An artificial intelligence-based network information security intrusion detection method

By embedding signal detection points in the network information transmission area, optimizing the layout of signal detection points, performing noise reduction processing, and detecting anomalies, combined with an intelligent management mechanism, the problems of intrusion pattern updates and noise impact in the network are solved, achieving efficient and low-power intrusion detection.

CN120692061BActive Publication Date: 2026-02-03ZHONGKE FUTURE TECHNOLOGY IND DEVELOPMENT (PANAN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510771924.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-11
Publication Date
2026-02-03
Estimated Expiration
2045-06-11

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively identify constantly evolving intrusion patterns in networks, and noise interference can cause intrusion signal detection failures, resulting in low identification efficiency.

Method used

By embedding signal detection points in the network information transmission area, and through optimization of signal detection point layout, noise reduction processing, signal amplification and anomaly detection, combined with an intelligent detection management mechanism, low-power intrusion detection can be achieved.

Benefits of technology

It improves the efficiency of identifying unknown intrusions, reduces the probability of detection failure caused by noise, and enables timely detection of intrusions while reducing power consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120692061B_ABST
    Figure CN120692061B_ABST
Patent Text Reader

Abstract

The application discloses a network information security intrusion detection method based on artificial intelligence and relates to the technical field of network security, which comprises the following steps: at least one signal detection point is adopted to capture actual network signals generated by network transmission at the signal detection point; a detection point layout optimization position is formed; network noise reduction signals are obtained; a signal processing mechanism is formed to obtain network amplification signals; abnormal detection is performed on the network amplification signals; when an abnormality is detected, the network amplification signals are terminated; when no abnormality is detected, the network amplification signals are released; an intelligent detection management mechanism is formed to realize low-power-consumption operation of detection. Through abnormal feature extraction and extension, as many unknown intrusions as possible can be identified according to existing intrusions, so that the intrusion probability is reduced, and noise is processed during detection, so that the probability of intrusion detection failure caused by noise is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, specifically to an artificial intelligence-based network information security intrusion detection method. Background Technology

[0002] Intrusion detection refers to the process of manipulating behavior, security logs, audit data, or other information available on the network to detect intrusions or attempts to break into a system. Intrusion detection is a discipline that detects and responds to computer misuse, and its functions include deterrence, detection, response, damage assessment, attack prediction, and prosecution support.

[0003] Detecting existing intrusions is relatively easy, but intrusions on the network are constantly being updated, and many new intrusion patterns will emerge, making them difficult to detect. At the same time, network transmission is affected by noise, which may affect the detection of a small number of intrusion signals, leading to identification failure and thus triggering an intrusion. Summary of the Invention

[0004] To address the aforementioned technical problems, this paper provides a network information security intrusion detection method based on artificial intelligence. This technical solution solves the problems mentioned in the background section.

[0005] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0006] An artificial intelligence-based network information security intrusion detection method includes:

[0007] In the area where network information is received, at least one signal detection point is embedded in the target detection area as the target detection area.

[0008] Use at least one signal detection point;

[0009] Optimize the layout of detection points, use the optimized layout of detection points to arrange the positions of signal detection points, and acquire at least one internal network signal at the optimized signal detection points. During information transmission, the signal detection points capture the actual network signal generated at the signal detection points.

[0010] The actual network signal is denoised to obtain the network denoised signal;

[0011] A signal processing mechanism is established, and the signal processing mechanism is used to amplify the network noise reduction signal to obtain the network amplified signal;

[0012] Anomaly detection is performed on the network amplified signal. If an anomaly is detected, the transmission of the network amplified signal is terminated. If no anomaly is detected, the network amplified signal is allowed to pass.

[0013] An intelligent detection management mechanism is established to achieve low-power operation of the detection process.

[0014] Preferably, the process of forming an optimized detection point layout position and using the optimized detection point layout position to arrange the signal detection points includes the following steps:

[0015] Obtain the information transmission topology in the target detection area, and obtain at least one structural entry point in the information transmission topology, wherein the structural entry point is a necessary entry point into the target detection area;

[0016] At least one sampling point is uniformly set at each node within the information transmission topology.

[0017] In the case of network information transmission, acquire network sampling information transmitted to the sampling point;

[0018] When network sampling information spreads at the sampling point, the sampling point is taken as the target sampling point;

[0019] Target sampling points and structural entrances that are different from signal detection points are used as the optimized locations for the detection point layout;

[0020] The optimized location of the detection point layout is used as the location for adding at least one signal detection point.

[0021] Preferably, acquiring at least one internal network signal includes the following steps:

[0022] During the intermittent period of network information transmission, at least one internal network signal is acquired at at least one signal detection point.

[0023] Preferably, the step of performing noise reduction processing on the actual network signal to obtain the network noise-reduced signal includes the following steps:

[0024] Based on historical transmission data, signal detection points that have generated abnormalities are considered as points with a high probability of intrusion.

[0025] The average value of the internal vibration signal is obtained by averaging the signal of at least one internal network.

[0026] The Fourier transform is used to decompose the actual network signal at the point of possible intrusion probability to obtain at least one actual basic signal.

[0027] The mean internal vibration signal is decomposed using Fourier transform to obtain at least one basic intrusion signal.

[0028] The actual basic signals that differ from the basic intrusion signal by less than a preset range are deleted. The preset range is the allowable error of the same signal based on experience.

[0029] The network denoised signal is obtained by combining at least one of the original basic signals after deletion using an inverse Fourier transform.

[0030] Preferably, the formation of the signal processing mechanism, and the amplification of the network noise reduction signal using the signal processing mechanism, includes the following steps:

[0031] The network noise reduction signal is filtered to obtain the network filtered signal;

[0032] Based on historical data, the range of signal amplification ratio is obtained, and the range of signal amplification ratio is divided into equal intervals to obtain at least one amplification point.

[0033] The network noise reduction signal is amplified according to the value at the amplification point to obtain the network amplified signal. The probability that the network amplified signal is misidentified is calculated and used as the feature probability.

[0034] When the feature probability is less than the preset probability, the value at the amplification point corresponding to the feature probability is taken as the optimal amplification ratio.

[0035] The filtering process and the amplification process using the optimal amplification ratio are used as signal processing mechanisms.

[0036] The network noise reduction signal is processed using signal processing mechanisms to obtain the network amplified signal, wherein one of the optimal amplification ratios is used for signal amplification.

[0037] Preferably, the anomaly detection of the network amplified signal includes the following steps:

[0038] Based on big data, existing historical transmission data of network transmission is obtained, and abnormal data is extracted from the historical transmission data to obtain sample abnormal data.

[0039] The data topology structure of the sample abnormal data is obtained, and the abnormal features of the data topology structure are extracted and extended to obtain at least one abnormal local structure.

[0040] The probability of the existence of abnormal local structures is statistically analyzed. At least one abnormal local structure is randomly combined to obtain at least one combination of abnormal local structures. The overall probability of the existence of abnormal local structure combinations is calculated. Abnormal local structure combinations with an overall probability of existence less than a preset probability are deleted. The preset probability is the maximum probability of low-probability events occurring in the network.

[0041] Abnormal local structures in the combination of abnormal local structures are merged to form a suspected abnormal structure;

[0042] Targeted detection data is generated for suspicious abnormal structures. The targeted detection data can quickly identify suspicious abnormal structures and contains signal termination data.

[0043] The network amplification signal is amplified using targeted detection data. When the network amplification signal is terminated, an anomaly is found in the network amplification signal.

[0044] When the network amplification signal is not terminated, the network amplification signal is allowed to be transmitted in the target detection area.

[0045] Preferably, the step of extracting and extending the abnormal features of the data topology to obtain at least one abnormal local structure includes the following steps:

[0046] The data topology is segmented to obtain at least one preliminary anomaly feature, which is the minimum structure to realize the data function.

[0047] In big data, at least one feature combination is randomly generated. The feature combination consists of two data features. When the two data features in the feature combination have the same effect, the feature combination is taken as the target feature combination.

[0048] Calculate the difference between two data features in the target feature combination as the data difference, and take the maximum value of the data difference of the target feature combination as the preset difference;

[0049] In big data, data features whose difference from the initial anomaly features is less than a preset difference are considered as similar features to the initial anomaly features.

[0050] The initial features of the anomaly and its similar features are each considered as the local structure of the anomaly.

[0051] Preferably, the process of generating targeted detection data for suspicious abnormal structures includes the following steps:

[0052] The suspicious abnormal structure is compared with other data structures to obtain the target structure. The target structure is a local structure in the suspicious abnormal structure and is different from the data structures other than the suspicious abnormal structure.

[0053] The dual structure that forms the target structure matches the missing part of the target structure;

[0054] Obtain the feature surface, which is the part of the dual structure at the position where the dual structure and the target structure are spliced ​​together;

[0055] At least one identification point is uniformly selected on the feature surface. Signal termination data is set at the identification point. The trigger condition for the signal termination data is that all identification points on the feature surface are in contact with the data structure to be detected. The signal termination data set at the identification points of the dual structure and the feature surface are summarized into target detection data.

[0056] Preferably, the formation of the intelligent detection management mechanism, which enables low-power operation of the detection, includes the following steps:

[0057] Obtain the total number of actual network signals captured at points with high intrusion probability and the number of actual network signals exhibiting attack behavior at points with high intrusion probability. Use the intrusion ratio formula to calculate the intrusion ratio at points with high intrusion probability.

[0058] The minimum intrusion ratio of the top 10% of possible intrusion probability points with the highest intrusion ratio is used as the preset ratio;

[0059] Based on the intrusion ratio, the possible points of intrusion probability are classified into non-essential collection points and essential collection points. Non-essential collection points are the possible points of intrusion probability with an intrusion ratio less than a preset ratio, and essential collection points are the possible points of intrusion probability with an intrusion ratio exceeding a preset ratio.

[0060] The intelligent detection management mechanism is as follows: suspend signal detection points at non-essential collection points, and keep signal detection points at essential collection points operational;

[0061] The intrusion rate formula is as follows:

[0062]

[0063] Where A is the intrusion ratio of a point with a high probability of intrusion, a is the number of actual network signals exhibiting attack behavior at a point with a high probability of intrusion, and b is the total number of actual network signals captured at a point with a high probability of intrusion.

[0064] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0065] By setting up signal detection points, monitoring is conducted at locations prone to intrusion, ensuring that any intrusion is detected promptly and preventing greater losses. Simultaneously, the number of operating signal detection points can be effectively controlled, achieving low-power operation. Furthermore, during anomaly detection, anomaly features are extracted and extended, enabling the identification of as many unknown intrusions as possible based on existing intrusions, thereby reducing the probability of intrusion. Noise processing during detection further reduces the probability of intrusion detection failures due to noise interference, ultimately improving the overall efficiency of security intrusion identification. Attached Figure Description

[0066] Figure 1 This is a flowchart illustrating the artificial intelligence-based network information security intrusion detection method of the present invention.

[0067] Figure 2 This is a flowchart illustrating the process of arranging signal detection points using the optimized detection point layout for the present invention.

[0068] Figure 3This is a schematic diagram illustrating the process of denoising actual network signals to obtain denoised network signals according to the present invention.

[0069] Figure 4 This invention provides a schematic diagram of the signal processing mechanism used to amplify network noise reduction signals.

[0070] Figure 5 This is a schematic diagram of the process for anomaly detection of network amplified signals according to the present invention;

[0071] Figure 6 This is a schematic diagram of the process of extracting and extending abnormal features of data topology to obtain at least one abnormal local structure according to the present invention.

[0072] Figure 7 This is a schematic diagram of the process for generating targeted detection data for suspicious abnormal structures according to the present invention;

[0073] Figure 8 This is a schematic diagram illustrating the process of forming an intelligent detection management mechanism to achieve low-power operation of detection. Detailed Implementation

[0074] The following description is intended to disclose the invention and enable those skilled in the art to implement it. The preferred embodiments described below are merely examples, and other obvious variations will occur to those skilled in the art.

[0075] Reference Figure 1 As shown, an artificial intelligence-based network information security intrusion detection method includes:

[0076] In the area where network information is received, at least one signal detection point is embedded in the target detection area as the target detection area.

[0077] Use at least one signal detection point;

[0078] Optimize the layout of detection points, use the optimized layout of detection points to arrange the positions of signal detection points, and acquire at least one internal network signal at the optimized signal detection points. During information transmission, the signal detection points capture the actual network signal generated at the signal detection points.

[0079] The actual network signal is denoised to obtain the network denoised signal;

[0080] A signal processing mechanism is established, and the signal processing mechanism is used to amplify the network noise reduction signal to obtain the network amplified signal;

[0081] Anomaly detection is performed on the network amplified signal. If an anomaly is detected, the transmission of the network amplified signal is terminated. If no anomaly is detected, the network amplified signal is allowed to pass.

[0082] An intelligent detection management mechanism is established to achieve low-power operation of the detection process.

[0083] This solution does not use existing intrusion detection as its main technical feature. It mainly monitors unknown intrusions. However, since their patterns are unknown, it can only predict as many intrusions as possible by observing the evolution of existing intrusions, so as to discover more intrusions in advance. But it is impossible to identify all unknown intrusions. It can only reduce the probability of being intruded.

[0084] Reference Figure 2 As shown, the optimized location for the detection point layout is formed. The process of arranging the signal detection points using this optimized location includes the following steps:

[0085] Obtain the information transmission topology in the target detection area, and obtain at least one structural entry point in the information transmission topology, wherein the structural entry point is a necessary entry point into the target detection area;

[0086] At least one sampling point is uniformly set at each node within the information transmission topology.

[0087] In the case of network information transmission, acquire network sampling information transmitted to the sampling point;

[0088] When network sampling information spreads at the sampling point, the sampling point is taken as the target sampling point;

[0089] Target sampling points and structural entrances that are different from signal detection points are used as the optimized locations for the detection point layout;

[0090] The optimized location of the detection point layout is used as the location for adding at least one signal detection point.

[0091] Because intrusion detection is probabilistic, especially when detecting unknown intrusions, multiple detection points are set up to prevent omissions. These points are primarily based on the information transmission topology of the target detection area. The information transmission topology may have multiple entry points, allowing intrusions to enter the target detection area through these points. Additionally, there are points within the information transmission topology that can spread. When an intrusion occurs, it can spread through these points, thus requiring monitoring at these points.

[0092] Acquiring at least one internal network signal includes the following steps:

[0093] During the intermittent period of network information transmission, at least one internal network signal is acquired at at least one signal detection point.

[0094] The internal network signals here are actually noise signals in network transmission. Since no information is being transmitted, these signals can be denoised, thereby identifying and terminating security intrusions that are easily masked by noise.

[0095] Reference Figure 3 As shown, the process of denoising the actual network signal to obtain the denoised network signal includes the following steps:

[0096] Based on historical transmission data, signal detection points that have generated abnormalities are considered as points with a high probability of intrusion.

[0097] The average value of the internal vibration signal is obtained by averaging the signal of at least one internal network.

[0098] The Fourier transform is used to decompose the actual network signal at the point of possible intrusion probability to obtain at least one actual basic signal.

[0099] The mean internal vibration signal is decomposed using Fourier transform to obtain at least one basic intrusion signal.

[0100] The actual basic signals that differ from the basic intrusion signal by less than a preset range are deleted. The preset range is the allowable error of the same signal based on experience.

[0101] The network denoised signal is obtained by combining at least one of the original basic signals after deletion using an inverse Fourier transform.

[0102] Reference Figure 4 As shown, a signal processing mechanism is formed, and the amplification of the network noise reduction signal using this mechanism includes the following steps:

[0103] The network noise reduction signal is filtered to obtain the network filtered signal;

[0104] Based on historical data, the range of signal amplification ratio is obtained, and the range of signal amplification ratio is divided into equal intervals to obtain at least one amplification point.

[0105] The network noise reduction signal is amplified according to the value at the amplification point to obtain the network amplified signal. The probability that the network amplified signal is misidentified is calculated and used as the feature probability.

[0106] When the feature probability is less than the preset probability, the value at the amplification point corresponding to the feature probability is taken as the optimal amplification ratio.

[0107] The filtering process and the amplification process using the optimal amplification ratio are used as signal processing mechanisms.

[0108] The network noise reduction signal is processed using signal processing mechanisms to obtain the network amplified signal, wherein one of the optimal amplification ratios is used for signal amplification.

[0109] Since all identifications involve errors, in order to improve the accuracy of detecting actual network signals, it is necessary to perform noise reduction processing to reduce the possibility of identification errors. At the same time, the noise-reduced signal is also amplified to further avoid the possibility of identification errors.

[0110] Reference Figure 5 As shown, anomaly detection for network amplified signals includes the following steps:

[0111] Based on big data, existing historical transmission data of network transmission is obtained, and abnormal data is extracted from the historical transmission data to obtain sample abnormal data.

[0112] The data topology structure of the sample abnormal data is obtained, and the abnormal features of the data topology structure are extracted and extended to obtain at least one abnormal local structure.

[0113] The probability of the existence of abnormal local structures is statistically analyzed. At least one abnormal local structure is randomly combined to obtain at least one combination of abnormal local structures. The overall probability of the existence of abnormal local structure combinations is calculated. Abnormal local structure combinations with an overall probability of existence less than a preset probability are deleted. The preset probability is the maximum probability of low-probability events occurring in the network.

[0114] Abnormal local structures in the combination of abnormal local structures are merged to form a suspected abnormal structure;

[0115] Targeted detection data is generated for suspicious abnormal structures. The targeted detection data can quickly identify suspicious abnormal structures and contains signal termination data.

[0116] The network amplification signal is amplified using targeted detection data. When the network amplification signal is terminated, an anomaly is found in the network amplification signal.

[0117] When the network amplification signal is not terminated, the network amplification signal is allowed to be transmitted in the target detection area.

[0118] Security intrusions primarily achieve their goals through the data structures they set. Therefore, analyzing the abnormal characteristics of existing intrusion data can yield preliminary abnormal features. These preliminary features can evolve, generating numerous abnormal local structures that may lead to intrusions. Using these abnormal local structures for detection is more effective than using only existing intrusion data, significantly expanding the detection and identification scope and reducing the probability of intrusion. During identification, targeted detection data is set based on the fit of the data structures. Targeted detection data is a data structure that perfectly matches the corresponding target structure. When the targeted detection data perfectly matches the data to be detected, it indicates that the data to be detected is highly likely to be the target structure. Therefore, the targeted detection data triggers a data termination command, enabling rapid identification.

[0119] Reference Figure 6 As shown, the process of extracting and extending abnormal features from the data topology to obtain at least one abnormal local structure includes the following steps:

[0120] The data topology is segmented to obtain at least one preliminary anomaly feature, which is the minimum structure to realize the data function.

[0121] In big data, at least one feature combination is randomly generated. The feature combination consists of two data features. When the two data features in the feature combination have the same effect, the feature combination is taken as the target feature combination.

[0122] Calculate the difference between two data features in the target feature combination as the data difference, and take the maximum value of the data difference of the target feature combination as the preset difference;

[0123] In big data, data features whose difference from the initial anomaly features is less than a preset difference are considered as similar features to the initial anomaly features.

[0124] The initial features of the anomaly and its similar features are each considered as the local structure of the anomaly.

[0125] Reference Figure 7 As shown, the process of generating targeted detection data for suspicious abnormal structures includes the following steps:

[0126] The suspicious abnormal structure is compared with other data structures to obtain the target structure. The target structure is a local structure in the suspicious abnormal structure and is different from the data structures other than the suspicious abnormal structure.

[0127] The dual structure that forms the target structure matches the missing part of the target structure;

[0128] Obtain the feature surface, which is the part of the dual structure at the position where the dual structure and the target structure are spliced ​​together;

[0129] At least one identification point is uniformly selected on the feature surface. Signal termination data is set at the identification point. The trigger condition for the signal termination data is that all identification points on the feature surface are in contact with the data structure to be detected. The signal termination data set at the identification points of the dual structure and the feature surface are summarized into target detection data.

[0130] Reference Figure 8 As shown, an intelligent detection management mechanism is formed, and the low-power operation of the detection is achieved through this mechanism, including the following steps:

[0131] Obtain the total number of actual network signals captured at points with high intrusion probability and the number of actual network signals exhibiting attack behavior at points with high intrusion probability. Use the intrusion ratio formula to calculate the intrusion ratio at points with high intrusion probability.

[0132] The minimum intrusion ratio of the top 10% of possible intrusion probability points with the highest intrusion ratio is used as the preset ratio;

[0133] Based on the intrusion ratio, the possible points of intrusion probability are classified into non-essential collection points and essential collection points. Non-essential collection points are the possible points of intrusion probability with an intrusion ratio less than a preset ratio, and essential collection points are the possible points of intrusion probability with an intrusion ratio exceeding a preset ratio.

[0134] The intelligent detection management mechanism is as follows: suspend signal detection points at non-essential collection points, and keep signal detection points at essential collection points operational;

[0135] The intrusion rate formula is as follows:

[0136]

[0137] Where A is the intrusion ratio of a point with a high probability of intrusion, a is the number of actual network signals exhibiting attack behavior at a point with a high probability of intrusion, and b is the total number of actual network signals captured at a point with a high probability of intrusion.

[0138] Since the network information entry situation is different at different times, the distribution in the target detection area is also different. However, there may be many signal detection points, and therefore the amount of data detected is also large. Therefore, the signal detection points are screened, and only a portion of the signal detection points are used. At this time, according to the characteristics of network information transmission, network information transmission will almost inevitably pass through the activated signal detection points. Therefore, as long as there is an anomaly, it is sufficient to complete the intrusion detection through these activated signal detection points, thereby completing the low-power operation.

[0139] Furthermore, this solution also proposes a storage medium on which a computer-readable program is stored. When the computer-readable program is invoked, the aforementioned AI-based network information security intrusion detection method is executed.

[0140] It is understandable that the storage medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; an optical medium, such as a DVD; or a semiconductor medium, such as a solid-state drive (SSD).

[0141] In summary, the advantages of this invention are as follows: by setting signal detection points, monitoring is conducted at locations prone to intrusion, ensuring that any intrusion can be detected promptly, thus preventing greater losses. Simultaneously, the number of operating signal detection points can be effectively controlled, achieving low-power operation. Furthermore, during anomaly detection, anomaly features are extracted and extended, enabling the identification of as many unknown intrusions as possible based on existing intrusions, thereby reducing the probability of intrusion. Additionally, noise is processed during detection, reducing the probability of intrusion detection failure due to noise interference, thereby improving the overall efficiency of security intrusion identification.

[0142] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the claimed invention. The scope of protection claimed by the appended claims and their equivalents is defined.

Claims

1. A network information security intrusion detection method based on artificial intelligence, characterized in that, include: In the area where network information is received, at least one signal detection point is embedded in the target detection area as the target detection area. Use at least one signal detection point; Optimize the layout of detection points, use the optimized layout of detection points to arrange the positions of signal detection points, and acquire at least one internal network signal at the optimized signal detection points. During information transmission, the signal detection points capture the actual network signals generated by the network transmission at the signal detection points. The actual network signal is denoised to obtain the network denoised signal; A signal processing mechanism is established, and the signal processing mechanism is used to amplify the network noise reduction signal to obtain the network amplified signal; Anomaly detection is performed on the network amplified signal. If an anomaly is detected, the transmission of the network amplified signal is terminated. If no anomaly is detected, the network amplified signal is allowed to pass. An intelligent detection management mechanism is established to achieve low-power operation of the detection process. The anomaly detection of the network amplified signal includes the following steps: Based on big data, existing historical transmission data of network transmission is obtained, and abnormal data is extracted from the historical transmission data to obtain sample abnormal data. The data topology structure of the sample abnormal data is obtained, and the abnormal features of the data topology structure are extracted and extended to obtain at least one abnormal local structure. The probability of the existence of abnormal local structures is statistically analyzed. At least one abnormal local structure is randomly combined to obtain at least one combination of abnormal local structures. The overall probability of the existence of abnormal local structure combinations is calculated. Abnormal local structure combinations with an overall probability of existence less than a preset probability are deleted. The preset probability is the maximum probability of low-probability events occurring in the network. Abnormal local structures in the combination of abnormal local structures are merged to form a suspected abnormal structure; Targeted detection data is generated for suspicious abnormal structures. The targeted detection data can quickly identify suspicious abnormal structures and contains signal termination data. The network amplification signal is amplified using targeted detection data. When the network amplification signal is terminated, an anomaly is found in the network amplification signal. When the network amplification signal is not terminated, the network amplification signal is allowed to be transmitted in the target detection area.

2. The network information security intrusion detection method based on artificial intelligence according to claim 1, characterized in that, The process of forming an optimized location for the detection point layout, and using this optimized location to arrange the signal detection points, includes the following steps: Obtain the information transmission topology in the target detection area, and obtain at least one structural entry point in the information transmission topology, wherein the structural entry point is a necessary entry point into the target detection area; At least one sampling point is uniformly set at each node within the information transmission topology. In the case of network information transmission, acquire network sampling information transmitted to the sampling point; When network sampling information spreads at the sampling point, the sampling point is taken as the target sampling point; Target sampling points and structural entrances that are different from signal detection points are used as the optimized locations for the detection point layout; The optimized location of the detection point layout is used as the location for adding at least one signal detection point.

3. The network information security intrusion detection method based on artificial intelligence according to claim 2, characterized in that, The acquisition of at least one internal network signal includes the following steps: During the intermittent period of network information transmission, at least one internal network signal is acquired at at least one signal detection point.

4. The network information security intrusion detection method based on artificial intelligence according to claim 3, characterized in that, The process of denoising the actual network signal to obtain the denoised network signal includes the following steps: Based on historical transmission data, signal detection points that have generated abnormalities are considered as points with a high probability of intrusion. The average value of the internal vibration signal is obtained by averaging the signal of at least one internal network. The Fourier transform is used to decompose the actual network signal at the point of possible intrusion probability to obtain at least one actual basic signal. The mean internal vibration signal is decomposed using Fourier transform to obtain at least one basic intrusion signal. The actual basic signals that differ from the basic intrusion signal by less than a preset range are deleted. The preset range is the allowable error of the same signal based on experience. The network denoised signal is obtained by combining at least one of the original basic signals after deletion using an inverse Fourier transform.

5. The network information security intrusion detection method based on artificial intelligence according to claim 4, characterized in that, The aforementioned signal processing mechanism, which amplifies the network noise reduction signal using the signal processing mechanism, includes the following steps: The network noise reduction signal is filtered to obtain the network filtered signal; Based on historical data, the range of signal amplification ratio is obtained, and the range of signal amplification ratio is divided into equal intervals to obtain at least one amplification point. The network noise reduction signal is amplified according to the value at the amplification point to obtain the network amplified signal. The probability that the network amplified signal is misidentified is calculated and used as the feature probability. When the feature probability is less than the preset probability, the value at the amplification point corresponding to the feature probability is taken as the optimal amplification ratio. The filtering process and the amplification process using the optimal amplification ratio are used as signal processing mechanisms. The network noise reduction signal is processed using signal processing mechanisms to obtain the network amplified signal, wherein one of the optimal amplification ratios is used for signal amplification.

6. The network information security intrusion detection method based on artificial intelligence according to claim 5, characterized in that, The step of extracting and extending abnormal features of the data topology to obtain at least one abnormal local structure includes the following steps: The data topology is segmented to obtain at least one preliminary anomaly feature, which is the minimum structure to realize the data function. In big data, at least one feature combination is randomly generated. The feature combination consists of two data features. When the two data features in the feature combination have the same effect, the feature combination is taken as the target feature combination. Calculate the difference between two data features in the target feature combination as the data difference, and take the maximum value of the data difference of the target feature combination as the preset difference; In big data, data features whose difference from the initial anomaly features is less than a preset difference are considered as similar features to the initial anomaly features. The initial features of the anomaly and its similar features are each considered as the local structure of the anomaly.

7. The network information security intrusion detection method based on artificial intelligence according to claim 6, characterized in that, The process of generating targeted detection data for suspicious abnormal structures includes the following steps: The suspicious abnormal structure is compared with other data structures to obtain the target structure. The target structure is a local structure in the suspicious abnormal structure and is different from the data structures other than the suspicious abnormal structure. The dual structure that forms the target structure matches the missing part of the target structure; Obtain the feature surface, which is the part of the dual structure at the position where the dual structure and the target structure are spliced ​​together; At least one identification point is uniformly selected on the feature surface. Signal termination data is set at the identification point. The trigger condition for the signal termination data is that all identification points on the feature surface are in contact with the data structure to be detected. The signal termination data set at the identification points of the dual structure and the feature surface are summarized into target detection data.

8. The network information security intrusion detection method based on artificial intelligence according to claim 7, characterized in that, The formation of the intelligent detection management mechanism, which enables low-power operation of the detection, includes the following steps: Obtain the total number of actual network signals captured at points with high intrusion probability and the number of actual network signals exhibiting attack behavior at points with high intrusion probability. Use the intrusion ratio formula to calculate the intrusion ratio at points with high intrusion probability. The minimum intrusion ratio of the top 10% of possible intrusion points with the highest intrusion ratio is used as the preset ratio; Based on the intrusion ratio, the possible points of intrusion probability are classified into non-essential collection points and essential collection points. Non-essential collection points are the possible points of intrusion probability with an intrusion ratio less than a preset ratio, and essential collection points are the possible points of intrusion probability with an intrusion ratio exceeding a preset ratio. The intelligent detection management mechanism is as follows: suspend signal detection points at non-essential collection points, and keep signal detection points at essential collection points operational; The intrusion rate formula is as follows: , Where A is the intrusion ratio of a point with a high probability of intrusion, a is the number of actual network signals exhibiting attack behavior at a point with a high probability of intrusion, and b is the total number of actual network signals captured at a point with a high probability of intrusion.

Citation Information

Patent Citations

  • Physical intrusion equipment positioning method and system based on pulse reflected wave detection

    CN113746669A

  • APT attack processing method and system, electronic equipment and readable storage medium

    CN116545738A