AI- and Big Data-Based Multi-Dimensional Risk Early Warning Methods and Systems for Smart Parks
By employing a multi-dimensional risk early warning method based on AI and big data, and utilizing the NK model and risk level prediction model, the problem of insufficient analysis of the coupling relationship of risk factors in smart parks has been solved, and more accurate risk level prediction and early warning have been achieved.
Patent Information
- Application Number
- CN202510792896.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-13
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2045-06-13
AI Technical Summary
Traditional cybersecurity monitoring methods lack in-depth analysis of the coupling relationships between various risk factors in smart parks, resulting in inaccurate risk level predictions and consequently affecting the accuracy of early warnings.
A multi-dimensional risk early warning method based on AI and big data is adopted. The factor risk coupling value is calculated through the NK model, abnormal monitoring data is identified, and a network security incident risk level prediction model is used for early warning. The risk level is predicted by combining the input layer, feature extraction layer, fusion layer and classification layer.
It improves the accuracy of predicting cybersecurity risk levels in smart parks and enhances the effectiveness of risk warnings. By considering the coupling relationship between various factors, it improves the accuracy and precision of warnings.
Smart Images

Figure CN120688060B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of smart park risk prediction technology, and in particular to a multi-dimensional risk early warning method and system for smart parks based on AI big data. Background Technology
[0002] With the rapid development of IoT technology, smart park construction has become an important trend in modern park management. However, a cybersecurity incident in a smart park can severely damage its operation and management, data security, and user privacy. Traditional cybersecurity monitoring methods predict risk levels based on single factors, lacking in-depth analysis of the coupling relationships between various factors and ignoring the interactions between different risk factors. This results in inaccurate risk level predictions for smart parks, leading to inaccurate early warnings. Therefore, improving the accuracy of risk level predictions for smart parks to enhance the accuracy of risk early warnings is a pressing technical problem that needs to be solved. Summary of the Invention
[0003] To address the aforementioned technical issues, the purpose of this application is to provide a multi-dimensional risk early warning method and system for smart parks based on AI big data, aiming to improve the accuracy of risk level prediction in smart parks and thus enhance the accuracy of risk early warning.
[0004] Firstly, embodiments of this application provide a multi-dimensional risk early warning method for smart parks based on AI big data, including:
[0005] For cybersecurity incidents in smart parks, historical data on various factors are collected, including hardware equipment, software systems, cyberattacks, data security, personnel operations, and third-party services.
[0006] Based on historical data of the aforementioned factors, the risk coupling value of each factor is calculated using the NK model.
[0007] Collect various monitoring data for predicting cybersecurity incident risks and identify abnormal monitoring data;
[0008] Determine the factor type to which the abnormal monitoring data belongs;
[0009] Based on the factor type to which each anomaly monitoring data belongs, the target risk coupling value is determined from the risk coupling values of each factor;
[0010] Based on the anomaly monitoring data and the target risk coupling value, the network security incident risk level is predicted using a network security incident risk level prediction model, and corresponding early warnings are issued based on the prediction results.
[0011] Furthermore, the step of calculating the risk coupling value of each factor using the NK model based on the historical data of the multiple factors includes:
[0012] The six-factor risk coupling value is calculated based on the following formula:
[0013] ;
[0014] h=1,2,...,H;i=1,2,...,I;j=1,2,...,J;k=1,2,...,K;l=1,2,...,L;m=1,2,...,M;
[0015] Where a represents hardware factors, b represents software system factors, c represents network attack factors, d represents data security factors, e represents human operation factors, and f represents third-party service factors; This represents the probability of a network security incident occurring in the following states: hardware device factors in state h, software system factors in state i, network attack factors in state j, data security factors in state k, human operation factors in state l, and third-party services in state f. This represents the probability of a network security incident occurring in a hardware device under state h. This represents the probability of a network security incident risk coupling occurring in the software system in state i. This represents the probability of a network attack and the occurrence of a network security incident risk coupling in state j. This represents the probability of a network security incident occurring in state k, where data security risks are coupled together. This represents the probability of a network security incident occurring when personnel operate in state l. This represents the probability of a network security incident occurring in a third-party service under state m. This represents the six-factor risk coupling value.
[0016] Furthermore, the network security incident risk level prediction model includes an input layer, a feature extraction layer, a fusion layer, and a classification layer. The feature extraction layer is used to extract features from the anomaly monitoring data to obtain the features of each anomaly monitoring data.
[0017] The fusion layer is used to nonlinearly fuse the features of each anomaly monitoring data with the target risk coupling value;
[0018] The classification layer is used to predict the risk level of a cybersecurity incident by combining the fused features and output the risk level of the cybersecurity incident.
[0019] Furthermore, the step of nonlinearly fusing the characteristics of each anomaly monitoring data with the target risk coupling value includes:
[0020] The features of each anomaly monitoring data are nonlinearly fused with the target risk coupling value according to the following formula to obtain the fused features:
[0021] ;
[0022] ;
[0023] in, The fused features are defined as follows: X is a vector composed of features from the anomaly monitoring data; s is the coupling coefficient; W is the weight matrix obtained from model training; R is the target risk coupling value; and k is a dynamically adjusted parameter determined by the intensity of the anomaly monitoring data. The calculation formula is as follows: N is the number of abnormal factors. Let n be the intensity value of the nth abnormal factor. .
[0024] Furthermore, the training loss function of the cybersecurity incident risk level prediction model adopts a classification loss function with ordinal relationships.
[0025] Furthermore, the step of determining the factor type to which the abnormal monitoring data belongs includes:
[0026] Obtain the pre-set mapping rule table between factor types and monitoring data;
[0027] Based on the anomaly monitoring data, the factor type to which the anomaly monitoring data belongs is determined through a mapping rule table between the factor type and the monitoring data.
[0028] Furthermore, the step of determining the target risk coupling value from the risk coupling values of each factor based on the factor type to which each anomaly monitoring data belongs includes:
[0029] Determine a unique coupling pattern formed by the factor types to which all the aforementioned anomaly monitoring data belong;
[0030] Obtain the pre-calculated risk coupling values of each factor;
[0031] The risk coupling value corresponding to the unique coupling pattern is identified from the risk coupling values of each factor and used as the target risk coupling value.
[0032] Secondly, embodiments of this application provide a multi-dimensional risk early warning system for smart parks based on AI big data, the system comprising:
[0033] The data collection module is used to collect historical data on various factors related to cybersecurity incidents in smart parks. These factors include hardware devices, software systems, cyberattacks, data security, personnel operations, and third-party services.
[0034] The calculation module is used to calculate the risk coupling value of each factor based on the historical data of the various factors using the NK model;
[0035] The data acquisition module is used to collect various monitoring data for predicting cybersecurity incident risks and to identify abnormal monitoring data.
[0036] The first determining module is used to determine the factor type to which the abnormal monitoring data belongs;
[0037] The second determination module is used to determine the target risk coupling value from the risk coupling values of each factor based on the factor type to which each anomaly monitoring data belongs;
[0038] The prediction and early warning module is used to predict the risk level of a cybersecurity incident based on the abnormal monitoring data and the target risk coupling value, using a cybersecurity incident risk level prediction model, and to issue corresponding early warnings based on the prediction results.
[0039] This application's embodiments target cybersecurity incidents in smart parks, collecting corresponding multi-factor historical data, including hardware devices, software systems, network attacks, data security, personnel operations, and third-party services. This lays the data foundation for subsequent calculation of the risk coupling value of each factor using the NK model. Including historical data on multiple factors such as hardware devices, software, network attacks, data security, personnel operations, and third-party services improves the comprehensiveness of risk identification. Based on the aforementioned multi-factor historical data, the risk coupling value of each factor is calculated using the NK model, enabling the assessment of the probability of different combinations of factors causing cybersecurity incidents. The higher the risk coupling value, the greater the probability of a cybersecurity incident occurring. By real-time monitoring of various monitoring data used to predict cybersecurity risks and identifying abnormal data, as well as determining the factor type to which the abnormal monitoring data belongs, and determining the target risk coupling value from the risk coupling values of each factor based on the factor type of each abnormal monitoring data; based on the abnormal monitoring data and the target risk coupling value, a cybersecurity risk level is predicted through an artificial intelligence model, and corresponding early warnings are issued based on the prediction results. The artificial intelligence model considers the risk coupling values corresponding to various combinations of abnormal monitoring data. The artificial intelligence model can learn the risk coupling values of various combinations of abnormal factors, the relationship between abnormal monitoring data and risk levels, making the prediction of cybersecurity risk levels more accurate, thereby improving the accuracy of risk early warning in smart parks. Attached Figure Description
[0040] To more clearly illustrate the technical solution of this application, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0041] Figure 1 This is a flowchart illustrating the multi-dimensional risk early warning method for smart parks based on AI big data provided in this application embodiment;
[0042] Figure 2 This is a schematic diagram of the structure of the AI big data-based smart park multi-dimensional risk early warning system provided in the embodiments of this application. Detailed Implementation
[0043] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0044] Those skilled in the art will understand that, unless explicitly stated otherwise, the singular forms “a,” “an,” “the,” and “the” used herein may also include the plural forms. It should be further understood that the term “comprising” as used in the specification of this application means the presence of features, integers, steps, operations, elements, modules, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, modules, components, and / or groups thereof. It should be understood that when we say an element is “connected” or “coupled” to another element, it can be directly connected or coupled to the other element, or there may be intermediate elements. Furthermore, “connected” or “coupled” as used herein can include wireless connections or wireless coupling. The term “and / or” as used herein includes all or any modules and all combinations of one or more associated listed items.
[0045] Those skilled in the art will understand that, unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains. It should also be understood that terms such as those defined in general dictionaries should be understood to have the same meaning as in the context of the prior art, and should not be interpreted in an idealized or overly formal sense unless specifically defined as herein.
[0046] Please see Figure 1 This application provides a method for multi-dimensional risk early warning in smart parks based on AI big data, the method including:
[0047] S1. For cybersecurity incidents in smart parks, collect historical data on various factors, including hardware equipment, software systems, network attacks, data security, personnel operations, and third-party services.
[0048] S2. Based on the historical data of the aforementioned multiple factors, calculate the risk coupling value of each factor using the NK model;
[0049] S3. Collect various monitoring data for predicting cybersecurity incident risks and identify abnormal monitoring data;
[0050] S4. Determine the factor type to which the abnormal monitoring data belongs;
[0051] S5. Based on the factor type to which each abnormal monitoring data belongs, determine the target risk coupling value from the risk coupling values of each factor.
[0052] S6. Based on the abnormal monitoring data and the target risk coupling value, predict the risk level of a network security incident using a network security incident risk level prediction model and issue a corresponding early warning based on the prediction results.
[0053] In step S1, for cybersecurity incidents in the smart park, a large amount of historical data on various factors is collected, such as integrating cybersecurity incidents within the park over the past three years. After collecting historical data on various factors, predictive preprocessing is performed, such as removing outliers and distributing the data for easy retrieval and use later, and avoiding single points of failure. Hardware devices include servers, network equipment, etc. For example, in a cybersecurity incident, server hardware failure leads to service interruption. Software systems include operating systems, application software, and middleware, etc. In a cybersecurity incident, system vulnerabilities are exploited, leading to malicious code execution. Network attacks include external and internal malicious network behaviors; in a cybersecurity incident, a DDoS attack causes network paralysis. Human operation includes human error or violation. In a cybersecurity incident, an administrator accidentally deletes system files, causing business interruption. Third-party services include outsourced services, API interfaces, and other third-party dependencies. In a cybersecurity incident, vulnerabilities in third-party cloud services lead to data theft. Data security includes the confidentiality and integrity of data storage, storage, and processing. In a cybersecurity incident, database leakage leads to the outflow of sensitive information. Among these six risk factors, there are correlations and coupled risk scenarios. For example, older servers may not support the latest security patches, leading to vulnerabilities being exploited. Administrators may fail to close test ports in a timely manner, creating entry points for attacks. This application's embodiments improve the comprehensiveness of risk identification by utilizing historical data from multiple factors, including hardware devices, software, network attacks, data security, personnel operations, and third-party services.
[0054] In step S2 above, to quantify the coupling degree of (risk) factors in cybersecurity incidents, cybersecurity incident risks are categorized into six types: hardware devices, software systems, network attacks, data security, personnel operations, and third-party services. The risk coupling value for each factor is calculated using the NK model. Calculating the risk coupling value for each factor using the NK model allows for the assessment of the probability of a cybersecurity incident occurring with different combinations of factors. A higher risk coupling value indicates a greater coupling risk and a higher probability of a cybersecurity incident occurring. The risk coupling values for each factor include two-factor, three-factor, four-factor, five-factor, and six-factor risk coupling values. The two-factor risk coupling value includes multiple values, corresponding to the risk coupling value between two different factors. The same applies to three-factor, four-factor, and five-factor values.
[0055] In steps S3-S5 above, various monitoring data are collected to predict cybersecurity risks, and abnormal monitoring data is identified. In one example, the monitoring data includes hardware device data, software system data, network attack data, data security data, personnel operation data, and third-party service data. Hardware device data includes CPU utilization, software system data includes the number of operating system vulnerabilities, network attack data includes DDoS attack traffic, data security data includes the number of unauthorized accesses, personnel operation data includes the number of accidental operations, and third-party service data includes the number of third-party response errors. In this example, abnormal monitoring data is identified by threshold comparison.
[0056] This application's embodiments target cybersecurity incidents in smart parks, collecting corresponding multi-factor historical data, including hardware devices, software systems, network attacks, data security, personnel operations, and third-party services. This lays the data foundation for subsequent calculation of the risk coupling value of each factor using the NK model. Including historical data on multiple factors such as hardware devices, software, network attacks, data security, personnel operations, and third-party services improves the comprehensiveness of risk identification. Based on the aforementioned multi-factor historical data, the risk coupling value of each factor is calculated using the NK model, enabling the assessment of the probability of different combinations of factors causing cybersecurity incidents. The higher the risk coupling value, the greater the probability of a cybersecurity incident occurring. By real-time monitoring of various monitoring data used to predict cybersecurity risks and identifying abnormal data, as well as determining the factor type to which the abnormal monitoring data belongs, and determining the target risk coupling value from the risk coupling values of each factor based on the factor type of each abnormal monitoring data; based on the abnormal monitoring data and the target risk coupling value, a cybersecurity risk level is predicted through an artificial intelligence model, and corresponding early warnings are issued based on the prediction results. The artificial intelligence model considers the risk coupling values corresponding to various combinations of abnormal monitoring data. The artificial intelligence model can learn the risk coupling values of various combinations of abnormal factors, the relationship between abnormal monitoring data and risk levels, making the prediction of cybersecurity risk levels more accurate, thereby improving the accuracy of risk early warning in smart parks.
[0057] In this embodiment, before calculating the risk coupling value of each factor, the coupling combination mode and frequency of six factors—hardware equipment, software system, network attack, data security, personnel operation, and third-party services—in a large number of network security incidents are analyzed. Each factor has two states: not occurring (0) and occurring (1), forming 63 coupling combinations. By statistically analyzing the coupling frequency of various coupling combinations, the frequency of each coupling combination can be calculated. Using the frequency of various coupling combinations, the risk coupling value of each factor can be calculated using the calculation formula of interaction information T in information theory to represent the coupling between security risks. For example, the risk coupling value of the six factors can be calculated using the following formula.
[0058] ;
[0059] h=1,2,...,H;i=1,2,...,I;j=1,2,...,J;k=1,2,...,K;l=1,2,...,L;m=1,2,...,M;
[0060] Where a represents hardware factors, b represents software system factors, c represents network attack factors, d represents data security factors, e represents human operation factors, and f represents third-party service factors; This represents the probability of a network security incident occurring in the following states: hardware device factors in state h, software system factors in state i, network attack factors in state j, data security factors in state k, human operation factors in state l, and third-party services in state f. This represents the probability of a network security incident occurring in a hardware device under state h. This represents the probability of a network security incident risk coupling occurring in the software system in state i. This represents the probability of a network attack and the occurrence of a network security incident risk coupling in state j. This represents the probability of a network security incident occurring in state k, where data security risks are coupled together. This represents the probability of a network security incident occurring when personnel operate in state l. This represents the probability of a network security incident occurring in a third-party service under state m. This represents the six-factor risk coupling value.
[0061] Similarly, when two risk factors are coupled, there are 15 possible coupling combinations: hardware device-software system, hardware device-network attack, hardware device-hardware device, ..., personnel operation and third-party services. Based on the formula for calculating interaction information, the risk coupling value of the device-software system is calculated using the formula... ;
[0062] h=1,2,...,H; i=1,2,...,I;
[0063] T(a,b) represents the risk coupling value of the device-software system. This represents the probability of risk coupling between hardware factors in state h and software system factors in state i. This represents the probability of the hardware device being in state h. This represents the probability of the software system being in state i.
[0064] The calculation of coupling values between other factors is similar, and is performed according to the interactive information calculation formula. This invention will not elaborate further.
[0065] In one embodiment, the network security incident risk level prediction model includes an input layer, a feature extraction layer, a fusion layer, and a classification layer. The feature extraction layer is used to extract features from the anomaly monitoring data to obtain the features of each anomaly monitoring data.
[0066] The fusion layer is used to nonlinearly fuse the features of each anomaly monitoring data with the target risk coupling value;
[0067] The classification layer is used to predict the risk level of a cybersecurity incident by combining the fused features and output the risk level of the cybersecurity incident.
[0068] In one example, the features extracted by the feature extraction layer include the ratio of the current CPU utilization to the maximum outlier of CPU utilization, the ratio of the current number of operating system vulnerabilities to the maximum outlier of operating system vulnerabilities, the ratio of the current number of unauthorized accesses to the maximum outlier of unauthorized accesses, the ratio of the current number of erroneous operations to the maximum outlier of erroneous operations, and the ratio of the current number of third-party response errors to the maximum outlier of third-party response errors. In one example, the feature extraction layer includes multiple channels for receiving various anomaly monitoring data and using a normalization module to calculate the features of each anomaly monitoring data. The fusion layer includes a fully connected layer and a coupling coefficient calculation module, which calculates the coupling coefficient. The classification layer uses a multilayer perceptron.
[0069] In one embodiment, the step of nonlinearly fusing the features of each anomaly monitoring data with the target risk coupling value includes:
[0070] The features of each anomaly monitoring data are nonlinearly fused with the target risk coupling value according to the following formula to obtain the fused features:
[0071] ;
[0072] ;
[0073] in, The fused features are defined as follows: X is a vector composed of features from the anomaly monitoring data; s is the coupling coefficient; W is the weight matrix obtained from model training; R is the target risk coupling value; and k is a dynamically adjusted parameter determined by the intensity of the anomaly monitoring data. The calculation formula is as follows: N is the number of abnormal factors. Let n be the intensity value of the nth abnormal factor. .
[0074] In this embodiment, the accuracy of risk prediction is improved by nonlinearly fusing the characteristics of each anomaly monitoring data with the target risk coupling value. By dynamically adjusting the coupling coefficient using the Sigmoid function, an intelligent balance between the severity of anomalies and the coupling effect is achieved in smart park risk early warning, thereby improving the accuracy and precision of risk prediction.
[0075] In one embodiment, the training loss function of the network security incident risk level prediction model adopts a classification loss function with ordinal relationships.
[0076] In this embodiment, the classification loss function with ordinal relation decomposes the ordered K-class classification task into K−1 binary classification tasks, enhancing classification robustness and reducing the overall false alarm rate. Each task uses an independent BCE loss (Binary Cross-Entropy).
[0077] In this embodiment, the samples used to train the network security incident risk level prediction model specifically include anomaly monitoring data, target risk coupling values, and corresponding risk levels. During training, a classification loss function with ordinal relationships is used.
[0078] In one embodiment, the step of determining the factor type to which the abnormal monitoring data belongs includes:
[0079] Obtain the pre-set mapping rule table between factor types and monitoring data;
[0080] Based on the anomaly monitoring data, the factor type to which the anomaly monitoring data belongs is determined through a mapping rule table between the factor type and the monitoring data.
[0081] In one embodiment, the step of determining the target risk coupling value from the risk coupling values of each factor based on the factor type to which each anomaly monitoring data belongs includes:
[0082] Determine a unique coupling pattern formed by the factor types to which all the aforementioned anomaly monitoring data belong;
[0083] Obtain the pre-calculated risk coupling values of each factor;
[0084] The risk coupling value corresponding to the unique coupling pattern is identified from the risk coupling values of each factor and used as the target risk coupling value.
[0085] In this embodiment, the anomaly monitoring data belongs to three factor types: hardware device factor a, software system factor b, and network attack factor c. The unique coupling pattern among these three is abc, and the target risk coupling value is the risk coupling value among abc. Furthermore, if no corresponding risk coupling value can be found from the risk coupling values of each factor, its risk coupling value is set to 0. Since the NK model calculates the risk coupling value between two or more factors, its risk coupling value is set to 0 for a single factor.
[0086] Please see Figure 2 This application also provides a smart park multi-dimensional risk early warning system based on AI big data, the system comprising:
[0087] Module 1 is used to collect historical data on various factors related to cybersecurity incidents in smart parks; these factors include hardware devices, software systems, network attacks, data security, personnel operations, and third-party services.
[0088] Calculation module 2 is used to calculate the risk coupling value of each factor based on the historical data of the multiple factors using the NK model;
[0089] The data acquisition module 3 is used to collect various monitoring data for predicting network security incident risks and to identify abnormal monitoring data;
[0090] The first determining module 4 is used to determine the factor type to which the abnormal monitoring data belongs;
[0091] The second determining module 5 is used to determine the target risk coupling value from the risk coupling values of each factor based on the factor type to which each anomaly monitoring data belongs;
[0092] The prediction and early warning module 6 is used to predict the risk level of a network security incident based on the abnormal monitoring data and the target risk coupling value, and to issue corresponding early warnings based on the prediction results.
[0093] In one embodiment, the computing module 2 is specifically used for:
[0094] The six-factor risk coupling value is calculated based on the following formula:
[0095] ;
[0096] h=1,2,...,H;i=1,2,...,I;j=1,2,...,J;k=1,2,...,K;l=1,2,...,L;m=1,2,...,M;
[0097] Where a represents hardware factors, b represents software system factors, c represents network attack factors, d represents data security factors, e represents human operation factors, and f represents third-party service factors; This represents the probability of a network security incident occurring in the following states: hardware device factors in state h, software system factors in state i, network attack factors in state j, data security factors in state k, human operation factors in state l, and third-party services in state f. This represents the probability of a network security incident occurring in a hardware device under state h. This represents the probability of a network security incident risk coupling occurring in the software system in state i. This represents the probability of a network attack and the occurrence of a network security incident risk coupling in state j. This represents the probability of a network security incident occurring in state k, where data security risks are coupled together. This represents the probability of a network security incident occurring when personnel operate in state l. This represents the probability of a network security incident occurring in a third-party service under state m. This represents the six-factor risk coupling value.
[0098] In one embodiment, the network security incident risk level prediction model includes an input layer, a feature extraction layer, a fusion layer, and a classification layer. The feature extraction layer is used to extract features from the anomaly monitoring data to obtain the features of each anomaly monitoring data.
[0099] The fusion layer is used to nonlinearly fuse the features of each anomaly monitoring data with the target risk coupling value;
[0100] The classification layer is used to predict the risk level of a cybersecurity incident by combining the fused features and output the risk level of the cybersecurity incident.
[0101] In one embodiment, the fusion layer is specifically used for:
[0102] The features of each anomaly monitoring data are nonlinearly fused with the target risk coupling value according to the following formula to obtain the fused features:
[0103] ;
[0104] ;
[0105] in, The fused features are defined as follows: X is a vector composed of features from the anomaly monitoring data; s is the coupling coefficient; W is the weight matrix obtained from model training; R is the target risk coupling value; and k is a dynamically adjusted parameter determined by the intensity of the anomaly monitoring data. The calculation formula is as follows: N is the number of abnormal factors. Let n be the intensity value of the nth abnormal factor. .
[0106] In one embodiment, the training loss function of the network security incident risk level prediction model adopts a classification loss function with ordinal relationships.
[0107] In one embodiment, the first determining module 4 includes:
[0108] The acquisition unit is used to acquire a pre-set mapping rule table between factor types and monitoring data;
[0109] The first determining unit is used to determine the factor type to which the abnormal monitoring data belongs based on the abnormal monitoring data and through a mapping rule table between the factor type and the monitoring data.
[0110] In one embodiment, the second determining module 5 includes:
[0111] The second determining unit is used to determine the unique coupling pattern formed by the factor types to which all the anomaly monitoring data belong;
[0112] The acquisition unit is used to acquire the pre-calculated risk coupling values of each factor;
[0113] The matching unit is used to find the risk coupling value corresponding to the unique coupling pattern from the risk coupling values of each factor as the target risk coupling value.
[0114] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in this application and in the embodiments can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual-speed SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).
[0115] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, article, or method that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, apparatus, article, or method. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, apparatus, article, or method that includes that element.
[0116] The above description is only a preferred embodiment of this application and does not limit the patent scope of this application. Any equivalent structural or procedural changes made based on the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.
Claims
1. A multi-dimensional risk early warning method for smart park based on AI big data, characterized in that, The method comprises: For the network security incident of the smart park, collect the corresponding multiple factor historical data thereof; wherein, the factors include hardware devices, software systems, network attacks, data security, personnel operations and third-party services; Based on the multiple factor historical data, calculate the risk coupling values of each factor by an N-K model; Collect various monitoring data for predicting the risk of network security incidents and identify abnormal monitoring data; Determine the factor type to which the abnormal monitoring data belongs; Based on the factor type to which each abnormal monitoring data belongs, determine the target risk coupling value from the risk coupling values of each factor; Based on the abnormal monitoring data and the target risk coupling value, predict the risk level of the network security incident by a network security incident risk level prediction model and perform corresponding early warning according to the prediction result; The step of determining the target risk coupling value from the risk coupling values of each factor based on the factor type to which each abnormal monitoring data belongs comprises: Determine a unique coupling mode composed of the factor types to which all the abnormal monitoring data belongs; Obtain the risk coupling values of each factor calculated in advance; Find out the risk coupling value corresponding to the unique coupling mode from the risk coupling values of each factor as the target risk coupling value. 2.The AI big data-based smart park multi-dimensional risk early warning method of claim 1, wherein, The step of calculating the risk coupling values of each factor based on the multiple factor historical data by the N-K model comprises: Calculate the six-factor risk coupling values based on the following formula: ; h=1,2,...,H;i=1,2,...,I;j=1,2,...,J;k=1,2,...,K;l=1,2,...,L;m=1,2,...,M; Wherein, a represents hardware device factor, b represents software system factor, c represents network attack factor, d represents data security factor, e represents personnel operation factor, f represents third party service factor; represents the probability of network security incident risk coupling occurring under the condition that hardware device factor is in the hth state, software system factor is in the ith state, network attack factor is in the jth state, data security factor is in the kth state, personnel operation factor is in the lth state, and third party service is in the mth state, represents the probability of network security incident risk coupling occurring under the condition that hardware device is in the hth state, represents the probability of network security incident risk coupling occurring under the condition that software system is in the ith state, represents the probability of network security incident risk coupling occurring under the condition that network attack is in the jth state, represents the probability of network security incident risk coupling occurring under the condition that data security is in the kth state, represents the probability of network security incident risk coupling occurring under the condition that personnel operation is in the lth state, represents the probability of network security incident risk coupling occurring under the condition that third party service is in the mth state, represents the six-factor risk coupling value. 3.The AI big data-based smart park multi-dimensional risk early warning method of claim 1, wherein, The network security incident risk level prediction model comprises an input layer, a feature extraction layer, a fusion layer and a classification layer, the feature extraction layer is used for feature extraction of the abnormal monitoring data to obtain the features of each abnormal monitoring data; The fusion layer is used for nonlinear fusion of the features of each abnormal monitoring data and the target risk coupling value; The classification layer is used for network security incident risk level prediction of the fused features and outputs the network security incident risk level. 4.The AI big data-based smart park multi-dimensional risk early warning method of claim 3, wherein, The step of nonlinearly fusing the features of each abnormal monitoring data and the target risk coupling value comprises: Nonlinearly fuse the features of each abnormal monitoring data and the target risk coupling value according to the following formula to obtain the fused features: ; ; wherein, is the fused feature, X is the feature vector of the abnormal monitoring data, s is the coupling coefficient, W is the weight matrix obtained by model training, R is the target risk coupling value, k is a dynamic adjustment parameter determined by the intensity of the abnormal monitoring data, and the calculation formula is: , N is the number of abnormal factors, is the intensity value of the nth abnormal factor, . 5.The AI big data-based smart park multi-dimensional risk early warning method of claim 3, wherein, The training loss function of the network security incident risk level prediction model adopts a classification loss function with ordinal relationship. 6.The AI big data-based smart park multi-dimensional risk early warning method of claim 1, wherein, The step of determining the factor type to which the abnormal monitoring data belongs comprises: Obtain a mapping rule table between the factor types and the monitoring data set in advance; Based on the abnormal monitoring data, determine the factor type to which the abnormal monitoring data belongs through the mapping rule table between the factor types and the monitoring data.
7. An AI big data-based smart park multi-dimensional risk early warning system, characterized in that, The system comprises: A collection module for collecting the corresponding multiple factor historical data of the network security incident of the smart park; wherein, the factors include hardware devices, software systems, network attacks, data security, personnel operations and third-party services; A calculation module for calculating the risk coupling values of each factor based on the multiple factor historical data by an N-K model; The collection module is configured to collect various monitoring data for predicting network security incident risks and identify abnormal monitoring data; The first determination module is configured to determine a factor type to which the abnormal monitoring data belongs; The second determination module is configured to determine a target risk coupling value from the factor risk coupling values based on the factor type to which each abnormal monitoring data belongs; The prediction and early warning module is configured to perform network security incident risk level prediction through a network security incident risk level prediction model based on the abnormal monitoring data and the target risk coupling value, and perform corresponding early warning according to a prediction result. The second determination module includes: A second determination unit configured to determine a unique coupling mode formed by the factor types to which all the abnormal monitoring data belongs; An acquisition unit configured to acquire the factor risk coupling values calculated in advance; A matching unit configured to find out a risk coupling value corresponding to the unique coupling mode from the factor risk coupling values as the target risk coupling value.
Citation Information
Patent Citations
Smart park distributed network security risk assessment method and device
CN114793182A
Network security early warning method and system
CN118646569A