Network security multi-mode intelligent detection system and method

Through the multimodal data acquisition and comprehensive analysis of network security multimodal intelligent detection system, the limitations of traditional detection methods are solved, accurate monitoring and rapid response to network security of power distribution systems are achieved, and the accuracy of threat detection and system stability are improved.

CN120498904AInactive Publication Date: 2025-08-15GUO WANG ZHE JIANG SHENG DIAN LI YOU XIAN GONG SI CI XI SHI GONG DIAN GONG SI

Patent Information

Application Number
CN202510979751.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-16
Publication Date
2025-08-15
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively deal with complex and changeable network attacks. Traditional single data detection means cannot detect hidden malicious behavior in time or ignore abnormalities at the network level, and lack a comprehensive and intelligent detection system.

Method used

It provides a network security multimodal intelligent detection system, which collects network traffic, device characteristics and behavior data through the multimodal data acquisition module, uses the detection engine module to perform comprehensive analysis, combines rule matching and machine learning models, generates detection results, and conducts risk assessment and automated response through the decision-making and response module.

Benefits of technology

It realizes comprehensive monitoring and in-depth analysis of the network security status of the power distribution system, improves the accuracy and timeliness of threat detection, can promptly detect potential threats and take quick response measures, reduces the losses of security incidents, and enhances the stability of the system and the continuity of power supply.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498904A_ABST
    Figure CN120498904A_ABST
Patent Text Reader

Abstract

The invention provides a network security multi-mode intelligent detection system and method, relates to the technical field of network security management, and is applied to a power distribution system which comprises a communication device and a power distribution device. The network security multi-modal intelligent detection system comprises a multi-modal data acquisition module used for acquiring network flow data, equipment characteristic data and behavior data of a power distribution system; the detection engine module is used for analyzing and detecting the network flow data, the equipment characteristic data and the behavior data to obtain a detection result; and the decision and response module is used for performing risk assessment according to the detection result based on a preset risk assessment model to obtain a risk grading result and a response strategy. According to the invention, comprehensive monitoring and deep analysis of the network security condition of the power distribution system are realized. By integrating multi-modal data, the limitation of a traditional single data detection mode is effectively overcome, and the accuracy and timeliness of threat detection are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network security management, and in particular to a network security multimodal intelligent detection system and method. Background Art

[0002] With the rapid development of information technology, power distribution systems are increasingly relying on complex network architectures to achieve efficient power transmission and distribution control, which makes power distribution systems face increasingly severe cybersecurity threats.

[0003] Traditional network security detection methods, such as single-source network traffic monitoring, device signature recognition, or behavioral data analysis, are no longer able to cope with complex and ever-changing attack patterns. For example, relying solely on network traffic monitoring may not detect hidden malicious behavior in a timely manner, focusing solely on device signatures may miss dynamic attack behaviors, and behavioral data analysis alone may overlook network-level anomalies. Existing technologies lack a comprehensive, intelligent detection system. Summary of the Invention

[0004] The problem solved by the present invention is one or more of the above-mentioned problems in the prior art.

[0005] To solve the above problems, the present invention provides a network security multimodal intelligent detection system and method.

[0006] In a first aspect, the present invention provides a multimodal intelligent network security detection system, which is applied to a power distribution system, wherein the power distribution system includes a communication device and a power distribution device; the multimodal intelligent network security detection system includes: A multimodal data acquisition module, configured to collect network traffic data, device feature data, and behavior data of each device in the power distribution system; A detection engine module is used to analyze and detect the network traffic data, the device feature data, and the behavior data to obtain a detection result; Wherein, the detection engine module includes a rule matching unit, and the detection result includes a rule detection result; The rule matching unit is configured to process the network traffic data, the device feature data, and the behavior data based on a preset initial knowledge graph to obtain the rule detection result, including: Performing entity recognition on the network traffic data, the device feature data, and the behavior data to obtain an entity recognition result; Processing the entity recognition result based on a preset initial knowledge graph to obtain the rule detection result; The decision-making and response module is used to perform risk assessment based on the detection results based on a preset risk assessment model to obtain risk classification results and response strategies.

[0007] Optionally, the detection result includes an anomaly detection result and an identification result, and the detection engine module includes an anomaly detection unit and an identification unit: The anomaly detection unit is configured to perform feature extraction on the network traffic data, the device feature data, and the behavior data, respectively, to obtain first feature data, second feature data, and third feature data, and input the first feature data, the second feature data, and the third feature data into a preset anomaly detection model to obtain the anomaly detection result; The recognition unit is configured to process the network traffic data and the behavior data according to a preset recognition model to obtain the recognition result, wherein the recognition model is constructed based on a CNN network and an LSTM network; The rule matching unit is used to process the network traffic data, the device feature data and the behavior data based on a preset initial knowledge graph to obtain the rule detection result.

[0008] Optionally, the recognition result includes a classification result and a corresponding confidence level; and the processing of the network traffic data and the behavior data according to a preset recognition model to obtain the recognition result includes: Performing local feature extraction on the network traffic data through the CNN network to obtain temporary feature data; Performing time series modeling processing on the behavior data through the LSTM network to obtain dynamic behavior feature data; Fusing the temporary feature data and the dynamic behavior feature data to obtain comprehensive feature data; The comprehensive feature data is classified to obtain the classification result, and the corresponding confidence level is determined according to the abnormal probability of the classification result.

[0009] Optionally, the processing of the entity recognition result based on a preset initial knowledge graph to obtain the rule detection result includes: Determine a target device node and an attack pattern node set; the target device node is a device node in any of the entity recognition results; the attack pattern node set includes high-risk nodes in the initial knowledge graph; According to a preset search method, starting from the target device node, query all path data to each node in the attack pattern node set; Evaluate each path data to obtain a path risk assessment result; Based on a preset graph neural network, the target device node and the attack pattern node set are processed to obtain an anomaly recognition result; The path risk assessment result and the anomaly identification result are integrated to obtain the rule detection result.

[0010] Optionally, the preset graph neural network is used to process the target device node and the attack pattern node set to obtain an anomaly recognition result, including: Encoding the target device node and the attack pattern node set respectively to obtain corresponding feature codes and structure codes; Based on the graph neural network, all the feature codes and the structure codes are identified to obtain the abnormality identification result.

[0011] Optionally, the decision and response module includes a risk assessment and classification unit and an automated response and blocking unit; The risk assessment and grading unit is configured to perform risk assessment based on the risk assessment model and the detection results to obtain a risk grading result and a response strategy; The automated response and blocking unit is used to send execution instructions based on the risk grading result and the response strategy, and feed back the executed response results to the system log and management interface of the network security multimodal intelligent detection system.

[0012] Optionally, the decision and response module further includes a manual intervention and collaboration unit. The manual intervention and collaboration unit is used to interact with the management interface of the network security multimodal intelligent detection system and adjust the response strategy.

[0013] Optionally, the network security multimodal intelligent detection system further includes a preprocessing module, and the preprocessing module includes a data cleaning unit and a normalization unit; The data cleaning unit is used to clean the network traffic data, the device feature data and the behavior data to obtain processed data; The normalization unit is used to perform feature extraction on each processed data to obtain corresponding feature data, and perform normalization processing on each feature data to obtain corresponding feature vector data.

[0014] Optionally, the network security multimodal intelligent detection system further includes a storage and generation module and an alarm module; The storage and generation module is used to store various types of data and processing results generated during the operation of the network security multimodal intelligent detection system; The storage and generation module is also used to generate an operation report and a security analysis report of the network security multimodal intelligent detection system.

[0015] In a second aspect, the present invention provides a network security multimodal intelligent detection method, which is applied to the network security multimodal intelligent detection system. The network security multimodal intelligent detection method includes: Collect network traffic data, device feature data, and behavior data of each device in the power distribution system; Analyzing and detecting the network traffic data, the device characteristic data, and the behavior data to obtain a detection result; Based on the preset risk assessment model, risk assessment is performed according to the detection results to obtain risk grading results and response strategies.

[0016] The beneficial effects of the network security multimodal intelligent detection system and method of the present invention are: First, the multimodal data acquisition module, serving as the system's data source, is responsible for comprehensively collecting key data from the power distribution system, including network traffic data, device characteristics, and behavioral data. Network traffic data typically includes real-time capture of network data packets, such as IP addresses, port numbers, protocol types, traffic volume, and transmission frequency. Device characteristics often include information such as the MAC address, VID / PID, device model, operating system version, and installed software for various devices in the power distribution system.

[0017] Behavioral data can be collected by installing behavior monitoring plug-ins on the distribution system's terminal devices and network servers. This continuously records user operations, such as the timing, frequency, and sequence of file access, application launches, network connection establishment and disconnection, and USB device usage, to deeply capture user operating habits and abnormal behavior. This data comprehensively reflects network activity, device status, and user or system behavior patterns within the distribution system, providing a foundation for subsequent analysis and decision-making.

[0018] The detection engine module then performs comprehensive analysis and detection on the collected multi-source heterogeneous data. It uses multivariate analysis techniques to uncover potential threats and abnormal patterns in the data and generate accurate detection results.

[0019] Finally, the decision-making and response module receives the detection results and performs quantitative analysis based on a pre-set risk assessment model. Based on the threat indicators and risk characteristics in the detection results, this model calculates risk values, implements risk grading, and formulates response strategies that match the risk level, providing strong support for the stable operation of the distribution system.

[0020] Therefore, the system of the present invention enables comprehensive monitoring and in-depth analysis of the network security status of the power distribution system. By integrating multimodal data, it effectively overcomes the limitations of traditional methods, which typically set fixed thresholds based on a single data source (such as network traffic or device status) and fail to integrate multi-dimensional data for analysis. This improves the accuracy and timeliness of threat detection. It can promptly identify potential network security threats, such as malicious network attacks, abnormal device behavior, and illegal operations. Decision support based on risk assessment models enables precise risk quantification and hierarchical management. Automated response functions can rapidly block malicious connections and isolate infected devices, minimizing the losses caused by security incidents. The entire system improves the network security protection level of the power distribution system, enhances its ability to cope with complex and changing network threats, and ensures stable operation and continuous power supply. Compared with traditional manual response methods, the system's automated response mechanism reduces the frequency and workload of manual intervention, reducing the burden on operations and maintenance personnel. Furthermore, by learning from historical data through machine learning models, the system can predict potential risks in advance, reduce the occurrence of recurring security incidents, and further reduce operations and maintenance costs. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 This is one of the structural diagrams of a multimodal intelligent network security detection system according to an embodiment of the present invention; Figure 2 This is a second structural diagram of a multimodal intelligent network security detection system according to an embodiment of the present invention; Figure 3 The figure is a flow chart of a multi-modal intelligent network security detection method according to an embodiment of the present invention. DETAILED DESCRIPTION

[0022] To make the above-mentioned objects, features, and advantages of the present invention more clearly understood, specific embodiments of the present invention are described in detail below with reference to the accompanying drawings. Although certain embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as being limited to the embodiments described herein. Instead, these embodiments are provided to provide a more thorough and complete understanding of the present invention. It should be understood that the drawings and embodiments of the present invention are for illustrative purposes only and are not intended to limit the scope of protection of the present invention.

[0023] It should be understood that the various steps described in the method embodiments of the present invention may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this respect.

[0024] The term "including" and its variations used in this document are open inclusions, that is, "including but not limited to"; the term "based on" means "based at least in part on"; the term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one other embodiment"; the term "some embodiments" means "at least some embodiments"; the term "optionally" means "optional embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts of "first", "second", etc. mentioned in the present invention are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0025] It should be noted that the modifications of "one" and "multiple" mentioned in the present invention are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".

[0026] The names of the messages or information exchanged between multiple devices in the embodiments of the present invention are only used for illustrative purposes and are not used to limit the scope of these messages or information.

[0027] like Figure 1 As shown, an embodiment of the present invention provides a multi-modal intelligent network security detection system, which is applied to a power distribution system. The power distribution system includes communication equipment and power distribution equipment. The multi-modal intelligent network security detection system includes: The multimodal data acquisition module is used to collect network flow data, device feature data and behavior data of the power distribution system.

[0028] Specifically, the network traffic data collection part: the network traffic data of the distribution equipment includes the network traffic data of the substation equipment, the medium-voltage distribution line communication traffic and the low-voltage distribution network communication traffic. Among them, the network traffic data of the substation equipment, that is, the internal communication traffic of the substation: collects the communication traffic between the main transformer, high-voltage switchgear, protection relays, distribution transformers and other equipment and the monitoring system, including equipment status information, protection signals, control instructions, etc. Medium-voltage distribution line communication traffic: collects the line status information (such as switch status, fault alarm) and control instructions of the ring network cabinet and pole-mounted switchgear. Low-voltage distribution network communication traffic: collects user electricity consumption data (such as electricity consumption, power, voltage, current) uploaded by smart meters and the operating data of distributed energy equipment (such as photovoltaic inverters and wind turbines).

[0029] Collection method: Deploy network traffic monitoring equipment at key network nodes (such as substation network switches and ring main unit communication interfaces) and capture network traffic data using port mirroring (e.g., SPAN port). Use traffic analysis tools (e.g., Wireshark, tcpdump) to analyze the captured traffic data and extract key features such as packet size, transmission frequency, and protocol type. This data includes the packet's source / destination IP address, port number, transport layer protocol (TCP / UDP), packet size, and transmission timestamp.

[0030] Network traffic data from communications equipment, specifically the communication traffic between the substation and the higher-level grid dispatch center, collects real-time operating data (such as voltage, current, and power) uploaded by the substation to the dispatch center, as well as dispatch instructions received. Communications equipment also includes monitoring devices, such as computers and various storage devices (USB flash drives). This information primarily includes the device's MAC address, hardware identifier (VID / PID), device model, operating system version, and installed software. This data helps accurately identify and manage devices on the network, and understands their operating environment and potential vulnerabilities.

[0031] Equipment characteristic data collection primarily includes: main transformers: model, capacity, rated voltage, age, and equipment identification (e.g., asset number). High-voltage switchgear: model, rated voltage, rated current, circuit breaker trip counts, etc. Protection relays: model, protection functions (e.g., overcurrent protection, overvoltage protection), and software version. Distribution transformers: model, capacity, rated voltage, and age. Ring main units and pole-mounted switchgear: model, switch type, rated voltage, and rated current. Smart meters and distributed energy devices: model, metering accuracy, communication protocol, software version, rated power, and conversion efficiency. Collection method: Regularly scan and obtain basic device information, operating parameters, and configuration status through the device's built-in management interface (e.g., SNMP, Modbus) or API. Collected data is synchronized to a central database to create a device characteristic profile. Monitoring devices includes MAC addresses, hardware identifiers (VID / PID), device models, operating system versions, and installed software. This data helps accurately identify and manage devices on the network, and understands their operating environment and potential vulnerabilities. That is, the data content mainly includes device model, specification parameters, operating parameters (such as temperature, current, voltage), software version, configuration information (such as network configuration, security policy), etc.

[0032] Behavioral data collection focuses on user or system operations within the power distribution system, such as file access records, application startup and shutdown operations, network connection establishment and disconnection, and USB device usage. By recording the time, frequency, and sequence of these behaviors, a complete behavioral data sequence is generated, enabling analysis of user operation patterns and system behavioral characteristics. This collection method involves installing a behavior monitoring plug-in on devices to record device operations, fault records, and maintenance logs in real time. This behavioral data is collected through a device management system or log server, and time series analysis is performed.

[0033] The comprehensive data collection capabilities of the multimodal data acquisition module provide a solid data foundation for the distribution system's cybersecurity protection, significantly improving the system's monitoring sophistication and threat detection capabilities. Network traffic data collection accurately captures signs of abnormal network communication, such as unusual traffic spikes and suspicious external connections, which is crucial for defending against cyberattacks. Device signature data collection enables precise control and vulnerability assessment of devices within the distribution system, quickly locating devices with security risks and implementing appropriate measures, such as updating or remediating vulnerabilities, to mitigate the risk of attack. Behavioral data collection focuses on user and system operations, enabling timely detection of potential internal violations or malicious actions by external attackers within the system, such as unauthorized file access and malware installation. The integration of these three types of data provides comprehensive insight into the distribution system's cybersecurity posture, enabling early warning and precise location of potential threats. This provides rich and accurate data support for subsequent in-depth detection, analysis, and decision-making, comprehensively improving the distribution system's ability to respond to cybersecurity threats.

[0034] The detection engine module is used to analyze and detect the network traffic data, the device feature data and the behavior data to obtain detection results.

[0035] Specifically, the detection engine module is the core analysis unit of the multimodal intelligent network security detection system. It performs in-depth analysis and detection processing on the network traffic data, device feature data, and behavioral data collected by the multimodal data acquisition module. The detection engine integrates a variety of advanced analysis technologies, including but not limited to anomaly detection algorithms, deep learning models, and rule-matching mechanisms. By analyzing network traffic data, the detection engine can identify abnormal traffic patterns, such as sudden increases in traffic, abnormal transmission frequencies, and suspicious network connections. Regarding device feature data, the detection engine can identify security risks such as abnormal changes in device configurations, the access of unknown devices, and potential device vulnerabilities. For behavioral data, the detection engine can detect behavioral patterns that deviate from normal operating patterns, such as abnormal user access to sensitive files, abnormal application startup, and unusual use of USB devices. These analysis results ultimately form comprehensive detection results, providing a basis for subsequent risk assessment and response strategy formulation.

[0036] For example, in a power distribution system, the detection engine, through analysis of network traffic data, discovered frequent data transmission between a certain device and an unknown external IP address, with the transmissions often occurring late at night, during non-working hours. Simultaneously, analysis of the device's behavioral data revealed that the device frequently launched specific high-risk applications during data transmission, and its USB device usage history showed unusual access to external storage devices. Combined with analysis of device signature data, the detection engine discovered unpatched security vulnerabilities in the device's operating system version. These multi-dimensional anomalies prompted the detection engine to determine that the device posed a high cybersecurity risk, potentially becoming a target of cyberattacks or having already suffered a malicious intrusion.

[0037] The detection engine module's comprehensive analytical capabilities enable the system to accurately and promptly identify cybersecurity threats within the power distribution system, effectively improving the system's threat detection accuracy and efficiency. Its multi-dimensional data analysis overcomes the limitations of traditional single-data detection methods, enabling the discovery of hidden malicious behavior and complex attack patterns. By comprehensively analyzing network traffic, device characteristics, and behavioral data, the detection engine module provides comprehensive threat detection results, providing accurate data support for the decision-making and response modules. This enables the system to rapidly implement appropriate response measures, reducing the probability of security incidents and potential losses, and ensuring the network security and power supply reliability of the power distribution system.

[0038] The decision-making and response module is used to perform risk assessment based on the detection results based on a preset risk assessment model to obtain risk classification results and response strategies.

[0039] Specifically, based on a pre-set risk assessment model, the detection results output by the detection engine module are evaluated. Based on the risk assessment results, a risk classification result (such as high risk, medium risk, low risk) and a response strategy are generated.

[0040] The risk assessment model comprehensively considers factors such as threat type, impact scope, and device criticality to quantify detected threats. For example, a cyberattack that directly impacts the operation of a main transformer is assessed as high risk, while an occasional communication failure of a smart meter is assessed as low risk.

[0041] Response Strategy Generation: Develops a corresponding response strategy based on risk grading results. For high-risk threats, automated response measures are immediately initiated (such as disconnecting the network, isolating affected devices, and sending alerts to operations personnel). For medium-risk threats, further monitoring and analysis are performed. For low-risk threats, logs are recorded and reviewed regularly. Automated Response and Manual Intervention: Supports both automated response measures (such as modifying network firewall rules and restarting devices) and manual intervention (such as manual handling of complex threats by operations personnel). This human-machine collaboration improves response efficiency and accuracy.

[0042] For example, during the operation of the power distribution system, the detection engine discovered that a key server was frequently exchanging data with multiple unknown external IP addresses, with the data transmission volume being unusually large. At the same time, an unknown malware process was detected on the server. After the decision-making and response module received these detection results, the risk assessment model quickly determined that the server was facing a high risk of malicious attack. Based on the preset response strategy, the module immediately generated instructions to block all network connections between the server and external unknown IP addresses, isolate the infected server, and notify the security operations team for emergency investigation and handling. This series of rapid and precise response measures effectively prevented the further spread of malware within the power distribution system, avoiding possible serious consequences such as power supply interruptions or data leaks.

[0043] The decision-making and response module enables accurate assessment and automated response to cybersecurity threats. A pre-set risk assessment model quantifies risks based on multi-dimensional detection results, ensuring the accuracy and objectivity of risk grading. The automated response mechanism rapidly implements targeted measures based on risk levels, enabling rapid blocking and resolution of high-risk threats, effectively reducing the probability of security incidents and potential losses. The module's efficient operation helps enhance the overall cybersecurity protection capabilities of the distribution system, ensuring stable system operation and power supply continuity, reducing power outages and economic losses caused by cybersecurity incidents, and ensuring the safe and reliable operation of the power grid.

[0044] In this embodiment, the multimodal data acquisition module serves as the system's data source, responsible for comprehensively collecting key data from the power distribution system, including network traffic data, device feature data, and behavioral data. Network traffic data typically includes real-time capture of network data packets, such as IP addresses, port numbers, protocol types, traffic volume, and transmission frequency.

[0045] Device characteristic data often includes characteristic information such as MAC address, VID / PID, device model, operating system version, and installed software of various devices in the power distribution system.

[0046] Behavioral data can be collected by installing behavior monitoring plug-ins on the terminal devices and network servers of the power distribution system to continuously record user operation behaviors, such as the time, frequency and sequence of file access, application startup, network connection establishment and disconnection, USB device use, etc., to deeply capture users' operating habits and abnormal behaviors.

[0047] These data can comprehensively reflect the network activities, equipment status, and user or system behavior patterns within the power distribution system, providing a data basis for subsequent analysis and decision-making.

[0048] The detection engine module then performs comprehensive analysis and detection on the collected multi-source heterogeneous data. It uses multivariate analysis techniques to uncover potential threats and abnormal patterns in the data and generate accurate detection results.

[0049] Finally, the decision-making and response module receives the detection results and performs quantitative analysis based on a pre-set risk assessment model. Based on the threat indicators and risk characteristics in the detection results, this model calculates risk values, implements risk grading, and formulates response strategies that match the risk level, providing strong support for the stable operation of the distribution system.

[0050] Therefore, the system of the present invention enables comprehensive monitoring and in-depth analysis of the network security status of the power distribution system. By integrating multimodal data, it effectively overcomes the limitations of traditional methods, which typically set fixed thresholds based on a single data source (such as network traffic or device status) and fail to integrate multi-dimensional data for analysis. This improves the accuracy and timeliness of threat detection. It can promptly identify potential network security threats, such as malicious network attacks, abnormal device behavior, and illegal operations. Decision support based on risk assessment models enables precise risk quantification and hierarchical management. Automated response functions can rapidly block malicious connections and isolate infected devices, minimizing the losses caused by security incidents. The entire system improves the network security protection level of the power distribution system, enhances its ability to cope with complex and changing network threats, and ensures stable operation and continuous power supply. Compared with traditional manual response methods, the system's automated response mechanism reduces the frequency and workload of manual intervention, reducing the burden on operations and maintenance personnel. Furthermore, by learning from historical data through machine learning models, the system can predict potential risks in advance, reduce the occurrence of recurring security incidents, and further reduce operations and maintenance costs.

[0051] Alternatively, as Figure 2 As shown, the detection results include anomaly detection results, recognition results and rule detection results, and the detection engine module includes an anomaly detection unit, a recognition unit and a rule matching unit: The anomaly detection unit is configured to perform feature extraction on the network traffic data, the device feature data, and the behavior data, respectively, to obtain first feature data, second feature data, and third feature data, and input the first feature data, the second feature data, and the third feature data into a preset anomaly detection model to obtain the anomaly detection result; The recognition unit is configured to process the network traffic data and the behavior data according to a preset recognition model to obtain the recognition result, wherein the recognition model is constructed based on a CNN network and an LSTM network; The rule matching unit is used to process the network traffic data, the device feature data and the behavior data based on a preset initial knowledge graph to obtain the rule detection result.

[0052] Specifically, the detection engine module comprehensively analyzes collected network traffic data, device signature data, and behavioral data, aiming to accurately identify potential network security threats through a variety of technical means. The module consists of three main units, each specialized for different types of data and analysis purposes. Ultimately, it generates a comprehensive detection report containing anomaly detection results, identification results, and rule-based detection results, providing detailed data support for subsequent risk assessment and response strategy development.

[0053] The anomaly detection unit performs feature extraction on network traffic data, device feature data, and behavior data. First, key features are extracted from the network traffic data, such as the transmission frequency of data packets, traffic volume, and connection status, to form the first feature data. Next, features such as the device's hardware information, software configuration, and operating status are extracted from the device feature data to construct the second feature data. Finally, for the behavior data, features such as the time, frequency, sequence, and pattern of user operations are extracted to obtain the third feature data. These three feature data are input into a preset anomaly detection model, which is based on a machine learning algorithm and can identify abnormal patterns in the data and output anomaly detection results. Among them, machine learning algorithms can be selected such as K-Means, SVM, LSTM, etc.

[0054] The anomaly detection unit promptly identifies unusual patterns in data that may indicate potential network security threats. By extracting and comprehensively analyzing features from multiple data sources, this unit effectively improves the accuracy and comprehensiveness of anomaly detection. For example, it can identify signs of DDoS attacks in network traffic, unusual changes in device configurations, and irregularities in user behavior. This provides accurate anomaly detection results for subsequent risk assessments, helping the system take proactive preventative measures.

[0055] The recognition unit relies on a recognition model based on CNN and LSTM networks to perform in-depth processing of network traffic and behavioral data. CNN networks excel at extracting local features from network traffic data, such as specific packet patterns and flow characteristics, to generate temporary feature data. LSTM networks focus on time series modeling of behavioral data, capturing the temporal dependencies and dynamic patterns of user or system behavior to generate dynamic behavioral feature data. These two types of feature data are fused to form comprehensive feature data. A classification algorithm is used to classify the comprehensive feature data, generating a classification result. The confidence level is determined based on the probability of anomaly in the classification result, ultimately forming the recognition result.

[0056] The identification unit leverages deep learning technology to accurately identify complex patterns in network traffic and behavioral data, effectively improving the accuracy and reliability of threat identification. The combination of the local feature extraction capabilities of the CNN network and the time series modeling capabilities of the LSTM network enables the system to capture hidden attack patterns and anomalous behavior. The output of classification results and confidence levels not only provides information on the threat type but also quantifies the confidence level of the identification, providing strong support for subsequent risk assessment and response strategy development.

[0057] The rule matching unit processes network traffic data, device feature data, and behavioral data based on a pre-defined initial knowledge graph. The initial knowledge graph integrates expert knowledge in network security and historical security incident information to construct a knowledge network consisting of entity nodes and relationship edges. The rule matching unit compares the collected data with the rules and patterns in the knowledge graph, identifies patterns that conform to pre-defined security rules, and outputs the rule detection results.

[0058] Leveraging the powerful semantic association capabilities of the knowledge graph, the rule matching unit can rapidly identify known attack patterns and security threats, effectively overcoming the shortcomings of purely data-driven approaches. Through deep integration with the knowledge graph, this unit achieves semantic understanding and logical reasoning of network security threats, improving its ability to identify complex attack scenarios. Rule detection results provide the system with a threat assessment basis based on expert experience and historical data, enhancing its reliability and practicality.

[0059] In some preferred embodiments, in a power distribution system, a large number of connection requests from external unknown IP addresses appear in the network traffic data, and these requests are concentrated on specific ports. After extracting the features of the network traffic data, the anomaly detection unit identifies this abnormal traffic pattern and determines that there may be a risk of DDoS attack. At the same time, the behavioral data shows that a user account attempts to access multiple sensitive files in a short period of time. The recognition unit models the time series of the behavioral data through the LSTM network, and combines the network traffic features extracted by the CNN network to determine that the behavior is highly similar to the known malicious scanning pattern, with a confidence level of 0.9. The rule matching unit finds that the access behavior of the user account violates the system's access control policy based on the rules in the knowledge graph, further confirming the potential security threat. The detection engine module integrates these results to form a comprehensive detection report, providing comprehensive and accurate data support for subsequent risk assessment and response strategy formulation.

[0060] Optionally, the recognition result includes a classification result and a corresponding confidence level; and the processing of the network traffic data and the behavior data according to a preset recognition model to obtain the recognition result includes: Performing local feature extraction on the network traffic data through the CNN network to obtain temporary feature data; Performing time series modeling processing on the behavior data through the LSTM network to obtain dynamic behavior feature data; Fusing the temporary feature data and the dynamic behavior feature data to obtain comprehensive feature data; The comprehensive feature data is classified to obtain the classification result, and the corresponding confidence level is determined according to the abnormal probability of the classification result.

[0061] Specifically, network traffic data usually contains a large number of network packets, each of which has features such as source IP, destination IP, source port, destination port, protocol type, and packet length. These data are converted into a matrix form, where each row represents a network packet and each column represents a feature. For example, a network packet can be represented as Source IP (src_ip): The IP address of the packet sender. Destination IP (dst_ip): The IP address of the packet receiver. Source Port (src_port): The port number of the packet sender. Destination Port (dst_port): The port number of the packet receiver. Protocol Type (protocol): The network protocol used by the packet, such as TCP or UDP. Packet Length (length): The length of the packet.

[0062] The convolutional layer of a CNN uses multiple filters to perform convolution operations on network traffic data. These filters slide over the data, performing convolution operations to extract local features. For example, one filter might detect a specific byte sequence pattern, while another filter might detect periodic patterns in traffic. The mathematical expression of the convolution operation is: ; in: It is the feature map after the convolution operation. During the convolution process, the input data is convolved with the convolution kernel to generate a feature map, in which each element represents the feature intensity at that position; The weight matrix of the convolution kernel (filter). The convolution kernel slides over the input data, performing a weighted sum on the input data to extract specific local features. The dimension of the weight matrix is determined by the size of the convolution kernel and the number of input channels; Represents input data. In network security testing, this is usually network traffic data. Is the bias term. In the convolution operation, the bias term is a constant used to adjust the convolution result and increase the flexibility of the model; Activation function. Activation functions introduce nonlinearity, enabling convolutional neural networks to learn complex feature patterns. Common activation functions include ReLU (Rectified Linear Unit), sigmoid, and tanh.

[0063] The pooling layer downsamples the convolutional features, reducing the amount of data while retaining the main features. Common pooling methods include maximum pooling and average pooling. Maximum pooling takes the maximum value in the pooling area, and the mathematical expression is: ; Average pooling takes the average value in the pooling area, and the mathematical expression is: ; in, Represents the output feature value or feature map after the pooling operation, :Indicates the first Rank The input feature values of the columns, Represents the total number of elements in the pooled region and is used to calculate the average value of all elements in average pooling. i and j represent the position index of the convolution kernel when it slides on the input data. i usually represents the row index and j represents the column index.

[0064] After multiple layers of convolution and pooling operations, temporary feature data of network traffic data is obtained. These temporary feature data are vectors extracted to represent the characteristics of network traffic.

[0065] The LSTM network performs time series modeling on behavioral data, including: Behavioral data is a sequence of operations performed by a user or system over a period of time, such as accessing a file, opening an application, connecting to a network, and so on. Each operation can be represented as a vector containing information such as the operation type and timestamp. For example, a behavioral data sequence can be represented as ; Each operation is a vector.

[0066] The LSTM network models the time series of behavioral data through a cyclic structure, which can remember key information in long time series. The hidden state update formula of LSTM is: ; in: is the hidden state at time step t, is the weight matrix, is the input at time step t, is the bias term, is the activation function.

[0067] LSTM controls the flow of information through input, forget, and output gates, allowing it to better capture long-term dependencies in time series. For example, it can identify abnormal behavior patterns such as users frequently accessing and deleting sensitive files over a period of time.

[0068] The temporary feature data extracted by CNN and the dynamic behavior feature data extracted by LSTM network will be input into the fusion layer. For example, the feature vector extracted by CNN is , the feature vector extracted by the LSTM network is .

[0069] Concatenate the two feature data or fuse them through more complex fusion strategies (such as attention mechanisms). For example, a simple concatenation operation combines two feature vectors into a long vector: .

[0070] Or more complex fusion methods such as attention mechanisms calculate the importance of two features before fusing them: ; in, is the attention weight, obtained through training, Represents the comprehensive feature data after fusion.

[0071] The comprehensive feature data is input into a classifier (such as a fully connected neural network layer). The classifier classifies the sample based on the characteristic patterns learned from the comprehensive feature data. The classifier's output is typically a probability distribution, indicating the probability that the sample belongs to different categories. For example, the classifier outputs a probability of 0.95 for malware traffic and a probability of 0.05 for normal traffic.

[0072] The abnormal probability of the classification result can be calculated by the Softmax function: ; in: Is the probability that the sample belongs to category c. In the classification process, this is the probability value calculated by the Softmax function; is the weight vector of category c. In the classifier, each category has a corresponding weight vector, which is used to calculate the score of the category; is the bias term for category c, The weight vector representing class d. In a classifier, each class has a corresponding weight vector, which is used to calculate the score for that class. The weight vector is learned during training using an optimization algorithm (such as gradient descent) to minimize the classification error. Represents the bias term for category d. In a classifier, the bias term is used to adjust the score calculation for a category. The bias term is also learned during training through an optimization algorithm to minimize classification error. In a classifier, the bias term is used to adjust the score calculation for a category. Is the total number of categories. In the classification task, it represents the total number of all possible categories.

[0073] Confidence is the probability that a classification result is abnormal. For example, if the classifier determines that a sample is malware traffic with a probability of 0.95, the confidence level is 0.95, indicating that the model has a high degree of confidence in this classification result.

[0074] Through this process, the recognition unit fully leverages the CNN's ability to extract local features from network traffic data and the LSTM network's ability to model time series for behavioral data, enabling in-depth fusion and analysis of network traffic and behavioral data. The resulting recognition results not only include the classification category but also quantify the reliability of the classification through confidence metrics, providing a reliable basis for subsequent risk assessment and response strategy development.

[0075] Optionally, the rule matching unit is specifically configured to: Performing entity recognition on the network traffic data, the device feature data, and the behavior data to obtain an entity recognition result; The entity recognition result is processed based on a preset initial knowledge graph to obtain the rule detection result.

[0076] Optionally, the processing of the entity recognition result based on a preset initial knowledge graph to obtain the rule detection result includes: Determine a target device node and an attack pattern node set; the target device node is a device node in any of the entity recognition results; the attack pattern node set includes high-risk nodes in the initial knowledge graph; According to a preset search method, starting from the target device node, query all path data to each node in the attack pattern node set; Evaluate each path data to obtain a path risk assessment result; Based on a preset graph neural network, the target device node and the attack pattern node set are processed to obtain an anomaly recognition result; The path risk assessment result and the anomaly identification result are integrated to obtain the rule detection result.

[0077] Optionally, the preset graph neural network is used to process the target device node and the attack pattern node set to obtain an anomaly recognition result, including: Encoding the target device node and the attack pattern node set respectively to obtain corresponding feature codes and structure codes; Based on the graph neural network, all the feature codes and the structure codes are identified to obtain the abnormality identification result.

[0078] Specifically, the target device node is any device node extracted from the entity recognition result, and these device nodes are the starting point of subsequent path queries. For example, entity recognition can be achieved by using rule-based methods and machine learning methods. For example, the rule-based method is used to identify device nodes by defining rules: Rule 1: If an IP address belongs to the internal network of the power company (such as 192.168.1.0 / 24), it is identified as an internal device. Rule 2: If the device model contains "transformer", it is identified as a transformer device. Define rules to identify user behavior entities: Rule 3: If the operation type is "login", it is identified as user login behavior. Machine learning methods can train a classifier to identify attack pattern entities, such as support vector machines (SVM), decision trees, random forests, etc.

[0079] The attack pattern node set is the attack pattern nodes marked as high-risk, filtered from the initial knowledge graph, forming the target set for subsequent analysis. Knowledge graph nodes: In the field of cybersecurity, nodes in a knowledge graph can include various entities, such as devices, users, IP addresses, domain names, files, processes, attack patterns, and vulnerabilities in the power distribution system. For example, a device node may contain attributes such as the device model, IP address, and location; a user node may contain attributes such as the username, role, and permissions; and an attack pattern node may contain attributes such as the attack type (such as DDoS attacks and SQL injection attacks), attack target, and attack path. Knowledge graph edges: Edges represent relationships between nodes. For example, the "association" relationship between a device and an IP address, the "login" relationship between a user and a device, the "attacked" relationship between a device and an attack pattern, and the "exploit" relationship between an attack pattern and a vulnerability. Edges can also have attributes such as the strength of the relationship and timestamps.

[0080] High-risk nodes in the initial knowledge graph are identified in the following ways: 1. Based on historical attack data: Analyze historical attack events and mark frequently attacked or easily exploited entities as high-risk nodes. For example, if a device has been attacked multiple times by DDoS attacks in the past, the node corresponding to that device and the associated attack pattern nodes (such as DDoS attacks) can be marked as high-risk nodes.

[0081] 2. Based on vulnerability information: Based on known vulnerability information, nodes corresponding to devices or software with serious vulnerabilities are marked as high-risk nodes. For example, if a piece of software has a high-risk vulnerability (such as a vulnerability with a high CVE score), the device node where the software is installed and the corresponding vulnerable node can be marked as high-risk nodes.

[0082] 3. Based on threat intelligence: Using external threat intelligence information, nodes corresponding to known malicious IP addresses, domain names, attack patterns, etc. are marked as high-risk nodes. For example, if a certain IP address is marked as a malicious attack source by multiple threat intelligence sources, the node corresponding to this IP address can be marked as a high-risk node.

[0083] 4. Expert knowledge: Network security experts manually mark some potentially high-risk nodes based on their experience and knowledge. For example, if an expert knows that a certain attack pattern poses a high risk in a specific environment, they will mark the relevant attack pattern nodes and potentially affected device nodes as high-risk nodes.

[0084] Based on pre-defined search rules (such as breadth-first search (BFS) and depth-first search (DFS), starting from the target device node, all path data leading to each node in the attack pattern node set in the graph is retrieved. Each path includes nodes and connection relationships, reflecting the potential association between the device and the attack pattern.

[0085] Path data is analyzed individually, taking into account factors such as path length and node risk attributes to quantify the risk value of each path. Shorter paths and more risky nodes indicate higher path risk. Quantifying risk values can be done using a weighted summation approach, for example: Risk Value = Σ(Node Risk Level × Weight Factor) + Path Length × Length Factor. Node Risk Level is a pre-defined value based on the node's risk level, the Weight Factor measures the importance of the node risk level in the overall risk assessment, the Path Length is the number of nodes or edges contained in the path, and the Length Factor measures the impact of path length.

[0086] Feature encoding: Convert the attribute information of the target device node and the attack pattern node set into a numerical vector to facilitate model processing. Feature encoding is the process of converting the attribute information of the target device node and the attack pattern node set into a numerical vector. For example, the attributes of the target device node include device type, model, IP address, operating status, etc., and the attributes of the attack pattern node include attack type, attack target, attack path, etc. When converting these attributes into numerical vectors, a fixed numerical range or encoding rule can be defined for each attribute. For example: device type: server (0), workstation (1), network printer (2); attack type: DDoS attack (0), SQL injection attack (1), brute force attack (2); in this way, the attributes of each node are converted into a numerical vector, which is convenient for model processing.

[0087] Structural encoding: Converting a graph's topology into an adjacency matrix represents the connections between nodes for use in graph neural network analysis. Structural encoding is the process of converting a graph's topology into an adjacency matrix. A graph's topology refers to the connections between nodes, including the composition of nodes and edges, as well as the direction and weight of edges. An adjacency matrix is a commonly used representation of graph structure. The rows and columns of the matrix represent the nodes in the graph, and the elements in the matrix indicate information such as whether an edge exists between two nodes and the weight of the edge.

[0088] Using a pre-set graph neural network, the model takes in feature and structural encodings, identifies node features and structural patterns, and outputs anomaly detection results. The graph neural network updates node embeddings by aggregating information from neighboring nodes to identify anomaly features.

[0089] The path risk assessment results and anomaly identification results are combined to generate rule-based detection results. The fusion process integrates the two results based on specific weights or rules to form a comprehensive judgment on network security threats.

[0090] For example, suppose the initial knowledge graph includes nodes such as device A, device B, attack mode X, and attack mode Y. Device A is connected to attack mode X, and attack mode X is connected to attack mode Y. The entity recognition result includes device A and device B.

[0091] Starting from device A, a BFS query finds two paths leading to the attack mode node set: device A → attack mode X and device A → device B → attack mode Y. After path evaluation, the risk value of the former is 0.8, and the risk value of the latter is 0.6.

[0092] Device A and the attack pattern node set are encoded separately to obtain feature encoding and structural encoding. After inputting into the graph neural network, the anomaly recognition result is obtained: Device A is abnormal, with an anomaly value of 0.7.

[0093] Finally, the path risk assessment results (average risk value 0.7) and the anomaly identification results (anomaly value 0.7) are combined and calculated with equal weights. The rule detection result is 0.7, indicating that device A faces a medium-high risk. The assessment criteria and corresponding risk value ranges can be defined based on the specific risk assessment model and application scenario. Generally speaking, the following standards can be used as a reference: Low risk: A value range of 0-0.3 indicates a low risk and may not require immediate action. Medium risk: A value range of 0.4-0.6 indicates a moderate risk and requires attention, with possible preventative measures. Medium-high risk: A value range of 0.7-0.9 indicates a high risk and recommends certain defensive measures. High risk: A value range of 1.0 indicates a very high risk and requires immediate action. In implementation, these value ranges can be adjusted and optimized based on historical data, expert experience, business needs, and other factors. For example, if historical data shows that events with a risk value exceeding 0.6 often lead to actual security issues, the medium-high risk threshold can be set to 0.6.

[0094] Through the above process, we can clearly identify the connection paths between devices and high-risk attack patterns, thereby accurately locating the source of potential security threats. Furthermore, this process quantifies path risk, providing intuitive risk assessment indicators to assist in decision-making. By comprehensively considering path risk and anomaly identification results, we further improve the accuracy and reliability of rule detection. Leveraging the powerful capabilities of graph neural networks in graph data analysis, we can uncover potential threats within complex relationship networks.

[0095] Alternatively, as Figure 2 As shown, the decision and response module includes a risk assessment and classification unit and an automated response and blocking unit; The risk assessment and grading unit is configured to perform risk assessment based on the risk assessment model and the detection results to obtain a risk grading result and a response strategy; The automated response and blocking unit is used to send execution instructions based on the risk grading result and the response strategy, and feed back the executed response results to the system log and management interface of the network security multimodal intelligent detection system.

[0096] Specifically, the decision-making and response module is a key component of the multimodal intelligent network security detection system. It primarily consists of a risk assessment and classification unit and an automated response and blocking unit. The risk assessment and classification unit analyzes detection results based on a risk assessment model to determine the risk level and formulate a response strategy. The automated response and blocking unit then executes specific actions based on these strategies to contain security threats and reports the results to the system log and management interface.

[0097] The Risk Assessment and Grading Unit receives detection results from the Detection Engine module, which integrate multiple dimensions of information, including network traffic, device characteristics, and behavioral data. The unit's built-in risk assessment model quantifies these results based on pre-set rules and algorithms, calculating a risk value to determine the risk level, typically categorized as high, medium, or low. Based on the risk level, the unit develops a corresponding response strategy. For example, a high risk risk may trigger a policy to block malicious connections and isolate infected devices, a medium risk risk may require further monitoring and analysis, and a low risk risk may require only logging.

[0098] The risk assessment model is a core component of the decision-making and response module, used to quantitatively analyze detection results to determine risk classifications and formulate response strategies. This model comprehensively considers multiple risk factors, including threat indicators and risk characteristics from detection results. The risk assessment model is constructed based on a weighted average principle. The model pre-defines multiple evaluation metrics, each weighted based on its impact on network security threats. Common evaluation metrics include the anomaly score in anomaly detection results, the confidence level in identification results, and the degree of rule matching in rule detection results.

[0099] The input to the risk assessment model is the detection results output by the detection engine module. These results cover a comprehensive analysis of network traffic data, device feature data, and behavioral data, and include anomaly detection results, identification results, and rule detection results. When performing a risk assessment, the model first standardizes each evaluation indicator to ensure that they are within the same numerical range. The model then weights each evaluation indicator according to a preset weight and finally calculates a weighted average risk value. Based on this risk value, the model categorizes the risk into three levels: high, medium, and low. The output of the risk assessment model includes a risk grading result and a response strategy. The risk grading result is used to indicate the severity of the current network security threat, while the response strategy provides specific execution guidance for the automated response and blocking units.

[0100] For example, in a specific scenario involving a power distribution system, suppose the detection engine module detects an abnormal network connection (anomaly score of 0.85) for a device, detects unusual operating patterns in its behavioral data (confidence level of 0.75), and detects that the device's behavior violates multiple security rules (rule match level of 0.9). The risk assessment model calculates a weighted average risk score of 0.83 based on preset weights (assuming 0.4, 0.3, and 0.3, respectively), indicating that the device poses a high risk. Based on this risk classification, the model develops a response strategy, recommending immediate blocking of the device's network connection and further isolation and inspection.

[0101] The risk assessment model accurately evaluates network security threats by quantifying and analyzing detection results. This not only improves the accuracy and objectivity of risk assessments but also provides clear implementation guidance for automated response and blocking units. This model enables the system to rapidly implement targeted measures, effectively reducing the probability of security incidents and potential losses, thereby ensuring network security and power supply reliability within the distribution system.

[0102] Therefore, the Risk Assessment and Grading Unit provides precise quantitative risk assessments, converting complex detection results into intuitive risk levels and providing clear guidance for subsequent responses. The response strategies it develops are closely aligned with risk levels, ensuring a rapid and effective response to high-risk threats, mitigating potential losses from security incidents, and rationally allocating security resources to avoid over- or under-reactions.

[0103] Specifically, the automated response and blocking unit generates and sends execution instructions to network devices, endpoint security software, and USB management devices based on the response strategy developed by the risk assessment and classification unit. For example, based on policy requirements, the unit might send instructions to firewalls to block connections from specific malicious IP addresses or instruct endpoint security software to isolate infected devices. After execution, the unit reports the response results to the system log and management interface, allowing administrators to promptly review the details of the operation.

[0104] Through automated response and blocking units, the system achieves automated and rapid responses to security threats, significantly shortening threat handling time, reducing the need for manual intervention, and improving operational efficiency. Through a feedback mechanism, the unit provides administrators with detailed execution results, enhancing their control over security status and facilitating subsequent audits and policy optimization.

[0105] For example, if the detection engine discovers that a device is frequently exchanging data with multiple unknown IP addresses and exhibiting unusual behavioral data, the risk assessment and grading unit, after analysis, determines the risk to be high and formulates a response strategy to block the connection and isolate the device. The automated response and blocking unit then sends instructions to the firewall to block the device's connection to the unknown IP addresses and notifies the endpoint security software to isolate the device. After execution, the unit reports operational details to the system log and management interface, ensuring administrators are promptly informed of the progress. This process fully demonstrates the crucial role of the decision-making and response module in rapidly addressing complex security threat scenarios.

[0106] In summary, the decision-making and response module effectively enhances the threat response capabilities of the multimodal intelligent network security detection system through precise risk assessment and automated response measures. This module not only rapidly mitigates security threats and reduces potential losses, but also enhances the system's manageability and sustainability through rational resource allocation and detailed feedback mechanisms. It is a core component for ensuring the secure and stable operation of the power distribution system network.

[0107] Alternatively, as Figure 2 As shown, the decision and response module also includes a manual intervention and collaboration unit, The manual intervention and collaboration unit is used to interact with the management interface of the network security multimodal intelligent detection system and adjust the response strategy.

[0108] Specifically, the Manual Intervention and Collaboration Unit, as part of the Decision and Response Module, interacts with the system's management interface. Administrators can use this interface to review the risk grading results and response strategies generated by the Risk Assessment and Grading Unit and adjust these strategies based on their own experience and judgment, such as modifying response priorities and changing specific response measures. The unit then sends the adjusted strategies to the Automated Response and Blocking Unit for execution and reports these adjustments to the system log for subsequent auditing and analysis.

[0109] This unit introduces a manual intervention mechanism into the system, leveraging the administrator's expertise and experience to make response strategies more flexible and adaptable, effectively addressing complex and ever-changing cybersecurity threats. The collaborative work feature promotes communication and cooperation among security operations team members, enhancing overall security protection capabilities.

[0110] In some embodiments, during a particular detection, the preprocessing module receives a raw data set containing network traffic data, device feature data, and behavioral data. The data cleaning unit first removes duplicate records and obvious errors, such as correcting malformed IP addresses in device feature data and filtering out records with abnormal timestamps in behavioral data. The normalization unit then performs feature extraction and normalization on the cleaned data, converting features such as the number of bytes in network traffic, device uptime, and behavioral operation frequency into numerical values between 0 and 1, forming a standardized feature vector.

[0111] This standardized feature vector data is then input into the detection engine module for analysis and detection processing. In the decision-making and response module, the manual intervention and collaboration unit enables administrators to view detection results and automatically generated response strategies in real time through the management interface. Assuming the system detects suspicious network connection behavior on a device, it initially generates a response strategy to block the connection. Administrators can adjust this strategy based on actual conditions within the management interface, such as extending the blocking period or conducting a more in-depth inspection. The adjusted strategy is then passed through the manual intervention and collaboration unit to the automated response and blocking unit for execution, and the execution results are fed back to the system log, enabling closed-loop management of the entire process.

[0112] Through the collaborative work of manual intervention and collaborative units and pre-processing modules, the system incorporates human expertise and experience on the basis of automation, improves the accuracy and flexibility of network security threat detection and response, and effectively ensures the safe and stable operation of the distribution system network.

[0113] Alternatively, as Figure 2 As shown, the network security multimodal intelligent detection system further includes a preprocessing module, and the preprocessing module includes a data cleaning unit and a normalization unit; The data cleaning unit is used to clean the network traffic data, the device feature data and the behavior data to obtain processed data; The normalization unit is used to perform feature extraction on each processed data to obtain corresponding feature data, and perform normalization processing on each feature data to obtain corresponding feature vector data.

[0114] Specifically, the preprocessing module is a key pre-processing component of the multimodal intelligent network security detection system, primarily consisting of a data cleaning unit and a normalization unit. The data cleaning unit performs preliminary purification on the raw collected data, removing noise and invalid information to improve data quality. The normalization unit further extracts features and normalizes the numerical range of the cleaned data, generating uniform and standardized feature vector data, laying the foundation for subsequent detection and analysis.

[0115] The data cleaning unit receives network traffic data, device signature data, and behavioral data from the multimodal data acquisition module. Its primary function is to remove duplicate, erroneous, invalid, or incomplete data records, retaining complete and accurate data portions to produce preliminarily processed data. For example, it removes anomalous records in network traffic data where the source and destination IP addresses are identical, corrects formatting errors in device signature data, and filters behavioral data where timestamps fall outside a reasonable range. Data cleaning effectively improves data quality, removes noise that interferes with subsequent analysis, and ensures high reliability and availability of data entering the detection engine, thereby enhancing the accuracy and efficiency of the entire system.

[0116] The normalization unit receives the processed data output by the data cleaning unit. First, feature extraction is performed on each data type to obtain corresponding feature data. For example, features such as traffic size and transmission frequency are extracted from network traffic data; features such as device type and operating status are extracted from device feature data; and features such as operation type and operation time are extracted from behavior data. Then, each feature data is normalized, and its numerical range is uniformly adjusted to between 0 and 1 to obtain the corresponding feature vector data. The commonly used normalization formula is: ; in, represents the normalized eigenvalue, is the original eigenvalue, and are the minimum and maximum values of the feature in the dataset, respectively.

[0117] Normalization makes data of different dimensions comparable, preventing certain features from dominating the final results due to their large numerical ranges, and ensuring that the detection engine module analyzes data more accurately and objectively. Furthermore, normalized data can accelerate the training of subsequent machine learning models, improving overall system performance.

[0118] In some embodiments, assume that during a certain detection task, the preprocessing module receives a raw data set containing network traffic data, device feature data, and behavioral data. The network traffic data may contain some duplicate records and abnormal records where the source and destination IP addresses are the same; the device feature data may contain malformed MAC address records; and the behavioral data may contain records with timestamps outside a reasonable range. The data cleaning unit first removes this invalid and erroneous data, retaining the complete and accurate data. For example, this may involve deleting duplicate network traffic records, correcting the MAC address format in the device feature data, and filtering out records with abnormal timestamps in the behavioral data.

[0119] The normalization unit then performs feature extraction and normalization on the cleaned data. For example, it extracts two features: traffic size and transmission frequency from network traffic data; two features: device type and operating status from device feature data; and two features: operation type and operation duration from behavior data. These features are then normalized. Assume that the original value range of traffic size in network traffic data is 0 to 10,000, and the original value range of transmission frequency is 0 to 100; the original value range of device type in device feature data is 1 to 5, and the original value range of operating status is 0 to 1; the original value range of operation type in behavior data is 1 to 10, and the original value range of operation duration is 0 to 86,400. Using the above normalization formula, the numerical ranges of these feature data are uniformly adjusted to between 0 and 1, forming standardized feature vector data: Traffic size: For example, the original value is 5,000, and the normalized value is 0.5. Transmission frequency: For example, the original value is 50, and the normalized value is 0.5. Device type: For example, the original value is 3, and the normalized value is 0.5. Operation status: For example, if the original value is 0.5, it will still be 0.5 after normalization. Operation type: For example, if the original value is 5, it will be 0.5 after normalization. Operation time: For example, if the original value is 43200, it will be 0.5 after normalization.

[0120] This standardized feature vector data is then fed into the detection engine module for analysis and detection processing. The cleaning and normalization operations in the preprocessing module ensure high-quality, uniformly formatted data before entering the detection engine, helping to improve the accuracy and reliability of detection results.

[0121] Alternatively, as Figure 2 As shown, the network security multimodal intelligent detection system also includes a storage and generation module and an alarm module; The storage and generation module is used to store various types of data and processing results generated during the operation of the network security multimodal intelligent detection system; The storage and generation module is also used to generate an operation report and a security analysis report of the network security multimodal intelligent detection system.

[0122] The alarm module is used to issue an alarm notification in time when a high-risk threat or system anomaly is detected, reminding the administrator to take measures.

[0123] Specifically, the storage and generation module is responsible for storing various types of data and processing results generated during the operation of the system. This includes but is not limited to the following data types: Raw data: network traffic data, device feature data, and behavior data collected from the multimodal data acquisition module. Processed data: data that has been cleaned and normalized by the preprocessing module for use by the detection engine. Detection results: anomaly detection results, recognition results, and rule detection results generated by the detection engine module. Response results: the execution results after the decision and response module executes the response strategy, including blocking operations, isolation operations, etc. System logs: operation logs, error logs, user operation logs, etc. recorded during system operation. Knowledge graphs and models: initial knowledge graph data and knowledge graphs updated during operation, and model parameters used by the detection engine.

[0124] The storage and generation modules ensure that the system can quickly resume operation after a power outage or restart. They also facilitate analysis and auditing of historical data, improving the efficiency of problem diagnosis and resolution. This provides the material foundation for continuous learning and optimization of the system.

[0125] The storage and generation module is also responsible for generating various reports based on the data and test results stored in the storage and generation module. These reports can be categorized as follows: Operational reports: These report on system operating status, performance indicators, resource utilization, etc. Security analysis reports: These analyze security trends, threat trends, and event details. Compliance reports: These reports are used to meet compliance reviews and demonstrate how the system meets legal and regulatory requirements. Customized reports: These reports are customized to specific formats or content based on user needs.

[0126] The storage and generation module also transforms complex data and analysis results into easy-to-understand reports, facilitating user insights. It also provides data support for administrators, enabling them to make more accurate decisions. Reports can also serve as evidence for audits and compliance checks.

[0127] The alarm module is used to promptly notify administrators when high-risk threats or system anomalies are detected. Alarms can be implemented in a variety of ways, including: Audio and visual alarms: Pop-up alarm windows or audible prompts are displayed through the system interface. Email alarms: Send alarm emails to the administrator's email address. SMS alarms: Send alarm text messages to the administrator's mobile phone. API calls: Send alarm information to other integrated systems, such as monitoring systems or alarm platforms, through APIs.

[0128] The alarm module ensures administrators can quickly learn about and address security incidents, reducing potential losses. It also reduces manual monitoring costs, improves the timeliness and accuracy of alarms, and effectively mitigates or prevents security risks through rapid response measures.

[0129] Through these modules, the network security multimodal intelligent detection system can not only efficiently detect and respond to security threats, but also provide comprehensive data support, clear reports and timely alarms, greatly enhancing the practicality and operability of the system, enabling administrators to better manage and protect network security.

[0130] like Figure 3 As shown, an embodiment of the present invention provides a network security multimodal intelligent detection method, which is applied to the network security multimodal intelligent detection system. The network security multimodal intelligent detection method includes: Collect network traffic data, device feature data, and behavior data of each device in the power distribution system; Analyzing and detecting the network traffic data, the device characteristic data, and the behavior data to obtain a detection result; Based on the preset risk assessment model, risk assessment is performed according to the detection results to obtain risk grading results and response strategies.

[0131] The advantages of the network security multimodal intelligent detection method of this embodiment over the existing technology are the same as the advantages of the above-mentioned network security multimodal intelligent detection system over the existing technology, and will not be repeated here.

[0132] Although the present invention is disclosed as above, the protection scope of the present invention is not limited thereto. Those skilled in the art may make various changes and modifications without departing from the spirit and scope of the present invention, and these changes and modifications will fall within the protection scope of the present invention.

Claims

1. A network security multimodal intelligent detection system, characterized in that: Applicable to a power distribution system, the power distribution system comprising communication equipment and power distribution equipment; The network security multimodal intelligent detection system includes: A multimodal data acquisition module, configured to collect network traffic data, device feature data, and behavior data of each device in the power distribution system; A detection engine module is used to analyze and detect the network traffic data, the device feature data, and the behavior data to obtain a detection result; Wherein, the detection engine module includes a rule matching unit, and the detection result includes a rule detection result; The rule matching unit is configured to process the network traffic data, the device feature data, and the behavior data based on a preset initial knowledge graph to obtain the rule detection result, including: Performing entity recognition on the network traffic data, the device feature data, and the behavior data to obtain an entity recognition result; Processing the entity recognition result based on a preset initial knowledge graph to obtain the rule detection result; The decision-making and response module is used to perform risk assessment based on the detection results based on a preset risk assessment model to obtain risk classification results and response strategies.

2. The network security multimodal intelligent detection system according to claim 1, characterized in that: The detection results include anomaly detection results and recognition results; the detection engine module includes an anomaly detection unit and a recognition unit: The anomaly detection unit is configured to perform feature extraction on the network traffic data, the device feature data, and the behavior data, respectively, to obtain first feature data, second feature data, and third feature data, and input the first feature data, the second feature data, and the third feature data into a preset anomaly detection model to obtain the anomaly detection result; The recognition unit is used to process the network traffic data and the behavior data according to a preset recognition model to obtain the recognition result, and the recognition model is constructed based on a CNN network and an LSTM network.

3. The network security multimodal intelligent detection system according to claim 2, characterized in that: The recognition result includes a classification result and a corresponding confidence level; the network traffic data and the behavior data are processed according to a preset recognition model to obtain the recognition result, including: Performing local feature extraction on the network traffic data through the CNN network to obtain temporary feature data; Performing time series modeling processing on the behavior data through the LSTM network to obtain dynamic behavior feature data; Fusing the temporary feature data and the dynamic behavior feature data to obtain comprehensive feature data; The comprehensive feature data is classified to obtain the classification result, and the corresponding confidence level is determined according to the abnormal probability of the classification result.

4. The network security multimodal intelligent detection system according to claim 1, characterized in that: The entity recognition result is processed based on the preset initial knowledge graph to obtain the rule detection result, including: Determine a target device node and an attack pattern node set; the target device node is a device node in any of the entity recognition results; the attack pattern node set includes high-risk nodes in the initial knowledge graph; According to a preset search method, starting from the target device node, query all path data to each node in the attack pattern node set; Evaluate each path data to obtain a path risk assessment result; Based on a preset graph neural network, the target device node and the attack pattern node set are processed to obtain an anomaly recognition result; The path risk assessment result and the anomaly identification result are integrated to obtain the rule detection result.

5. The network security multimodal intelligent detection system according to claim 4, characterized in that: The preset graph neural network is used to process the target device node and the attack pattern node set to obtain an anomaly recognition result, including: Encoding the target device node and the attack pattern node set respectively to obtain corresponding feature codes and structure codes; Based on the graph neural network, all the feature codes and the structure codes are identified to obtain the abnormality identification result.

6. The network security multimodal intelligent detection system according to claim 1, characterized in that: The decision and response module includes a risk assessment and classification unit and an automated response and blocking unit; The risk assessment and grading unit is configured to perform risk assessment based on the risk assessment model and the detection results to obtain a risk grading result and a response strategy; The automated response and blocking unit is used to send execution instructions based on the risk grading result and the response strategy, and feed back the executed response results to the system log and management interface of the network security multimodal intelligent detection system.

7. The network security multimodal intelligent detection system according to claim 6, characterized in that: The decision and response module also includes a manual intervention and collaboration unit. The manual intervention and collaboration unit is used to interact with the management interface of the network security multimodal intelligent detection system and adjust the response strategy.

8. The network security multimodal intelligent detection system according to claim 1, characterized in that: The network security multimodal intelligent detection system further includes a preprocessing module, which includes a data cleaning unit and a normalization unit; The data cleaning unit is used to clean the network traffic data, the device feature data and the behavior data to obtain processed data; The normalization unit is used to perform feature extraction on each processed data to obtain corresponding feature data, and perform normalization processing on each feature data to obtain corresponding feature vector data.

9. The network security multimodal intelligent detection system according to claim 1, characterized in that: The network security multimodal intelligent detection system also includes a storage and generation module and an alarm module; The storage and generation module is used to store various types of data and processing results generated during the operation of the network security multimodal intelligent detection system; The storage and generation module is also used to generate an operation report and a security analysis report of the network security multimodal intelligent detection system.

10. A multimodal intelligent network security detection method, characterized in that: Applied to the network security multimodal intelligent detection system according to any one of claims 1 to 9, the network security multimodal intelligent detection method comprises: Collect network traffic data, device feature data, and behavior data of each device in the power distribution system; Analyzing and detecting the network traffic data, the device characteristic data, and the behavior data to obtain a detection result; Based on the preset risk assessment model, risk assessment is performed according to the detection results to obtain risk grading results and response strategies.

Citation Information

Patent Citations

  • Enterprise network security self-checking method and system

    CN119210908A

  • Cross-domain network security policy automatic generation and protection policy collaboration method and system

    CN119449428A

  • Information security risk assessment whole-process management system

    CN119939591A

  • Information security management system based on big data

    CN120086768A

  • Power grid safety protection system and method based on large language model

    CN120200802A

Cited By

  • Network security multi-mode intelligent detection method and device, equipment and storage medium

    CN120956524A

  • Private network dynamic access control method and system

    CN121261998A

  • Network security vulnerability detection method and system based on artificial intelligence

    CN121283772A

  • An artificial intelligence-based network security vulnerability detection method and system

    CN121283772B

  • Network security protection method, system, device, medium and product

    CN121418201A