Network security threat intelligent detection method based on big data analysis
By constructing a spatiotemporal fusion matrix and dynamic feature dimension alignment mechanism, combining bionic optimization algorithm and multi-level confidence verification, the problems of single-dimensional log analysis and data fragmentation are solved, and efficient detection and adaptability of network security threats are achieved.
Patent Information
- Application Number
- CN202510861888.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2045-06-25
AI Technical Summary
There are problems in the prior art such as single-dimensional log analysis defects, dynamic and static data fragmentation and algorithm selection solidification, resulting in insufficient accuracy and adaptability of network security threat detection.
By constructing a spatiotemporal fusion matrix of network behavior, dynamic feature dimension alignment mechanism and adaptive tensor interpolation technology are adopted, and dynamically selecting the optimal threat detection algorithm is combined with a bionic optimization algorithm to realize the fusion of dynamic and static data and multi-level confidence verification, improving the accuracy and adaptability of detection.
It improves the attack path restoration capability of advanced sustainable threats, enhances the perception of complex threats, reduces the misjudgment rate, meets the real-time response needs, simplifies the deployment complexity of the defense system, and enhances the stability in the confrontation environment.
Smart Images

Figure CN120498872A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a method for intelligently detecting network security threats based on big data analysis. Background Art
[0002] Network security means that the hardware, software and data of the network system are protected from damage, change and leakage due to accidental or malicious reasons, and the system runs continuously, reliably and normally without interruption of network services.
[0003] However, the existing technology has the following problems: 1. One-dimensional log analysis defects; 2. Dynamic and static data separation; 3. Algorithm selection is solidified.
[0004] Therefore, the present invention provides a network security threat intelligent detection method based on big data analysis, which solves the above problems by collecting network device traffic log data, constructing a network behavior spatiotemporal fusion matrix and calling the optimal threat detection algorithm. Summary of the Invention
[0005] (1) Technical problems solved In response to the shortcomings of the existing technology, the present invention provides a network security threat intelligent detection method based on big data analysis, which solves the problems raised in the above background technology.
[0006] (2) Technical solution To achieve the above objectives, the present invention provides the following technical solutions: a method for intelligent detection of network security threats based on big data analysis, the method comprising the following steps: S1. Collect dynamic traffic log data of network devices and static baseline log data of assets; S2. Perform feature sampling dimension measurement processing on the dynamic traffic log data and the static baseline log data to generate dynamic traffic feature dimension data and static baseline feature dimension data; S3, judging feature dimension alignment based on the dynamic traffic feature dimension data and the static baseline feature dimension data, and generating feature dimension alignment identification data; if the dimensions are consistent, executing S5; S4. If the dimensions are inconsistent, use a tensor interpolation algorithm to adjust the feature dimensions of the static baseline log data to generate static baseline feature-adjusted data; S5. Perform feature fusion on the dynamic traffic log data, the static baseline log data, and the static baseline feature adjustment data based on timestamps to construct a network behavior spatiotemporal fusion matrix. S6. Matching the network behavior spatiotemporal fusion matrix with pre-stored standard threat feature matrices corresponding to multiple types of threat detection algorithms, and screening the optimal threat detection algorithm type through a bionic optimization algorithm; S7. Call the optimal threat detection algorithm to perform threat analysis on the network behavior spatiotemporal fusion matrix to generate a real-time threat map and disposal instructions.
[0007] Preferably, the S1 includes: S11, using distributed probes to collect five-tuple traffic data packets from network devices in operation, extracting session connection frequency, load entropy value, and protocol distribution vector, and generating dynamic traffic log data Q; S12. Extract asset port baselines, service dependency topology, and vulnerability fingerprint vectors through the configuration management database to generate static baseline log data R.
[0008] Preferably, the S2 includes: S21. Use a multi-scale sliding window to perform time slicing on Q, calculate the standard deviation of the sampling interval of the features in each time window, and generate dynamic traffic feature dimension data. ; S22. Perform topological feature analysis on R, extract dimension parameters of the asset service chain, and generate static baseline feature dimension data. .
[0009] Preferably, the S3 includes: S31, calculation and Euclidean distance ,in, is the dynamic traffic feature dimension data, It is the static baseline feature dimension data; S32, if , generate feature dimension alignment identification data And execute S5, where, is the preset dimension alignment threshold; Otherwise generate .
[0010] Preferably, the S4 includes: S41, when When , construct the feature tensor of the static baseline ,according to Perform high-order interpolation on the dimensions of : in, is the tensor interpolation function, is the interpolation target dimension; Generate static baseline characteristic adjustment data .
[0011] Preferably, the S5 includes: S51, will and and Align by time axis and construct a three-dimensional fusion matrix: in, is the network behavior spatiotemporal fusion matrix, For dynamic traffic data packet characteristics, For static service dependency topology features, is the dynamic load entropy characteristic, It is a static vulnerability fingerprint feature. Represents a tensor concatenation operation.
[0012] Preferably, the S6 includes: S61. Establish a threat detection algorithm feature library , Indicates the Standard threat feature matrix corresponding to the class algorithm; S62, calculated by improving the Osprey algorithm and Matching degree: Initialize the osprey population position: in is the feature dimension, is the position of the i-th individual in the osprey population in the d-dimensional space, is the lower boundary of the search space, is the upper boundary of the search space, A random number in the interval [0,1]; Exploration phase update location: in, is the current optimal solution, is the attack strength constant, A random number in the interval [0,1]; Development phase: refined search ,in is the number of iterations of the current algorithm; S63. Output optimal matching algorithm type identifier .
[0013] Preferably, the Osprey algorithm further includes: Introducing adaptive weights Control the search step size; in, is the space-time fusion matrix The information entropy value of is the maximum entropy value of the system; Define the fitness function: in, is the cosine similarity calculation, is a matrix and Frobenius norm of When the number of iterations When the elite retention mechanism is activated, the bottom 20% of individuals are replaced.
[0014] Preferably, the S7 includes: S71, will enter The corresponding detection engine performs threat pattern matching: in A threat signature pattern library; S72. Generate a threat map including attack paths and risk levels .
[0015] Preferably, the threat pattern matching process adopts a multi-level confidence verification mechanism, including: Primary verification layer: Generates candidate threat sets by performing regular matching through a pre-built threat rule library: in is the rule matching threshold, For the threat feature pattern library, is the rule matching score function; Intermediate verification layer: Perform behavioral chain analysis on candidate threat sets and calculate context relevance: in is the time decay function, is the behavior chain continuity indicator, is the completeness of the behavior chain, is the total length of the behavior chain; Advanced Validation Layer: Yes We perform adversarial sample testing based on the threat and verify the robustness by perturbation injection: in, To add disturbance After similarity calculation, is the original threat judgment result, is the threat pattern library capacity; Only when Output the final threat judgment.
[0016] (3) Beneficial effects Compared with the existing technology, the present invention provides a method for intelligent detection of network security threats based on big data analysis, which has the following beneficial effects: 1. Solve the core defects of multi-source log fusion Through the innovatively designed dynamic feature dimension alignment mechanism, the tensor structure mismatch problem caused by the difference in sampling frequency between asset static data and network traffic data in traditional solutions is overcome. Adaptive tensor interpolation technology is used to realize the mapping of dynamic and static logs in the time and space dimensions, reducing the systematic deviation during feature fusion and improving the accuracy of subsequent threat analysis.
[0017] 2. Enhanced awareness of complex threats By establishing a network behavior spatiotemporal fusion matrix, the asset service topology, vulnerability fingerprints and real-time traffic behavior are modeled in three dimensions for the first time. This matrix breaks through the limitations of traditional one-dimensional log analysis, characterizes the behavioral chain characteristics of attackers during lateral movement and privilege escalation, and improves the ability to restore the attack path of advanced persistent threats, especially for targeted attacks with long incubation periods and dispersed behaviors.
[0018] 3. Implement dynamic optimization of detection algorithms By building an intelligent algorithm decision engine, the bionic optimization algorithm matches the best detection model in real time, changing the technical route of traditional solutions that rely on fixed algorithms, and dynamically selecting detection strategies based on network behavior characteristics, it not only ensures the efficient identification of known threats, but also enhances the adaptability to new attacks, effectively responding to the attack challenges of massive variant threats.
[0019] 4. Optimize the reliability of full-chain verification Through an innovative multi-level confidence verification mechanism, from basic rule matching and behavior chain continuity analysis to adversarial robustness testing, the system reduces the false positive rate while ensuring the rigor of threat assessment conclusions. This mechanism particularly enhances the ability to identify carefully disguised evasive attacks and resolves the logical loopholes of traditional solutions in the threat verification link.
[0020] 5. Improve the system's real-time response performance Through the architectural design of online feature fusion and streaming processing, the redundant data preprocessing steps in traditional solutions are reduced. Based on parallel tensor calculation and optimization algorithm convergence strategy, efficient processing of the entire process from data collection to instruction generation is achieved, meeting the stringent requirements of critical infrastructure for timely threat response.
[0021] 6. Reduce the complexity of defense system deployment Through an integrated technical solution, the organic unification of dynamic and static defense elements is achieved, reducing the compatibility risks brought by enterprises deploying independent systems for log collection, asset scanning, and traffic analysis. The standardized data interface design between system modules reduces the difficulty of integration with existing security equipment and promotes the smooth evolution of the defense system towards intelligence.
[0022] 7. Strengthening technical resilience in adversarial environments By introducing a perturbation robustness testing mechanism, noise samples are actively injected to verify the stability of the detection conclusions. This mechanism identifies model deception behaviors implemented by attackers through subtle feature tampering, enabling the system to maintain stable detection performance in adversarial attack scenarios, filling the technical blind spots of current mainstream solutions. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 It is a schematic diagram of the overall method framework of the present invention. DETAILED DESCRIPTION
[0024] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0025] See also Figure 1 , a network security threat intelligent detection method based on big data analysis, comprising the following steps: S1. Collect dynamic traffic log data of network devices and static baseline log data of assets; S2. Perform feature sampling dimension measurement processing on the dynamic traffic log data and the static baseline log data to generate dynamic traffic feature dimension data and static baseline feature dimension data; S3, judging feature dimension alignment based on the dynamic traffic feature dimension data and the static baseline feature dimension data, and generating feature dimension alignment identification data; if the dimensions are consistent, executing S5; S4. If the dimensions are inconsistent, use a tensor interpolation algorithm to adjust the feature dimensions of the static baseline log data to generate static baseline feature-adjusted data; S5. Perform feature fusion on the dynamic traffic log data, the static baseline log data, and the static baseline feature adjustment data based on timestamps to construct a network behavior spatiotemporal fusion matrix. S6. Matching the network behavior spatiotemporal fusion matrix with pre-stored standard threat feature matrices corresponding to multiple types of threat detection algorithms, and screening the optimal threat detection algorithm type through a bionic optimization algorithm; S7, calling the optimal threat detection algorithm to perform threat analysis on the network behavior spatiotemporal fusion matrix, and generating a real-time threat map and disposal instructions; S1 includes: S11, using distributed probes to collect five-tuple traffic data packets from network devices in operation, extracting session connection frequency, load entropy value, and protocol distribution vector, and generating dynamic traffic log data Q; S12, extracting asset port baselines, service dependency topology, and vulnerability fingerprint vectors from the configuration management database to generate static baseline log data R; S2 includes: S21. Use a multi-scale sliding window to perform time slicing on Q, calculate the standard deviation of the sampling interval of the features in each time window, and generate dynamic traffic feature dimension data. ; S22. Perform topological feature analysis on R, extract dimension parameters of the asset service chain, and generate static baseline feature dimension data. ; S3 includes: S31, calculation and Euclidean distance ,in, is the dynamic traffic feature dimension data, It is the static baseline feature dimension data; S32, if , generate feature dimension alignment identification data And execute S5, where, is the preset dimension alignment threshold; Otherwise generate ; S4 includes: S41, when When , construct the feature tensor of the static baseline ,according to Perform high-order interpolation on the dimensions of : in, is the tensor interpolation function, is the interpolation target dimension; Generate static baseline characteristic adjustment data ; S5 includes: S51, will and and Align by time axis and construct a three-dimensional fusion matrix: in, is the network behavior spatiotemporal fusion matrix, For dynamic traffic data packet characteristics, For static service dependency topology features, is the dynamic load entropy characteristic, It is a static vulnerability fingerprint feature. Represents a tensor concatenation operation; S6 includes: S61. Establish a threat detection algorithm feature library , Indicates the Standard threat feature matrix corresponding to the class algorithm; S62, calculated by improving the Osprey algorithm and Matching degree: Initialize the osprey population position: in is the feature dimension, is the position of the i-th individual in the osprey population in the d-dimensional space, is the lower boundary of the search space, is the upper boundary of the search space, A random number in the interval [0,1]; Exploration phase update location: in, is the current optimal solution, is the attack strength constant, A random number in the interval [0,1]; Development phase: refined search ,in is the number of iterations of the current algorithm; S63. Output optimal matching algorithm type identifier ; The Osprey algorithm also includes: Introducing adaptive weights Control the search step size; in, is the space-time fusion matrix The information entropy value of is the maximum entropy value of the system; Define the fitness function: in, is the cosine similarity calculation, is a matrix and Frobenius norm of When the number of iterations When the number of individuals in the last 20% is reached, the elite retention mechanism is activated to replace the last 20% of individuals; S7 includes: S71, will enter The corresponding detection engine performs threat pattern matching: in A threat signature pattern library; S72. Generate a threat map including attack paths and risk levels ; The threat pattern matching process uses a multi-level confidence verification mechanism, including: Primary verification layer: Generates candidate threat sets by performing regular matching through a pre-built threat rule library: in is the rule matching threshold, For the threat feature pattern library, is the rule matching score function; Intermediate verification layer: Perform behavioral chain analysis on candidate threat sets and calculate context relevance: in is the time decay function, is the behavior chain continuity indicator, is the completeness of the behavior chain, is the total length of the behavior chain; Advanced Validation Layer: Yes We perform adversarial sample testing based on the threat and verify the robustness by perturbation injection: in, To add disturbance After similarity calculation, is the original threat judgment result, is the threat pattern library capacity; Only when Output the final threat judgment.
[0026] Example 1: Actual deployment scenario of a financial data center Step 1: Multi-source log collection and feature extraction A distributed probe cluster deployed in the core switching area captures east-west traffic in real time and extracts dynamic traffic logs at a 5-second interval. The specific implementation is as follows: By parsing quintuple information from VXLAN encapsulated traffic, calculating the session connection frequency, and analyzing load characteristics using the Shannon entropy formula, we discovered that the load entropy value of a certain Kafka producer suddenly dropped to 0.3. We then simultaneously retrieved asset static data from the CMDB, confirming that the server corresponding to the IP address had opened non-essential API ports and contained an unpatched Log4j vulnerability.
[0027] Step 2: Feature dimension alignment and fusion When the dynamic traffic log sampling interval conflicts with the static scanning period: The Euclidean distance between the protocol distribution vector of dynamic traffic and the static baseline is calculated to be 32.7, and third-order tensor interpolation is initiated: the 19-dimensional topological features of the static baseline service are interpolated with cubic spline based on the dynamic traffic timeline to generate dimensionally adapted adjustment data. A spatiotemporal fusion matrix is constructed at the 9:15:03 timestamp to associate the abnormal connection frequency in the dynamic traffic with the static vulnerability fingerprint.
[0028] Step 3: Dynamic matching of detection algorithms The algorithmic decision engine executes the Osprey optimization algorithm: Initialize 30 algorithm agents. During the exploration phase, calculate the cosine similarity of the current spatiotemporal matrix. The GNN algorithm becomes the optimal solution with a match of 0.92. During the development phase, refine the search parameters within the GNN neighborhood and adjust the node aggregation function to GraphSAGE to improve the accuracy of lateral movement attack path identification. Output the final algorithm type identifier G_alg="GNN_GraphSAGE_V3".
[0029] Step 4: Threat Assessment and Response Call the selected detection model to perform multi-level verification: Primary verification: matches CobaltStrike attack signatures with a confidence level of 85%. Intermediate verification: analyzes the continuity of the behavior chain: external scanning of port 8085 at 9:12:17, implantation of a Webshell using the Log4j vulnerability at 9:14:53, lateral movement initiated at 9:15:01, and behavior chain integrity ρ=0.89. Advanced verification: after injecting Gaussian noise, the attack path identification results remain stable, generating a threat map including: attack path: [external IP] → [vulnerable server] → [database cluster]. Risk level: severe. Real-time triggering of disposal instructions: isolating the infected server and blocking the ASN segment of the malicious IP. Step 5: Dynamic system tuning In continuous operation: When a DNS covert tunnel attack is detected, the characteristic entropy value exceeds the limit, triggering the algorithm reselection mechanism. The adaptive weight ω is adjusted from 0.6 to 0.78 to enhance the sensitivity to payload characteristics, and the threat rule library incrementally updates the CNAME masquerade attack characteristics.
[0030] Example 2: Defending a Commercial Bank’s Data Center against Ransomware Attacks Step 1: Collaborative collection of dynamic and static logs The security probe cluster captures abnormal encrypted traffic on the core switch mirror port, triggering the multi-source collection mechanism: Dynamic traffic layer: Real-time analysis of the SSL handshake protocol revealed that 17 intranet IP addresses initiated TLS 1.3 connections to the same external domain name within 180 seconds. Each session lasted 8.2 seconds, with a constant payload length of 512KB and a payload entropy value consistently below 0.45. Static asset layer: Linking with CMDB to extract the asset profile of the target server group confirmed that 12 of them were database nodes with unpatched SMBv3 vulnerabilities. The vulnerability fingerprint matched the exploitation characteristics of the ransomware Conti at a 91% match.
[0031] Step 2: Dynamic calibration of feature dimensions When the dynamic traffic sampling interval conflicts with the asset scanning cycle: Calculating the protocol distribution vector offset: The proportion of SMB protocol in dynamic traffic suddenly increased to 63%, and the Euclidean distance value reached 41.6; Perform tensor interpolation reconstruction: Perform cubic B-spline interpolation on the 25-dimensional features of the static asset topology according to the dynamic time window to generate feature-adjusted data with matching time resolution; Constructing a spatiotemporal threat matrix: At the timestamp 11:27:45.023, the encrypted connection patterns in the dynamic traffic are three-dimensionally correlated with the vulnerability exploitation features to form a 32×32×16 behavior tensor.
[0032] Step 3: Optimal detection algorithm matching Algorithmic decision engine operation improves Osprey optimization process: Initialization population: 50 algorithm agents. Exploration phase: Calculate the cosine similarity between the current behavior tensor and the standard threat matrix library. The knowledge graph algorithm is currently the best with a match of 0.89. Development phase: Adjust the relationship extraction depth to level three within the knowledge graph neighborhood, identify abnormal encrypted propagation paths between database nodes, and output the algorithm identifier: KG_DeepLink_V2.
[0033] Step 4: Multi-level threat verification Start the three-level confidence verification chain: Rule matching layer: hits ransomware behavior rule RL0723, with an original confidence of 83%; Behavior chain analysis layer: Exploited the SMBv3 vulnerability to break through the border firewall at 11:25:11, moved laterally to the database cluster at 11:26:29, and began to encrypt system files at 11:27:32. The behavior chain integrity ρ=0.92; Adversarial robustness test layer: Injected protocol confusion noise and injected payload perturbations, the attack path identification results remained unchanged, and the robustness score reached 0.93.
[0034] Step 5: Response, Disposition and Evolution Generate in-depth threat maps and perform blocking: Attack path: [Overseas C2] → [Border Server] → [Database Cluster] → [Backup Storage], Risk Mark: Severe, Real-time Disposal Action: Automatically isolate 12 infected nodes, block malicious domain name resolution, and activate backup verification mechanism; Dynamic system optimization: When a new vulnerability exploit is detected, the adaptive weight ω is increased from 0.7 to 0.85, and the incremental learning module captures new features of encrypted traffic.
[0035] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.
[0036] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A method for intelligent detection of network security threats based on big data analysis, characterized by: The method comprises the following steps: S1. Collect dynamic traffic log data of network devices and static baseline log data of assets; S2. Perform feature sampling dimension measurement processing on the dynamic traffic log data and the static baseline log data to generate dynamic traffic feature dimension data and static baseline feature dimension data; S3, judging feature dimension alignment based on the dynamic traffic feature dimension data and the static baseline feature dimension data, and generating feature dimension alignment identification data; if the dimensions are consistent, executing S5; S4. If the dimensions are inconsistent, use a tensor interpolation algorithm to adjust the feature dimensions of the static baseline log data to generate static baseline feature-adjusted data; S5. Perform feature fusion on the dynamic traffic log data, the static baseline log data, and the static baseline feature adjustment data based on timestamps to construct a network behavior spatiotemporal fusion matrix. S6. Matching the network behavior spatiotemporal fusion matrix with pre-stored standard threat feature matrices corresponding to multiple types of threat detection algorithms, and screening the optimal threat detection algorithm type through a bionic optimization algorithm; S7. Call the optimal threat detection algorithm to perform threat analysis on the network behavior spatiotemporal fusion matrix to generate a real-time threat map and disposal instructions.
2. The method for intelligent network security threat detection based on big data analysis according to claim 1, characterized in that: Said S1 comprises: S11, using distributed probes to collect five-tuple traffic data packets from network devices in operation, extracting session connection frequency, load entropy value, and protocol distribution vector, and generating dynamic traffic log data Q; S12. Extract asset port baselines, service dependency topology, and vulnerability fingerprint vectors through the configuration management database to generate static baseline log data R.
3. The method for intelligently detecting network security threats based on big data analysis according to claim 1, characterized in that: The S2 includes: S21. Use a multi-scale sliding window to perform time slicing on Q, calculate the standard deviation of the sampling interval of the features in each time window, and generate dynamic traffic feature dimension data. ; S22. Perform topological feature analysis on R, extract dimension parameters of the asset service chain, and generate static baseline feature dimension data. .
4. The method for intelligent network security threat detection based on big data analysis according to claim 1, characterized in that: The S3 includes: S31, calculation and Euclidean distance ,in, is the dynamic traffic feature dimension data, It is the static baseline feature dimension data; S32, if , generate feature dimension alignment identification data And execute S5, where, is the preset dimension alignment threshold; Otherwise generate .
5. The method for intelligent network security threat detection based on big data analysis according to claim 1, characterized in that: The S4 includes: S41, when When , construct the feature tensor of the static baseline ,according to Perform high-order interpolation on the dimensions of : in, is the tensor interpolation function, is the interpolation target dimension; Generate static baseline characteristic adjustment data .
6. The method for intelligent network security threat detection based on big data analysis according to claim 1, characterized in that: The S5 includes: S51, will and and Align by time axis and construct a three-dimensional fusion matrix: in, is the network behavior spatiotemporal fusion matrix, For dynamic traffic data packet characteristics, For static services, the topology features are dependent on the is the dynamic load entropy characteristic, It is a static vulnerability fingerprint feature. Represents a tensor concatenation operation.
7. The method for intelligent network security threat detection based on big data analysis according to claim 1, characterized in that: The S6 includes: S61. Establish a threat detection algorithm feature library , Indicates the Standard threat feature matrix corresponding to the class algorithm; S62, calculated by improving the Osprey algorithm and Matching degree: Initialize the osprey population position: in is the feature dimension, is the position of the i-th individual in the osprey population in the d-dimensional space, is the lower boundary of the search space, is the upper boundary of the search space, A random number in the interval [0,1]; Exploration phase update location: in, is the current optimal solution, is the attack strength constant, A random number in the interval [0,1]; Development phase: refined search ,in is the number of iterations of the current algorithm; S63. Output optimal matching algorithm type identifier .
8. The method for intelligent network security threat detection based on big data analysis according to claim 7, characterized in that: The Osprey algorithm also includes: Introducing adaptive weights Control the search step size; in, is the space-time fusion matrix The information entropy value of is the maximum entropy value of the system; Define the fitness function: in, is the cosine similarity calculation, is a matrix and Frobenius norm of When the number of iterations When the elite retention mechanism is activated, the bottom 20% of individuals are replaced.
9. The method for intelligent network security threat detection based on big data analysis according to claim 1, characterized in that: The S7 includes: S71, will enter The corresponding detection engine performs threat pattern matching: in A threat signature pattern library; S72. Generate a threat map including attack paths and risk levels .
10. The method for intelligent network security threat detection based on big data analysis according to claim 9, characterized in that: The threat pattern matching process uses a multi-level confidence verification mechanism, including: Primary verification layer: Generates candidate threat sets by performing regular matching through a pre-built threat rule library: in is the rule matching threshold, For the threat feature pattern library, is the rule matching score function; Intermediate verification layer: Perform behavioral chain analysis on candidate threat sets and calculate context relevance: in is the time decay function, is the behavior chain continuity indicator, is the completeness of the behavior chain, is the total length of the behavior chain; Advanced Validation Layer: Yes We perform adversarial sample testing based on the threat and verify the robustness by perturbation injection: in, To add disturbance After similarity calculation, is the original threat judgment result, is the threat pattern library capacity; Only when Output the final threat judgment.
Citation Information
Patent Citations
APT attack detection method based on threat feature fusion and meta learning
CN116248367A
Air temperature refined monitoring method based on dynamic neighbor selection and space-time modeling
CN119375982A
Holographic road network and Internet of Vehicles fusion method and device, equipment and storage medium
CN119397480A
Network security situation generation method based on multi-view monitoring
CN119583219A
Software system development method based on multi-modal AI large model
CN120029605A
Cited By
Network security dynamic early warning method and system based on knowledge graph
CN120811768A
Intrusion detection system applied to network security field
CN121441596A
Self-learning optimization method and device for secure digital fingerprints
CN121598205A
Intelligent management and control system based on equipment identifier dynamic detection
CN121686526A
An intelligent management and control system based on device identification dynamic detection
CN121686526B