Method and system for intelligently generating security label of API (Application Program Interface) data stream

By cleaning and reducing the dimensionality of API data streams, building an autoencoder network to generate hierarchical security labels, and dynamically updating the rule base, the problems of low data processing efficiency and insufficient adaptability in existing technologies are solved, and efficient API data stream security management is achieved.

CN120653675APending Publication Date: 2025-09-16GUANGXI POWER GRID CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510511180.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

The existing technology for generating API data stream security labels has problems such as low data preprocessing efficiency, lack of dynamic update mechanism, and difficulty in adapting to complex and changing business scenarios and data characteristics.

Method used

Data streams are collected through the API interface, cleaned and reduced in dimension, an autoencoder network is constructed to map to a low-dimensional latent space, hierarchical security labels are generated, and the rule base is dynamically updated.

Benefits of technology

It improves data processing efficiency, captures deep-level features of data, generates accurate security labels, adapts to complex and changing business scenarios, and enhances the flexibility and adaptability of the rule base.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120653675A_ABST
    Figure CN120653675A_ABST
Patent Text Reader

Abstract

The invention discloses an API data flow security label intelligent generation method and system, and relates to the technical field of information flow control and API security management.The API data flow security label intelligent generation method comprises the steps that data flow is collected through an API interface, data is cleaned, dimension reduction processing is conducted on the cleaned data, and an auto-encoder network is constructed; and inputting the data subjected to dimension reduction into an auto-encoder network, mapping the data to a low-dimensional potential space, reconstructing the data, generating hierarchical security tags based on the data subjected to dimension reduction and potential features learned by the auto-encoder, performing classified storage on security tag rules, and dynamically updating a rule base. According to the method, the efficiency and the accuracy of data processing are improved, the pertinence and the practicability of the security label are enhanced, the flexibility and the adaptability of the rule base are ensured, and an efficient and reliable solution is provided for security monitoring and risk management of the API data flow.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information flow control and API security management, and in particular to a method and system for intelligently generating API data flow security labels. Background Art

[0002] With the rapid development of information technology, APIs have become a crucial means of data exchange and system integration. The security management of API data flows is receiving increasing attention. While traditional security measures such as access control and encryption have provided some assurance of data security, they remain insufficient when faced with complex and ever-changing business scenarios and massive amounts of data. In recent years, the application of artificial intelligence (AI) in data security has gradually gained momentum. In particular, the unique advantages of autoencoder networks in feature learning and data reconstruction have provided new insights for the intelligent generation of security labels for API data flows.

[0003] However, existing technologies still have many shortcomings in generating security labels for API data streams. First, the data preprocessing stage often lacks effective dimensionality reduction methods, resulting in low data processing efficiency and difficulty in capturing the deep-level characteristics of the data. Second, existing security label generation methods are mostly based on static rules and lack a dynamic update mechanism, making it difficult to adapt to changing business models and data characteristics. In addition, when conducting security assessments on data streams, existing technologies often ignore in-depth analysis of business scenarios, resulting in the generated security labels lacking pertinence and accuracy. Summary of the Invention

[0004] In view of the above-mentioned existing problems, the present invention provides a method and system for intelligently generating API data stream security labels, which is used to solve the problems in the existing technology of insufficient adaptability to the dynamics and uncertainty of API data streams, lack of granularity and hierarchical capabilities in security label generation, and insufficient interpretability and scalability of the rule base in complex data stream scenarios.

[0005] To solve the above technical problems, a method for intelligently generating API data stream security labels is proposed, including:

[0006] Data streams are collected through the API interface, and the data is cleaned and then subjected to dimensionality reduction processing. An autoencoder network is constructed, and the reduced-dimensional data is input into the autoencoder network to be mapped to a low-dimensional latent space, and the data is reconstructed. Based on the reduced-dimensional data and the potential features learned by the autoencoder, hierarchical security labels are generated, and security label rules are classified and stored, and the rule base is dynamically updated.

[0007] As a preferred embodiment of the method for intelligently generating security labels for API data streams described in the present invention, the data cleaning includes obtaining data streams from the API interface at preset time intervals, uniformly converting character strings, time formats, units, and standardized data, using a filtering algorithm to remove noise data, and correcting and eliminating erroneous values;

[0008] The dimensionality reduction process includes calculating the contribution of each dimension of data based on Gaussian distribution, and screening high-contribution dimensions for dimensionality reduction.

[0009] As a preferred solution of the method for intelligently generating security labels for API data streams described in the present invention, the dimensionality reduction processing also includes calculating the mean and variance of the data of each dimension, evaluating the contribution, and setting a contribution threshold, retaining dimensions whose contribution is greater than the contribution threshold, and using the cumulative contribution rate to filter dimensions until the preset dimensionality reduction target is met.

[0010] As a preferred embodiment of the method for intelligently generating security labels for API data streams according to the present invention, the construction of an autoencoder network includes mapping the dimensionality-reduced data to a low-dimensional latent space through a multi-layer neural network, and reconstructing the data through inverse mapping to minimize the error between the original data and the reconstructed data;

[0011] The mapping of the reduced-dimensional data into the autoencoder network to a low-dimensional latent space includes linearly transforming the input data through a weight matrix and a bias vector, and performing nonlinear mapping using an activation function to compress the data dimension layer by layer.

[0012] As a preferred solution of the method for intelligently generating security labels for API data streams described in the present invention, wherein: generating hierarchical security labels includes generating bottom-level labels, middle-level labels, and high-level labels;

[0013] The bottom-level labels include numerical or range-based labels generated based on the basic attributes and physical meaning of the data; the middle-level labels include the refinement of bottom-level labels based on business scenario knowledge and the introduction of historical data or credit rating information; the high-level labels include the integration of multiple data stream interactions and business processes to generate security labels that reflect the global status;

[0014] The range-type tag is determined based on the rated parameters of the power grid equipment and the fluctuation range allowed for normal operation. The parameters and ranges of the data vary depending on the business. The formula is:

[0015]

[0016] Among them, I min is the lower limit of the current range, I max is the upper limit of the current range, Srated is the rated power, U rated is the rated voltage.

[0017] As a preferred embodiment of the method for intelligently generating security labels for API data streams described in the present invention, the mid-level labels further include calculating the degree of deviation of transaction volume or price fluctuations from historical averages, combining credit rating information to determine the transaction risk level, and generating risk labels based on preset thresholds;

[0018] The formula for calculating trading volume is:

[0019] Q=μ Q +γσ Q

[0020] Among them, μ Q is the historical mean of transaction volume, σ Q is the historical standard deviation of the traded electricity volume, γ is the excess coefficient, and Q is the historical electricity trading volume. When the actual electricity trading volume is greater than the historical electricity trading volume, it is determined that the traded electricity volume far exceeds the average level;

[0021] The formula for calculating price anomaly is:

[0022]

[0023] Among them, μ P is the historical average transaction price, σ P is the historical price standard deviation, CV P is the price anomaly coefficient; when CV P >σ P When CV P ≤σ P When , the transaction price is normal;

[0024] The credit rating information includes: when the performance rate is greater than or equal to 98%, the credit rating is determined to be A, which means low risk; when the performance rate is greater than or equal to 95% and less than 98%, the credit rating is determined to be B, which means medium risk; when the performance rate is less than 95%, the credit rating is determined to be C, which means high risk;

[0025] The high-level tags also include monitoring changes in power demand, transaction orders and transmission line load rates, counting the amount of abnormal data within a preset time window, and generating a comprehensive risk tag when multiple abnormal conditions are met at the same time.

[0026] As a preferred embodiment of the method for intelligently generating security labels for API data streams described in the present invention, the dynamically updating rule base includes classifying and storing rules according to business domain, risk level, and scope of application, using a visualization tool to display rule triggering conditions and logical relationships, and dynamically updating the rule base to adapt to new business models and data characteristics.

[0027] The dynamically updated rule base also includes analyzing new business scenarios and data features, extracting key patterns, generating new rules based on the autoencoder learning results and historical label data, adding the new rules to the rule base and visually displaying them.

[0028] Another object of the present invention is to provide an intelligent generation system for API data stream security labels. The present invention effectively improves the level of data stream security management and ensures the security and reliability of data exchange and system integration. The system of the present invention realizes effective monitoring, feature extraction and intelligent generation of security labels for API data streams through the collaborative work of multiple modules such as data preprocessing, autoencoder network construction and mapping, and security label generation and rule base management, which significantly improves the security management level of data streams, adapts to complex and changeable business scenarios and data characteristics, and ensures the security and reliability of data exchange and system integration.

[0029] As a preferred solution of the API data stream security label intelligent generation system described in the present invention, it is characterized by including a data preprocessing module, an autoencoder network construction and mapping module, and a security label generation and rule base management module.

[0030] The data preprocessing module includes a data acquisition unit, a data cleaning unit and a data dimension reduction unit, which are used to regularly collect data streams through the API interface and perform data cleaning and dimension reduction processing on the data.

[0031] The autoencoder network construction and mapping module includes an autoencoder construction unit and a data mapping and reconstruction unit, which are used to input preprocessed data into the network and map it to a low-dimensional latent space. Through the encoding and decoding process of the multi-layer neural network, the data is effectively compressed and reconstructed to capture the deep-level features of the data.

[0032] The security label generation and rule base management module includes a security label generation unit and a rule base management unit, which are used to generate hierarchical security labels based on the potential features and business scenario knowledge learned by the autoencoder, manage the rule base, classify and store security label rules, dynamically update rules to adapt to new business models and data features, and display rule logic through visualization tools.

[0033] A computer device includes a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the steps of the method described in the intelligent generation of API data stream security labels are implemented.

[0034] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of a method for intelligently generating an API data stream security label.

[0035] The beneficial effects of the present invention are as follows: the present invention collects data streams regularly through the API interface, ensuring the real-time and integrity of the data, and cleans and reduces the dimensionality of the data, thereby improving data quality, reducing data redundancy, and reducing computational complexity, providing a reliable foundation for subsequent processing; by constructing an autoencoder network to map the reduced dimensionality data to a low-dimensional latent space, and reconstructing the data through inverse mapping, the deep-level features of the data are effectively captured, the data representation capability is enhanced, and strong support is provided for generating accurate security labels; by generating bottom-level, middle-level, and high-level labels, a hierarchical security label system is formed, which reflects the direct security status of the data, refined labels combined with business scenarios and historical data, and security labels of the global status, providing a comprehensive security risk assessment; by dynamically updating the rule base, the rules are classified and stored according to business fields, risk levels, and applicable scopes, and visual tools are used to display the rule triggering conditions and logical relationships. The rule base is dynamically updated to adapt to new business models and data characteristics, ensuring the flexibility and adaptability of the system and improving the perfection and foresight of the rule base. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0037] Figure 1 An overall flow chart of a method for intelligently generating security labels for an API data stream provided by one embodiment of the present invention.

[0038] Figure 2 A system solution flow chart of an API data stream security label intelligent generation system provided by one embodiment of the present invention. DETAILED DESCRIPTION

[0039] To make the above-mentioned objects, features, and advantages of the present invention more clearly understood, the following detailed description of the specific embodiments of the present invention is given in conjunction with the accompanying drawings. It is obvious that the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in this field without creative work should fall within the scope of protection of the present invention.

[0040] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those described herein. Those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0041] Secondly, the term "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in various places throughout this specification does not necessarily refer to the same embodiment, nor does it individually or selectively refer to an embodiment that is mutually exclusive of other embodiments.

[0042] The present invention is described in detail with reference to schematic diagrams. For ease of illustration, cross-sectional views of device structures may be partially enlarged and not to scale when describing embodiments of the present invention. Furthermore, the schematic diagrams are merely illustrative and should not limit the scope of the present invention. Furthermore, in actual production, the three-dimensional dimensions of length, width, and depth should be included.

[0043] In the description of the present invention, it should be noted that the terms "upper, lower, inner, and outer" and other references to orientations or positional relationships are based on the orientations or positional relationships shown in the accompanying drawings and are intended solely to facilitate and simplify the description of the present invention. They are not intended to indicate or imply that the devices or components referred to must have, be constructed, or operate in a specific orientation, and therefore should not be construed as limitations on the present invention. Furthermore, the terms "first, second, or third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0044] In this disclosure, unless otherwise specified or limited, the terms "mounted," "connected," and "connected" should be interpreted broadly. For example, they may refer to fixed, removable, or integral connections. They may also refer to mechanical, electrical, or direct connections, indirect connections through an intermediary, or internal communication between two components. Those skilled in the art will understand the specific meanings of these terms in this disclosure.

[0045] Example 1, with reference to Figure 1 , which is the first embodiment of the present invention, provides a method for intelligently generating security labels for API data streams, comprising:

[0046] S1: Collect data streams through the API interface, clean the data, and perform dimensionality reduction on the cleaned data.

[0047] Furthermore, by establishing a stable connection with each API interface, we can obtain data streams every 5 minutes as set, and perform data preprocessing to address the format inconsistencies that arise during the collection process.

[0048] Data preprocessing includes: (1) data parsing and data type identification, converting string values ​​into numeric values; (2) time format standardization; (3) unit conversion; (4) data standardization, ensuring that the data format is unified and computable;

[0049] Data cleaning is performed and erroneous values ​​in the data are corrected or eliminated. The correction is based on the statistical characteristics of the historical data of the same device or the normal operating parameter range of the same type of equipment. The hierarchical Gaussian dimensionality reduction algorithm is used to reduce the dimensionality of the cleaned data.

[0050] Furthermore, the median filter algorithm is used to clean the data, and the formula is expressed as:

[0051]

[0052] in, is the smoothed voltage value, x(t) is the original voltage value, the window size is 2K+1, t, tk and t+k are time points;

[0053] The hierarchical Gaussian dimensionality reduction algorithm includes calculating the Gaussian distribution parameters of each dimension data, which is expressed as:

[0054]

[0055] Among them, ρ i is the mean of the i-th API data dimension, is the variance of the i-th API data dimension, y ij represents the data value of the jth sample in the i-th dimension, N is the total number of samples, i and j are variable indices;

[0056] The contribution of each dimension to the overall characteristics of the data is evaluated based on the parameters. The higher the contribution, the greater the influence of the API dimension on the overall data pattern. The formula for calculating the contribution value is:

[0057]

[0058] Among them, C i is the contribution index of the i-th dimension, is the variance of the i-th API data dimension, n is the number of dimensions of the original dataset, m is the number of dimensions retained after dimensionality reduction, S m is the cumulative contribution rate, i and l are variable indices;

[0059] Set the cumulative contribution rate threshold to 95%, and prioritize the cumulative contribution rate S through a hierarchical approach. m Greater than 95% of the dimension data generated by the security labels.

[0060] In an optional embodiment, the dimensionality reduction processing includes calculating the contribution of each dimensional data based on Gaussian distribution, screening high-contribution dimensions for dimensionality reduction, and calculating the mean and variance of each dimensional data, evaluating the contribution, and setting a contribution threshold, retaining dimensions with contributions greater than the contribution threshold, and using the cumulative contribution rate to screen dimensions until the preset dimensionality reduction target is met.

[0061] In an optional embodiment, the dimensionality reduction processing can also calculate the covariance matrix of the preprocessed API data stream to obtain the correlation between the dimensions, and perform eigendecomposition on the covariance matrix to extract eigenvalues ​​and eigenvectors, sort them according to the size of the eigenvalues, select the eigenvectors corresponding to the first m largest eigenvalues ​​as the principal components, project the original data onto the selected principal components, and obtain the data representation after dimensionality reduction.

[0062] In another optional embodiment, the dimensionality reduction process may also randomly generate an n×m-dimensional projection matrix, where n is the original dimension and m is the target dimension, and multiply the original high-dimensional data by the random projection matrix to achieve dimensionality compression.

[0063] S2: Build an autoencoder network, input the reduced-dimensional data into the autoencoder network to map it to a low-dimensional latent space, and reconstruct the data.

[0064] Furthermore, the construction of the autoencoder network includes designing a network architecture consisting of an encoder and a decoder, wherein the encoder uses a multi-layer fully connected neural network structure to take the m-dimensional feature data after dimensionality reduction as input, performs linear transformation through a weight matrix and a bias vector, and uses a ReLU activation function for nonlinear mapping to gradually compress the high-dimensional data into a low-dimensional latent space;

[0065] The nonlinear mapping formula is expressed as:

[0066] z=f(a)=τ(Wa+b)

[0067] τ(a)=max(0,a)

[0068] Among them, W is the weight matrix, b is the bias vector, τ is the activation function, a is the input data, z is the output of the encoder, and f(a) is the mapping function of the encoder.

[0069] Furthermore, the decoder performs the inverse process of the encoder, reconstructing the latent space representation z into output data that matches the original input dimension through inverse transformation. During the training process, the reconstruction error is minimized as the optimization goal, and the reconstructed data is made as close to the original input as possible through iterative optimization.

[0070] The reconstruction error formula is:

[0071]

[0072] Where L is the reconstruction error, g r For the original API data, is the data reconstructed by the decoder, M is the number of data points sampled by the API, and r is the variable index.

[0073] S3: Generate hierarchical security labels based on the reduced-dimensional data and the potential features learned by the autoencoder, classify and store the security label rules, and dynamically update the rule base.

[0074] Furthermore, generating the hierarchical security labels includes generating bottom-level labels, middle-level labels, and high-level labels;

[0075] The bottom-level labels include numerical or range-based labels generated based on the basic attributes and physical meaning of the data; the middle-level labels include the refinement of bottom-level labels based on business scenario knowledge and the introduction of historical data or credit rating information; the high-level labels include the integration of multiple data stream interactions and business processes to generate security labels that reflect the global status;

[0076] The range-type tag is determined based on the rated parameters of the power grid equipment and the fluctuation range allowed for normal operation. The parameters and ranges of the data vary depending on the business. The formula is:

[0077]

[0078] Among them, I min is the lower limit of the current range, I max is the upper limit of the current range, S rated is the rated power, U rated is the rated voltage.

[0079] It should be noted that the mid-level label also includes calculating the degree of deviation of trading volume or price fluctuations from the historical average, combining credit rating information to determine the transaction risk level, and generating a risk label based on a preset threshold;

[0080] The formula for calculating trading volume is:

[0081] Q=μ Q +γσQ

[0082] Among them, μ Q is the historical mean of transaction volume, σ Q is the historical standard deviation of the traded electricity volume, γ is the excess coefficient, and Q is the historical electricity trading volume. When the actual electricity trading volume is greater than the historical electricity trading volume, it is determined that the traded electricity volume far exceeds the average level;

[0083] The formula for calculating price anomaly is:

[0084]

[0085] Among them, μ P is the historical average transaction price, σ P is the historical price standard deviation, CV P is the price anomaly coefficient; when CV P >σ P When CV P ≤σ P When , the transaction price is normal;

[0086] The credit rating information includes: when the performance rate is greater than or equal to 98%, the credit rating is determined to be A, which means low risk; when the performance rate is greater than or equal to 95% and less than 98%, the credit rating is determined to be B, which means medium risk; when the performance rate is less than 95%, the credit rating is determined to be C, which means high risk;

[0087] The high-level tags also include monitoring changes in power demand, transaction orders and transmission line load rates, counting the amount of abnormal data within a preset time window, and generating a comprehensive risk tag when multiple abnormal conditions are met at the same time.

[0088] Furthermore, the dynamically updated rule base includes classifying and storing rules according to business areas, risk levels, and scopes of application, using visualization tools to display rule triggering conditions and logical relationships, and dynamically updating the rule base to adapt to new business models and data characteristics;

[0089] The dynamically updated rule base also includes analyzing new business scenarios and data features, extracting key patterns, generating new rules based on the autoencoder learning results and historical label data, adding the new rules to the rule base and visually displaying them.

[0090] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

[0091] Example 2, reference Figure 2 , which is the second embodiment of the present invention, provides an API data stream security label intelligent generation system, including a data preprocessing module, an autoencoder network construction and mapping module, and a security label generation and rule base management module.

[0092] The data preprocessing module includes a data acquisition unit, a data cleaning unit and a data dimensionality reduction unit, which are used to regularly obtain data streams through an API interface, uniformly convert character strings, time formats, units and standardized data, use a filtering algorithm to remove noise data, and correct and eliminate error values. It also calculates the contribution of each dimension of data based on Gaussian distribution, and screens high-contribution dimensions for dimensionality reduction; calculates the mean and variance of each dimension of data, evaluates the contribution, and sets a contribution threshold, retains dimensions whose contribution is greater than the contribution threshold, and uses the cumulative contribution rate to screen dimensions until the preset dimensionality reduction target is met.

[0093] The autoencoder network construction and mapping module includes an autoencoder construction unit and a data mapping and reconstruction unit, which are used to construct an autoencoder network, map the reduced-dimensional data to a low-dimensional latent space through a multi-layer neural network, perform a linear transformation on the input data through a weight matrix and a bias vector, use an activation function for nonlinear mapping, compress the data dimension layer by layer, and reconstruct the data through inverse mapping to minimize the error between the original data and the reconstructed data.

[0094] The security label generation and rule base management module includes a security label generation unit and a rule base management unit, which is used to generate hierarchical security labels based on the reduced-dimensional data and the potential features learned by the autoencoder, classify and store the rules according to business areas, risk levels and scopes of application, use visualization tools to display the rule triggering conditions and logical relationships, and dynamically update the rule base to adapt to new business models and data features.

[0095] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

[0096] Embodiment 3, the third embodiment of the present invention, is different from the first two embodiments in that:

[0097] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0098] The logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device.

[0099] More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection with one or more wires (electronic devices), a portable computer disk cartridge (magnetic devices), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disc read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering, or processing in another suitable manner as necessary, and then stored in a computer memory.

[0100] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

Claims

1. A method for intelligently generating security labels for API data streams, characterized by: include, Collect data streams through API interfaces, clean the data, and perform dimensionality reduction on the cleaned data; Build an autoencoder network, input the reduced-dimensional data into the autoencoder network to map it into a low-dimensional latent space, and reconstruct the data; Based on the reduced-dimensional data and the potential features learned by the autoencoder, hierarchical security labels are generated, the security label rules are classified and stored, and the rule base is dynamically updated.

2. The method for intelligently generating API data stream security labels according to claim 1, wherein: The data cleaning includes obtaining data streams from the API interface at preset time intervals, converting character strings, time formats, units, and standardized data, using filtering algorithms to remove noise data, and correcting and eliminating erroneous values; The dimensionality reduction process includes calculating the contribution of each dimension of data based on Gaussian distribution, and screening high-contribution dimensions for dimensionality reduction.

3. The method for intelligently generating API data stream security labels according to claim 2, wherein: The dimensionality reduction process also includes calculating the mean and variance of each dimension data, evaluating the contribution, and setting a contribution threshold, retaining dimensions with contributions greater than the contribution threshold, and using the cumulative contribution rate to filter dimensions until the preset dimensionality reduction target is met.

4. The method for intelligently generating API data stream security labels according to claim 3, wherein: The construction of the autoencoder network includes mapping the dimensionality-reduced data to a low-dimensional latent space through a multi-layer neural network, and reconstructing the data through inverse mapping to minimize the error between the original data and the reconstructed data; The mapping of the reduced-dimensional data into the autoencoder network to a low-dimensional latent space includes linearly transforming the input data through a weight matrix and a bias vector, and performing nonlinear mapping using an activation function to compress the data dimension layer by layer.

5. The method for intelligently generating API data stream security labels according to claim 4, wherein: Generating hierarchical security labels includes generating bottom-level labels, middle-level labels, and high-level labels; The bottom-level labels include numerical or range-based labels generated based on the basic attributes and physical meaning of the data; the middle-level labels include the refinement of bottom-level labels based on business scenario knowledge and the introduction of historical data or credit rating information; the high-level labels include the integration of multiple data stream interactions and business processes to generate security labels that reflect the global status; The range-type tag is determined based on the rated parameters of the power grid equipment and the fluctuation range allowed for normal operation. The parameters and ranges of the data vary depending on the business. The formula is: Among them, I min is the lower limit of the current range, I max is the upper limit of the current range, S rated is the rated power, U rated is the rated voltage.

6. The method for intelligently generating API data stream security labels according to claim 5, characterized in that: The mid-level label also includes calculating the degree of deviation of trading volume or price fluctuations from historical averages, combining credit rating information to determine the transaction risk level, and generating a risk label based on a preset threshold; The formula for calculating trading volume is: Q=μ Q +gs Q Among them, μ Q is the historical mean of transaction volume, σ Q is the historical standard deviation of the traded electricity volume, γ is the excess coefficient, and Q is the historical electricity trading volume. When the actual electricity trading volume is greater than the historical electricity trading volume, it is determined that the traded electricity volume far exceeds the average level; The formula for calculating price anomaly is: Among them, μ P is the historical average transaction price, σ P is the historical price standard deviation, CV P is the price anomaly coefficient; when CV P >σ P When CV P ≤σ P When , the transaction price is normal; The credit rating information includes: when the performance rate is greater than or equal to 98%, the credit rating is determined to be A, which means low risk; when the performance rate is greater than or equal to 95% and less than 98%, the credit rating is determined to be B, which means medium risk; when the performance rate is less than 95%, the credit rating is determined to be C, which means high risk; The high-level tags also include monitoring changes in power demand, transaction orders and transmission line load rates, counting the amount of abnormal data within a preset time window, and generating a comprehensive risk tag when multiple abnormal conditions are met at the same time.

7. The method for intelligently generating API data stream security labels according to claim 6, characterized in that: The dynamically updating rule base includes classifying and storing rules according to business areas, risk levels, and scopes of application, using visualization tools to display rule triggering conditions and logical relationships, and dynamically updating the rule base to adapt to new business models and data characteristics; The dynamically updated rule base also includes analyzing new business scenarios and data features, extracting key patterns, generating new rules based on the autoencoder learning results and historical label data, adding the new rules to the rule base and visually displaying them.

8. A system using the method for intelligently generating API data stream security labels according to any one of claims 1 to 7, characterized in that: It includes data preprocessing module, autoencoder network construction and mapping module, and security label generation and rule base management module; The data preprocessing module includes a data acquisition unit, a data cleaning unit and a data dimension reduction unit, which is used to regularly collect data streams through the API interface and perform data cleaning and dimension reduction processing; The autoencoder network construction and mapping module includes an autoencoder construction unit and a data mapping and reconstruction unit, which is used to input preprocessed data into the network and map it to a low-dimensional latent space. Through the encoding and decoding process of the multi-layer neural network, the data is effectively compressed and reconstructed to capture the deep-level features of the data; The security label generation and rule base management module includes a security label generation unit and a rule base management unit, which are used to generate hierarchical security labels based on the potential features and business scenario knowledge learned by the autoencoder, manage the rule base, classify and store security label rules, dynamically update rules to adapt to new business models and data features, and display rule logic through visualization tools.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the processor implements the steps of the method for intelligently generating API data stream security labels according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method for intelligently generating API data stream security labels according to any one of claims 1 to 7 are implemented.