Platform security information integration situational early warning method

By standardizing, aligning, and mapping the equipment and network security data of the emergency command platform, the stability coefficient and correlation of the equipment are calculated, which solves the problem of incomplete equipment security situation assessment, enables early identification and warning of potential faults, and improves emergency response capabilities.

CN120675888BActive Publication Date: 2025-11-14HEFEI SHENGWEN INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511149067.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-18
Publication Date
2025-11-14
Estimated Expiration
2045-08-18

AI Technical Summary

Technical Problem

Existing emergency command platforms lack in-depth integration and analysis of equipment operation data and network security data, making it impossible to comprehensively assess the security correlation between devices and the impact of their failures, resulting in incomplete and delayed security situation assessments.

Method used

By acquiring network security element data and device operating data for each device type on the platform, standardizing and aligning them with time series, generating a network security element knowledge graph, calculating the device's operational stability coefficient and security correlation, and combining this with a graph-structured security situation early warning model for early warning.

Benefits of technology

It enables comprehensive security posture assessment of equipment and networks, allowing for early identification of potential faults and risks, and improving emergency response capabilities and platform operational stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675888B_ABST
    Figure CN120675888B_ABST
Patent Text Reader

Abstract

This invention provides a platform security information integration situational early warning method, relating to the field of security situational early warning technology. This invention acquires network security element data and device operating data for each device type on the platform, performs standardization and time-series alignment, generates a network security element knowledge graph from the network security element dataset, calculates the operational stability coefficient of each device based on the operating data of each device type, and determines the security correlation of each device based on its network topology and historical fault data. By constructing graph-structured data, a security situational early warning model is established to provide early warnings for the security situation in the next time window. Device stability is determined based on the predicted operational stability coefficient in the operating type data, and network stability of each device is determined based on the predicted network security element data. Early warnings are provided based on the calculated functional loss rate of platform device types.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of security situation early warning technology, specifically to a platform security information integration situation early warning method. Background Technology

[0002] With the continuous development of information technology infrastructure, especially in critical infrastructure such as emergency command platforms, the stability of equipment and the security of networks directly affect the normal operation of the platform and the efficiency of emergency response. Currently, many emergency command platforms rely on traditional security monitoring methods, such as event-based security monitoring and log analysis. These methods are typically static and one-sided, lacking real-time and dynamic assessment of the overall security status of the equipment. Therefore, how to quickly extract effective security information from massive amounts of equipment data and conduct a comprehensive analysis in conjunction with the equipment's operational status has become a pressing technical challenge.

[0003] While existing security monitoring solutions based on data analytics and machine learning exist, most methods lack in-depth fusion analysis of device operational data and network security data. This is particularly problematic when dealing with complex network topologies and interdependent devices, making it difficult to comprehensively assess the security correlations between devices and the impact of their failures. Therefore, how to integrate multi-source data and provide security early warnings based on the relationship between device operational data and network topology remains a critical issue for emergency command platforms.

[0004] The information disclosed in the background section is only intended to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0005] The purpose of this invention is to provide a platform security information integration situational early warning method to solve the problems mentioned in the background art.

[0006] To achieve the above objectives, the present invention provides the following technical solution:

[0007] A platform security information integration situational early warning method, the specific steps of which include:

[0008] Step 1: Obtain network security element data and device operation data for each device type from the database, device logs, and network traffic of the platform to be warned, and perform standardization and time-series alignment;

[0009] Step 2: Using device name and network security element fault type as entities, establish and extract entity relationships from the network security element dataset to generate a network security element knowledge graph;

[0010] Step 3: Calculate the operational stability coefficient of each device based on the working data of each device type, and determine the security correlation of each device based on the network topology relationship and historical fault data of each device;

[0011] Step 4: Using each device as a node, working data and security correlation as node data, network topology as edges, and together with the network security element knowledge graph, construct a graph structure of security situation data. By establishing a security situation early warning model, provide early warning of the security situation in the next window of time.

[0012] Step 5: Determine equipment stability based on the operational stability coefficient in the predicted work type data, determine the network stability of each device based on the predicted network security element data, and issue an early warning based on the result of calculating the functional loss rate of platform device types.

[0013] Furthermore, the device types include servers, command terminals, communication terminals, and edge terminals;

[0014] The network security data includes traffic anomalies, protocol compliance, access control logs, process anomalies, firmware version, and memory usage.

[0015] The standardized calculation formula is: normalization,

[0016]

[0017] in, The standard value is the normalized value. For network security element data and operational data, This is the average of historical data. Standard deviation;

[0018] The formula for calculating the timing alignment is:

[0019] Using a 5-minute time window, align the timestamps of the data from each device, and fill missing values ​​using linear interpolation:

[0020]

[0021] in, Fill in missing values. The timestamp of the moment before the missing value. The timestamp after the missing value. The timestamp of the current moment where the missing value is. These are the data values ​​at adjacent time points.

[0022] Furthermore, the method for extracting entity relationships is as follows: The network security element dataset is processed by time... Divide the window into sections, if the first section... One device Triggering the same network security element consecutively within a time window Then, the relationship is established, and the mathematical calculation formula is:

[0023]

[0024] in, The size of the time window. This is an indicator function; it returns 1 if the condition is true, and 0 otherwise. For continuous triggering threshold, Indicates equipment and cybersecurity elements The strength of the relationship, For network security elements In the time window Standardized values ​​within, Threshold for determining the relationship For the number of windows, For the first One cybersecurity element;

[0025] The knowledge graph is expressed in the following form:

[0026]

[0027] in, For cybersecurity element knowledge graph, For entities, For the strength of the relationship, For related entities.

[0028] Furthermore, the operational data from the command center, server, and communication terminals include equipment temperature, equipment voltage stability, ambient temperature, and ambient humidity.

[0029] The operational data at the edge includes power consumption, device temperature, position stability, and signal interference intensity.

[0030] The method for calculating the operational stability coefficient of each device is as follows:

[0031]

[0032]

[0033]

[0034]

[0035] in, For the first in the working data The first device Standardized values ​​of the work data For the number of devices, For the first The work data in the first Probability distribution in each device For the first Information entropy of the work data For the first The weight of the work data, For the amount of working data, For the first Information entropy of working data For operational stability coefficient, For the first in the working data Standardized values ​​for the work data.

[0036] Furthermore, the formula for calculating the security correlation degree is:

[0037]

[0038] in, For equipment For equipment Security correlation, , These are the influence weights of the number of node connections and the anomaly ratio, respectively. For equipment The number of node connections, For equipment in historical fault data The malfunction caused the equipment Abnormal proportions For operational stability coefficient, These are the weights for the impact of nodes and the operational stability coefficient, respectively. + , .

[0039] Furthermore, the security situation early warning model includes a graph convolutional neural network and a long short-term memory neural network, with the following specific structure:

[0040] Identification is performed based on real-time work data.

[0041] Image layer:

[0042]

[0043] in, For the first The output feature matrix of a layered graph convolutional neural network. This represents the sigmoid function. It is an adjacency matrix. For the first The input graph structure data for layered graph convolutional neural networks, For the first The weight matrix of the layer, It is a degree matrix;

[0044] The equation for the forgetting gate is:

[0045]

[0046] in , The current open / closed state of the forget gate. This represents the sigmoid function. For the weight of the forget gate, Forget gate bias parameters, This is the hidden state from the previous moment. To output the feature matrix;

[0047] The equation for the input gate is:

[0048]

[0049] in, To input the current open / closed state of the door. For the input gate weights, For input gate bias parameters;

[0050]

[0051] in, Candidate cell state To represent the hyperbolic tangent function, For candidate cell weights, These are the candidate cell state bias parameters;

[0052] The update equation is:

[0053]

[0054] in, Current cell state This represents the cell state at the previous moment;

[0055] The equation for the output gate is:

[0056]

[0057]

[0058] in, To output the current open / closed state of the gate. For the output gate weights, These are the output gate bias parameters. For the predicted graph structure data;

[0059] The mathematical expressions for the sigmoid function and the hyperbolic tangent function are as follows:

[0060]

[0061]

[0062] in, For the sigmoid function, For the input of the sigmoid function, It is the hyperbolic tangent function.

[0063] Furthermore, the method for determining equipment stability is as follows:

[0064] when At this time, it is determined that the equipment is in a stable working state;

[0065] in, Thresholds for determining the stable working state of equipment;

[0066] The technical methods for determining the functional loss rate for each type are as follows:

[0067]

[0068] in, For platform functionality loss rate, For the quantity of each type of equipment, The number of faults for each type of equipment. For the number of faults affecting each type of equipment, For the first Functional loss rate for each type of equipment;

[0069] when If the platform's functionality is severely compromised, an early warning will be issued.

[0070] in, The threshold for judging the loss of platform functionality.

[0071] Compared with the prior art, the beneficial effects of the present invention are:

[0072] This invention acquires network security element data and device operation data for each device type on the platform, performs standardization and time-series alignment, generates a network security element knowledge graph from the network security element dataset, calculates the operational stability coefficient of each device based on the operation data of each device type, and determines the security correlation of each device based on the network topology relationship and historical fault data of each device. By constructing graph structure data, a security situation early warning model is established to provide early warning of the security situation in the next window time. Based on the predicted operational stability coefficient in the operation type data, the device stability is judged. Based on the predicted network security element data, the network stability of each device is judged. Early warning is provided based on the result of calculating the functional loss rate of platform device types.

[0073] This invention addresses the problem of incomplete assessments of device and network security posture in traditional methods by constructing an integrated situational awareness model based on network security elements and device operational data. First, the solution unifies the processing of data from different sources through standardization and time-series alignment, enabling effective analysis of various data types on a single platform. Second, by constructing a knowledge graph, it extracts network security elements and fault types of devices, further revealing the correlations between devices and potential security risks. This graph-based situational awareness modeling method helps to better understand the impact of device faults and their security roles within the overall network.

[0074] This invention also calculates the operational stability coefficient and safety correlation of each device, and combines the historical fault data of the device to predict the safety status of the device in real time and issue early warnings before potential faults occur. This comprehensive safety situation early warning model effectively improves the emergency command platform's ability to predict device and network faults, and can identify and prevent possible system risks in advance, thereby improving the platform's operational stability and emergency response capabilities. Attached Figure Description

[0075] Figure 1 This is a schematic diagram of the overall method flow of the present invention. Detailed Implementation

[0076] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to specific embodiments.

[0077] It should be noted that, unless otherwise defined, the technical or scientific terms used in this invention should have the ordinary meaning understood by one of ordinary skill in the art to which this invention pertains. The terms "first," "second," and similar terms used in this invention do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as "upper," "lower," "left," and "right" are used only to indicate relative positional relationships; when the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0078] Example:

[0079] Please see Figure 1 The present invention provides a technical solution:

[0080] A platform security information integration situational early warning method, the specific steps of which include:

[0081] Step 1: Obtain network security element data and device operation data for each device type from the database, device logs, and network traffic of the platform to be warned, and perform standardization and time-series alignment.

[0082] For emergency command platforms, network security directly impacts their normal operation. Therefore, network security elements are crucial indicators for assessing device security status. These include traffic anomalies, protocol compliance, access control logs, process anomalies, firmware version, and memory usage. These data reflect potential security vulnerabilities in network devices during operation. For example, traffic anomalies may indicate a network attack or drastic traffic fluctuations, while process anomalies may suggest malware intrusion or system vulnerabilities. Analyzing this data allows for early detection of potential security issues, preventing network attacks or data breaches. Network security element data is critical for timely identification of network attacks, vulnerabilities, and unauthorized access risks, helping to predict potential network security threats and implement preventative measures.

[0083] Equipment operating data includes equipment temperature, voltage stability, ambient temperature, and humidity. This data directly reflects the equipment's operational status. Abnormal operating conditions, such as excessively high temperatures or unstable voltage, can lead to equipment malfunctions, or even system-level failures or shutdowns. Real-time monitoring and analysis of this data allows for accurate determination of whether the equipment is in normal working order, and thus predicts the possibility of potential failures. Equipment operating data is crucial for assessing equipment health, especially for equipment requiring high reliability and long-term operation (such as servers, command and control terminals, and communication terminals). Anomalies in operating data are often precursors to impending failures. Tracking and analyzing this data helps the platform identify problems earlier and take corrective action, preventing the spread and escalation of failures.

[0084] A server is computer hardware that provides services, processes data, and supports the operation of other devices within a network. It operates in data centers or cloud platforms and provides computing power, storage services, and data processing functions over the network. A command center refers to equipment used for command and dispatch, and decision support, including smart control consoles and broadcast terminals. A communication center refers to all equipment used for data transmission and communication, including wireless communication base stations, wired network terminals, and satellite communication equipment. Edge devices refer to devices deployed at the network edge, close to data sources or end users, including smart sensors and mobile terminals.

[0085] Combining device operational data with network security data can provide dual protection for both devices and the network. Relying solely on device operational data may not fully identify potential network attack risks, while relying solely on network security data may not reveal whether hardware malfunctions are causing security issues. Therefore, by analyzing both device operational data and network security data, a more comprehensive and accurate understanding of the platform's security posture can be achieved, allowing for the early identification of potential faults and security vulnerabilities.

[0086] For example, abnormal operating conditions of a device may trigger cybersecurity issues, such as overheating leading to decreased processor performance, which in turn affects the execution of network protocols or causes abnormal access control logs. In such cases, joint analysis of cybersecurity element data and device operating data can predict and issue warnings earlier, helping the platform to repair and adjust before problems occur.

[0087] In this embodiment, the device types include servers, command terminals, communication terminals, and edge terminals;

[0088] The network security data includes traffic anomalies, protocol compliance, access control logs, process anomalies, firmware version, and memory usage.

[0089] The standardized calculation formula is: normalization,

[0090]

[0091] in, The standard value is the normalized value. For network security element data and operational data, This is the average of historical data. Standard deviation;

[0092] The formula for calculating the timing alignment is:

[0093] Using a 5-minute time window, align the timestamps of the data from each device, and fill missing values ​​using linear interpolation:

[0094]

[0095] in, Fill in missing values. The timestamp of the moment before the missing value. The timestamp after the missing value. The timestamp of the current moment where the missing value is. These are the data values ​​at adjacent time points.

[0096] The purpose of standardization is to transform data from different devices and data sources into a unified scale or range, thereby eliminating differences in data dimensions. Operating data and network security element data from different devices may have different units and dimensions, such as device temperature, memory usage, and network traffic; their numerical ranges can vary significantly. Standardization can transform this data with different dimensions into a dimensionless value, typically between 0 and 1, making the data comparable when analyzed on the same platform.

[0097] Time-series alignment refers to synchronizing and aligning the operational data and network security element data of various devices according to timestamps, ensuring that the data at each point in time corresponds. In actual data acquisition, data may be missing at certain times. By using methods such as time-series alignment and linear interpolation, missing data can be filled in, making the entire dataset complete, thereby improving the accuracy of subsequent analysis and avoiding the failure of early warnings due to missing data.

[0098] Standardization and time alignment play a crucial role in data preprocessing. Standardization ensures comparability between different data sets and eliminates differences in units of measurement; time alignment ensures data synchronization and consistency, addressing inconsistencies over time. These two operations enable the integration of operational and cybersecurity data from different devices and data sources onto a single platform for unified analysis. This provides a solid data foundation for subsequent fault prediction and security posture assessment, thereby improving the accuracy and real-time performance of the early warning system.

[0099] Step 2: Using device name and network security element fault type as entities, establish and extract entity relationships from the network security element dataset to generate a network security element knowledge graph.

[0100] A knowledge graph is a way to represent knowledge through a graph structure, where nodes represent entities and edges represent relationships between entities. Knowledge graphs can not only include direct relationships between entities but also depict more complex dependencies and influences. In the field of cybersecurity, knowledge graphs are used to associate entities such as devices, cybersecurity elements, and fault types, revealing potential risks in the security posture through the relationships between entities. In traditional cybersecurity management, data is often stored and processed in a scattered manner, which may lead to incomplete or delayed assessments of device status. However, by establishing a cybersecurity element knowledge graph, security data, fault types, and relationships between different devices can be integrated into a unified graph structure. This integrated approach provides a more comprehensive perspective for security analysis, especially in environments with complex network topologies and interdependent devices, effectively improving the ability to predict and identify security risks.

[0101] By unifying the processing of data from various sources (such as device logs, network traffic, and device status data) and presenting it in a graph structure, knowledge graphs help decision-makers understand and address the complex security relationships and potential impacts of failures between devices. Through entity relationship extraction, strong associations can be established between devices, failure types, and security elements, thereby more clearly demonstrating the interactions and dependencies between devices.

[0102] In this embodiment, the method for extracting entity relationships is as follows: the network security element dataset is processed by time... Divide the window into sections, if the first section... One device Triggering the same network security element consecutively within a time window Then, the relationship is established, and the mathematical calculation formula is:

[0103]

[0104] in, The size of the time window. This is an indicator function; it returns 1 if the condition is true, and 0 otherwise. For continuous triggering threshold, Indicates equipment and cybersecurity elements The strength of the relationship, For network security elements In the time window Standardized values ​​within, Threshold for determining the relationship For the number of windows, For the first One cybersecurity element;

[0105] The knowledge graph is expressed in the following form:

[0106]

[0107] in, For cybersecurity element knowledge graph, For entities, For the strength of the relationship, For related entities.

[0108] Step 3: Calculate the operational stability coefficient of each device based on the working data of each device type, and determine the security correlation of each device based on the network topology relationship of each device and the historical fault data of each device.

[0109] The operational stability coefficient is an indicator used to measure the health status of equipment. By analyzing the equipment's operating data (such as temperature, voltage, and power supply status), its operational stability under specific environments can be determined. As operating conditions and the external environment change, the operational stability of the equipment will also change. By dynamically calculating the operational stability coefficient, the operating status of the equipment can be tracked in real time, ensuring the continuous stability of the system.

[0110] In this embodiment, the working data of the command terminal, server, and communication terminal include equipment temperature, equipment voltage stability, ambient temperature, and ambient humidity;

[0111] The operational data at the edge includes power consumption, device temperature, position stability, and signal interference intensity.

[0112] The method for calculating the operational stability coefficient of each device is as follows:

[0113]

[0114]

[0115]

[0116]

[0117] in, For the first in the working data The first device Standardized values ​​of the work data For the number of devices, For the first The work data in the first Probability distribution in each device For the first Information entropy of the work data For the first The weight of the work data, For the amount of working data, For the first Information entropy of working data For operational stability coefficient, For the first in the working data Standardized values ​​for the work data.

[0118] Security interdependence of devices quantifies the interdependencies between them and their impact on the network. Devices often connect and collaborate with each other through various communication protocols, data streams, and control signals. A failure in one device can affect the normal operation of other devices; therefore, understanding the security interdependence between devices is crucial for assessing the overall security status of the system.

[0119] The stability coefficient reflects the state of an individual device, while the security correlation reflects the mutual influence between devices. By combining the two, the platform can not only know whether a certain device is currently stable, but also understand whether a failure of that device will affect other devices, thus gaining a comprehensive understanding of the security status of devices and the network.

[0120] In this embodiment, the formula for calculating the security correlation degree is:

[0121]

[0122] in, For equipment For equipment Security correlation, , These are the influence weights of the number of node connections and the anomaly ratio, respectively. For equipment The number of node connections, For equipment in historical fault data The malfunction caused the equipment Abnormal proportions For operational stability coefficient, These are the weights for the impact of nodes and the operational stability coefficient, respectively. + , .

[0123] Step 4: Using each device as a node, the operational stability coefficient and security correlation degree as node data, and the network topology relationship as edges, a graph structure of security situation data is constructed together with the network security element knowledge graph. By establishing a security situation early warning model, the security situation in the next window time is given an early warning.

[0124] Equipment is a fundamental component of an emergency command platform, representing independent entities in its operation. The status, malfunctions, and cybersecurity issues of each device impact the overall stability of the platform. Therefore, by treating each device as a node in the graph, its status, behavior, and relationships with other devices can be modeled in detail. This facilitates a holistic assessment of the platform's operational status and provides accurate node information for security posture prediction.

[0125] Equipment stability reflects whether the equipment is currently operating normally. By using equipment operational stability as node data, the health status of the equipment can be dynamically monitored, and potential failure risks can be detected in a timely manner.

[0126] The security interdependence between devices reflects their mutual dependence. If device A is connected to device B, a failure in A may affect the normal operation of B. Therefore, the security interdependence, by measuring the risk propagation and fault linkage between devices, can comprehensively reflect the potential security risks between them.

[0127] Network topology determines the connections and dependencies between devices. When a device fails, network topology helps analyze the propagation path of the failure's impact on the entire system. For example, if device A and device B are directly connected, a failure in device A will propagate its impact on device B through this topological edge. Therefore, modeling network topology as edges helps capture the patterns of fault expansion and propagation within the network.

[0128] Graph convolutional neural networks (GNNs) are highly effective at processing graph-structured data, particularly suitable for handling graph-based data such as device network topologies. In a GNN, each node not only considers its own features but also transmits and aggregates information from its neighboring nodes, thus obtaining more comprehensive contextual information. Therefore, GNNs can effectively capture complex relationships and potential influencing factors between devices (such as fault propagation and inter-device dependencies).

[0129] Graph convolutional neural networks (GNNs) can learn the influence propagation patterns between different devices from the device topology, thereby enabling security posture modeling based on security elements, device status, and interrelationships within the network. For example, when a device malfunctions, a GNN can infer whether the malfunction will have a cascading effect on other devices, thus providing early warning.

[0130] Equipment operation and network security data typically exhibit strong time-series characteristics. Long Short-Term Memory (LSTM) neural networks are excellent tools for processing time-series data. They can store historical information through their internal memory units and selectively forget unnecessary information through gating mechanisms. For historical fault and anomaly data of equipment, LSTM neural networks can capture long-term dependencies in the data, thereby enabling accurate fault prediction and security posture early warning. LSTM neural networks can help predict the equipment state at the next moment and identify potential fault trends in advance based on historical data. This is crucial for preventing potential risks, especially in dynamically changing network environments.

[0131] In this embodiment, the security situation early warning model includes a graph convolutional neural network and a long short-term memory neural network, with the following specific structure:

[0132] Identification is performed based on real-time work data.

[0133] Image layer:

[0134]

[0135] in, For the first The output feature matrix of a layered graph convolutional neural network. This represents the sigmoid function. It is an adjacency matrix. For the first The input graph structure data for layered graph convolutional neural networks, For the first The weight matrix of the layer, It is a degree matrix;

[0136] The equation for the forgetting gate is:

[0137]

[0138] in, The current open / closed state of the forget gate. This represents the sigmoid function. For the weight of the forget gate, Forget gate bias parameters, This is the hidden state from the previous moment. To output the feature matrix;

[0139] The equation for the input gate is:

[0140]

[0141] in, To input the current open / closed state of the door. For the input gate weights, For input gate bias parameters;

[0142]

[0143] in, Candidate cell state To represent the hyperbolic tangent function, For candidate cell weights, These are the candidate cell state bias parameters;

[0144] The update equation is:

[0145]

[0146] in, Current cell state This represents the cell state at the previous moment;

[0147] The equation for the output gate is:

[0148]

[0149]

[0150] in, To output the current open / closed state of the gate. For the output gate weights, These are the output gate bias parameters. For the predicted graph structure data;

[0151] The mathematical expressions for the sigmoid function and the hyperbolic tangent function are as follows:

[0152]

[0153]

[0154] in, For the sigmoid function, For the input of the sigmoid function, It is the hyperbolic tangent function.

[0155] Step 5: Determine equipment stability based on the operational stability coefficient in the predicted work type data, determine the network stability of each device based on the predicted network security element data, and issue an early warning based on the result of calculating the functional loss rate of platform device types.

[0156] The operational stability factor reflects the difference between the equipment's operating state and its design expectations, and is usually derived from the equipment's operating data. It measures whether the equipment can stably perform its tasks under current conditions. The operational stability factor reflects the equipment's performance under specific operating conditions, avoiding simplistic judgments based on a single indicator. For example, equipment may have normal temperature in some environments, but unstable voltage; the operational stability factor can comprehensively consider multiple factors to more accurately assess equipment stability.

[0157] Network stability is a key factor affecting device performance, especially when communicating with other devices or systems. By predicting network data (such as bandwidth usage, latency, and packet loss rate), it is possible to determine whether the interaction between the device and the network is stable and whether there are any potential risks in the network.

[0158] Assessing network stability helps system administrators identify and optimize network bottlenecks, preventing device communication interruptions or performance degradation caused by network failures. By predicting network conditions, administrators can proactively adjust network configurations or allocate more resources to ensure smooth device communication.

[0159] By combining these two aspects, the stability of the equipment and the network can be predicted, providing strong guarantees for the platform's security, reliability, and efficiency. Especially when facing complex equipment and network environments, this helps to effectively avoid sudden failures, reduce system downtime, and improve overall emergency response capabilities.

[0160] In predicting the types of network security elements, a threshold is set for the number of different data types. When the predicted number of network security elements exceeds this threshold, the device is considered to be in a faulty state. For example, if a device has more than five different types of network security element data (such as abnormal traffic, protocol compliance, access logs, etc.) within a time window, it indicates that the device faces a high security risk, which may lead to device failure.

[0161] In this embodiment, the method for determining device stability is as follows:

[0162] when At this time, it is determined that the equipment is in a stable working state;

[0163] in, 1 is the threshold for judging the stable working state of the equipment;

[0164] The technical methods for determining the functional loss rate for each type are as follows:

[0165]

[0166] in, For platform functionality loss rate, For the quantity of each type of equipment, The number of faults for each type of equipment. For the number of faults affecting each type of equipment, For the first Functional loss rate for each type of equipment;

[0167] when If the platform's functionality is severely compromised, an early warning will be issued.

[0168] in, Threshold for determining platform functionality loss:

[0169] Functional Loss Rate (FDR) reflects the impact of equipment failure on platform operation. Assessing only the operational stability of equipment and network stability may be insufficient, as these only focus on localized equipment or network conditions. FDR, however, considers the overall impact of failure at both the device and platform levels. Early warning based on FDR goes beyond detecting individual device failures; it emphasizes the impact of equipment failure on the entire system, ensuring the platform can handle multiple device failures. Based on the FDR of different equipment types, the platform can flexibly adjust emergency response strategies to minimize overall functional loss. As a comprehensive indicator, FDR reflects the combined impact of equipment failure on system stability and is a core basis for effective early warning and response decisions. Therefore, early warning based on FDR helps improve system robustness and emergency response capabilities.

[0170] The above formulas are all dimensionless calculations. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0171] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented in software, the above embodiments can be implemented, in whole or in part, as a computer program product. Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution.

[0172] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment, depending on actual needs.

[0173] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application.

Claims

1. A platform security information integration situational early warning method, characterized in that, The specific steps include: Step 1: Obtain network security element data and device operation data for each device type from the database, device logs, and network traffic of the platform to be warned, and perform standardization and time-series alignment; Step 2: Using device name and network security element fault type as entities, establish and extract entity relationships from the network security element dataset to generate a network security element knowledge graph; Step 3: Calculate the operational stability coefficient of each device based on the working data of each device type, and determine the security correlation of each device based on the network topology relationship and historical fault data of each device; Step 4: Using each device as a node, working data and security correlation as node data, network topology as edges, and together with the network security element knowledge graph, construct a graph structure of security situation data. By establishing a security situation early warning model, provide early warning of the security situation in the next window of time. Step 5: Determine equipment stability based on the operational stability coefficient in the predicted work type data, determine the network stability of each device based on the predicted network security element data, and issue early warnings based on the calculated functional loss rate of platform device types; The method for extracting entity relationships is as follows: The network security element dataset is processed by time... Divide the window into sections, if the first section... One device Triggering the same network security element consecutively within a time window Then, the relationship is established, and the mathematical calculation formula is: in, The size of the time window. This is an indicator function; it returns 1 if the condition is true, and 0 otherwise. For continuous triggering threshold, Indicates equipment and cybersecurity elements The strength of the relationship, For network security elements In the time window Standardized values ​​within, Threshold for determining the relationship For the number of windows, For the first One cybersecurity element; The knowledge graph is expressed in the following form: in, For cybersecurity element knowledge graph, For entities, For the strength of the relationship, For related entities; The operational data from the command center, server, and communication terminals include equipment temperature, equipment voltage stability, ambient temperature, and ambient humidity. The operational data at the edge includes power consumption, device temperature, position stability, and signal interference intensity. The method for calculating the operational stability coefficient of each device is as follows: in, For the first in the working data The first device Standardized values ​​of the work data For the number of devices, For the first The work data in the first Probability distribution in each device For the first Information entropy of the work data For the first The weight of the work data, For the amount of working data, For the first Information entropy of working data For operational stability coefficient, For the first in the working data Standardized values ​​of the work data; The formula for calculating the security correlation degree is: in, For equipment For equipment Security correlation, These are the influence weights of the number of node connections and the anomaly ratio, respectively. For equipment The number of node connections, For equipment in historical fault data The malfunction caused the equipment Abnormal proportions For operational stability coefficient, These are the weights for the impact of nodes and the operational stability coefficient, respectively. , .

2. The platform security information integration situational early warning method according to claim 1, characterized in that: The device types include servers, command terminals, communication terminals, and edge terminals; The network security data includes traffic anomalies, protocol compliance, access control logs, process anomalies, firmware version, and memory usage. The standardized calculation formula is: normalization, in, The standard value is the normalized value. For network security element data and operational data, This is the average of historical data. Standard deviation; The formula for calculating the timing alignment is: Using a 5-minute time window, align the timestamps of the data from each device, and fill missing values ​​using linear interpolation: in, Fill in missing values. The timestamp of the moment before the missing value. The timestamp after the missing value. The timestamp of the current moment where the missing value is. These are the data values ​​at adjacent time points.

3. The platform security information integration situational early warning method according to claim 1, characterized in that: The security situation early warning model includes a graph convolutional neural network and a long short-term memory neural network, with the following specific structure: Identification is performed based on real-time work data. Image layer: in, For the first The output feature matrix of a layered graph convolutional neural network. This represents the sigmoid function. It is an adjacency matrix. For the first The input graph structure data for layered graph convolutional neural networks, For the first The weight matrix of the layer, It is a degree matrix; The equation for the forgetting gate is: in, The current open / closed state of the forget gate. This represents the sigmoid function. For the weight of the forget gate, Forget gate bias parameters, This is the hidden state from the previous moment. To output the feature matrix; The equation for the input gate is: in, To input the current open / closed state of the door. For the input gate weights, For input gate bias parameters; in, Candidate cell state To represent the hyperbolic tangent function, For candidate cell weights, These are the candidate cell state bias parameters; The update equation is: in, Current cell state This represents the cell state at the previous moment; The equation for the output gate is: in, To output the current open / closed state of the gate. For the output gate weights, These are the output gate bias parameters. For the predicted graph structure data; The mathematical expressions for the sigmoid function and the hyperbolic tangent function are as follows: in, For the sigmoid function, For the input of the sigmoid function, It is the hyperbolic tangent function.

4. The platform security information integration situational early warning method according to claim 1, characterized in that: The method for determining equipment stability is as follows: when At this time, it is determined that the equipment is in a stable working state; in, Thresholds for determining the stable working state of equipment; The technical methods for determining the functional loss rate for each type are as follows: in, For platform functionality loss rate, For the quantity of each type of equipment, The number of faults for each type of equipment. For the number of faults affecting each type of equipment, For the first Functional loss rate for each type of equipment; when If the platform's functionality is severely compromised, an early warning will be issued. in, The threshold for judging the loss of platform functionality.

Citation Information

Patent Citations

  • Network attack link tracking and threat situation reasoning method based on knowledge graph

    CN119544327A

  • Network security early warning method and system based on artificial intelligence

    CN120342671A