Machine learning-based convergence media network security threat perception and control method and system

By constructing a heterogeneous relationship graph of the converged media network and using deep learning methods, generating low-dimensional vectors of nodes, and conducting semi-supervised training and reinforcement learning to optimize protection strategies, the problems of insufficient data fusion and poor dynamic adaptability in the converged media network are solved, and efficient threat detection and protection are achieved.

CN120729653AActive Publication Date: 2025-09-30JIANGSU BROADCASTING CORPORATION
View PDF 12 Cites 0 Cited by

Patent Information

Application Number
CN202511238860.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-01
Publication Date
2025-09-30
Estimated Expiration
2045-09-01

AI Technical Summary

Technical Problem

Existing network security detection technologies face problems such as insufficient data fusion, difficulty in feature extraction, and poor dynamic adaptability in converged media networks, making it difficult to effectively handle multi-source heterogeneous data and complex node interaction relationships.

Method used

By collecting multi-source heterogeneous data from the converged media network, a heterogeneous relationship graph between data nodes is constructed, and a deep learning method based on clustering algorithm and graph embedding is used to generate low-dimensional vectors of nodes. Semi-supervised joint training is performed, and graph attention network and reinforcement learning are used to optimize protection strategies, detect in real time, and automatically trigger protection actions.

Benefits of technology

It achieves efficient threat detection and protection, significantly improves the real-time and accuracy of network security protection, reduces false alarm and missed alarm rates, and has stronger scalability and intelligence.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729653A_ABST
    Figure CN120729653A_ABST
Patent Text Reader

Abstract

The invention discloses a convergence media network security threat perception and control method and system based on machine learning, and relates to the technical field of convergence media network security, and the method comprises the steps: collecting multi-source heterogeneous data of a convergence media network, carrying out the fusion, and constructing a heterogeneous relation graph between data nodes; dividing the nodes based on a clustering algorithm, generating a low-dimensional vector of each node by adopting a graph embedding method, and distributing a pseudo tag and a corresponding confidence coefficient for each node; inputting the historical label sample and the pseudo label sample into a graph attention network according to confidence coefficient weighting for semi-supervised joint training to obtain a threat detection model; re-executing clustering and pseudo label updating, and iteratively updating the model; and deploying the trained threat detection model, outputting a threat score to each node in the convergence media network sub-graph in real time, and automatically triggering a protection action according to a preset strategy. According to the method, threats can be accurately identified and evaluated, the protection action is automatically triggered, and the real-time performance and the accuracy of network security protection are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of converged media network security technology, and in particular to a converged media network security threat perception and control method and system based on machine learning. Background Art

[0002] With the rapid development of information technology and the widespread adoption of the internet, converged media networks (including the integration of multiple information sources such as multimedia, social platforms, and mobile devices) have become a core component of information dissemination. The complexity and diversity of converged media networks have led to increasingly severe security threats. Traditional network security protection technologies primarily focus on monitoring and protecting network traffic, user behavior, or device status. However, these approaches often overlook the heterogeneous nature of converged media networks and the complex interactions between nodes. In recent years, security protection methods based on graph networks have gradually attracted attention from both academia and industry. By modeling individual nodes and their relationships in the network, these methods can more accurately capture the interactions and potential threats between nodes, particularly in converged media networks that face large-scale data and complex interaction patterns. However, existing graph models primarily focus on the construction and analysis of static graphs and lack the ability to handle the dynamic and multi-source heterogeneous data unique to converged media networks.

[0003] Current network security detection methods rely on rule-driven detection engines or statistical learning-based models. While these methods can be effective when processing large-scale traffic data, they still face significant challenges. First, rule-driven detection methods often suffer from high false positive and false negative rates, making them difficult to adapt to new attack patterns. Existing statistical learning-based models typically rely on specific feature engineering, requiring extensive prior knowledge and manual intervention, and struggle to effectively capture potential correlations between data when fusing heterogeneous data from multiple sources. Furthermore, traditional methods often lack sufficient flexibility and scalability when dealing with dynamic interactions between nodes. Existing technologies struggle to provide effective security protection strategies from a global perspective given the complex relationships between multi-level and multi-type nodes (such as user nodes, device nodes, and resource nodes). Summary of the Invention

[0004] In view of the above existing problems, the present invention is proposed.

[0005] Therefore, the present invention provides a converged media network security threat perception and control method based on machine learning to solve the problems faced by existing network security detection technologies such as insufficient data fusion, difficulty in feature extraction, and poor dynamic adaptability.

[0006] In order to solve the above technical problems, the present invention provides the following technical solutions:

[0007] In a first aspect, the present invention provides a method for threat perception and control of converged media network security based on machine learning, which includes collecting multi-source heterogeneous data of the converged media network for integration and constructing a heterogeneous relationship graph between data nodes;

[0008] The nodes are divided based on a clustering algorithm, a graph embedding method is used on the heterogeneous relationship graph to generate a low-dimensional vector for each node, and a pseudo label and corresponding confidence level are assigned to each node;

[0009] The historically labeled samples and pseudo-labeled samples are weighted by confidence and input into the graph attention network for semi-supervised joint training to obtain a threat detection model.

[0010] Re-clustering and pseudo-label updating are performed based on the latest node representation, and the model is updated iteratively.

[0011] Deploy the trained threat detection model, output threat scores for each node in the converged media network subgraph in real time, and automatically trigger protection actions according to preset strategies.

[0012] As a preferred solution of the machine learning-based converged media network security threat perception and control method of the present invention, wherein: the construction of a heterogeneous relationship graph between data nodes includes modeling the converged media network graph structure, defining node types, and establishing edge relationships between different types of nodes based on business connections and security semantics; extracting multi-dimensional features for each type of collected nodes and edges;

[0013] The node types include user nodes, IP nodes, device nodes, and resource nodes;

[0014] When new data arrives, if a node does not exist yet, it is automatically added and its features are initialized; edge attributes and weights are assigned based on the type of interaction between nodes; multiple interactions between the same pair of nodes are stored as edge objects with timestamps.

[0015] As a preferred solution of the machine learning-based converged media network security threat perception and control method described in the present invention, the node division based on the clustering algorithm includes: using historically labeled samples as seed points to cluster the node behavior data; dividing the node behavior data into K clusters through the algorithm; for seed points with known partial threat data, using a semi-supervised clustering algorithm, using the labeled data to guide the clustering process; calculating the cluster distance for each node behavior data, and dividing the node behavior data into clusters based on the criterion of minimum intra-cluster distance;

[0016] For unsupervised scenarios, the silhouette coefficient is used to evaluate the clustering effect and select the K value;

[0017] Assign a label to each cluster. If a cluster contains a known threat sample, the cluster is labeled as a threat; if the sample in the cluster is a normal sample, it is labeled as normal. For behavioral data without explicit labels, a soft labeling method is used to assign a threat probability label based on its distance within the cluster to obtain a pseudo-labeled sample.

[0018] As a preferred solution of the method for converged media network security threat perception and control based on machine learning described in the present invention, the graph embedding method includes embedding the graph using a random walk algorithm to generate a low-dimensional vector representation of the node;

[0019] For each node Initialize a random vector in the graph ; Randomly select a starting node in the graph and perform multiple walks; each walk starts from the node Start by randomly jumping to adjacent nodes along the edge of the graph ; Walk to get the node sequence , indicating the slave node The starting walking path;

[0020] According to the node pairs in the walking path To model, the objective function is to maximize the given node When , the probability of the remaining nodes in the path is predicted; the negative sampling method is used to approximate the objective function, and the training is performed to obtain the probability of each node Low-dimensional vector representation of , containing the structure and attribute information of the node.

[0021] As a preferred solution of the machine learning-based converged media network security threat perception and control method of the present invention, the semi-supervised joint training includes calculating the confidence of the pseudo-label sample of each node and adjusting the confidence by the graph embedding similarity of the node;

[0022] The model is built using a graph attention network, which inputs historically labeled samples and pseudo-labeled samples weighted by confidence. For each node, the attention coefficient between the node and its adjacent nodes is calculated. Based on the calculated attention coefficient, the information of neighboring nodes is aggregated to update the representation of each node. The cross-entropy loss function is used to evaluate the performance of the model.

[0023] After training the graph attention network, the node representation is updated; the node representation is a vector that includes the node's position in the graph and the node's behavior characteristics;

[0024] Use the updated node representation to perform secondary clustering operations to re-divide the nodes into different clusters;

[0025] After obtaining the new node representation and the updated secondary clustering results, the pseudo label of each node is recalculated. The specific process includes:

[0026] Based on the similarity update between the node and the cluster center, if the node representation of the node is close to the cluster center, the pseudo label of the node is adjusted to be consistent with the cluster label;

[0027] Based on neighbor consistency update, if the pseudo labels of a node's neighbor nodes are the same, the pseudo label of the node is updated to be consistent with that of the neighbor nodes;

[0028] In each round of training, clustering is re-executed based on the current node representation to obtain new node clusters and cluster centers; the pseudo-label of each node is updated based on the new node representation and clustering results, and the model is continued to be trained using the updated pseudo-label and node representation; the node representation, clustering results and pseudo-label are iteratively updated to optimize the graph attention model until the model's loss function converges.

[0029] As a preferred solution of the machine learning-based integrated media network security threat perception and control method described in the present invention, the output threat score includes calculating the similarity between the output results of the graph attention model of each node and known types of threats; based on the results of the similarity calculation, the threat level is scored and divided into serious, high risk, medium risk, and low risk levels.

[0030] As a preferred solution of the method for fusion media network security threat perception and control based on machine learning described in the present invention, wherein: the automatic triggering of protection actions according to the preset strategy includes using a reinforcement learning algorithm to optimize the preset strategy through a Q-value function; state Represents the global state of the current graph structure, that is, the feature vectors of the nodes and edges in the current graph; node features are aggregated through the graph attention network to finally obtain a high-dimensional feature representation of each node , we can get a global representation of the entire graph; , Indicates the number of nodes, Representation node At the moment The eigenvector of

[0031] Each action It is the defensive operation that can be performed to minimize the threat in the current state. The executable actions include blocking edges, isolating nodes, limiting speed, and adjusting firewall policies. The Q value function represents the state Next action The maximum cumulative reward that can be obtained after the attack; the reward is obtained by evaluating the reward function, which is set according to preventing the spread of threats, reducing false blocking and delays;

[0032] When an abnormal node is detected, the optimal defense operation is automatically executed through the reinforcement learning algorithm; and Calculate the similarity of abnormal node pairs and preliminarily estimate the propagation path of the threat;

[0033] For each abnormal node, gradually build a propagation chain along the node with the greatest similarity in the graph; set the propagation threshold , only when the similarity is greater than the threshold When the decision node is part of the transmission path;

[0034] Through reverse tracing, the origin of the threat is tracked, the score of the tracing propagation path is evaluated, and based on the score of the propagation path, the nodes are sorted according to the relevance of the threat source to obtain the source node of the threat; after the risk tracing is completed, the tracing results are visualized and the impact range of the threat propagation chain is evaluated.

[0035] In a second aspect, the present invention provides a converged media network security threat perception and management system based on machine learning, including a data acquisition module that collects multi-source heterogeneous data from the converged media network and constructs a heterogeneous relationship graph;

[0036] The label generation module uses a semi-supervised clustering algorithm to cluster node behavior data and assign a label to each cluster;

[0037] The threat monitoring module uses a trained threat detection model to perform real-time threat scoring on nodes in the converged media network and trigger protection actions based on preset strategies.

[0038] In a third aspect, the present invention provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: when the computer program is executed by the processor, it implements any step of the method for media convergence network security threat perception and control based on machine learning as described in the first aspect of the present invention.

[0039] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, it implements any step of the method for media convergence network security threat perception and control based on machine learning as described in the first aspect of the present invention.

[0040] The beneficial effects of the present invention are as follows: by integrating multi-source heterogeneous data of the converged media network, constructing a heterogeneous relationship graph between data nodes, and adopting a deep learning method based on clustering algorithm and graph embedding, dynamically updating node representation and pseudo-labels, and realizing efficient threat detection. Through the semi-supervised training of the graph attention network and the optimization of protection strategies driven by reinforcement learning, the present invention can accurately identify and evaluate threats, automatically trigger protection actions, and significantly improve the real-time and accuracy of network security protection. Compared with traditional technologies, the present invention can effectively reduce the false alarm rate and the missed alarm rate, and adapt to the complex and dynamic interactive threat changes in the converged media network, and has a stronger scalability and intelligence level. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0042] Figure 1 This is a flowchart of the converged media network security threat perception and control method based on machine learning. DETAILED DESCRIPTION

[0043] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0044] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways different from those described herein. Those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0045] Secondly, the term "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in various places throughout this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive of other embodiments.

[0046] Reference Figure 1 , is an embodiment of the present invention, which provides a method for media convergence network security threat perception and control based on machine learning, including the following steps:

[0047] S1: Collect multi-source heterogeneous data from the converged media network and fuse them to build a heterogeneous relationship graph between data nodes.

[0048] Furthermore, the node types are defined, including: user node, user account, session ID; IP node, source IP, target IP; device node, terminal device ID, media server node; resource node, URL, API interface, media file.

[0049] Define edge types, including: access edge, which records access relationships; communication edge, which records network session traffic; login edge, which binds users to devices; and dependency edge, which records calls between services.

[0050] The construction of a heterogeneous relationship graph between data nodes includes modeling the structure of a converged media network graph, defining node types, establishing edge relationships between different types of nodes based on business connections and security semantics; and extracting multi-dimensional features for each type of collected nodes and edges.

[0051] Furthermore, the node types include user nodes, IP nodes, device nodes, and resource nodes.

[0052] When new data arrives, if a node does not exist yet, it is automatically added and its features are initialized; edge attributes and weights are assigned based on the type of interaction between nodes; multiple interactions between the same pair of nodes are stored as edge objects with timestamps.

[0053] For each type of collected node and edge, multi-dimensional features are extracted. Node features include user node login frequency and abnormal behavior counts, device node operating system type and vulnerability counts, IP node geographic location and blacklist status, etc. Edge features include access count, request latency, data flow, call interval, etc.

[0054] All features are standardized or normalized, and some categorical features are one-hot encoded to ensure that the features can be directly input and processed by subsequent graph neural networks.

[0055] The relationship graph uses "node-edge-node" as the basic unit, and dynamically organizes all entities and their relationships into a heterogeneous relationship graph as follows:

[0056] Whenever new data arrives, if a node does not exist yet, a new node is automatically added and its features are initialized; based on the events or interactions in the data, corresponding edges are established between nodes, and the weights or attributes of the edges are assigned according to the actual interaction content.

[0057] Supports time-series edge modeling, storing multiple interactions between the same pair of nodes as time-stamped edge objects to preserve historical evolution information. A distributed graph computing platform is used to manage graph structures, enabling efficient addition, deletion, modification, and query operations, as well as batch operations. Incremental updates to the graph structure include batch insertion of new nodes and edges for newly added data, and regular cleanup of old or unused nodes.

[0058] It should be noted that this service provides efficient graph-structured data export and interface services, allowing the constructed heterogeneous relationship graphs to be fed into subsequent graph neural networks (GCN, GAT, and other modules) for threat detection and analysis. Export is supported in various formats, such as batch subgraphs and time slices, enabling efficient data supply for diverse analysis tasks. Through an algorithmic process combining multi-source data fusion and graph construction, it enables structured, dynamic, and scalable modeling of various security-related entities and behaviors within converged media network environments, significantly enhancing subsequent threat detection and anomaly propagation tracing capabilities.

[0059] S2: Divide the nodes based on the clustering algorithm, use the graph embedding method to generate a low-dimensional vector for each node on the heterogeneous relationship graph, and assign a pseudo label and corresponding confidence to each node.

[0060] Furthermore, the node division based on the clustering algorithm includes: using historically labeled samples as seed points to cluster the node behavior data; dividing the node behavior data into K clusters through the algorithm; for seed points with known partial threat data, using a semi-supervised clustering algorithm to guide the clustering process using labeled data. The cluster distance is calculated for each node behavior data, and the node behavior data is divided into clusters according to the criterion of minimum distance within the cluster. For each node , calculate its distance to other nodes in the cluster, usually using Euclidean distance:

[0061]

[0062] in, It is a cluster The minimum distance criterion within the cluster: According to the minimum distance criterion within the cluster, the node Assign to the closest cluster .

[0063] Unsupervised clustering and evaluation,In an unsupervised scenario, there is no pre-labeled threat data, and the clustering process relies entirely on the similarity between nodes.,To this end, the silhouette coefficient is used to evaluate the clustering effect and select the appropriate number of clusters. :

[0064]

[0065] in, is the average distance between nodes in the cluster, is the average distance from a node to the nearest cluster. Choose the one that maximizes the silhouette coefficient. , as the final number of clusters.

[0066] For each cluster ,Assign labels based on the labeling of nodes in the cluster. Labeled threat data: If the cluster contains known threat samples, the cluster is labeled as threat. Labeled normal data: If the cluster is full of normal nodes, the cluster is labeled as normal. For nodes without explicit labels, a soft label method is used to assign them a threat probability label. The threat probability of each node is calculated based on the relative distance of the node in its cluster (the proximity to the cluster center). :

[0067]

[0068] in, Representation node To cluster center In this way, a pseudo label is generated for each unlabeled node and its confidence is stored in middle.

[0069] Assign a label to each cluster. If a cluster contains a known threat sample, the cluster is labeled as a threat; if the sample in the cluster is a normal sample, it is labeled as normal. For behavioral data without explicit labels, a soft labeling method is used to assign a threat probability label based on its distance within the cluster to obtain a pseudo-labeled sample.

[0070] The graph embedding method includes embedding the graph using a random walk algorithm to generate a low-dimensional vector representation of the node.

[0071] A random walk algorithm is used to embed heterogeneous relational graphs, thereby generating low-dimensional vector representations of nodes. The goal of the random walk method is to learn the embedding representation of nodes based on the structural relationships between nodes, thereby capturing the potential correlations between nodes.

[0072] Initialize the node vector for each node in the graph Randomly initialize a vector . Indicates all The set of n-dimensional real vectors is the domain of the embedding space. Represents the embedding space dimension. Walking process: From any node To begin, a random starting node is selected and multiple random walks are performed. In each walk, the node randomly jumps to adjacent nodes along the edge of the graph, generating a walk path. Walk path modeling: Modeling is done by using node pairs in the walk path. The goal is to maximize the probability of predicting other nodes in the path when a given node is present:

[0073]

[0074] in, is a node in the walk path. The negative sampling method is used to approximate the objective function and reduce the amount of calculation. The goal of the negative sampling method is to optimize the embedding representation of each node by comparing the probabilities of positive and negative samples. :

[0075]

[0076] in, is the sigmoid function, and is a node and The low-dimensional embedding representation of is the representation of the negative sample node of negative sampling.

[0077] For each node Initialize a random vector in the graph ; Randomly select a starting node in the graph and perform multiple walks; each walk starts from the node Start by randomly jumping to adjacent nodes along the edge of the graph ; Walk to get the node sequence , indicating the slave node The starting walking path.

[0078] According to the node pairs in the walking path To model, the objective function is to maximize the given node When , the probability of the remaining nodes in the path is predicted; the negative sampling method is used to approximate the objective function, and the training is performed to obtain the probability of each node Low-dimensional vector representation of , containing the structure and attribute information of the node.

[0079] It should be noted that the nodes are divided into multiple clusters, and pseudo labels and corresponding confidence scores are generated for each node. The low-dimensional vector representation of each node is generated using the graph embedding method. These representations contain the structure and attribute information of the node, which can be used for subsequent threat detection and protection strategies. The low-dimensional representation training is carried out through multiple iterations to make the low-dimensional vector representation of each node It can capture the structural information and attribute information of the node as much as possible. Finally, a low-dimensional vector representation of each node is obtained. , which will be helpful for subsequent threat detection and prediction tasks.

[0080] S3: Historically labeled samples and pseudo-labeled samples are weighted by confidence and input into the graph attention network for semi-supervised joint training to obtain a threat detection model.

[0081] The semi-supervised joint training includes calculating the confidence of the pseudo-label samples of each node and adjusting the confidence by the graph embedding similarity of the nodes.

[0082] The graph attention network is used for modeling, and historical annotated samples and pseudo-labeled samples are input weighted by confidence. For each node, the attention coefficient between the node and the adjacent nodes is calculated. Based on the calculated attention coefficient, the information of the neighboring nodes is aggregated to update the representation of each node. The cross-entropy loss function is used to evaluate the performance of the model.

[0083] Calculate the pseudo label confidence of each node First, for each node , it is necessary to calculate the confidence of its pseudo label The pseudo labels are generated based on the distance between the node and the cluster center and the consistency of the node’s neighbors. The confidence of a node is related to its position in the cluster and its similarity to its neighbors. The formula is:

[0084]

[0085] in, is a node The center of the cluster, Representation node With cluster center The smaller the distance, the closer the node is to the cluster center and the higher the confidence.

[0086] Modeling using Graph Attention Network Next, we use Graph Attention Network (GAT) to model the nodes. Calculate each node Its adjacent nodes The attention coefficient between , dynamically adjusted through node features and adjacency information:

[0087]

[0088] in, Representation node and nodes The correlation between them can be obtained by calculating the inner product of the node representation or other similarity metrics. ,node Aggregate its neighbor nodes Information, update its feature representation:

[0089]

[0090] in, is the updated node representation, is the weight matrix, is the activation function, is the bias term.

[0091] During the training process, historically labeled samples and pseudo-labeled samples are weighted according to their confidence and fed into the graph attention network. The confidence of historically labeled samples is 1, while the confidence of pseudo-labeled samples is Adjust based on its similarity to the cluster center:

[0092]

[0093] in, is a node The eigenvector of is the confidence of the node. Represents the adjusted vector value. By weighting the input, the model will pay more attention to samples with higher confidence, ensuring the effectiveness and robustness of training.

[0094] The training process uses the cross entropy loss function. To evaluate the performance of the model:

[0095]

[0096] in, is a node The true label, is the label predicted by the model. The loss calculation for historically labeled samples is the same as standard supervised learning methods, while the loss for pseudo-labeled samples is weighted according to their confidence.

[0097] It should be noted that after multiple iterations of training, the graph attention network will learn representations for each node. These representations contain not only the node's own features but also its structural information within the graph. Once training is complete, the model can perform real-time threat detection and protection decisions based on the latest node representations.

[0098] S4: Re-clustering and pseudo-label updating based on the latest node representation, and iteratively update the model.

[0099] After training the graph attention network, the node representation is updated; the node representation is a vector including the position of the node in the graph and the node behavior characteristics.

[0100] After each round of training, clustering is performed again based on the latest node representation. By calculating the representation vector of each node The similarity with the cluster center is used to update the cluster label of each node.

[0101] The similarity between the node and the cluster center is updated. If the node New expression of With cluster center If the node is similar (the distance is small), the pseudo label of the node is updated to the label of the cluster, that is, .

[0102] Neighbor consistency update: If the node The pseudo labels of the neighbor nodes of node are consistent, then node The pseudo labels of are also updated to be consistent with those of the neighbors, i.e. (For all neighbors ). In this way, the pseudo labels are updated according to the position of the nodes in the graph and the consistency of their neighbors.

[0103] The updated node representation is used to perform a secondary clustering operation to re-divide the nodes into different clusters.

[0104] After obtaining the new node representation and the updated secondary clustering results, the pseudo label of each node is recalculated. The specific process includes:

[0105] Based on the similarity update between the node and the cluster center, if the node representation of the node is close to the cluster center, the pseudo label of the node is adjusted to be consistent with the label of the cluster.

[0106] Based on neighbor consistency update, if the pseudo labels of a node's neighbor nodes are the same, the pseudo label of the node is updated to be consistent with that of the neighbor nodes.

[0107] In each round of training, clustering is re-executed based on the current node representation to obtain new node clusters and cluster centers; the pseudo-label of each node is updated based on the new node representation and clustering results, and the model is continued to be trained using the updated pseudo-label and node representation; the node representation, clustering results and pseudo-label are iteratively updated to optimize the graph attention model until the model's loss function converges.

[0108] In each round of training, the node representation, clustering results and pseudo labels are updated, and the model is trained using the updated pseudo labels and node representations. This process is repeated until the model's loss function is convergence:

[0109]

[0110] in, is the loss of historical labeled samples, is the weighted loss of pseudo-label samples. The graph attention model is optimized through continuous iterative updates.

[0111] It should be noted that the semi-supervised joint training process uses a graph attention network to weightedly input historically annotated samples and pseudo-labeled samples, and updates pseudo-labels based on node representations. This iterative update process ultimately results in a robust threat detection model. With each round of training, node representations, pseudo-labels, and clustering results are optimized, improving the model's performance and accuracy.

[0112] S5: Deploy the trained threat detection model, output threat scores for each node in the converged media network subgraph in real time, and automatically trigger protection actions according to preset strategies.

[0113] Furthermore, the high-dimensional feature representation of each node is a weighted aggregation result based on the features of its neighboring nodes, capturing the relationship between the node and other nodes in the graph.

[0114] Feature representation for each node Calculate the similarity with the feature vector of the known threat type. Assume that the threat type is , each threat type has a representative feature vector .

[0115] Similarity The calculation uses cosine similarity:

[0116]

[0117] in, represents the dot product, is the norm of the vector.

[0118] Threat scoring and level classification, based on the results of similarity calculation, evaluate the threat level of the node. Threat Type The higher the similarity, the more serious the threat level.

[0119] Automatically triggering protective actions based on preset strategies includes using reinforcement learning algorithms to optimize preset strategies through Q-value functions; Represents the global state of the current graph structure, that is, the feature vectors of the nodes and edges in the current graph; node features are aggregated through the graph attention network to finally obtain a high-dimensional feature representation of each node , we can get a global representation of the entire graph; , Indicates the number of nodes, Representation node At the moment The eigenvector of .

[0120] Based on the similarity value, the threat level is divided into severe, high risk, medium risk, and low risk.

[0121] Each action These are the defensive actions that can be performed in the current state. In each state, the system can perform a range of defensive actions, including: blocking edges (isolating threat propagation paths), isolating nodes (isolating abnormal nodes from the network), limiting speed (reducing network bandwidth to slow the spread of potential threats), and adjusting firewall policies (enhancing firewall rules to prevent attacks).

[0122] Q-value function Assessment in state Next action The maximum cumulative reward that can be obtained after:

[0123]

[0124] in, is the discount factor, It is the immediate reward obtained after performing an action. Indicates the number of future time steps. When calculating the expected cumulative reward, Starting from 0, it means from the current time step The number of time steps from now to the future. Corresponding to the current moment go through Rewards for each step .so, The increase in means a "future" discount on the reward, that is, considering the distance from the current moment The rewards of further time.

[0125] Reward Function Evaluation is based on the following factors: Preventing Threat Propagation: If the defensive action effectively slows the spread of the threat, a positive reward is given. Reducing False Negative Blockage: If the defensive action does not accidentally damage healthy nodes, a higher reward is given. Minimizing Latency: The defensive action should be executed as quickly as possible, and the shorter the latency, the higher the reward.

[0126] Through the Q learning algorithm, the system continuously optimizes the protection strategy, so that it can select the best defense operation in each state. .

[0127] When an abnormal node is detected, the optimal defense operation is automatically executed through the reinforcement learning algorithm; and The abnormal node pairs are found, similarity is calculated, and the propagation path of the threat is preliminarily estimated.

[0128] For each abnormal node, we gradually build a propagation chain along the nodes with the largest similarity in the graph; propagation path calculation, assuming that a set of abnormal nodes have been detected , hoping to predict the propagation paths of these abnormal nodes. By calculating the similarity between abnormal nodes and other nodes, the possible propagation paths of threats are estimated. and , calculate their similarity:

[0129]

[0130] in, and Node and The embedding vector of and is their Euclidean norm.

[0131] The propagation chain prediction is based on the similarity of node embedding vectors and uses the shortest path algorithm to find the most likely propagation path of the abnormal node in the graph. The path selection prioritizes those nodes with high similarity to the abnormal node.

[0132] For each abnormal node , along the nodes with the greatest similarity in the graph, gradually build the propagation chain.

[0133] Propagation threshold: Set the propagation threshold , only if the similarity Greater than threshold When the node considered part of the transmission pathway.

[0134] Through reverse tracing, the origin of the threat is tracked, the score of the tracing propagation path is evaluated, and based on the score of the propagation path, the nodes are sorted according to the relevance of the threat source to obtain the source node of the threat; after the risk tracing is completed, the tracing results are visualized and the impact range of the threat propagation chain is evaluated.

[0135] Once reverse propagation discovers an abnormal node, it can trace back to the source of the threat. The core idea of ​​reverse propagation is to find the source node that may cause the threat by following the direction opposite to the abnormal node in the graph.

[0136] The path is traced back, starting from the abnormal node, and propagating back along the path with the greatest similarity. For example, for node ,calculate , thereby tracing back to the possible source node.

[0137] Propagation path score, each time backtracking, evaluate the score of the path , and judge whether the path is the actual threat propagation path based on the score.

[0138] The tracing node sorting is based on the score of the propagation path and the relevance of the threat source, and finally the most likely source node of the threat is obtained. :

[0139]

[0140] in, Is with the node All related nodes.

[0141] After risk tracing is complete, the results are visualized to help security personnel locate the source of the threat and assess the impact of the threat propagation chain. The propagation path and traceability relationship between each node can be displayed through a graphical interface.

[0142] Combining propagation path prediction with source tracing analysis creates a multi-layered threat analysis view. By analyzing each node's propagation path and source tracing history, the node's role in the overall threat chain (such as attack source, propagation node, or target node) can be determined.

[0143] It should be noted that low-dimensional node representations: Graph embeddings generate low-dimensional representations by capturing the structural features of the graph, which can help subsequent tasks (such as clustering and similarity calculation) to be performed efficiently. For some tasks, low-dimensional representations are sufficient to provide information about the relationships between nodes. High-dimensional node representations: Graph neural networks generate high-dimensional representations using deep learning techniques, which can capture more complex relationships between node features and their surroundings. These representations are continuously optimized through training, making them indispensable for more complex tasks (such as threat detection and decision support).

[0144] This embodiment also provides a converged media network security threat perception and control system based on machine learning, including: a data acquisition module that collects multi-source heterogeneous data from the converged media network and constructs a heterogeneous relationship graph.

[0145] The label generation module uses a semi-supervised clustering algorithm to cluster node behavior data and assign a label to each cluster.

[0146] The threat monitoring module uses a trained threat detection model to perform real-time threat scoring on nodes in the converged media network and trigger protection actions based on preset strategies.

[0147] This embodiment also provides a computer device, which is suitable for the case of a converged media network security threat perception and control method based on machine learning, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute computer-executable instructions to implement the converged media network security threat perception and control method based on machine learning proposed in the above embodiment.

[0148] The computer device may be a terminal, comprising a processor, memory, a communication interface, a display, and an input device connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores an operating system and computer programs. The internal memory provides an environment for the operating system and computer programs stored in the non-volatile storage media. The communication interface of the computer device is used to communicate with external terminals via wired or wireless communication. Wireless communication may be achieved via Wi-Fi, a carrier network, NFC (near-field communication), or other technologies. The display of the computer device may be a liquid crystal display or an electronic ink display. The input device may be a touchscreen overlay on the display, buttons, a trackball, or a touchpad on the computer device housing, or an external keyboard, touchpad, or mouse.

[0149] This embodiment also provides a storage medium having a computer program stored thereon, which, when executed by a processor, implements the method for realizing converged media network security threat perception and control based on machine learning as proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (Static Random Access Memory, abbreviated as SRAM), electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, abbreviated as EEPROM), erasable programmable read-only memory (Erasable Programmable Read-Only Memory, abbreviated as EPROM), programmable read-only memory (Programmable Red-Only Memory, abbreviated as PROM), read-only memory (Read-Only Memory, abbreviated as ROM), magnetic memory, flash memory, disk or optical disk.

[0150] In summary, the present invention collects multi-source heterogeneous data from a converged media network and fuses them to construct a heterogeneous relationship graph between data nodes; divides the nodes based on a clustering algorithm, uses a graph embedding method on the heterogeneous relationship graph to generate a low-dimensional vector for each node, and assigns a pseudo-label and a corresponding confidence level to each node; inputs historical annotated samples and pseudo-label samples into a graph attention network weighted by confidence level for semi-supervised joint training to obtain a threat detection model; re-executes clustering and pseudo-label updates based on the latest node representation, and iteratively updates the model; deploys the trained threat detection model, outputs a threat score for each node in the converged media network subgraph in real time, and automatically triggers protection actions according to preset strategies.

[0151] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A method for media convergence network security threat perception and control based on machine learning, characterized by: include, Collect multi-source heterogeneous data from the converged media network, fuse them, and build a heterogeneous relationship graph between data nodes; The nodes are divided based on a clustering algorithm, a graph embedding method is used on the heterogeneous relationship graph to generate a low-dimensional vector for each node, and a pseudo label and corresponding confidence level are assigned to each node; The historically labeled samples and pseudo-labeled samples are weighted by confidence and input into the graph attention network for semi-supervised joint training to obtain a threat detection model. Re-clustering and pseudo-label updating are performed based on the latest node representation, and the model is updated iteratively. Deploy the trained threat detection model, output threat scores for each node in the converged media network subgraph in real time, and automatically trigger protection actions according to preset strategies.

2. The method for media convergence network security threat perception and control based on machine learning according to claim 1, characterized in that: The construction of a heterogeneous relationship graph between data nodes includes modeling the structure of a converged media network graph, defining node types, establishing edge relationships between different types of nodes based on business connections and security semantics; and extracting multi-dimensional features from each type of collected nodes and edges. The node types include user nodes, IP nodes, device nodes, and resource nodes; When new data arrives, if the node does not exist yet, it is automatically added and its features are initialized; Edge attributes and weights are assigned based on the type of interaction between nodes; multiple interactions between the same pair of nodes are stored as edge objects with timestamps.

3. The method for media convergence network security threat perception and control based on machine learning according to claim 2, characterized in that: The node division based on the clustering algorithm includes clustering the node behavior data using historically labeled samples as seed points; Divide the node behavior data into K clusters through the algorithm; For seed points with known partial threat data, a semi-supervised clustering algorithm is used to guide the clustering process using the labeled data; Calculate the clustering distance for each node behavior data, and divide the node behavior data into clusters according to the criterion of minimum distance within the cluster; For unsupervised scenarios, the silhouette coefficient is used to evaluate the clustering effect and select the K value; Assign a label to each cluster. If a cluster contains a known threat sample, the cluster is labeled as a threat; if the sample in the cluster is a normal sample, it is labeled as normal. For behavioral data without explicit labels, a soft labeling method is used to assign a threat probability label based on its distance within the cluster to obtain a pseudo-labeled sample.

4. The method for media convergence network security threat perception and control based on machine learning according to claim 3, characterized in that: The graph embedding method includes embedding the graph using a random walk algorithm to generate a low-dimensional vector representation of the node; For each node Initialize a random vector in the graph ; Randomly select a starting node in the graph and perform multiple walks; each walk starts from the node Start by randomly jumping to adjacent nodes along the edge of the graph ; Walk to get the node sequence , indicating the slave node The starting walking path; According to the node pairs in the walking path To model, the objective function is to maximize the given node When , the probability of the remaining nodes in the path is predicted; the negative sampling method is used to approximate the objective function, and the training is performed to obtain the probability of each node Low-dimensional vector representation of , containing the structure and attribute information of the node.

5. The method for media convergence network security threat perception and control based on machine learning according to claim 4, characterized in that: The semi-supervised joint training includes calculating the confidence of the pseudo-label samples of each node and adjusting the confidence by the graph embedding similarity of the node; Use graph attention network for modeling, and input historical labeled samples and pseudo-label samples weighted by confidence; For each node, the attention coefficient between the node and the adjacent nodes is calculated. Based on the calculated attention coefficient, the information of the neighboring nodes is aggregated to update the representation of each node. Use the cross entropy loss function to evaluate the performance of the model; After training the graph attention network, the node representation is updated; the node representation is a vector that includes the node's position in the graph and the node's behavior characteristics; Use the updated node representation to perform secondary clustering operations to re-divide the nodes into different clusters; After obtaining the new node representation and the updated secondary clustering results, the pseudo label of each node is recalculated. The specific process includes: Based on the similarity update between the node and the cluster center, if the node representation of the node is close to the cluster center, the pseudo label of the node is adjusted to be consistent with the cluster label; Based on neighbor consistency update, if the pseudo labels of a node's neighbor nodes are the same, the pseudo label of the node is updated to be consistent with that of the neighbor nodes; In each round of training, clustering is re-executed based on the current node representation to obtain new node clusters and cluster centers; the pseudo-label of each node is updated based on the new node representation and clustering results, and the model is continued to be trained using the updated pseudo-label and node representation; the node representation, clustering results and pseudo-label are iteratively updated to optimize the graph attention model until the model's loss function converges.

6. The method for media convergence network security threat perception and control based on machine learning according to claim 5, characterized in that: The output threat score includes calculating the similarity between the output result of the graph attention model of each node and the known types of threats; scoring the threat level based on the result of the similarity calculation and dividing it into serious, high risk, medium risk, and low risk levels.

7. The method for media convergence network security threat perception and control based on machine learning according to claim 6, characterized in that: The automatic triggering of protective actions according to the preset strategy includes using a reinforcement learning algorithm to optimize the preset strategy through a Q-value function; Represents the global state of the current graph structure, including the feature vectors of nodes and edges in the current graph; aggregates node features through the graph attention network, and finally obtains a high-dimensional feature representation of each node , we can get a global representation of the entire graph; , Indicates the number of nodes, Representation node At the moment The eigenvector of Each action It is the defensive operation that can be performed in the current state. The executable actions include blocking edges, isolating nodes, limiting speed, and adjusting firewall policies. The Q value function represents the state Next action The maximum cumulative reward that can be obtained after the attack; the reward is obtained by evaluating the reward function, and the reward function is set according to preventing the spread of threats, reducing false blocking and minimizing delays; When an abnormal node is detected, the optimal defense operation is automatically executed through the reinforcement learning algorithm; and Calculate the similarity of abnormal node pairs and preliminarily estimate the propagation path of the threat; For each abnormal node, gradually build a propagation chain along the node with the greatest similarity in the graph; set the propagation threshold , only when the similarity is greater than the threshold When the decision node is part of the transmission path; Through reverse tracing, the origin of the threat is tracked, the score of the tracing propagation path is evaluated, and based on the score of the propagation path, the nodes are sorted according to the relevance of the threat source to obtain the source node of the threat; after the risk tracing is completed, the tracing results are visualized and the impact range of the threat propagation chain is evaluated.

8. A machine learning-based converged media network security threat perception and control system, based on the machine learning-based converged media network security threat perception and control method according to any one of claims 1 to 7, characterized in that: It includes a data acquisition module that collects multi-source heterogeneous data from the converged media network and constructs a heterogeneous relationship graph; The label generation module uses a semi-supervised clustering algorithm to cluster node behavior data and assign a label to each cluster; The threat monitoring module uses a trained threat detection model to perform real-time threat scoring on nodes in the converged media network and trigger protection actions based on preset strategies.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the machine learning-based media convergence network security threat perception and control method described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the machine learning-based media convergence network security threat perception and control method described in any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Threat intelligence knowledge graph processing method and device, equipment and storage medium

    CN116150392A

  • Network node threat index detection method and device

    CN117614637A

  • Advanced persistent threat detection and response method based on improved self-supervised learning

    CN119316220A

  • Network threat multi-modal detection method based on large model

    CN120185905A

  • Network security big data state evaluation method based on pattern recognition

    CN120301637A