measures for the high-level risk event includes: Based on the spatiotemporal trajectory of the high-level risk event and the event types involved, corresponding response measures are matched from a preset emergency plan library. The response measures include at least one of optimizing the inspection route of security personnel, prioritizing the review of monitoring screen lists, controlling the operation of alarm devices, and controlling the locking of automatic doors.

6. The dynamic security method based on big data according to claim 1, characterized in that: The data source includes at least one of a surveillance camera, a thermal imager, an access control system, a network traffic monitor, an audio collection device, and a license plate collection system.

7. A dynamic security system based on big data, characterized in that: The first processing module is used to input the security data to be processed collected at the target location into the dynamic spatiotemporal baseline model to identify initial abnormal events that deviate from the normal state; The dynamic spatiotemporal baseline model is obtained by training based on historical time series of different data sources of the target field; A second processing module is configured to use the initial abnormal event as an index to query associated event data from other data sources within an associated spatiotemporal range corresponding to the initial abnormal event; a third processing module, configured to identify, from the associated event data, historical standardized events associated with the initial abnormal event in terms of time and space dimensions according to a preset spatiotemporal association rule, and to form a candidate abnormal event chain with the initial abnormal event and the historical standardized events; a fourth processing module configured to confirm the candidate abnormal event chain, predict the high-level risk event that the confirmed abnormal event chain may evolve into based on a preset risk knowledge graph, and determine response measures for the high-level risk event; the abnormal event chain includes events associated with a target object, and the fourth processing module is further configured to determine a pre-calibrated visual monitoring fuzzy area in the target location; Based on the associated event data corresponding to the target object, determining a potential activity area of ​​the target object from the visual monitoring fuzzy area, and determining a potential activity trajectory of the target object; A supplementary event is determined based on the potential activity trajectory of the target object and inserted into the candidate abnormal event chain.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor, characterized in that: When the processor executes the program, the dynamic security method based on big data as described in any one of claims 1 to 6 is implemented.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the dynamic security method based on big data as described in any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Event early warning method, device and equipment based on big data analysis and storage medium

    CN117171231A

  • Risk processing method and device, electronic equipment and storage medium

    CN117455235A