Artificial intelligence-based collaborative office network security management method and system and medium

By leveraging artificial intelligence engines and edge computing technology, dynamic encryption and anomaly detection are implemented in collaborative office networks. This addresses the issue of low response efficiency in abnormal situations, achieving efficient data security and rapid response, and enhancing network security and collaboration.

CN120710768BActive Publication Date: 2026-03-27山东大通世纪实业有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-16
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing collaborative office networks rely on manual intervention in the event of network anomalies or security incidents, resulting in low response efficiency, easy data leakage or system paralysis, and traditional access control is difficult to adapt to dynamic business needs, affecting network security and collaboration.

Method used

We adopt an AI-based collaborative office network security management method. By allocating access control policies and dynamically encrypting multi-dimensional office data, we utilize edge computing and AI engines to construct network feature matrices and perform dual-channel anomaly detection, automatically generating network anomaly resolution strategies.

Benefits of technology

It improved data security and network monitoring efficiency, reduced network latency, optimized data processing efficiency, enabled rapid response and automated management, and established a complete network security risk management mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120710768B_ABST
    Figure CN120710768B_ABST
Patent Text Reader

Abstract

The application discloses a collaborative office network security management method and system based on artificial intelligence and a medium, belongs to the technical field of artificial intelligence network security, and is used for solving the technical problem that when the existing collaborative office network has network abnormal conditions or network security events, the emergency mechanism mainly depends on manual intervention, and the response efficiency is low when data leakage or system paralysis is caused. The method comprises the following steps: through an edge computing node and based on an artificial intelligence engine architecture, performing edge preprocessing on initial office network data about adversarial samples to obtain a network feature matrix based on the initial office network data; through the artificial intelligence engine architecture, performing double-channel network anomaly detection processing on the network feature matrix to obtain network anomaly detection result data; and according to the network anomaly detection result data, performing corresponding network risk response actions and automatically generating a network anomaly solution strategy.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of artificial intelligence network security, and in particular to a collaborative office network security management method and system based on artificial intelligence and a medium. BACKGROUND

[0002] With the advancement of digital transformation, collaborative office systems face many security challenges. (1) Data storage and transmission risks: traditional centralized storage is vulnerable to single-point attacks, and data transmission is subject to interception and tampering risks. (2) Inadequate permission management: static role authorization is difficult to adapt to dynamic business needs, and it is difficult to trace permission abuse. (3) Security incident response lag: manual emergency mechanisms result in low response efficiency.

[0003] When there is an access or use anomaly in a traditional office network, there is often a large lag, making it difficult to respond quickly and issue warnings, which can lead to network security problems, and even data leaks in severe cases. Moreover, when a network anomaly occurs or a network attack is received during collaborative use of an office network, the remaining collaborative office links will also be affected, affecting the normal use of the office network and reducing work efficiency, which greatly reduces the collaboration of the collaborative office network and is not conducive to the security management of the office network. SUMMARY

[0004] The embodiments of the present application provide a collaborative office network security management method and system based on artificial intelligence and a medium, which are used to solve the following technical problems: when there is a network anomaly or a network security event in the existing collaborative office network, the emergency mechanism mainly relies on manual intervention, which can easily lead to low response efficiency in the event of data leakage or system failure.

[0005] The embodiments of the present application adopt the following technical solutions:

[0006] In one aspect, the embodiment of the present application provides a collaborative office network security management method based on artificial intelligence, comprising: performing permission policy distribution on multi-dimensional office data in a collaborative office network to obtain office implementation transmission data; performing dynamic transmission encryption processing on the office implementation transmission data in each department by an artificial intelligence engine architecture, and obtaining office encrypted data based on a distributed storage gateway; performing decryption data classification collection processing on the office encrypted data in the office network export to obtain initial office network data; performing edge preprocessing on the initial office network data based on adversarial samples by an edge computing node and based on the artificial intelligence engine architecture to obtain a network feature matrix based on the initial office network data; performing double-channel network anomaly detection processing on the network feature matrix by the artificial intelligence engine architecture to obtain network anomaly detection result data; executing corresponding network risk response actions according to the network anomaly detection result data to automatically generate a network anomaly solution strategy.

[0007] The embodiment of the present application can protect the office data of each department from unauthorized access through dynamic transmission encryption processing, and enhance the security of the data. It can also identify data sensitivity and perform special encryption processing on sensitive data to further protect critical information. Moreover, the double-channel network anomaly detection processing can timely detect abnormal behaviors in the network, improve the efficiency and accuracy of network security monitoring. Preprocessing data by an edge computing node can reduce data transmission volume, reduce network delay, and improve data processing efficiency. According to the network anomaly detection result, the corresponding risk response actions can be quickly executed to reduce the impact of security incidents on the network. The network anomaly solution strategy helps to establish a complete network security risk management mechanism and improve the overall security of the network.

[0008] In an embodiment, the multi-dimensional office data in the collaborative office network is assigned with execution of permission policy to obtain office implementation transmission data, specifically comprising: before transmission collaboration in the collaborative office network, extracting a cascade identifier corresponding to each department link in the collaborative office network; wherein the cascade identifier is an upper and lower identifier mark under the association relationship of each department; layering and dividing the role attribute in the same cascade identifier to obtain role level information; wherein the role level information is the hierarchical relationship information of data permission in the same department link; collecting real-time office transmission data corresponding to each role level information in each cascade identifier; performing data fusion processing on the cascade identifier, the role level information and the real-time office transmission data to obtain the multi-dimensional office data; according to the level of the transmission data in the collaborative office network, dynamically generating processing of the multi-dimensional office data with permission policy, and automatically executing authorization and / or recovery to obtain data transmission permission policy; based on the data transmission permission policy, performing priority execution allocation on the multi-dimensional office data related to transmission permission to obtain the office implementation transmission data.

[0009] In an implementation, the initial office network data is preprocessed by the edge computing node to obtain a network feature matrix based on the initial office network data, and the preprocessing includes: constructing a feature vector related to time characteristics, space characteristics, and network protocol anomaly characteristics by the edge computing node to obtain a space-time protocol feature matrix, including: generating features of the data packets in the initial office network data under time factors to obtain the time characteristics; wherein the time characteristics include: interval time, session duration, and periodic behavior patterns; performing topology positioning processing on the initial office network data under network location to determine the space characteristics; wherein the space characteristics include: device physical topology location, logical network partition location, and device movement trajectory; converting the initial office network data under a tree structure by a protocol syntax tree parsing engine, and scoring abnormal information in the network protocol based on sub-tree similarity to obtain the network protocol anomaly characteristics; wherein the abnormal information includes: abnormal combination of header field of protocol layer, abnormal combination of TCP flag bit, and TLS handshake parameter entropy value; performing exponentially weighted moving average processing on the time sequence characteristics in the initial office network data according to the time sequence rule mechanism in the artificial intelligence engine architecture and through a sliding window to obtain dynamic time alignment data; adding adversarial sample data to the training sample data corresponding to the initial office network data; wherein the adversarial sample data is a lagging network attack sample, including: extracting the dormant period mode in historical APT attacks; synthesizing attack traffic with time delay characteristics by an LSTM-GAN generator, and generating lagging features with attack chain characteristics; hiding the lagging features of the adversarial sample in the periodic fluctuations of legal traffic by a time confusion encoder to obtain the adversarial sample data; performing optimization processing on the space-time protocol feature matrix according to the dynamic time alignment data and the adversarial sample data to obtain the network feature matrix, including: performing time axis splicing processing on the time sequence data after TCN alignment and the space-time protocol feature matrix to obtain an enhanced matrix; wherein the enhanced matrix at least includes: new time delay jitter, traffic entropy, and burst coefficient; performing adversarial robust enhancement processing on the enhanced matrix by feature random masking and adversarial gradient punishment; extracting the lagging attack features in the enhanced matrix by a time-sensitive convolution kernel, and outputting the network feature matrix.

[0010] In an implementable implementation, the network feature matrix is subjected to a double-channel network anomaly detection processing by the artificial intelligence engine architecture to obtain network anomaly detection result data, specifically including: the network feature matrix is subjected to a known network threat feature identification calculation by a Transformer-CNN hybrid model in the artificial intelligence engine architecture, and an attack type confidence in a known threat channel is output; wherein the higher the attack type confidence, the stronger the degree of the current network feature matrix being subjected to a known network attack model, including: the network feature matrix is subjected to a time dimension self-correlation and spatial dimension dependency calculation under a multi-head space-time attention mechanism by an encoding layer in the Transformer-CNN hybrid model to obtain a space-time attention feature; the space-time attention feature is subjected to a dynamic parameter adjustment under a dynamic convolution kernel, and the network feature matrix is subjected to a multi-scale identification calculation of known network threat features by a known network threat classifier; the known network threat features are subjected to a matching degree calculation under a similarity by a dilated convolution layer in the Transformer-CNN hybrid model to obtain the attack type confidence in the known threat channel; a hidden space divergence is calculated between the current network traffic and the historical baseline network traffic in the network feature matrix by a deep clustering algorithm, and a divergence value in an unknown threat channel is output, including: the historical baseline network traffic is subjected to a dimension compression processing by a variational autoencoder, and the current network traffic is subjected to a sample addition to generate a 32-dimensional hidden space; new and old data in the 32-dimensional hidden space are subjected to a data distribution drift calculation by an adversarial domain adaptation mechanism to obtain a real-time traffic mapping relationship; the real-time traffic mapping relationship is subjected to a divergence measurement calculation under a Wasserstein distance to obtain the divergence value in the unknown threat channel; if the attack type confidence is greater than or equal to a first preset threshold, the initial office network data has known threat network anomaly result data; if the divergence value is greater than or equal to a second preset threshold, the initial office network data has unknown threat network anomaly result data; wherein the network anomaly detection result data includes the known threat network anomaly result data and the unknown threat network anomaly result data.

[0011] In a feasible implementation, according to the network anomaly detection result data, a corresponding network risk response action is performed, and a network anomaly solution strategy is automatically generated, specifically including: performing digital work order generation processing on the network anomaly detection result data to obtain high-risk abnormal network data work orders; according to the OpenFlow protocol and through the SDN controller, the corresponding collaborative office host and the corresponding network execution link of the network anomaly detection result data are isolated to obtain network isolation data; the network service type corresponding to the network anomaly detection result data is subjected to resource scheduling processing to obtain resource scheduling data; wherein the resource scheduling at least includes: bandwidth reserve reservation and server backup deployment; based on the high-risk abnormal network data work order, the network isolation data and the resource scheduling data, and through the artificial intelligence engine architecture, the network anomaly solution strategy is automatically converted into an executable instruction set and generated.

[0012] In a feasible implementation, the Transformer-CNN hybrid model is a pre-trained deep learning model that combines the advantages of convolutional neural networks and Transformer architecture, and is used to identify the known network threat features in the global structure of the feature matrix.

[0013] In a feasible implementation, through the artificial intelligence engine architecture, the office implementation transmission data in each department is subjected to dynamic transmission encryption processing related to data sensitivity, and based on a distributed storage gateway, office encrypted data is obtained, specifically including: through the artificial intelligence language processing mechanism in the artificial intelligence engine architecture, the office implementation transmission data is subjected to keyword identification processing related to data sensitivity, and the sensitivity label of each office implementation transmission data is determined; wherein the sensitivity label includes: public, internal and confidential; through a dynamic encryption engine and based on the sensitivity label, the office implementation transmission data is subjected to data encryption processing to generate a key pair for each office implementation transmission data; according to the key pair and based on the distributed storage gateway, a globally unique storage ID is generated for each office implementation transmission data; through the globally unique storage ID, the office implementation transmission data corresponding to the key pair is subjected to encrypted transmission processing to obtain the office encrypted data in data transmission.

[0014] In an implementable embodiment, the classified collection and processing of the decrypted data of the office encrypted data in the office network export obtains initial office network data, specifically including: collecting the office encrypted data that has completed data transmission and is in the office network export; performing decryption processing on the office encrypted data through the key pair of the current node to obtain office decrypted data; performing data capture processing on the office decrypted data through the sensor array deployed at the office network export; performing tree-shaped classification processing on the captured data through the data automatic recognition mechanism in the artificial intelligence engine architecture, and counting traffic metadata, behavior logs and device states to obtain the initial office network data; wherein the traffic metadata at least includes: five-tuple, TCP flag bit distribution and packet size distribution; the behavior logs at least include: user login track, file access sequence and permission change record; and the device states at least include: CPU / memory occupancy, abnormal process signature and security baseline deviation value.

[0015] In a second aspect, the embodiments of the present application also provide a collaborative office network security management system based on artificial intelligence, including: a transmission encryption module, configured to perform permission policy allocation on multi-dimensional office data in a collaborative office network to obtain office implementation transmission data; perform dynamic transmission encryption processing on the office implementation transmission data in each department in relation to data sensitivity, and obtain office encrypted data based on a distributed storage gateway; a data collection module, configured to perform classified collection and processing of decrypted data of the office encrypted data in the office network export to obtain initial office network data; an edge computing module, configured to perform edge preprocessing on the initial office network data in relation to adversarial samples through an edge computing node to obtain a network feature matrix based on the initial office network data; an artificial intelligence anomaly analysis module, configured to perform double-channel network anomaly detection processing on the network feature matrix to obtain network anomaly detection result data; and a risk response module, configured to perform corresponding network risk response actions according to the network anomaly detection result data to generate a network anomaly solution strategy.

[0016] In a third aspect, the embodiments of the present application also provide a non-volatile computer storage medium, characterized in that the storage medium is a non-volatile computer readable storage medium, and the non-volatile computer readable storage medium stores at least one program, each of the programs includes instructions, and the instructions, when executed by a terminal, cause the terminal to execute the collaborative office network security management method based on artificial intelligence described in any of the embodiments.

[0017] The present application provides a collaborative office network security management method, system and medium based on artificial intelligence. Compared with the prior art, the embodiments of the present application have the following beneficial technical effects:

[0018] 1. Improve data security: Through dynamic transmission encryption processing and the driving of artificial intelligence engine, the office data of each department can be protected from unauthorized access, enhancing the security of data. It can also identify data sensitivity and perform special encryption processing on sensitive data to further protect critical information.

[0019] 2. Enhance network monitoring capability: Based on the driving of artificial intelligence engine and through double-channel network anomaly detection processing, abnormal behaviors in the network can be detected in a timely manner, improving the efficiency and accuracy of network security monitoring.

[0020] 3. Optimize data processing efficiency: Through edge computing nodes for data preprocessing, data transmission volume can be reduced, network latency can be reduced, and data processing efficiency can be improved.

[0021] 4. Improve response speed: According to the network anomaly detection results, corresponding risk response actions can be quickly executed to reduce the impact of security incidents on the network.

[0022] 5. Automation management: Based on the driving of artificial intelligence engine, data encryption and decryption processes can be automatically executed, reducing manual intervention and improving the automation level of network security management.

[0023] 6. Distributed storage optimization: Through distributed storage gateway, data storage can be effectively managed and optimized, improving data access speed and storage efficiency.

[0024] 7. Comprehensive risk management: Network anomaly solution strategy is generated, which helps to establish a complete network security risk management mechanism and improve the overall security of the network. BRIEF DESCRIPTION OF DRAWINGS

[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiment or prior art description. Obviously, the drawings in the following description are only some embodiments described in the present application, and those skilled in the art can obtain other drawings according to these drawings without creative labor. In the drawings:

[0026] Figure 1 A flow chart of a collaborative office network security management method based on artificial intelligence is provided for the embodiments of the present application;

[0027] Figure 2 A structural schematic diagram of a collaborative office network security management device based on artificial intelligence is provided for the embodiments of the present application. DETAILED DESCRIPTION

[0028] In order for those skilled in the art to better understand the technical solutions in the present application, the technical solutions in the embodiments of the present application will be clearly and completely described in the following with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative labor should be within the scope of protection of the present application.

[0029] The embodiments of the present application provide an artificial intelligence-based collaborative office network security management method, as shown in Figure 1 The artificial intelligence-based collaborative office network security management method specifically includes steps S101-S106:

[0030] S101, performing permission policy distribution on multi-dimensional office data in the collaborative office network to obtain office implementation transmission data.

[0031] Specifically, before transmission collaboration in the collaborative office network, the cascading identifier corresponding to each department link in the collaborative office network needs to be extracted. The cascading identifier is the superior and subordinate identifier mark under the association relationship of each department.

[0032] Further, the role attributes in the same cascading identifier are hierarchically divided to obtain role level information. The role level information is the hierarchical relationship information of data permissions in the same department link.

[0033] Further, real-time office transmission data corresponding to each role level information in each cascading identifier is collected.

[0034] Further, the cascading identifier, the role level information and the real-time office transmission data are subjected to data fusion processing to obtain multi-dimensional office data.

[0035] Further, according to the level of transmission data in the collaborative office network, the multi-dimensional office data is subjected to dynamic generation processing of permission policy, and automatic execution of authorization and / or recovery to obtain data transmission permission policy. Based on the data transmission permission policy, the multi-dimensional office data is subjected to priority execution distribution of transmission permission to obtain office implementation transmission data.

[0036] As a feasible implementation, in the collaborative office network, a unique cascade identifier is assigned to each department link through network topology analysis. The cascade identifier contains the level and superior-inferior relationship of the department in the organizational structure. The association between departments can be automatically identified and extracted using network scanning tools and database management systems. Then for each department, according to its business process and responsibilities, the role attributes are hierarchically divided to form role level information. For example, for the human resources department, it may include "employee", "manager", "director" and other roles. Then deploy data collection agents to collect office transmission data in real time in each department link, including file transmission, email communication, instant messaging, etc. Network traffic monitoring tools and log analysis software can be used to ensure the real-time and integrity of the data. A multi-dimensional office data set is created by fusing the cascade identifier, role level information and real-time office transmission data. Different sources of data can be integrated into a unified data model through data warehouse and ETL (Extract, Transform, Load) tools. Then use machine learning algorithms to analyze historical data to predict the permissions that different roles may need, and automatically generate policies. Finally, a rule-based engine is implemented to assign priority to each data transmission request based on role level and transmission data importance.

[0037] In one embodiment, the human resources department manager needs to view the employee file. The system identifies the cascade identifier and role level of the human resources department manager, and then collects the real-time office transmission data of the manager. After data fusion processing, the system generates the corresponding permission policy. At the same time, the control policy engine determines the priority of the permission to view the employee file. Finally, the system automatically authorizes the manager to access the employee file and assigns appropriate transmission priority.

[0038] S102, through the artificial intelligence engine architecture, the office implementation transmission data in each department is dynamically encrypted for data sensitivity, and office encrypted data is obtained based on a distributed storage gateway.

[0039] Specifically, first, through the artificial intelligence language processing mechanism in the artificial intelligence engine architecture, the office implementation transmission data is processed for keyword recognition under data sensitivity to determine the sensitivity label of each office implementation transmission data. The sensitivity label includes: public, internal, and confidential.

[0040] Further, through the dynamic encryption engine and based on the sensitivity label, the office implementation transmission data is processed for data encryption to generate a key pair for each office implementation transmission data. According to the key pair and based on the distributed storage gateway, a globally unique storage ID is generated for each office implementation transmission data.

[0041] Further, by the globally unique storage ID, the office implementation transmission data corresponding to the key pair is encrypted and transmitted to obtain office encrypted data in data transmission.

[0042] In one embodiment, it is necessary to implement dynamic encryption for office documents, operation logs and other data of office implementation transmission data in each department. Adaptive encryption engine is used to automatically select SM4 / AES algorithm according to data sensitivity, and distributed storage gateway is used to realize encrypted data sharding storage. That is, before data transmission, the office implementation transmission data of each department is preprocessed. Using natural language processing (NLP) technology and keyword library, sensitive information in the data is identified. NLP analysis tools and pre-defined keyword database can be deployed to automatically identify data sensitivity. Then, according to the identified sensitive keywords, a sensitivity label is assigned to each office implementation transmission data. The label is divided into three levels: "public", "internal" and "confidential". Then a dynamic encryption engine is deployed, which can adjust the encryption algorithm and key length according to the sensitivity label. Encryption libraries such as Advanced Encryption Standard (AES) can be used to realize dynamic encryption combined with sensitivity labels. Then, for each office implementation transmission data with a sensitivity label, the dynamic encryption engine generates a pair of keys (public key and private key). For example, a pair of keys is generated using asymmetric encryption algorithm (such as RSA), and the public key is used for data transmission encryption, and the private key is used for decryption. It is also necessary to configure a distributed storage gateway to manage the storage and retrieval of encrypted data. Among them, distributed file system (such as HDFS) and storage gateway solution (such as NetApp ONTAP) can be used. Then, using a hash algorithm, a unique ID is generated based on the data content, key and storage gateway identifier. Finally, using the globally unique storage ID, the encrypted data is transmitted to the destination. That is, the data can be encrypted during transmission through the Secure Sockets Layer (SSL / TLS) protocol.

[0043] S103, office encrypted data in the office network export is classified and collected to obtain initial office network data.

[0044] Specifically, office encrypted data in the office network export is collected first. The office encrypted data is decrypted by the key pair of the current node to obtain office decrypted data.

[0045] Further, the office decrypted data is captured by a sensor array deployed at the office network exit. Then, the captured data is classified in a tree structure by a data automatic recognition mechanism in the artificial intelligence engine architecture, and the traffic metadata, behavior logs and device status are counted to obtain initial office network data. The traffic metadata at least includes: five-tuple, TCP flag distribution and packet size distribution. The behavior logs at least include: user login track, file access sequence and permission change record. The device status at least includes: CPU / memory occupancy, abnormal process signature and security baseline deviation value.

[0046] As a feasible implementation, an FPGA-accelerated sensor array (for example, model: Xilinx Alveo U50) is deployed at the office network exit to capture the traffic metadata: five-tuple, TCP flag distribution, packet size distribution (sampling rate: 1 / 1000), behavior logs: user login track, file access sequence, permission change record, and device status: CPU / memory occupancy, abnormal process signature, and security baseline deviation value in the office decrypted data in real time. Then, the data is transmitted by a time-sensitive network (TSN) protocol to ensure that the transmission delay from the collection end to the edge node is less than 2 ms.

[0047] In one embodiment, a data collection device such as a network packet capture device or an intrusion detection system (IDS) is deployed at the office network exit to capture all office encrypted data transmitted to the outside. For example, network monitoring tools such as Sniffer, Wireshark, etc. are used to ensure that data packets at the network exit can be collected in real time. Then, the collected office encrypted data is decrypted using the private key of the current node. For example, an encryption library such as OpenSSL is developed or integrated for decryption process. Then, a sensor array composed of multiple sensors is deployed at the office network exit to capture the decrypted data. The captured decrypted data is then classified in a tree structure according to different data types and attributes. That is, a data classification module can be developed to classify the data according to predefined rules and algorithms. Then, network traffic analysis tools such as Bro or Suricata are used to extract traffic metadata from the classified data, including five-tuple (source IP, destination IP, source port, destination port, protocol type), TCP flag distribution and packet size distribution. User login track, file access sequence and permission change record are recorded as behavior logs, and system monitoring tools such as Nagios or Zabbix are used to monitor device status, including CPU / memory occupancy, abnormal process signature and security baseline deviation value.

[0048] S104, edge preprocessing the initial office network data on the adversarial samples based on the artificial intelligence engine architecture through the edge computing node, to obtain a network feature matrix based on the initial office network data.

[0049] Specifically, it is also necessary to construct feature vectors of the initial office network data on time features, space features, and network protocol anomaly features through the edge computing node, to obtain a space-time protocol feature matrix.

[0050] As a feasible implementation, it is also necessary to generate features of the data packets in the initial office network data under the time factor, to obtain time features. The time features include interval time, session duration, and periodic behavior patterns. Then, the initial office network data is processed for topology positioning under network location, to determine space features. The space features include device physical topology location, logical network partition location, and device movement trajectory. Then, the initial office network data is converted under a tree structure by combining a protocol syntax tree analysis engine, and the abnormal information in the network protocol is scored based on sub-tree similarity, to obtain network protocol anomaly features. The abnormal information includes abnormal combination of header fields of protocol layers, abnormal combination of TCP flag bits, and TLS handshake parameter entropy value.

[0051] Further, the time sequence rule mechanism in the artificial intelligence engine architecture is used to perform exponentially weighted moving average processing on the time sequence features in the initial office network data through a sliding window, to obtain dynamic time alignment data. Then, the adversarial sample data is also added to the training sample data corresponding to the initial office network data. The adversarial sample data is a lagging network attack sample.

[0052] As a feasible implementation, the dormant period pattern in historical APT attacks can be extracted first. Through the LSTM-GAN generator, attack traffic with time delay characteristics is synthesized, and lagging features with attack chain characteristics are generated. Then, through the time confusion encoder, the lagging features of the adversarial samples are hidden in the periodic fluctuations of the legal traffic, to obtain the adversarial sample data.

[0053] Further, according to the dynamic time alignment data and the adversarial sample data, the space-time protocol feature matrix is optimized for feature matrix, to obtain a network feature matrix.

[0054] As a feasible implementation, the time series data aligned with the TCN can be spliced with the time axis of the space-time protocol feature matrix to obtain an enhanced matrix. The enhanced matrix at least includes: new delay jitter, traffic entropy, and burst coefficient. Through feature random masking and adversarial gradient penalty, the enhanced matrix is subjected to adversarial robust enhancement processing. Through a time-sensitive convolution kernel, the lag attack features in the enhanced matrix are extracted and processed, and a network feature matrix is output.

[0055] As a feasible implementation, the edge computing node (NVIDIA Jetson AGX Orin) performs three-dimensional feature vector construction (constructs a space-time protocol feature matrix). The code that can be used is, for example:

[0056]

[0057]

[0058] Then, the exponential weighted moving average method in the sliding window (default 15 seconds) is used to align the sensor time series to obtain dynamic time alignment data. In the adversarial sample injection, 20% of the GAN generated attack samples (such as slow DDoS features) are mixed into the training data. Finally, the dynamic time alignment data parameters and the anti-sample data parameters are combined to optimize the feature matrix of the space-time protocol feature matrix, and a network feature matrix is obtained.

[0059] S105, through the artificial intelligence engine architecture, the network feature matrix is subjected to double-channel network anomaly detection processing to obtain network anomaly detection result data.

[0060] Specifically, first, through the Transformer-CNN hybrid model in the artificial intelligence engine architecture, the network feature matrix is subjected to identification calculation related to known network threat features, and the attack type confidence in the known threat channel is output. The higher the attack type confidence, the stronger the degree of the current network feature matrix being subjected to the known network attack model.

[0061] As a feasible implementation, through the encoding layer in the Transformer-CNN hybrid model, the network feature matrix is subjected to time dimension autocorrelation and spatial dimension dependency calculation under the multi-head space-time attention mechanism to obtain space-time attention features. Then, the space-time attention features are subjected to dynamic parameter adjustment under the dynamic convolution kernel, and the network feature matrix is subjected to multi-scale identification calculation related to known network threat features through the known network threat classifier. Finally, through the dilated convolution layer in the Transformer-CNN hybrid model, the known network threat features are subjected to matching degree calculation under similarity to obtain the attack type confidence in the known threat channel.

[0062] As a feasible implementation, the Transformer-CNN hybrid model is a deep learning model that combines the advantages of pre-trained convolutional neural networks and Transformer architecture, and is used for identifying known network threat features in the global structure of the feature matrix.

[0063] Further, it is also necessary to calculate the scatter value of the unknown threat channel by calculating the scatter value between the current network traffic and the historical baseline network traffic in the network feature matrix through a deep clustering algorithm.

[0064] As a feasible implementation, the historical baseline network traffic can be dimensionally compressed by a variational autoencoder, and the current network traffic can be added as a sample to generate a 32-dimensional latent space. Then, through an adversarial domain adaptation mechanism, the new and old data in the 32-dimensional latent space are calculated for data distribution drift, and the real-time traffic mapping relationship is obtained. Finally, the scatter value of the unknown threat channel is obtained by calculating the scatter value of the real-time traffic mapping relationship under the Wasserstein distance.

[0065] If the attack type confidence is greater than or equal to the first preset threshold, the initial office network data has known threat network anomaly result data. If the scatter value is greater than or equal to the second preset threshold, the initial office network data has unknown threat network anomaly result data. The network anomaly detection result data includes: known threat network anomaly result data and unknown threat network anomaly result data.

[0066] As a feasible implementation, first, use network traffic analysis tools (such as Bro, Snort) and feature extraction libraries (such as scikit-learn) to construct a feature matrix. That is, extract key features from network traffic data to construct a network feature matrix. These features may include source IP, destination IP, port, protocol type, traffic size, timestamp, etc. Then train a Transformer-CNN hybrid model that combines the advantages of Transformer and CNN to identify known threat features in the network feature matrix. That is, Transformer: uses its self-attention mechanism to capture long-range dependencies, suitable for processing sequential data, CNN: used to capture local features and patterns, especially suitable for image processing, but also used for local pattern recognition in network traffic analysis.

[0067] As a feasible implementation, the trained Transformer-CNN hybrid model is used to analyze the network feature matrix and identify known network threat features. The model outputs the attack type confidence in the known threat channel. Then, a deep clustering algorithm (such as t-SNE, UMAP) is applied to convert the network feature matrix to the latent space to calculate the divergence between the current network traffic and the historical baseline network traffic, and output the divergence value in the unknown threat channel. Then, the anomaly detection result is determined: 1) Set two preset thresholds to determine known threats and unknown threats. 2) If the attack type confidence is greater than or equal to the first preset threshold, it is determined as a known threat network anomaly. 3) If the divergence value is greater than or equal to the second preset threshold, it is determined as an unknown threat network anomaly. Finally, the network anomaly detection result data is output, including known threat network anomaly result data and unknown threat network anomaly result data.

[0068] In one embodiment, an enterprise network detects abnormal traffic. First, collect traffic data from network devices to build a feature matrix. Then use the Transformer-CNN hybrid model to train and identify known threat features in the feature matrix. Use the above model to output the confidence of known threats, such as finding that the confidence of a certain feature matrix exceeds the threshold, and determining it as a known threat anomaly. Then apply a deep clustering algorithm to convert the feature matrix to a latent space and calculate the divergence from the historical baseline data. If the divergence value exceeds the second threshold, it is determined as an unknown threat anomaly. Finally, the system generates network anomaly detection result data, including known and unknown threat information, for further investigation by security analysts.

[0069] S106, according to the network anomaly detection result data, execute the corresponding network risk response action, automatically generate network anomaly solution strategy.

[0070] Specifically, the network anomaly detection result data is first processed to generate a digital work order, obtaining a high-risk abnormal network data work order.

[0071] Further, according to the OpenFlow protocol, and through the SDN controller, the network anomaly detection result data corresponding to the collaborative office host and the corresponding network execution link are isolated, obtaining network isolation data.

[0072] In one embodiment, the OpenFlow protocol is called to issue a dynamic rule to the SDN controller: ovs-ofctl add-flow br0 "priority=300,ip,nw_src=192.168.1.100,actions=drop".

[0073] Further, the network service type corresponding to the network anomaly detection result data is subjected to resource scheduling processing to obtain resource scheduling data. The resource scheduling at least includes: bandwidth reservation and server backup deployment.

[0074] In one embodiment, the network service type corresponding to the network anomaly detection result data is subjected to resource scheduling processing, and a resource scheduling matrix: Priority = a • SLA level + β • Data sensitivity - γ • Recovery cost can be started, wherein the weight coefficients a, β and γ can be dynamically adjusted according to real-time business load, and the resource scheduling matrix integrates business impact evaluation factors. Based on the resource scheduling matrix, 30% of the backup bandwidth can be reserved for the key business system (such as financial ERP), or the AI-WAF container can also be automatically deployed to the target Web server (the start delay is less than 500 ms).

[0075] Further, based on the high-risk abnormal network data work order, the network isolation data and the resource scheduling data, and through the artificial intelligence engine architecture, the executable instruction set is automatically converted, and the network anomaly solution strategy is generated.

[0076] In addition, the embodiment of the application further provides a collaborative office network security management system based on artificial intelligence, as shown in Figure 2 The collaborative office network security management system 200 based on artificial intelligence includes:

[0077] The transmission encryption module 210 is configured to perform permission policy allocation on multi-dimensional office data in the collaborative office network to obtain office implementation transmission data, and perform dynamic transmission encryption processing on the office implementation transmission data in each department based on the distributed storage gateway to obtain office encrypted data.

[0078] The data acquisition module 220 is configured to perform decryption data classification acquisition processing on the office encrypted data in the office network outlet to obtain initial office network data.

[0079] The edge computing module 230 is configured to perform edge preprocessing on the initial office network data through an edge computing node to obtain a network feature matrix based on the initial office network data.

[0080] The artificial intelligence anomaly analysis module 240 is configured to perform double-channel network anomaly detection processing on the network feature matrix to obtain network anomaly detection result data.

[0081] The risk response module 250 is configured to execute corresponding network risk response actions according to the network anomaly detection result data to generate a network anomaly solution strategy.

[0082] The embodiments of the present application can protect the office data of each department from unauthorized access through dynamic transmission encryption processing, and enhance the security of the data. The data sensitivity can also be identified, and the sensitive data can be specially encrypted, further protecting the key information. Moreover, through the double-channel network anomaly detection processing, abnormal behaviors in the network can be discovered in a timely manner, improving the efficiency and accuracy of network security monitoring. Through the pre-processing of the data by the edge computing node, the data transmission amount can be reduced, the network delay can be reduced, and the data processing efficiency can be improved. According to the network anomaly detection result, the corresponding risk response action can be quickly executed, reducing the influence of the security event on the network. The collection of network anomaly solving strategies helps to establish a complete network security risk management mechanism and improve the overall security of the network.

[0083] Each of the embodiments of the present application is described in a progressive manner, and the same or similar parts of each embodiment can be referred to each other. Each embodiment focuses on the difference from other embodiments. In particular, for the device and non-volatile computer storage medium embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the method embodiment.

[0084] The device and medium provided by the embodiments of the present application are one-to-one corresponding to the method, so the device and medium also have similar beneficial technical effects as the corresponding method. Since the beneficial technical effects of the method have been described in detail above, the beneficial technical effects of the device and medium will not be described here.

[0085] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer usable program code.

[0086] The present application is described with reference to flowcharts and / or block diagrams according to the method, device (system), and computer program product of the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of the flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a machine that implements the flowcharts and / or block diagrams. Figure 1one or more processes and / or blocks Figure 1 an apparatus that implements the functionality of one or more blocks or sub-blocks.

[0087] Memory can include, without limitation, non- persistent memory, random access memory (RAM), and / or non-volatile memory, etc. such as read only memory (ROM), electrically programmable read only memory (EPROM), or electrically erasable programmable read only memory (EEPROM), flash memory, etc. Memory is an example of computer readable storage media.

[0088] Computer readable media includes permanent and non-permanent, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other memory technology, compact disc read only memory (CD-ROM), digital versatile disc (DVD), or other optical storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer readable media does not include transitory media, such as modulated data signals and carrier waves.

[0089] The above-described embodiments of the application have been described in connection with what are presently considered to be the most practical and preferred embodiments. It will, of course, be appreciated that the application is intended to cover all possible embodiments and modifications thereto within the spirit and scope of the application, as defined by the appended claims. Other embodiments of the application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. For example, to specify an action or a step as “followed” or “preceded” by another action or step does not require that the specified action or step occur immediately after or before the other action or step. Additionally, the processes depicted in the accompanying figures do not necessarily require the particular order shown, or sequential order in order to achieve the desired results. In some implementations, multitasking and parallel processing can be advantageous.

[0090] The foregoing is a summary of an embodiment of the application and not intended to limit the application. Embodiments of the application can be modified and varied as desired by those skilled in the art in light of the teachings herein. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and scope of the embodiments of the application should be included in the scope of the specification.

Claims

1. An artificial intelligence-based collaborative office network security management method, characterized by, The method comprises: The method comprises: According to the level of the transmission data in the collaborative office network, the multi-dimensional office data is dynamically generated with a permission policy, and authorization and / or recovery are automatically performed to obtain a data transmission permission policy; Based on the data transmission permission policy, the multi-dimensional office data is assigned a priority for transmission permission to obtain the office real-time transmission data; Through an artificial intelligence engine architecture, the office real-time transmission data in each department is dynamically transmitted and encrypted based on data sensitivity, and office encrypted data is obtained based on a distributed storage gateway; The office encrypted data in the office network export is classified and collected to obtain initial office network data; Through an edge computing node and based on the artificial intelligence engine architecture, the initial office network data is preprocessed for adversarial samples to obtain a network feature matrix based on the initial office network data, comprising: Through the edge computing node, the initial office network data is constructed into a feature vector related to time features, space features, and network protocol anomaly features to obtain a time-space protocol feature matrix; According to the timing rule mechanism in the artificial intelligence engine architecture and through a sliding window, the timing features in the initial office network data are processed by an exponentially weighted moving average to obtain dynamic time alignment data; Adversarial sample data is added to the training sample data corresponding to the initial office network data; wherein the adversarial sample data is a lagging network attack sample; According to the dynamic time alignment data and the adversarial sample data, the time-space protocol feature matrix is optimized to obtain the network feature matrix; Through the artificial intelligence engine architecture, the network feature matrix is processed by a dual-channel network anomaly detection to obtain network anomaly detection result data; wherein the dual-channel network anomaly detection processing includes attack type confidence detection processing and divergence value detection processing; According to the network anomaly detection result data, a corresponding network risk response action is performed to automatically generate a network anomaly solution strategy.

2. The method of claim 1, wherein the method is based on artificial intelligence. The method comprises: Before the collaborative office network is transmitted and coordinated, the cascading identifier corresponding to each department link in the collaborative office network is extracted; wherein the cascading identifier is the superior and subordinate identifier mark under the association relationship of each department; The role attributes in the same cascading identifier are hierarchically divided to obtain role level information; wherein the role level information is the hierarchical relationship information of data permissions in the same department link; Collect real-time office transmission data corresponding to each role level information in each cascading identifier; The cascading identifier, the role level information, and the real-time office transmission data are data fused to obtain the multi-dimensional office data; The method comprises: According to the level of data transmission in the collaborative office network, the multi-dimensional office data is dynamically generated with a permission policy, and authorization and / or recovery are automatically executed to obtain a data transmission permission policy; Based on the data transmission permission policy, the multi-dimensional office data is assigned a priority for transmission permission to obtain the office real-time transmission data.

3. The method of claim 1, wherein the method further comprises: Through the edge computing node and based on the artificial intelligence engine architecture, the initial office network data is preprocessed for adversarial samples to obtain a network feature matrix based on the initial office network data, specifically including: Through the edge computing node, the initial office network data is processed for feature vector construction related to time characteristics, spatial characteristics, and network protocol anomaly characteristics to obtain a time-space protocol feature matrix, including: The data packets in the initial office network data are processed for feature generation under time factors to obtain the time characteristics; wherein the time characteristics include: interval time, session duration, and periodic behavior patterns; The initial office network data is processed for topology positioning under network location to determine the spatial characteristics; wherein the spatial characteristics include: device physical topology location, logical network partition location, and device movement trajectory; Through the protocol syntax tree parsing engine, the initial office network data is converted under the tree structure, and based on the sub-tree similarity, the abnormal information in the network protocol is scored to obtain the network protocol anomaly characteristics; wherein the abnormal information includes: abnormal combination of header fields of protocol layer, abnormal combination of TCP flag bits, and TLS handshake parameter entropy value; According to the timing rule mechanism in the artificial intelligence engine architecture, and through the sliding window, the timing characteristics in the initial office network data are processed for exponential weighted moving average to obtain dynamic time alignment data; The adversarial sample data is added to the training sample data corresponding to the initial office network data; wherein the adversarial sample data is a lagging network attack sample, including: Extract the dormant period pattern in historical APT attacks; through the LSTM-GAN generator, synthesize attack traffic with time delay characteristics, and generate lagging features with attack chain characteristics; Through the time confusion encoder, the lagging features of the adversarial sample are hidden in the periodic fluctuations of the legal traffic to obtain the adversarial sample data; According to the dynamic time alignment data and the adversarial sample data, the time-space protocol feature matrix is optimized for feature matrix to obtain the network feature matrix, including: The time series data after TCN alignment is spliced with the time axis of the time-space protocol feature matrix to obtain an enhanced matrix; wherein the enhanced matrix at least includes: new time delay jitter, traffic entropy, and burst coefficient; Through feature random masking and adversarial gradient penalty, the enhanced matrix is processed for adversarial robust enhancement; Through the time-sensitive convolution kernel, the lagging attack features in the enhanced matrix are extracted and output as the network feature matrix.

4. The method of claim 1, wherein the method is based on artificial intelligence. The network feature matrix is subjected to double-channel network anomaly detection processing through the artificial intelligence engine architecture to obtain network anomaly detection result data, specifically including: The network feature matrix is subjected to known network threat feature identification calculation through a Transformer-CNN hybrid model in the artificial intelligence engine architecture, and an attack type confidence in the known threat channel is output; wherein the higher the attack type confidence, the stronger the degree of current network feature matrix affected by the known network attack model, including: The network feature matrix is subjected to time dimension self-correlation and spatial dimension dependency calculation under a multi-head spatio-temporal attention mechanism through an encoding layer in the Transformer-CNN hybrid model to obtain spatio-temporal attention features; The spatio-temporal attention features are subjected to dynamic parameter adjustment under a dynamic convolution kernel, and the network feature matrix is subjected to multi-scale identification calculation of known network threat features through a known network threat classifier; The known network threat features are subjected to matching degree calculation under similarity through a dilated convolution layer in the Transformer-CNN hybrid model to obtain the attack type confidence in the known threat channel; The current network traffic in the network feature matrix and the historical baseline network traffic are subjected to latent space scatter calculation through a deep clustering algorithm, and a scatter value in the unknown threat channel is output, including: The historical baseline network traffic is subjected to dimension compression processing through a variational autoencoder, and the current network traffic is subjected to sample addition to generate a 32-dimensional latent space; New and old data in the 32-dimensional latent space are subjected to data distribution drift calculation through an adversarial domain adaptation mechanism to obtain a real-time traffic mapping relationship; The real-time traffic mapping relationship is subjected to scatter measurement calculation under Wasserstein distance to obtain the scatter value in the unknown threat channel; If the attack type confidence is greater than or equal to a first preset threshold, the initial office network data has known threat network anomaly result data; If the scatter value is greater than or equal to a second preset threshold, the initial office network data has unknown threat network anomaly result data; The network anomaly detection result data includes the known threat network anomaly result data and the unknown threat network anomaly result data.

5. The method of claim 1, wherein the method is based on artificial intelligence, and According to the network anomaly detection result data, corresponding network risk response actions are performed to automatically generate network anomaly solving strategies, specifically including: The network anomaly detection result data is subjected to digital work order generation processing to obtain high-risk abnormal network data work orders; According to the OpenFlow protocol and through an SDN controller, the network anomaly detection result data is subjected to isolation processing of corresponding collaborative office hosts and corresponding network execution links to obtain network isolation data; The network anomaly detection result data is subjected to resource scheduling processing of corresponding network service types to obtain resource scheduling data; wherein resource scheduling at least includes bandwidth reserve reservation and server standby deployment; Based on the high-risk abnormal network data ticket, the network isolation data and the resource scheduling data, and through the artificial intelligence engine architecture, it is automatically converted into an executable instruction set and a network anomaly solution strategy is generated.

6. The artificial intelligence-based collaborative office network security management method of claim 4, wherein, The Transformer-CNN hybrid model is a deep learning model that combines the advantages of pre-trained convolutional neural networks and Transformer architecture, and is used to identify known network threat features in the global structure of the feature matrix.

7. The artificial intelligence-based collaborative office network security management method of claim 1, wherein, Through the artificial intelligence engine architecture, the office real-time transmission data in each department is dynamically transmitted and encrypted based on data sensitivity, and office encrypted data is obtained based on a distributed storage gateway, specifically including: Through the artificial intelligence language processing mechanism in the artificial intelligence engine architecture, the office real-time transmission data is processed for keyword recognition under data sensitivity, and the sensitivity label of each office real-time transmission data is determined; wherein the sensitivity label includes: public, internal and confidential; Through the dynamic encryption engine and based on the sensitivity label, the office real-time transmission data is encrypted to generate a key pair for each office real-time transmission data; According to the key pair and based on the distributed storage gateway, a globally unique storage ID is generated for each office real-time transmission data; Through the globally unique storage ID, the office real-time transmission data corresponding to the key pair is encrypted and transmitted to obtain the office encrypted data in data transmission.

8. The artificial intelligence-based collaborative office network security management method of claim 1, wherein, The office encrypted data in the office network export is classified and collected to obtain initial office network data, specifically including: Collecting the office encrypted data that has completed data transmission and is in the office network export; Through the key pair of the current node, the office encrypted data is decrypted to obtain office decrypted data; Through the sensor array deployed at the office network export, the office decrypted data is captured; Through the data automatic recognition mechanism in the artificial intelligence engine architecture, the captured data is processed for tree classification, and traffic metadata, behavior logs and device states are counted to obtain the initial office network data; wherein the traffic metadata includes at least: five-tuple, TCP flag distribution and packet size distribution; the behavior log includes at least: user login track, file access sequence and permission change record; the device state includes at least: CPU / memory occupancy, abnormal process signature, security baseline deviation value.

9. An artificial intelligence-based collaborative office network security management system, comprising: The transmission encryption module is used for performing permission policy allocation on multi-dimensional office data in the collaborative office network to obtain office real-time transmission data, including: performing dynamic generation processing of permission policy on the multi-dimensional office data according to the level of transmission data in the collaborative office network, and automatically performing authorization and / or recovery to obtain a data transmission permission policy; performing priority allocation of transmission permission on the multi-dimensional office data based on the data transmission permission policy to obtain the office real-time transmission data; and performing dynamic transmission encryption processing of the office real-time transmission data in each department on data sensitivity based on an artificial intelligence engine architecture, and obtaining office encrypted data based on a distributed storage gateway. The data acquisition module is used for performing decryption data classification acquisition processing on the office encrypted data in the office network export to obtain initial office network data. The edge computing module is used for performing edge preprocessing of adversarial samples on the initial office network data based on the artificial intelligence engine architecture through an edge computing node to obtain a network feature matrix based on the initial office network data, including: performing feature vector construction of time features, space features and network protocol anomaly features on the initial office network data through the edge computing node to obtain a time-space protocol feature matrix; performing exponential weighted moving average processing on time sequence features in the initial office network data according to a time sequence rule mechanism in the artificial intelligence engine architecture through a sliding window to obtain dynamic time alignment data; adding adversarial sample data to training sample data corresponding to the initial office network data; wherein the adversarial sample data is a lagging network attack sample; and performing optimization processing of the time-space protocol feature matrix to obtain the network feature matrix based on the dynamic time alignment data and the adversarial sample data. The artificial intelligence anomaly analysis module is used for performing double-channel network anomaly detection processing on the network feature matrix based on the artificial intelligence engine architecture to obtain network anomaly detection result data; wherein the double-channel network anomaly detection processing includes attack type confidence detection processing and divergence value detection processing. The risk response module is used for performing corresponding network risk response actions according to the network anomaly detection result data to generate a network anomaly solution strategy.

10. A non-transitory computer storage medium, comprising, The storage medium is a non-volatile computer readable storage medium, which stores at least one program, each of which includes instructions that, when executed by a terminal, cause the terminal to execute a collaborative office network security management method based on artificial intelligence according to any one of claims 1-8.

Citation Information

Patent Citations

  • Remote office network security protection method and system based on big data

    CN119728311A

  • Risk sensing and early warning method and system for operation state of oil and gas pipe network

    CN119990786A