Dynamic updating and adaptive optimization method for multi-source security intelligence fusion

By building a dynamic dual-closed-loop optimization architecture, the problems of insufficient timeliness and model rigidity in network security threat analysis are solved, real-time and accurate analysis of multi-source security intelligence is achieved, adaptation to new attack patterns is achieved, and the false alarm rate is reduced.

CN120768604APending Publication Date: 2025-10-10GUANGXI POWER GRID CORP
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510950647.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-10
Publication Date
2025-10-10

AI Technical Summary

Technical Problem

Existing network security threat analysis methods have problems such as insufficient timeliness, weak data heterogeneity processing capabilities and model rigidity. They cannot meet the real-time detection needs of APT attacks, have a high false alarm rate, and cannot effectively respond to new attack modes.

Method used

A dynamic dual-closed-loop optimization architecture is constructed, combining time-sensitive feature extraction with a parameter adaptation mechanism driven by reinforcement learning. Through dynamic preprocessing of multi-source data, adaptive fusion weight calculation, incremental fusion engine and credibility feedback closed loop, unified representation of heterogeneous data and adaptive parameter optimization are achieved.

Benefits of technology

It improves the real-time, accuracy and adaptability of security intelligence analysis to new attack patterns, reduces the false alarm rate, and improves the timeliness and adaptability of multi-source security intelligence fusion.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120768604A_ABST
    Figure CN120768604A_ABST
Patent Text Reader

Abstract

The invention discloses a dynamic updating and adaptive optimization method for multi-source security intelligence fusion, and belongs to the field of network security. According to the method, a dynamic double-closed-loop optimization architecture is constructed, and five modules including a multi-source data dynamic preprocessing module, a self-adaptive fusion weight calculation module, an incremental fusion engine module, a reinforcement learning optimization module and a credibility feedback closed loop module are included. The method comprises the following steps: processing heterogeneous data through a space-time semantic joint embedding model, driving parameter self-adaptive adjustment by utilizing reinforcement learning, realizing incremental online fusion in combination with a sliding time window, and updating model feedback credibility through Bayesian evidence. Experiments prove that the detection accuracy of the method reaches 93.6%, the false alarm rate is 1.2%, the average response time is 28.4 ms, the timeliness, adaptability and accuracy of multi-source safety information fusion are remarkably improved, and the problems of a traditional method in the aspects of real-time performance, heterogeneous data processing, model stiffness and the like are effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of network security, and specifically relates to a multi-source security intelligence fusion dynamic updating and adaptive optimization method, which is used for solving the problems of multi-source heterogeneous data fusion, dynamic threat response and system adaptability in network security threat analysis. BACKGROUND

[0002] With the increasing complexity of network security threats, security intelligence analysis faces three major challenges of multi-source heterogeneous data fusion, dynamic threat response and system adaptability. The existing methods mainly adopt static weight distribution and offline batch processing mode, which have the following defects:

[0003] Lack of timeliness: the traditional fusion cycle exceeds 30 minutes, which cannot meet the real-time detection needs of APT attacks.

[0004] Weak processing ability of data heterogeneity: the semantic gap between structured logs and unstructured threat reports leads to a fusion error rate as high as 18%-25%.

[0005] Model rigidity problem: the false alarm rate of fixed parameter model increases by 3-5 times under new attack mode.

[0006] Terminology and abbreviation full name

[0007] ·APT attack: Advanced Persistent Threat

[0008] ·LSTM: Long Short-Term Memory

[0009] ·CNN: Convolutional Neural Network

[0010] ·DQN: Deep Q-Network

[0011] ·MLP: Multi-Layer Perceptron

[0012] ·KDE: Kernel Density Estimation

[0013] ·EWMA: Exponential Weighted Moving Average

[0014] ·CVE: Common Vulnerabilities and Exposures SUMMARY

[0015] The application provides a multi-source security information fusion dynamic updating and adaptive optimization method, constructs a dynamic double closed-loop optimization architecture, combines time-sensitive feature extraction and reinforcement learning driven parameter adaptive mechanism, and specifically includes five modules of multi-source data dynamic preprocessing, adaptive fusion weight calculation, incremental fusion engine, reinforcement learning optimization module and credibility feedback closed loop. Through the spatio-temporal semantic joint embedding model, the heterogeneous data is uniformly represented, the LSTM-attention mechanism is used to dynamically generate the fusion weight, the incremental fusion is performed based on the sliding time window, the parameter adaptive optimization is realized by means of DQN, and the credibility feedback is completed by the Bayesian evidence update model, thereby improving the timeliness, accuracy and adaptability of multi-source security information fusion.

[0016] Technical scheme

[0017] In order to solve the problems of poor timeliness, weak data heterogeneity processing capability and rigid model in the prior art, a method capable of realizing multi-source security information dynamic updating and adaptive optimization is provided, the real-time performance, accuracy and adaptability to new attack modes of security information analysis are improved, and the complex network security threat is effectively coped with. The specific implementation process is as follows:

[0018] 1. Multi-source data dynamic preprocessing module

[0019] 1.1 Heterogeneous data unified representation model

[0020]

[0021] Formula analysis:

[0022] · Spatio-temporal coding function

[0023] A hierarchical spatio-temporal feature extraction architecture is adopted, which includes:

[0024] (1) Time feature coding:

[0025] A multi-scale time perception unit is designed to convert the absolute timestamp into a relative time interval Δt=t-t0, and a frequency decomposition is realized through a sine function group:

[0026]

[0027] Wherein, the base frequency f0=1 / 3600 (hour-level perception), k=8, and a 16-dimensional time feature vector is generated.

[0028] (2) Spatial feature coding:

[0029] The IP address is encoded by double hashing:

[0030] First layer: 64-bit binary encoding based on GeoHash (precision level 5);

[0031] Second layer: probabilistic feature compression based on Bloom Filter (false positive rate P = 0.001);

[0032] Finally, the spatial features are extracted through a pre-trained convolutional neural network (CNN) and a 128-dimensional vector is output.

[0033] Semantic embedding operator ψ(·):

[0034] Build a hierarchical semantic understanding model, including:

[0035] (1) Vocabulary-level embedding:

[0036] Use character-level CNN to process unstructured text (threat reports) with a window size of 5 and an output dimension of 256.

[0037] (2) Sentence-level fusion:

[0038] Generate context-aware semantic vectors through bidirectional LSTM+Self-Attention:

[0039]

[0040] Where W is a 300×300 weight matrix, and the final output dimension is 300.

[0041] (3) Domain knowledge enhancement:

[0042] Knowledge graph embedding (TransE model) is introduced to map entities (such as CVE-2023-1234) into a 100-dimensional vector space, which is then concatenated with text embedding and input into the attention mechanism.

[0043] Time decay factor τ(·):

[0044] The exponential decay model is used to describe the time decay factor, and its expression is:

[0045] τ(t-t0)=exp(-λ(t-t0))

[0046] Where t represents the current time, t0 represents the start time, and λ is the decay coefficient, which determines the rate at which data decays over time. In order to more intuitively understand the characteristics of decay, the half-life T is introduced. half-life The concept of half-life is the time required for data to decay to half of its initial value. When t-t0=T half-life hour, Substituting it into the exponential decay formula, we get:

[0047]

[0048] This shows that the decay coefficient λ is related to the half-life T half-life Inversely proportional. We can dynamically adjust the half-life T according to different data types. half-life , and then determine the appropriate attenuation coefficient λ:

[0049] For high-time data (such as real-time traffic logs), the timeliness requirement is high and the value of the data decreases rapidly over time. Therefore, a shorter half-life is set, such as T half-life = 15 minutes. The corresponding attenuation coefficient at this time (Time unit is seconds).

[0050] For low-timeliness data (such as threat knowledge base), the timeliness requirement is relatively low and the value of the data decays slowly over time, so a longer half-life is set, such as T half-life =72 hours. The corresponding attenuation coefficient at this time (Time unit is seconds).

[0051] By dynamically adjusting the half-life T according to the data type (half-life adaptive algorithm based on online Bayesian optimization) half-life We can flexibly control the decay of different data types over time, allowing the time decay factor to better reflect the timeliness of the data. This allows for a more reasonable weighting of data at different time points within a unified representation model for heterogeneous data. In practical applications, the most appropriate half-life values ​​for different data types can be determined through experimentation and optimization based on a large amount of historical data to achieve optimal processing results.

[0052] Half-life adaptive algorithm based on online Bayesian optimization:

[0053] For different data types (such as real-time logs and threat reports), an online learning framework is designed to achieve dynamic optimization of half-life:

[0054]

[0055]

[0056] Description of association logic:

[0057] Data type classification: divided into three categories based on data timeliness (real-time logs, short-term reports, and long-term knowledge base);

[0058] Performance feedback: Dynamically adjust the half-life based on the detection accuracy and false alarm rate of the fusion engine;

[0059] Optimization goal: Minimize the error rate of heterogeneous data fusion (the operating error).

[0060] • Tensor operations:

[0061] ⊕ (Tensor concatenation): Concatenate along channel dimension (spatio-temporal features 16 + 128 = 144 dimensions + semantic features 300 + 100 = 400 dimensions -> total 544 dimensions);

[0062] (Element-wise multiplication): Time decay factor applied to the first 200 dimensions of semantic embeddings (high-frequency update features), preserving the last 200 dimensions (stable semantic features).

[0063] 1.2 Implementation details

[0064] (1) Data alignment and cleaning:

[0065] • Time alignment:

[0066] Linear interpolation is used to handle missing timestamps, with a maximum allowed interval Δt max = 5 seconds;

[0067] Time synchronization error is controlled within ±100 ms (based on NTP protocol).

[0068] • Structured data cleaning:

[0069] Define 200+ regular expression rules to match common log formats (e.g., Apache, Windows Event Log);

[0070] Anomaly detection: Identify outliers based on Isolation Forest (threshold T = 3σ).

[0071] • Unstructured data processing:

[0072] Use spaCy NER model (en_core_web_trf) to extract entities, supporting 13 threat-related entity types;

[0073] Text denoising: Stopword filtering + lemmatization, preserving verb prototypes and singular noun forms.

[0074] (2) Feature normalization:

[0075] • Numerical features:

[0076] Use Box-Cox transformation to handle skewed distributions, with λ parameter determined by maximum likelihood estimation;

[0077] Normalize to range [-1, 1], preserving original distribution shape.

[0078] • Discrete features:

[0079] Use target encoding for high-cardinality features (such as URLs) and combine it with leave-one-out (LOO) to prevent overfitting;

[0080] Low-cardinality features (such as HTTP method) are one-hot encoded.

[0081] (3) Parallel processing optimization:

[0082] Hardware acceleration:

[0083] Spatiotemporal coding uses CUDA parallel computing, and a single NVIDIA A100 GPU can process data with a latency of <2ms per 10,000 records.

[0084] Semantic embedding is optimized with TensorRT, increasing inference speed by 40%.

[0085] Distributed architecture:

[0086] Build data stream pipelines based on Kafka message queues, supporting horizontal expansion to 100+ nodes;

[0087] Data sharding strategy: Double hash sharding by time window (5 seconds) and data type (structured / unstructured).

[0088] (4) Outlier processing:

[0089] Time anomaly: For Δt>T max The data is marked as "stale", triggering the historical data recalibration process.

[0090] Semantic anomaly: The degree of outlier in text embedding is calculated based on cosine similarity. Data with similarity < 0.2 will be put into the manual review queue.

[0091] 2 Adaptive fusion weight calculation

[0092] 2.1 Dynamic Weight Generation Based on LSTM-Attention Mechanism

[0093] In multi-source data processing scenarios, different data sources have different importance for the final decision at different times. To achieve effective fusion of multi-source data, we use a dynamic weight generation method based on the LSTM-attention mechanism. Its core formula is:

[0094]

[0095] Where w i (t) represents the fusion weight of the i-th data source at time t, n is the total number of data sources. σ(·) is the bilinear attention function, h t-1is the state hidden variable of the system at time t-1, v i (t) is the feature vector of the i-th data source at time t, which is generated by the unified representation model of heterogeneous data mentioned above.

[0096] (1) Bilinear attention function σ(·)

[0097] Bilinear attention function σ(h t-1 ,v i (t)) is used to measure the system state hidden variable h t-1 and the i-th data source feature vector v i (t). Its specific form is:

[0098]

[0099] Where W is a learnable weight matrix with dimension d h ×d v , d h is the system state hidden variable h t-1 The dimension, d v is the eigenvector v i By learning the W matrix, the model can adaptively capture the relationship between different data sources and system states.

[0100] (2) System state hidden variable h

[0101] The system state latent variable h is generated by a long short-term memory (LSTM) network. LSTM can effectively handle long-term dependencies in sequential data and is suitable for modeling the state of the system at different times. The core formula of LSTM is as follows:

[0102] 1) Input Gate

[0103] i t =σ(W ii x t +W hi h t-1 +b i )

[0104] 2) Forget Gate

[0105] f t =σ(W if x t +W hf h t-1 +b f )

[0106] 3) Cell status update

[0107]

[0108] 4) Output Gate

[0109] o t = σ(W io x t + W ho h t-1 + b o )

[0110] h t = o t ⊙ tanh(C t )

[0111] where x t is the input vector at time t, W is the weight matrix, b is the bias vector, σ is the sigmoid function, tanh is the hyperbolic tangent function, and ⊙ denotes element-wise multiplication.

[0112] 2.2 Implementation details

[0113] (1) Data input

[0114] The feature vector v i (t) obtained by processing the multi-source data through the heterogeneous data unified representation model is taken as the input, and the historical state information of the system is input into the LSTM to generate h t-1 .

[0115] (2) Weight calculation

[0116] According to the bilinear attention function, σ(h t-1 , v i (t)) is calculated, and then the fusion weight w i (t) of each data source is obtained through the softmax function.

[0117] (3) Model training

[0118] The backpropagation algorithm and stochastic gradient descent (SGD) or its variants (such as Adam, Adagrad, etc.) are used to update the weight matrix W and bias vector b in the LSTM, as well as the weight matrix W in the bilinear attention function. The training objective can be to minimize the loss function between the predicted result and the true label, such as cross-entropy loss.

[0119] 3 Incremental fusion engine

[0120] 3.1 Online fusion model under sliding time window constraint

[0121]

[0122] Formula analysis:

[0123] Time window constraint: adopt a sliding window with length T (default T=60s), only keep the fusion results of the last T time steps: F(t-T+1),...,F(t). When t<T, F(t) directly takes the current weighted sum.

[0124] Dynamic adjustment of forgetting factor:

[0125] a(t) = KL-Adjustement(D KL (P t || P t-1 ))

[0126] where D KL is the KL divergence, measuring the difference between the current distribution P t and the historical distribution P t-1 :

[0127]

[0128] When the KL divergence increases, a(t) decreases, enhancing the weight of current data; otherwise, a(t) increases, preserving historical information.

[0129] MLP feature transformation:

[0130] Design a 3-layer fully connected network with input dimension d v =544 and output dimension d f =256, and the activation function is Swish:

[0131] MLP(v i (t)) = Swish(W3·Swish(W2·wish(W1·v i (t)+b1)+b2)+b3)

[0132] Weight matrix

[0133] 3.2 Implementation details

[0134] (1) Time window management:

[0135] Use a ring buffer to store the last T F(t) values, with time complexity O(1);

[0136] When the window slides, automatically remove old data that exceeds the time range (based on timestamp comparison).

[0137] (2) Forgetting factor calculation:

[0138] Distribution estimation: For the current fusion result F(t) and the historical result F(t-1), generate the probability density function Pt and P t-1 .

[0139] Dynamic adjustment rule: α(t) = α min +(α max -α min )·exp(-γ·D KL ), where α min =0.2,α max =0.9,γ=10 (determined by cross-validation)

[0140] (3) Incremental computing optimization:

[0141] cache Intermediate results to avoid repeated calculations;

[0142] Using TensorFlow Lite for MLP inference optimization, the single data processing delay is less than 0.5ms.

[0143] (4) Abnormal fusion detection:

[0144] When the KL divergence exceeds the threshold ∈=2.0, the abnormal fuse mechanism is triggered and historical information is temporarily disabled (α=0);

[0145] The exponentially weighted moving average (EWMA) is introduced to monitor the fluctuation of α(t), and the model is restarted when the standard deviation is greater than 0.3.

[0146] 4 Reinforcement Learning Optimization Module

[0147] 4.1 Parameter Adaptation Mechanism Based on DQN

[0148] Q(s,a)←Q(s,a)+η[r+γmax a' Q(s′,a′)-Q(s,a)]

[0149] Formula analysis:

[0150] (1) Q-learning update rule:

[0151] Use the Deep Q-Network (DQN) to approximate the action-value function Q(s,a), where: is the state vector; a∈{a1,a2,…,a k} is the discrete action set (k=10); η∈[0.01,0.1] is the learning rate (dynamic decay); γ=0.95 is the discount factor.

[0152] (2) State space s:

[0153] Contains 7-dimensional features:

[0154] 1) Threat level (0-100): Based on CVE vulnerability scoring;

[0155] 2) Data freshness (0-1): time decay factor τ(t-t0);

[0156] 3) System load (0-1): CPU utilization (sliding window average);

[0157] 4) False positive rate (0-1): FPR in the last 100 decisions;

[0158] 5) False negative rate (0-1): TPR in the last 100 attacks;

[0159] 6) Timestamp feature: sinusoidal encoding of the current hour (2D);

[0160] 7) Data type: One-hot encoding (3 types: log / traffic / report).

[0161] (3) Reward function r:

[0162] r=λ1·TPR-λ2·FPR

[0163] TPR: True Positive Rate (number of detected attacks / number of actual attacks);

[0164] FPR: false positive rate (number of false positives / number of normal events);

[0165] Weight configuration: λ1 = 1.5, λ2 = 1.0 (determined by Pareto optimization).

[0166] 4.2 Implementation Details

[0167] (1) Q network architecture:

[0168] Input layer: 7-dimensional state vector;

[0169] Hidden layer 1: 256 neurons, activation function ReLU;

[0170] Hidden layer 2: 128 neurons, activation function ReLU;

[0171] Output layer: k = 10 action values, linear activation;

[0172] Loss function: Huber loss;

[0173] Optimizer: AdamW (weight decay 0.001).

[0174] (2) Experience replay mechanism:

[0175] Experience pool capacity: 100,000 samples;

[0176] Sampling strategy: Prioritized Replay, samples with large TD errors are selected first;

[0177] Batch size: 64.

[0178] (3) Target network update:

[0179] The parameters of the main network and the target network are synchronized every 1000 steps;

[0180] Soft update: θ'←τθ+(1-τ)θ', where τ=0.001.

[0181] (4) Action space discretization:

[0182] The continuous parameters α (forgetting factor) and λ (decay coefficient) are discretized into 10 intervals:

[0183] α∈[0.2,0.9]→step size 0.078; λ∈[1×10 -6 ,1×10 -3 ]→Logarithmic space discretization.

[0184] 5 Credibility Feedback Loop

[0185] 5.1 Bayesian Evidence Update Model

[0186] In the scenarios of multi-source data fusion and threat analysis, we need to continuously update the credibility of hypotheses based on new evidence. To this end, a Bayesian evidence updating model is established, whose core formula is:

[0187]

[0188] Where P(H|E) is the posterior probability that hypothesis H is true after observing evidence E; P(E|H) is the likelihood probability of observing evidence E when hypothesis H is true; P(H) is the prior probability of hypothesis H; ∑P(E|H i )P(H i ) is the sum of all possible hypotheses H i The probability of the evidence E is summed up to normalize it; β(t) is the time confidence coefficient, which is used to consider that the credibility of the evidence may change over time.

[0189] (1) Time confidence coefficient β(t)

[0190] The time confidence coefficient β(t) decays exponentially, and its expression is: β(t) = e -kt , where k is the decay coefficient, which determines the rate at which the credibility of evidence decays over time. t represents the time interval from the generation of evidence to the current moment.

[0191] (2) Determination of attenuation coefficient k:

[0192] The value of the attenuation coefficient k needs to be adjusted according to different types of evidence and application scenarios. For example, for network attack detection scenarios with high real-time requirements, the value of k can be set to a larger value to reduce the weight of old evidence more quickly; while for some long-term stable threat intelligence, the value of k can be set to a smaller value. The appropriate value of k can be determined through a large amount of historical data and experiments. Assuming that we find through analysis of historical data that the credibility of a certain type of evidence is reduced to 50% of its original value after 24 hours, we can use the formula β(24) = e -24k =0.5 to calculate the value of k:

[0193] e -24k =0.5

[0194] -24k=ln(0.5)

[0195]

[0196] 5.2 Model implementation details

[0197] (1) Definition of hypothesis and evidence

[0198] Hypothesis H: In the field of network security, a hypothesis can be a statement about whether a certain type of attack exists, such as "there is a DDoS attack", "there is a SQL injection attack", etc. The set of hypotheses {H i} covers all possible attack types as well as normal situations.

[0199] Evidence E: Evidence can come from multiple data sources, such as network traffic data, system logs, security audit information, etc. For example, abnormal network traffic peaks and frequent login failure records can be used as evidence.

[0200] (2) Determination of prior probability P(H)

[0201] The prior probability P(H) can be determined based on historical data statistics, expert experience, or industry reports. For example, based on the network security incident records of the past year, it is found that the frequency of DDoS attacks is 10%. Then the prior probability P(H) of the hypothesis "there is a DDoS attack" can be set to DDoS ) is set to 0.1.

[0202] (3) Calculation of likelihood probability P(E|H)

[0203] The likelihood probability P(E|H) represents the probability of observing evidence E given hypothesis H. This requires analyzing historical data to calculate the frequency of each piece of evidence under each hypothesis. For example, during a DDoS attack, the probability of a network traffic peak exceeding a certain threshold can be determined by analyzing historical DDoS attack events.

[0204] (4) Evidence updating process

[0205] When new evidence E appears, the posterior probability P(H|E) of all hypotheses is updated according to the above formula. The specific steps are as follows:

[0206] 1) Calculate the likelihood probability P(E|H) of evidence E under each hypothesis i ).

[0207] 2) Calculate the sum of the probabilities of evidence E under all hypotheses ∑P(E|H i )P(H i ).

[0208] 3) Calculate the posterior probability P(H|E) of each hypothesis.

[0209] 4) Considering the time factor, multiply it by the time confidence coefficient β(t) to obtain the final posterior probability.

[0210] (5) System Implementation

[0211] A database can be used to store information such as the prior probability and likelihood of a hypothesis, as well as historical evidence. When new evidence becomes available, the system automatically retrieves the relevant information from the database, calculates it, and updates it. Furthermore, to improve computational efficiency, parallel computing techniques can be used to perform parallel calculations on the posterior probabilities of different hypotheses. BRIEF DESCRIPTION OF THE DRAWINGS

[0212] Figure 1 This is a system architecture diagram of an embodiment of the method described in the present invention. DETAILED DESCRIPTION

[0213] The present invention will be further described below in conjunction with specific embodiments:

[0214] 2.1 Implementation Method

[0215] 2.1.1 System Architecture

[0216] like Figure 1 As shown, the system consists of five core modules:

[0217] Multi-source data dynamic preprocessing module (A)

[0218] Adaptive fusion weight calculation module (B)

[0219] Incremental fusion engine (C)

[0220] Reinforcement learning optimization module (D)

[0221] Credibility feedback loop (E)

[0222] 2.1.2 Multi-source data dynamic preprocessing module (A)

[0223] Heterogeneous data unified representation model

[0224] Input structured logs (such as firewall logs) and unstructured threat reports, generate unified feature vectors through the following steps:

[0225] (1) Spatio-temporal encoding

[0226] Temporal encoding: sinusoidal position encoding on timestamp T i (t) to generate 16-dimensional temporal features;

[0227] Spatial encoding: double hash encoding (GeoHash + Bloom Filter) on IP address, extract 128-dimensional spatial features through CNN.

[0228] (2) Semantic embedding ψ(·)

[0229] Text processing: generate 300-dimensional semantic vectors using character-level CNN + bidirectional LSTM + Self-Attention;

[0230] Knowledge enhancement: generate 100-dimensional entity embeddings combined with TransE model.

[0231] (3) Time decay τ(t-t0)

[0232] Half-life T half-life = 15 minutes (log) / 72 hours (report);

[0233] Decay coefficient Calculate τ = exp(-λΔt).

[0234] (4) Feature fusion

[0235] Tensor concatenation: spatio-temporal features (144-dimensional) + semantic features (400-dimensional) = 544-dimensional vector;

[0236] Element multiplication: τ acts on the first 200 dimensions of the semantic features.

[0237] Code implementation fragment

[0238] class UnifiedEmbedding(nn.Module):

[0239] def__init__(self):

[0240] super().__init__();

[0241] self.time_encoder=TimeEncoder(dim=16);

[0242] self.space_encoder=SpaceEncoder(dim=128);

[0243] self.semantic_encoder=SemanticEncoder(dim=300);

[0244] self.knowledge_embed=nn.Embedding.from_pretrained(kg_embeddings);

[0245] def forward(self,log_entry,report_text,timestamp):

[0246] time_feat=self.time_encoder(timestamp);

[0247] space_feat=self.space_encoder(log_entry['src_ip']);

[0248] semantic_feat=self.semantic_encoder(report_text);

[0249] knowledge_feat=self.knowledge_embed(report_text.entities);

[0250] return torch.cat([time_feat,space_feat,semantic_feat,knowledge_feat],dim=-1);

[0251] 2.1.3 Adaptive Fusion Weight Calculation Module (B)

[0252] LSTM-Attention Mechanism

[0253] Input preprocessed feature vector v i (t), the dynamic weight w is generated by the following stepsi (t):

[0254] (1) LSTM state update

[0255] h t =LSTM(h t-1 ,v i (t))

[0256] (2) Bilinear Attention Calculation

[0257]

[0258] (3) Softmax weight normalization

[0259] w i (t)=softmax(σ(h t-1 ,v i (t)))

[0260] 2.1.4 Incremental Fusion Engine (C)

[0261] Sliding time window fusion

[0262] Using a 60-second sliding window, the calculation formula is:

[0263]

[0264] Dynamic adjustment of the forgetting factor: α(t) is calculated by KL divergence. When the distribution difference exceeds the threshold, α(t) is reduced from 0.9 to 0.2

[0265] MLP feature transformation: 3-layer fully connected network (544→1024→512→256), activation function Swish.

[0266] 2.1.5 Reinforcement Learning Optimization Module (D)

[0267] DQN parameter adaptation

[0268] The state space s contains 7-dimensional features (threat level, data freshness, etc.), and the action space is discretized into 10 parameter intervals:

[0269] class DQN(nn.Module):

[0270] def__init__(self):

[0271] super().__init__();

[0272] self.layers = nn.Sequential(

[0273] nn.Linear(7,256),

[0274] nn.ReLU(),

[0275] nn.Linear(256,128),

[0276] nn.ReLU(),

[0277] nn.Linear(128,10); )

[0279] def forward(self,state):

[0280] return self.layers(state);

[0281] Reward function: r = 1.5·TPR-1.0·FPR, trained by prioritized experience replay.

[0282] 2.1.6 Credibility Feedback Loop (E)

[0283] Bayesian Evidence Update

[0284]

[0285] Decay coefficient k: for real-time logs, k = 0.00077 / s (half-life 15 minutes), for threat reports, k = 0.0000026 / s (half-life 72 hours).

[0286] 2.2 Experimental Verification

[0287] (1) Test environment

[0288] Hardware: Intel Xeon 8375C ×2, NVIDIA A100 ×4;

[0289] Dataset: MITRE ATT&CK 2023Q3 (1.2M events, including 0-day attacks).

[0290] (2) Performance indicators

[0291]

[0292] (3) Cross-domain test results

[0293] Test scenario:

[0294] Industrial Control Systems (ICS): S7comm protocol logs (Numenta Anomaly Benchmark);

[0295] Cloud native environment: Kubernetes audit logs (AWS CloudTrai l);

[0296] Internet of Things (IoT): Mirai botnet traffic (ISC X-Force dataset).

[0297]

[0298] The embodiments of the present invention are not limited to the above description. The dynamic update strategy of the time decay factor λ, the half-life adaptive algorithm parameters based on online Bayesian optimization, the weight matrix W dimension of the LSTM-attention mechanism, the state space feature dimension of the reinforcement learning optimization module and the reward function weight configuration can be adjusted according to actual network security scenarios. Such improvements all fall within the scope of protection of the present invention.

Claims

1. A dynamic update and adaptive optimization method for multi-source security intelligence fusion, characterized in that: The following steps are involved: Dynamic preprocessing of multi-source data: Using a unified representation model for heterogeneous data, structured logs and unstructured threat reports are subjected to spatiotemporal encoding, semantic embedding, and time decay to generate a unified feature vector. Adaptive fusion weight calculation: Utilizes the LSTM-attention mechanism to dynamically generate the fusion weights of each data source based on the correlation between the system state latent variables and the data source feature vectors; Incremental fusion: An online fusion model with sliding time window constraints and dynamic adjustment of the forgetting factor is used to achieve incremental fusion of security intelligence. Reinforcement learning optimization: Based on the parameter adaptation mechanism of DQN, the system parameters are optimized through the design of state space, action space and reward function; Credibility feedback loop: Use Bayesian evidence to update the model and combine it with the temporal confidence coefficient to update the posterior probability of the hypothesis.

2. The method according to claim 1, characterized in that The expression of the unified representation model of heterogeneous data is: where φ(·) is the spatiotemporal encoding function, ψ(·) is the semantic embedding operator, and τ(·) is the temporal decay factor.

3. The method according to claim 2, characterized in that The spatiotemporal encoding function φ(·) includes a multi-scale time perception unit and a double hash space encoding, and the semantic embedding operator ψ(·) includes vocabulary-level embedding, sentence-level fusion and domain knowledge enhancement.

4. The method according to claim 1, wherein The dynamic weight generation formula of the LSTM-attention mechanism is: where σ(·) is the bilinear attention function, h t-1 is the system state hidden variable.

5. The method according to claim 1, wherein The expression of the incremental fusion model is: Where α(t) is the forgetting factor, which is dynamically adjusted through KL divergence.

6. The method according to claim 1, characterized in that The state space of the DQN includes threat level, data freshness, system load, false alarm rate, false negative rate, timestamp characteristics and data type, and the reward function is r = λ1·TPR-λ2·FPR.

7. The method according to claim 1, characterized in that The expression of the Bayesian evidence updating model is: Where β(t) is the time confidence coefficient, which decays exponentially.

8. A computer-readable storage medium storing a computer program, characterized in that: When the program is executed by the processor, the steps of the dynamic update and adaptive optimization method of multi-source security intelligence fusion described in any one of claims 1 to 7 are implemented.

9. A computer program product comprising computer executable instructions, characterized in that: The instruction is used to implement the function of the dynamic update and adaptive optimization method of multi-source security intelligence fusion described in any one of claims 1 to 7.

Citation Information

Cited By

  • Network security vulnerability automatic management method based on network security intelligence

    CN120979828A