A security identification method and system based on intelligent AI

By establishing a standard behavioral model library and dynamically adjusting the scanning interval, combined with monitoring signal feature values ​​and depth analysis, the problem of insufficient accuracy and adaptability of existing security identification technologies in complex threat environments has been solved, achieving efficient and flexible security identification.

CN120811728BActive Publication Date: 2026-01-06GUANGDONG QIMING INFORMATION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511125436.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-12
Publication Date
2026-01-06
Estimated Expiration
2045-08-12

AI Technical Summary

Technical Problem

Existing security identification technologies struggle to achieve accuracy, efficiency, and dynamic adaptability when facing increasingly complex and covert network threats. Traditional methods suffer from identification delays, resource waste, misjudgments, and missed detections.

Method used

By establishing a standard behavioral model library, dynamically adjusting the security scanning interval, using the average feature value of monitoring signals as a judgment benchmark, and combining parameter attributes and behavioral pattern features for in-depth analysis, suspicious abnormal behaviors are identified, and related attack patterns are discovered through classification algorithms, thereby dynamically updating risk assessment and scanning strategies.

Benefits of technology

It achieves precision and dynamism in the security identification process, reduces false positives, optimizes resource utilization, improves identification efficiency and adaptability, and enables timely response to complex threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120811728B_ABST
    Figure CN120811728B_ABST
Patent Text Reader

Abstract

This invention relates to the field of intelligent security identification technology, and discloses an intelligent AI-based security identification method and system. The method collects historical data on abnormal behavior to establish a standard behavior model library; after collecting real-time monitoring datasets, it determines the security scanning interval based on the data scale; within the scanning interval, it acquires all monitoring signals and calculates the average feature value as a security judgment benchmark; based on the benchmark and the standard model library, it evaluates the monitoring signals, identifies and labels suspicious abnormal behaviors. When suspicious behavior exists, its parameter attributes and behavioral pattern features are extracted to determine whether it is a real threat behavior, and then a basic risk value is determined based on the frequency of threat occurrence. Subsequently, the behavioral sequences, operation types, and interaction trajectories of real threats are analyzed, and the trajectories are used as feature vectors for classification analysis using a classification algorithm to determine whether there are associated attack patterns; if so, a correction factor is calculated to update the basic risk value, and the next security scanning interval is reconfigured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of intelligent security identification technology, specifically to an intelligent AI-based security identification method and system. Background Technology

[0002] With the rapid development of information technology, security threats in various network and physical environments are becoming increasingly complex and covert, placing higher demands on security identification technologies. Traditional security identification methods often rely on fixed rules or static thresholds for anomaly detection, making it difficult to adapt to dynamically changing threat scenarios. In practical applications, these methods often suffer from rigid scanning intervals, using a uniform scanning frequency regardless of the size of the real-time monitoring data. This leads to identification delays when the data volume surges, while wasting resources when the data volume is small.

[0003] Current technologies for identifying anomalous behavior largely rely on simple feature comparison, lacking in-depth analysis of behavioral patterns. Most methods label anomalies based solely on a single feature deviating from a standard value, failing to adequately consider the parametric attributes and pattern characteristics of the behavior. This easily leads to misjudging normal fluctuations as anomalies or missing genuine threat behaviors due to incomplete feature extraction. Furthermore, in the risk assessment phase, traditional methods typically determine risk values ​​based on the occurrence of a single threat, ignoring potential correlations between threat behaviors. Many attacks are not isolated but are implemented progressively through a series of related operations. Current technologies struggle to identify such correlated attack patterns, resulting in discrepancies between risk assessment results and the actual threat level, failing to provide an effective basis for adjusting security protection strategies.

[0004] In terms of dynamic adaptability, traditional security identification systems mostly have pre-set configuration parameters that cannot be dynamically updated based on real-time threat analysis results. When new threat patterns emerge, the system often requires manual intervention to adjust parameters, resulting in a delayed response and difficulty in dealing with rapidly evolving security threats. These problems collectively lead to shortcomings in the accuracy, efficiency, and dynamic adaptability of existing security identification technologies, making them unable to meet the security protection needs of complex environments. Summary of the Invention

[0005] The purpose of this invention is to provide a security identification method based on intelligent AI to solve the problems mentioned in the background art.

[0006] To achieve the above objectives, the present invention provides a security identification method based on intelligent AI, the method comprising:

[0007] Collect historical data on behaviors without abnormalities to establish a standard behavior model library;

[0008] Collect real-time monitoring datasets and determine the security scan interval based on the data size of the real-time monitoring datasets;

[0009] All monitoring signals are acquired within the safety scanning interval and the average characteristic value of the monitoring signals is calculated. The average characteristic value of the monitoring signals is used as the safety judgment benchmark.

[0010] Based on security judgment criteria and standard behavior model library, the monitoring signals are evaluated to identify and mark any suspicious abnormal behaviors. When suspicious abnormal behaviors are found, the parameter attributes and behavioral pattern characteristics of each suspicious abnormal behavior are extracted. Based on the parameter attributes and behavioral pattern characteristics, it is determined whether the suspicious abnormal behavior is a real threat behavior. When the suspicious abnormal behavior is determined to be a real threat behavior, the basic risk value is determined based on the frequency of the threat behavior.

[0011] Analyze real threat behaviors and identify behavior sequences, operation types and interaction trajectories. Use the interaction trajectory as a feature vector and use classification algorithms to classify and analyze all real threat behaviors. Based on the classification results, determine whether there are related attack patterns.

[0012] When a correlated attack pattern is identified, a correction factor is calculated based on the characteristics of the correlated attack pattern to update the basic risk value, and the next security scan interval is reconfigured.

[0013] Preferably, when determining the security scanning interval based on the data size of the real-time monitoring dataset, the method includes: comparing the data size with a low data size threshold and a high data size threshold, and setting the security scanning interval based on the comparison result; the low data size threshold is less than the high data size threshold.

[0014] When the data size is less than or equal to the low data size threshold, the security scan interval is set to the first interval duration.

[0015] When the data size is greater than the low data size threshold and less than or equal to the high data size threshold, the security scan interval is set to the second interval duration.

[0016] When the data size exceeds the high data size threshold, the security scan interval is set to the third interval duration.

[0017] The first interval duration is longer than the second interval duration, and the second interval duration is longer than the third interval duration;

[0018] The data size of the real-time monitoring dataset is directly passed to the safety judgment benchmark calculation process to adjust the generation of the average characteristic value of the monitoring signal.

[0019] Preferably, when evaluating the monitoring signals based on the security judgment criteria and the standard behavior model library, and identifying and labeling any suspicious abnormal behaviors, the process includes: matching the behavior sequences of all monitoring signals with the standard behavior model library, comparing the feature intensity of each monitoring signal with the average feature value of the monitoring signal, and identifying and labeling any suspicious abnormal behaviors based on the matching and comparison results.

[0020] When the characteristic intensity of the monitoring signal exceeds a multiple of the average characteristic value of the monitoring signal, the monitoring signal is identified as a suspicious abnormal behavior and marked.

[0021] When the behavioral sequence of a monitoring signal does not appear in the standard behavioral model library, the monitoring signal is identified as a suspicious abnormal behavior and labeled.

[0022] The output data from the standard behavior model library is used in the feature strength comparison process to ensure that the annotation results are consistent with historical data on behaviors without anomalies.

[0023] Preferably, when determining whether a suspicious abnormal behavior is a real threat behavior based on parameter attributes and behavioral pattern characteristics, the following steps are included: when the parameter attributes of a suspicious abnormal behavior are inconsistent with common parameter attributes in the standard behavior model library, the suspicious abnormal behavior is determined to be a real threat behavior.

[0024] Behavioral pattern features include the morphology of the behavioral pattern graph. When the behavioral pattern graph of a suspicious abnormal behavior shows discrete behavioral peaks, the suspicious abnormal behavior is determined to be a real threat behavior.

[0025] Parameter attribute data is extracted from suspicious abnormal behavior annotations and passed to the behavior pattern graph morphology analysis process to determine the real threat behavior.

[0026] Preferably, when determining the basic risk value based on the frequency of threat behavior, the basic risk value is calculated by comprehensively considering the frequency of threat behavior and the degree of deviation between the parameter attributes of each real threat behavior and the most approximate parameter attribute in the standard behavior model library.

[0027] The frequency of threat behavior and the deviation data of parameter attributes are obtained from the actual threat behavior judgment results and are used in the basic risk value calculation process.

[0028] Preferably, when classifying and analyzing all real threat behaviors using a classification algorithm and determining whether there is a related attack pattern based on the classification results, the interaction trajectory includes the number of interaction trajectory fluctuations and the rate of change of the interaction trajectory.

[0029] The initial classification boundary is determined by the feature density distribution map, and the minimum number of samples is set to a fixed value.

[0030] Each feature vector of a real threat behavior is treated as a data point. All data points are traversed, and the point with the minimum number of data points within the classification boundary is identified as the core point.

[0031] Starting from each core point, examine the points within its classification boundary;

[0032] If a point within the boundary is a core point, expand the category cluster; if a point within the boundary is an edge point, add it to the current category cluster.

[0033] If a point does not belong to the classification boundary of any core point and cannot form a category cluster, it is marked as an isolated point;

[0034] When a category cluster contains at least two real threat behaviors and the operation types of the real threat behaviors are at least two, the real threat behaviors in the category cluster are determined to be an associated attack pattern.

[0035] Interaction trajectory data is fed in from real threat behavior analysis and used in the feature vector construction process.

[0036] Preferably, when updating the basic risk value by calculating the correction factor based on the characteristics of the associated attack patterns, the following features are included: the characteristics of the associated attack patterns include the total number of associated attack patterns and the operation type of each associated attack pattern, and the operation type includes data tampering operation, privilege escalation operation, and spoofing operation.

[0037] The characteristics of the associated attack patterns are matched with historical correction schemes, and the correction factors are determined based on the matching results to update the basic risk value.

[0038] The historical correction scheme includes the characteristics of multiple historically associated attack patterns and multiple historical correction factors, with each historically associated attack pattern corresponding to a historical correction factor.

[0039] Calculate the similarity between the features of the associated attack patterns and the features of each historical associated attack pattern;

[0040] When there are records in the features of historical associated attack patterns that have a similarity to the features of associated attack patterns that exceed the similarity threshold, the historical correction factor is determined based on the features of the historical associated attack patterns corresponding to the highest similarity and is used as the correction factor to update the basic risk value.

[0041] When the similarity between the features of historical associated attack patterns and the features of associated attack patterns does not exceed the similarity threshold, the correction factor is determined based on the total number of associated attack patterns to update the basic risk value.

[0042] The basic risk value and the characteristic data of the associated attack pattern are exchanged and transmitted to correct the factor calculation process.

[0043] Preferably, when updating the basic risk value by determining the correction factor based on the total number of associated attack modes, the correction factor has a linear relationship with the total number of associated attack modes, and the value range of the correction factor is within a fixed interval.

[0044] The output data of the correction factor is directly used in the basic risk value update process to ensure that the update results reflect the impact of the total number of associated attack patterns.

[0045] Preferably, when reconfiguring the next security scan interval, the process includes: obtaining the updated risk value, determining the interval adjustment factor based on the updated risk value, and reconfiguring the next security scan interval. The interval adjustment factor has an inverse relationship with the updated risk value, and the value range of the interval adjustment factor is within a fixed range.

[0046] The updated risk value data is fed into the interval adjustment factor calculation process to generate the next safety scan interval configuration.

[0047] Preferably, the present invention also includes an intelligent AI-based security identification system for applying the above-mentioned intelligent AI-based security identification method, comprising: a data collection module configured to collect historical data on abnormal behavior to establish a standard behavior model library, collect a real-time monitoring dataset, and determine the security scanning interval based on the data size of the real-time monitoring dataset;

[0048] All monitoring signals are acquired within the safety scanning interval and the average characteristic value of the monitoring signals is calculated. The average characteristic value of the monitoring signals is used as the safety judgment benchmark.

[0049] The threat identification module is configured to evaluate monitoring signals based on security judgment benchmarks and a standard behavior model library, identify and label any suspicious or abnormal behaviors.

[0050] When suspicious abnormal behavior is found, the parameter attributes and behavioral pattern characteristics of each suspicious abnormal behavior are extracted. Based on the parameter attributes and behavioral pattern characteristics, it is determined whether the suspicious abnormal behavior is a real threat behavior. When the suspicious abnormal behavior is determined to be a real threat behavior, the basic risk value is determined based on the frequency of the threat behavior.

[0051] The attack analysis module is configured to analyze real threat behaviors and identify behavior sequences, operation types and interaction trajectories. The interaction trajectory is used as a feature vector, and a classification algorithm is used to classify and analyze all real threat behaviors. Based on the classification results, it is determined whether there are related attack patterns.

[0052] When a correlated attack pattern is identified, a correction factor is calculated based on the characteristics of the correlated attack pattern to update the basic risk value, and the next security scan interval is reconfigured.

[0053] The response execution module is configured to initiate protective measures based on the updated risk value and output details of the actual threat behavior;

[0054] The log storage module is configured to store threat behavior records; the output of the data collection module is passed to the threat identification module, the output of the threat identification module is passed to the attack analysis module, and the output of the attack analysis module is passed to the response execution module.

[0055] Compared with the prior art, the beneficial effects of the present invention are:

[0056] This AI-based security identification method achieves precision and dynamism in the security identification process through multi-stage optimization. When establishing the standard behavior model library, historical data on behaviors without anomalies is used as a foundation, providing a practical reference for subsequent anomaly detection. This ensures a stable and reliable comparison benchmark for anomaly identification, reducing misjudgments caused by ambiguous reference standards.

[0057] The scanning interval is dynamically adjusted based on the size of the real-time monitoring dataset, allowing for flexible adaptation to different data volume scenarios. When the data volume is large, reasonably extending the scanning interval can avoid excessive resource consumption caused by frequent scanning and ensure the stability of system operation; while when the data volume is small, shortening the scanning interval can improve the timeliness of identification and ensure that no potential threat signals are missed. This on-demand adjustment method achieves a balance between resource utilization and identification efficiency.

[0058] Using the average characteristic value of the monitoring signal as a security judgment benchmark, the interference caused by fluctuations in a single signal is weakened by calculating the average of the characteristics of all monitoring signals within the scanning interval, making the judgment benchmark more representative and stable. Based on this benchmark combined with a standard behavioral model library, suspicious abnormal behaviors can be identified and labeled more accurately, laying a solid foundation for subsequent threat assessment.

[0059] In the verification phase of suspicious abnormal behavior, in-depth analysis of parameter attributes and behavioral pattern characteristics can effectively distinguish between genuine threat behaviors and false alarms. Determining basic risk values ​​based on the frequency of threat behavior allows risk assessments to intuitively reflect the frequency of threat occurrences, providing a quantitative reference for security protection.

[0060] Analyzing the behavioral sequences, operational types, and interaction trajectories of real threat behaviors, and using classification algorithms for classification analysis, helps to discover the correlations between different threat behaviors. When correlated attack patterns are identified, updating the base risk value by calculating correction factors allows the risk assessment results to better reflect the actual threat landscape and fully consider the potential cumulative effects of correlated attacks. Simultaneously, reconfiguring the next security scan interval based on the analysis results enables the system to dynamically adjust its identification strategy according to threat changes, enhancing its responsiveness to emerging threats and complex attack patterns, and improving the adaptability and effectiveness of the overall security identification system. Attached Figure Description

[0061] Figure 1 This is a timing diagram of the intelligent AI-based security identification method described in this invention;

[0062] Figure 2 A flowchart for determining the safe scanning interval based on data size;

[0063] Figure 3 A flowchart for calculating the basic risk value;

[0064] Figure 4 A flowchart for calculating the correction factor for associated attack patterns. Detailed Implementation

[0065] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0066] Please see Figure 1 This invention provides a security identification method and system based on intelligent AI, the method comprising:

[0067] Historical data on abnormal behavior is acquired through a data acquisition module to build a standard behavior model library. After the real-time monitoring dataset is collected, the security scan interval is dynamically adjusted based on its data size. Within the set scan interval, the system calculates the average characteristic value of the monitoring signal as a security judgment benchmark. This benchmark, combined with the standard behavior model library, is used to assess whether the monitoring signal is abnormal. Suspicious abnormal behaviors are labeled and further analyzed for their parameter attributes and behavioral pattern characteristics to determine whether they constitute a real threat. If confirmed as a real threat, a basic risk value is calculated based on the frequency of occurrence. Subsequently, by analyzing behavioral sequences, operation types, and interaction trajectories, a classification algorithm is used to identify associated attack patterns. If associated attack patterns exist, a correction factor is calculated to update the risk value, and the next scan interval is reconfigured.

[0068] Example 1: See Figure 2 The dynamic adjustment mechanism for data scale is based on preset low and high data scale thresholds. During operation, the system continuously collects real-time monitoring datasets and calculates their data scale, specifically in terms of data volume, signal quantity, or number of behavior records. This data scale is compared with the preset low and high thresholds to determine the safe scanning interval for the current environment. When the data scale does not exceed the low threshold, the system uses a longer first interval, suitable for low-load scenarios, reducing computational resource consumption. If the data scale is between the low and high thresholds, a medium-length second interval is used to balance detection frequency and system overhead. When the data scale exceeds the high threshold, the system automatically switches to a shorter third interval to meet the safety monitoring needs under high-load environments.

[0069] After determining the security scanning interval, the system collects all monitoring signals within a set time window and calculates their average feature value. This feature value is generated based on indicators such as signal behavior intensity, frequency, or pattern similarity, and serves as a benchmark for subsequent security determination. The data size directly affects the calculation method of the average feature value. For example, with a large data size, the system may use a sliding window or sampling strategy to improve computational efficiency. The data size information of the real-time monitoring dataset is directly transmitted to the security determination benchmark calculation module, ensuring that the feature value generation process can adapt to different data load conditions.

[0070] The evaluation process for monitoring signals combines a standard behavioral model library with calculated safety judgment benchmarks. The standard behavioral model library is constructed from historical data of normal behavior without anomalies, covering typical sequences and feature distributions of normal behavior. The system matches the behavioral sequence of the current monitoring signal with records in the model library; if an abnormal sequence not found in the library is detected, it is marked as suspicious behavior. Simultaneously, the feature intensity of each monitoring signal is compared with the average feature value; if it exceeds a preset multiple threshold, it is also judged as abnormal. The output data from the standard behavioral model library is used in the feature intensity comparison module to ensure that the annotation results are consistent with historical data of normal behavior without anomalies, avoiding misjudgments or omissions.

[0071] The labeling process for suspicious abnormal behavior employs a dynamic threshold mechanism. The multiplier setting for feature intensity can be adjusted according to the actual application scenario. For example, a higher multiplier threshold may be used in network traffic monitoring to reduce false alarms, while a lower threshold may be used in sensitive operation auditing to improve detection sensitivity. Matching of behavioral sequences uses fuzzy matching or similarity calculation, allowing for a certain degree of deviation to accommodate reasonable variations in normal behavior. If a monitoring signal simultaneously meets the conditions of both sequence abnormality and feature intensity abnormality, it is marked as high-confidence suspicious behavior and given priority in subsequent analysis processes.

[0072] The standard behavior model library is updated using an incremental learning mechanism. The system periodically adds validated behavioral data to the model library to cover new legitimate operating patterns. The model library maintenance process includes deduplication, clustering, and noise filtering to ensure the representativeness and stability of the stored behavioral sequences. When evaluating monitoring signals, the model library queries employ index optimization techniques to accelerate the matching process with large-scale data. The calculation results of the feature intensity comparison module are cached to reduce the overhead of redundant calculations and support application scenarios with high real-time requirements.

[0073] The design that links data size with security scanning intervals allows the system to adapt to security monitoring needs under different load conditions. In low-data-size scenarios, longer scanning intervals reduce system overhead; in medium-scale scenarios, they balance detection frequency and resource consumption; and in high-scale scenarios, shorter intervals improve threat response speed. The data size information of the real-time monitoring dataset is not only used for interval adjustment but also influences the calculation strategy of security judgment benchmarks, such as using distributed computing or downsampling techniques to improve processing efficiency under high load.

[0074] The calculation of the average feature value of the monitoring signal supports multiple aggregation methods, including arithmetic mean, weighted average, or sliding window statistics. The specific method used depends on the data characteristics and application requirements. For example, network intrusion detection may focus more on the peak characteristics of burst traffic, while user behavior analysis may emphasize long-term trends in behavioral patterns. The dynamic adjustment mechanism of the feature value allows the system to automatically optimize the baseline value based on the real-time data distribution, avoiding detection bias caused by environmental changes.

[0075] The standard behavior model library is constructed using a hierarchical storage structure, distinguishing between high-frequency behavior patterns and low-frequency legitimate operations. High-frequency behaviors are stored using a compact data structure to optimize query efficiency; low-frequency behaviors are recorded in more detail to ensure that rare but legitimate operations are not misjudged. The model library's version management mechanism supports backtracking and recovery to address potential model degradation or contamination issues. When matching behavior sequences, the system employs a multi-level filtering strategy, first performing coarse-grained matching, and then calculating fine-grained similarity between candidate sequences to improve overall efficiency.

[0076] The labeling results of suspicious and abnormal behaviors are passed to subsequent analysis modules, including parameter attribute extraction and behavioral pattern analysis. Metadata generated during the labeling process, such as anomaly confidence and matching deviation, assists subsequent modules in making more accurate threat determinations. Matching results and feature strength comparison data from the standard behavioral model library are logged to the log system for subsequent auditing and model optimization. Intermediate calculation results throughout the evaluation process support visualization, facilitating operations personnel's understanding of the system's judgment logic and current security status.

[0077] A data-scale-aware security scanning interval adjustment mechanism and a monitoring signal evaluation process together constitute an adaptive security monitoring framework. This framework can dynamically optimize detection strategies based on actual data load, rationally allocating computing resources while ensuring security. Continuous updates and optimizations of the standard behavior model library ensure that the system can adapt to constantly changing normal behavior patterns, reducing false alarm rates. The design of the average feature value calculation and anomaly labeling logic for monitoring signals balances detection sensitivity and operational efficiency, making it suitable for large-scale real-time security monitoring scenarios.

[0078] The real-time monitoring of the dataset's size information is used not only to set the initial scan interval but also continuously during system operation to trigger dynamic adjustments to the interval. For example, if the data size increases from a low threshold range to a high threshold range during operation, the system will automatically shorten the scan interval without manual intervention. This dynamic adjustment capability allows the system to adapt to fluctuations in business volume, such as traffic surges during promotional activities or load drops during off-peak hours at night.

[0079] The calculation process for the average characteristic value of the monitoring signal supports robust outlier handling. When calculating characteristic values, the system detects and removes extreme values ​​that significantly deviate from the normal range, preventing them from excessively impacting the baseline value. This robust design allows the safety judgment baseline to more accurately reflect the characteristic levels of the vast majority of normal signals, reducing baseline drift caused by individual abnormal signals. The characteristic value calculation cycle is synchronized with the safety scan interval, ensuring that each scan is evaluated based on the latest data characteristics.

[0080] The matching algorithm in the standard behavioral model library supports parallel processing to handle the real-time evaluation requirements of high-concurrency monitoring signals. In large-scale deployment scenarios, the model library may adopt a distributed storage architecture, with different nodes responsible for matching different categories of behavioral patterns. Query requests are routed to the appropriate processing nodes to reduce the computational burden on individual nodes. The aggregation process of matching results employs a consistency protocol to ensure the accuracy of judgments in a distributed environment.

[0081] Example 2: See Figure 3 The process of identifying suspicious and abnormal behavior is based on in-depth analysis of parameter attributes and behavioral pattern characteristics. The system extracts key parameter attributes from labeled suspicious and abnormal behaviors, including structured data such as operation frequency, resource access patterns, and time distribution characteristics. These attributes are compared with common parameter ranges stored in a standard behavioral model library. When a significant deviation from the normal statistical distribution is observed, a preliminary determination of a real threat behavior is triggered. The comparison of parameter attributes employs a multi-dimensional joint analysis strategy to avoid misjudgments based on a single indicator. For example, a high frequency of a certain operation may belong solely to normal business peaks, but if it is accompanied by unconventional resource access patterns, it will be judged as abnormal.

[0082] Verification of behavioral patterns focuses on the graphical analysis of behavioral sequences. The system converts the operation records of monitored signals into time-series behavioral graphs and detects discrete behavioral peaks using morphological analysis methods. Normal behavioral patterns typically exhibit a continuous and smooth graph shape, while malicious operations often display sudden and discontinuous peak characteristics. The graph analysis algorithm can identify these abnormal patterns; even if the parameter attributes of a single operation do not exceed the threshold, the overall abnormal pattern of the graph can still trigger threat determination. Parameter attribute data is input in real time from the suspicious abnormal behavior annotation module, providing the necessary input dimensions for graph morphological analysis, enabling behavioral pattern verification to make comprehensive judgments based on specific operational characteristics.

[0083] The determination of genuine threat behavior employs a tiered verification mechanism. The system first performs an initial screening based on significant anomalies in parameter attributes, and then conducts a secondary verification using morphological features of the behavioral pattern graph. This dual verification structure effectively reduces the false positive rate while ensuring that complex, covert threats can be identified. Intermediate results generated during the determination process, including quantitative indicators such as parameter deviation and graph anomaly scores, are passed to the risk value calculation module as basic input. The cross-verification logic of parameter attributes and behavioral pattern features supports dynamic adjustment, allowing the determination stringency to be configured according to the security requirements of different application scenarios.

[0084] The calculation of the basic risk value integrates two core dimensions: the frequency of threat behavior and the degree of deviation of parameter attributes. The frequency of occurrence reflects the activity level of the threat, obtained by counting the number of occurrences of similar threat behaviors per unit of time. The degree of deviation of parameter attributes quantifies the difference between the current threat behavior and the closest normal sample in the standard behavior model library, implemented using a multi-attribute weighted deviation algorithm. Data for both dimensions is obtained in real-time from the real threat behavior judgment module, ensuring that the risk value reflects the latest threat situation. The calculation process employs normalization processing to ensure that the output value falls within a standardized risk range, facilitating unified processing by subsequent modules.

[0085] The frequency of threat behaviors is statistically analyzed using a sliding time window mechanism, considering both short-term explosive threats and long-term persistent risks. The system maintains statistical data across multiple time windows at different scales, including minute-level, hourly-level, and daily-level frequency indicators, selecting an appropriate statistical period based on the characteristics of the threat type. For sudden attack patterns, the focus is on analyzing minute-level frequency changes; for latent threats, more attention is paid to hourly or daily trend fluctuations. The frequency statistics module supports outlier filtering to prevent individual extreme values ​​from interfering with the overall frequency calculation.

[0086] The calculation of parameter attribute deviation employs differentiated weight allocation for different types of threat behaviors. The system predefines core parameter sets for each type of behavior and assigns importance weights to each parameter. For example, in account login behavior analysis, the weight of login time distribution may be higher than the number of logins; while in data access behavior monitoring, the sensitivity level of the accessed target resource may occupy the main weight. The weight configuration scheme supports dynamic updates and can be adjusted according to the actual evolution of threats during operation. A smoothing process is incorporated into the deviation calculation process to avoid misjudgments caused by normal parameter fluctuations.

[0087] The algorithm for generating basic risk values ​​non-linearly fuses frequency and deviation indicators. High-frequency behaviors with high deviation are assigned the highest risk level, while low-frequency, low-deviation behaviors receive the lowest score. For combinations of medium frequency or medium deviation, the algorithm employs a more granular grading strategy to accurately reflect the risk differences between various threat combinations. The risk value calculation process is performed in real time, with each newly identified real threat behavior triggering an update to the risk value. The calculation results are cached and timestamped, supporting historical risk trend analysis.

[0088] The risk assessment and calculation module adopts a distributed architecture to handle the high-concurrency processing requirements of large-scale monitoring environments. Subtasks such as parameter attribute comparison, behavioral pattern analysis, and risk value calculation are decomposed and executed in parallel on different processing nodes. Intermediate data is transmitted via a high-speed message bus to ensure real-time collaboration among processing stages. The system maintains an independent risk status record for each monitored entity, including current risk value, a list of historical threat behaviors, and other complete contextual information, supporting fine-grained risk tracking and management.

[0089] The construction of the behavioral pattern map employs an adaptive sampling strategy to balance analysis accuracy and computational cost. For high-frequency monitoring signals, the system automatically adjusts the temporal resolution of the map, optimizing storage and computational efficiency while ensuring that key features are not lost. The map analysis algorithm supports incremental updates, allowing new behavioral data to be integrated into the existing map in real time without requiring the reconstruction of a complete time-series model. Feature extraction utilizes a multi-scale analysis method, simultaneously capturing macroscopic patterns and microscopic anomalies to comprehensively cover threat features at different scales.

[0090] The parameter attribute library's maintenance mechanism supports dynamic expansion. The parameter ranges stored in the standard behavioral model library are updated periodically to incorporate newly emerging normal business patterns. The system automatically detects trends in parameter distribution; when a continuous shift in business patterns is detected, it triggers a version upgrade process for the model library. The attribute comparison module employs fuzzy matching technology, capable of handling scenarios such as changes in parameter definitions or adjustments to measurement units, maintaining the continuity of judgments. Historical parameter data is archived and stored, supporting backtracking analysis and model validation.

[0091] The configurability of the threat assessment logic is reflected in multiple layers. The system supports policy-based assessment rule management, allowing security administrators to define personalized assessment thresholds and weights for different business systems. The assessment module provides a plug-in architecture, which can integrate third-party threat intelligence data to enhance analytical capabilities. The confidence score of the assessment results is explicitly recorded for subsequent response decision-making reference. All assessment operations generate detailed audit logs, recording the assessment basis, analysis process, and final conclusions, meeting compliance requirements.

[0092] The output of basic risk values ​​uses a standardized interface, supporting seamless integration with downstream security systems. Risk update events are broadcast via a publish-subscribe model, allowing relevant systems to subscribe to specific levels of risk alerts as needed. Time-series data of risk values ​​is persistently stored for long-term trend analysis and security posture assessment. The system provides risk visualization tools to intuitively display the risk distribution and evolution trends of different monitored entities and business units. The performance metrics of the risk calculation module are monitored in real time to ensure stable service quality even under high load.

[0093] Example 3: The interaction trajectory analysis module extracts key motion features from real threat behavior data, including two core dimensions: the number of fluctuations and the rate of change. The number of fluctuations quantifies the number of turning points in the operation path per unit time, reflecting the complexity of the behavior; the rate of change measures the transition speed between adjacent operation nodes, reflecting the urgency of the behavior. These two dimensions of data, after normalization, constitute the basic components of the feature vector. The system uses a sliding time window mechanism to dynamically calculate the interaction trajectory features. The window size is automatically adjusted according to the behavior type; a larger window is used for continuous operations to capture the complete pattern, while a smaller window is used for transient behaviors to improve temporal resolution.

[0094] The feature density distribution map is constructed using a kernel density estimation algorithm, and the initial classification boundary is determined by the following formula:

[0095]

[0096] Explanation of the symbols: B represents the final determined classification boundary position, indicating the separating hyperplane in the feature space that satisfies the density condition; The operator is used to find the minimum x value that makes subsequent conditions true; n is the total number of sample points in the current analysis window; K(·) is the Gaussian kernel function, a non-linear transformation function for calculating the similarity between sample points; x is the positional variable in the feature space, a multidimensional vector; x i Let θ be the coordinates of the i-th sample point in the feature space; θ is the density threshold parameter, which controls the tightness of the classification boundary, and its value ranges from (0,1).

[0097] The core point identification process employs a bidirectional scanning strategy. The system first uniformly distributes probe points within the feature space and calculates the number of samples within a radius *r* of each probe point. If the number of samples in the neighborhood of a point exceeds *m*, it is marked as a potential core point. Subsequently, these candidate points undergo secondary verification to check the uniformity of sample distribution within their neighborhoods and filter out locally clustered noise points. The final determination of core points must satisfy both density persistence and widespread distribution conditions to ensure they represent true category centers.

[0098] The category cluster expansion algorithm employs a breadth-first search strategy. Starting from each confirmed core point, the system sequentially examines all data points within its classification boundary. For other core points within the boundary, bidirectional connections are established and their respective category clusters are merged; for marginal points, their inclusion in the current cluster is determined based on their similarity to the core points. The similarity calculation comprehensively considers the Euclidean distance of feature vectors and the degree of matching of operation types, ensuring semantic consistency during the expansion process. The category cluster growth process records the classification status of each point in real time, avoiding duplicate processing or classification conflicts.

[0099] The outlier detection mechanism operates after category cluster expansion is complete. The system scans all data points not covered by any core point boundary and calculates their distance *d* to the nearest category cluster. If *d* exceeds a dynamic threshold *T*, it is identified as an outlier. The threshold *T* is adaptively adjusted based on the overall density of the feature space, relaxing the criteria in sparse regions and increasing sensitivity in dense regions. Outliers are stored and marked separately for subsequent manual review or specialized analysis.

[0100] The criteria for determining correlated attack patterns are based on the internal structural characteristics of category clusters. The system requires that a valid correlated attack must contain at least two real threat behavior instances, and these instances must exhibit at least two different operation types. The verification of operation type differences uses semantic similarity calculations to avoid superficially different but essentially identical operations being misclassified as different types. The spatiotemporal distribution patterns of behaviors within category clusters are also taken into consideration; truly correlated attacks typically exhibit coordinated time-series characteristics or logical dependencies.

[0101] The feature vector construction process employs a hierarchical encoding technique. The raw data of the interaction trajectories is first converted into fixed-dimensional statistical features, including the mean, extreme values, and standard deviation of the number of fluctuations, as well as the percentiles of the rate of change. These statistics are then combined with one-hot encoding of the operation type to form a high-dimensional feature vector. Dimensionality reduction algorithms are applied to the final feature representation, retaining over 90% of the original information while reducing computational complexity. The feature vector update frequency is synchronized with the safe scanning interval, ensuring that classification analysis is based on the latest behavioral data.

[0102] The incremental learning mechanism of the classification algorithm supports dynamic model optimization. After each scan cycle, the system adds newly confirmed associated attack pattern samples to the training set, triggering fine-tuning of the classification model's parameters. Model updates employ an online learning approach, adjusting only the classification boundaries of affected local regions to maintain the stability of the overall structure. Historical classification decisions are recorded and analyzed to identify potential systematic biases and correct the classification strategy accordingly.

[0103] The visualization analysis interface presents classification results from multiple perspectives. The feature space is projected onto a two-dimensional plane, using color and shape to distinguish different category clusters and outliers. The raw data and classification results of the interactive trajectory can be viewed in conjunction, supporting drill-down analysis of detailed features of specific threat behaviors. The dynamic changes in the classification boundary are displayed in animation, helping to understand the algorithm's response patterns to new data. Users can interactively adjust classification parameters through the interface and observe their impact on the results in real time.

[0104] The abnormal category cluster detection module monitors special patterns during the classification process. The system identifies category clusters that meet formal association conditions but lack semantic rationality, such as combinations containing multiple unrelated operation types. These abnormal clusters are marked separately, potentially indicating novel attack patterns or system misjudgments. The detection algorithm analyzes the contextual relevance of behaviors within a category cluster, calculates its logical coherence score, and triggers a special review process for clusters below a threshold.

[0105] The classification results are stored in a hierarchical structure. Core category cluster information is stored in the main database, including cluster feature summaries, member lists, and association attack determination conclusions; detailed feature vectors and interaction trajectory data are stored in a secondary storage system and loaded for analysis as needed; outlier data are archived separately to support long-term tracking and research. Data retention strategies are set according to importance, with key association attack pattern data permanently stored and ordinary classification results periodically cleaned up.

[0106] Performance optimization measures ensure real-time classification capabilities for large-scale data. Feature vector computation employs a parallel pipeline architecture, with features of different dimensions extracted synchronously by dedicated processing units. The classification boundary update algorithm implements incremental computation, re-evaluating only data points in affected regions. The memory management mechanism dynamically adjusts the caching strategy, keeping frequently accessed category cluster data resident in memory and swapping infrequent data to disk. The distributed computing framework supports cross-node load balancing and automatically expands computing resources when processing ultra-large-scale feature spaces.

[0107] Example 4: See Figure 4The feature analysis system for correlated attack patterns processes security event data using a structured approach. The following case illustrates its workflow. A financial system detects a set of suspicious operations, including abnormal account queries, permission change requests, and data export behavior. The system first arranges these events chronologically and extracts key feature parameters to form the basis for analysis.

[0108] The historical correction scheme database stores typical characteristics and corresponding correction factors for various associated attack patterns. The database employs a hierarchical index structure, with the top layer categorized by attack type and the lower layers storing specific feature combinations. Each record contains three parts: a feature vector, a correction factor value, and a description of the applicable scenario. System maintenance personnel regularly review the database content, merging similar records and breaking down fuzzy categories to maintain the clarity of the database structure. Currently detected suspicious behavior groups are processed through feature extraction to generate feature vectors.

[0109] Table 1: Analysis of Characteristics of Related Attack Behaviors

[0110] Behavior sequence number Operation type Target Resources Time interval (seconds) Parameter anomaly SEQ-202308-1 Account Inquiry Customer Database 0 0.72 SEQ-202308-2 Privilege escalation request Administrator privileges 43 0.85 SEQ-202308-3 Batch data export Transaction record sheet 218 0.91

[0111] The similarity calculation process employs a multi-dimensional weighted comparison algorithm. The system compares the current feature vector with each historical record, calculating a comprehensive score across three dimensions: operation type matching degree, temporal pattern similarity, and parameter anomaly distribution distance. Operation type matching degree examines the overlap ratio of specific operation categories; temporal pattern similarity analyzes the distribution characteristics of intervals between behaviors; and parameter anomaly distribution distance measures the degree of similarity in overall anomaly levels. The weights of these three dimensions are dynamically adjusted according to the attack type; for data theft attacks, more emphasis is placed on operation type, while for system destruction attacks, more attention is paid to parameter anomaly.

[0112] When a historical record is found to have a similarity exceeding a preset threshold, the system automatically applies the corresponding historical correction factor. For example, a historical record showing an attack containing the sequence of "account query - privilege escalation - data export" has an 87% similarity to the current case, and the correction factor for this record is 1.32. The system applies this factor to the base risk value of the current case, generating an adjusted risk score.

[0113] For cases without a history of high similarity, the correction factor is calculated based on the total number of associated attack patterns. The system maintains a quantity-factor mapping table, which uses a piecewise linear function to describe the relationship between quantity and factor. When 3 associated attack behaviors are detected, the corresponding correction factor is 1.25; for 5 behaviors, it rises to 1.48; and for more than 8 behaviors, the upper limit of 1.75 is used. This mapping relationship is customized according to the security requirements of different industries; the factor growth slope of the financial system is usually higher than that of the education system.

[0114] The application of the correction factor takes into account the spatial distribution characteristics of attack behaviors. The system not only calculates the total number of related attacks but also analyzes the distribution range of these behaviors within the system. Attacks widely distributed across multiple functional modules receive a higher correction factor bonus than attacks concentrated in a single module. The quantification of the distribution range is achieved by statistically counting the number of affected functional modules, with each additional module adding a correction factor of 0.05.

[0115] The interaction between the base risk value and the correction factor utilizes a real-time data channel. Immediately after generating the base value, the risk calculation module triggers the correction process, transmitting all characteristic parameters of the current threat to the correction factor calculation engine via a high-speed bus. The correction engine performs two analyses in parallel: historical record matching and quantitative statistics, selecting the more applicable correction scheme. The entire interaction process is completed within milliseconds, ensuring the timeliness of risk management.

[0116] The historical correction scheme update mechanism employs a two-stage verification process. Newly emerging related attack patterns, after initial processing, have their characteristics and the correction factors used placed under observation. Only when the same pattern reappears and the processing effect meets expectations is the scheme officially added to the historical database. Schemes within the observation period are marked as temporary records, for internal system reference only. This mechanism effectively prevents sporadic patterns or misjudgments from contaminating historical data.

[0117] The semantic analysis of operation types employs an ontology-based approach. The system constructs a knowledge graph containing hundreds of operation types, defining the relationships between them. For example, "password modification" and "permission change" are categorized as permission-related operations, while "data query" and "export" belong to data access operations. This structured knowledge supports deeper attack pattern analysis, enabling the identification of seemingly different but substantially related combinations of operations. The knowledge graph is regularly updated to incorporate new business operations and attack techniques.

[0118] The time interval analysis module identifies the temporal coordination characteristics of attack behaviors. Genuine correlated attacks often exhibit specific temporal patterns, such as rapid, continuous operations, timed triggering, or periodic repetition. The module transforms the original time series into multi-scale features, including precise second-level intervals of continuous operations, minute-level operation density, and hourly trend changes. Combining these features with operation types improves the accuracy of correlation determination.

[0119] The correction factor calculation engine employs a microservice architecture, supporting dynamic expansion. Each analytical dimension runs as an independent service, including historical record matching, quantity statistics, and distribution analysis services. Services communicate via a lightweight protocol, and a coordinator component integrates the outputs of each service to generate the final correction factor. This architecture allows for the flexible addition of new analytical dimensions, such as network topology analysis or user behavior profiling, without impacting existing functionality.

[0120] The risk value update process is audit-tracked. The system records complete information including the base risk value, the correction factors used and their calculation basis, and the final adjusted risk value. This data is stored in association with the original security incident, forming a traceable risk management chain. Audit logs support retrieval by multiple criteria such as time range, risk level, and attack type, facilitating post-event analysis and compliance checks.

[0121] The feature analysis visualization interface presents a panoramic view of correlated attacks. Operation sequences are displayed on a timeline, highlighting key parameters and anomalies; historical matching results are sorted in descending order of similarity, showing the top five candidate solutions; the calculation process of correction factors is broken down and shown, illustrating the contribution ratio of each dimension. Security personnel can interactively adjust parameter weights through the interface, observing their impact on the final risk value in real time, thus aiding the decision-making process.

[0122] Example 5: The risk value-driven scan interval adjustment mechanism achieves adaptive configuration through dynamic calculation of the interval adjustment factor. The system receives the updated risk value R from the risk analysis module, which, after normalization, falls within the [0,1] interval. The interval adjustment factor α is calculated using an inverse S-shaped curve response:

[0123]

[0124] Explanation of symbols: α is the interval adjustment factor for the final output, a dimensionless coefficient; α max To adjust the upper limit of the factor, a typical setting is 2.0-3.0; α min To adjust the lower limit of the factor, a typical setting is 0.3-0.5; e is the natural constant, approximately equal to 2.71828; k is the curve steepness parameter, controlling the response sensitivity, a positive real number; R is the input risk value, the normalized value in the [0,1] interval; R0 is the midpoint of the risk response, the center point of symmetry of the S-shaped curve.

[0125] The preprocessing of risk values ​​includes two key steps: time-based weighting and spatial aggregation. Time-based weighting assigns weights based on the timestamps of the risk values, with more recently generated risk values ​​receiving higher weights, while the influence of historical risk values ​​decays over time. Spatial aggregation processes risk values ​​from different monitoring areas, summing them according to regional importance to generate a globally unified risk indicator. This preprocessing eliminates spatiotemporal biases in the risk data, providing a stable and reliable input for interval adjustments.

[0126] The adjustment factor application process employs a gradual change strategy. The system maintains the current scan interval T. current Interval T with target target Two states, where T target =α×T base T base This is the baseline interval duration. Each adjustment does not directly switch to the target interval, but rather follows T...new =βT current +(1-β)T target A smooth transition is achieved, with β∈(0,1) controlling the adjustment speed. This gradual change avoids system instability caused by drastic fluctuations in the scan frequency, making it particularly suitable for continuously running critical business systems.

[0127] Reference interval duration T base The determination of the threshold takes into account the inherent characteristics of the system. The security team presets baseline values ​​for different security levels based on factors such as the business cycle of the monitored targets, data sensitivity, and hardware performance. During system operation, the actual overhead of scanning operations is continuously monitored, including metrics such as CPU utilization, memory consumption, and network load, and the threshold (T) is dynamically fine-tuned. base This flexible benchmark mechanism ensures that interval adjustments respond to changes in risk without exceeding the system's resource carrying capacity.

[0128] The configuration of the risk response midpoint parameter R0 employs an adaptive learning algorithm. The system analyzes the historical risk value distribution and automatically sets R0 within the 60th-70th percentile range of the risk distribution, ensuring that most routine risk fluctuations fall within the flattened response zone of the curve, while extreme risks trigger a strong response. When a persistent change in the risk pattern is detected, the distribution characteristics are recalculated and the R0 value is adjusted to maintain the alignment between the response strategy and the environmental risk.

[0129] The dynamic optimization of the curve steepness parameter k is based on response feedback. The system records the risk control effect after each interval adjustment, evaluating response timeliness and resource consumption ratio. When a delay in response to a high-risk event or resource waste during a low-risk period is detected, the value of k is gradually adjusted to optimize the shape of the response curve. The optimization process employs a small-step trial-and-error method to avoid system oscillations caused by sudden parameter changes.

[0130] The setting of the upper and lower limits of the adjustment factor follows business constraints. α max Typically set to 2.0-3.0, this limits the minimum scan interval to a hard limit that restricts it to no less than the system's processing power; α min Set the interval between 0.3 and 0.5 to prevent blind spots caused by excessively long intervals. These limits can be temporarily overridden during special business periods, such as forcibly setting α during transaction settlement. max =4.0, increase monitoring frequency.

[0131] The reconfiguration process for the scan interval includes an integrity check. The system verifies that the new interval value does not resonate with the cycles of critical business processes, avoiding monitoring vulnerabilities caused by the synchronization of fixed intervals with periodic operations. A time prime number check ensures that the interval duration is not an integer multiple of common cycles, such as avoiding setting it to an approximation of 60 seconds. If the check fails, the interval value is automatically fine-tuned to eliminate potential monitoring blind spots while maintaining effective risk response.

[0132] The resource budget management module coordinates scanning tasks with system load. Interval adjustment decisions consider not only risk values ​​but also real-time metrics such as current CPU utilization, memory pressure, and I / O latency. When system load exceeds a safety threshold, a temporary risk-driven interval contraction is implemented to maintain service stability. Once the load eases, the risk response strategy is restored, and the interval is compensatorily shortened to fill monitoring gaps.

[0133] The audit trail for configuration changes records the complete decision-making chain. The system persistently stores the risk value input, adjustment factor calculation parameters, the final adopted new interval value, and the reason for the change for each interval adjustment. Audit logs support multi-dimensional retrieval by time range, risk level, adjustment magnitude, etc., facilitating post-event analysis and strategy optimization. A critical configuration change trigger notification mechanism reminds the security team to review and automatically make decisions.

[0134] Cross-system collaborative adjustments achieve global resource optimization. When multiple related systems share infrastructure, the coordinator component uniformly analyzes the risk status and resource requirements of each system, and calculates the optimal global interval configuration scheme. The collaborative algorithm avoids resource contention caused by all systems simultaneously entering a high-frequency scanning state, and maintains overall stability through peak-shaving scheduling. The collaborative results are distributed to each participating system for execution through a standard interface.

[0135] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0136] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. An intelligent AI-based security identification method, characterized in that, The method comprises the following steps: collecting historical normal behavior data to establish a standard behavior model library; collecting real-time monitoring data sets, and determining a security scanning interval according to the data size of the real-time monitoring data sets; acquiring all monitoring signals and calculating average characteristic values of the monitoring signals within the security scanning interval, and taking the average characteristic values of the monitoring signals as a security judgment benchmark; evaluating the monitoring signals according to the security judgment benchmark and the standard behavior model library to identify whether there is suspicious abnormal behavior and to mark the suspicious abnormal behavior; when there is suspicious abnormal behavior, extracting parameter attributes and behavior pattern characteristics of each suspicious abnormal behavior, determining whether the suspicious abnormal behavior is a real threat behavior according to the parameter attributes and the behavior pattern characteristics, and determining a basic risk value based on the frequency of the threat behavior when the suspicious abnormal behavior is determined to be a real threat behavior; analyzing the real threat behavior, identifying behavior sequences, operation types and interaction trajectories, taking the interaction trajectories as a feature vector, classifying and analyzing all real threat behaviors by using a classification algorithm, and judging whether there is an associated attack mode according to the classification result; when it is determined that there is an associated attack mode, updating the basic risk value by calculating a correction factor according to the characteristics of the associated attack mode, and reconfiguring a next security scanning interval; when the data size is less than or equal to the low data size threshold, the security scanning interval is set to a first interval duration; when the data size is greater than the low data size threshold and less than or equal to the high data size threshold, the security scanning interval is set to a second interval duration; when the data size is greater than the high data size threshold, the security scanning interval is set to a third interval duration; the first interval duration is greater than the second interval duration, and the second interval duration is greater than the third interval duration; the data size of the real-time monitoring data sets is directly transmitted to the security judgment benchmark calculation process for adjusting the generation of the average characteristic values of the monitoring signals; the characteristics of the associated attack mode include the total number of the associated attack mode and the operation type of each associated attack mode, and the operation type includes data tampering operation, privilege escalation operation and camouflage operation; matching the characteristics of the associated attack mode with historical correction schemes, and updating the basic risk value by determining a correction factor according to the matching result; the historical correction schemes contain characteristics of a plurality of historical associated attack modes and a plurality of historical correction factors, and each historical associated attack mode corresponds to a historical correction factor; calculating the similarity between the characteristics of the associated attack mode and the characteristics of each historical associated attack mode; when there is a record in the characteristics of the historical associated attack mode that has a similarity to the characteristics of the associated attack mode exceeding a similarity threshold, the historical correction factor corresponding to the historical associated attack mode with the highest similarity is determined as the correction factor for updating the basic risk value. ​ When the similarity between the feature of the historical correlation attack mode and the feature of the correlation attack mode is less than the similarity threshold, the base risk value is updated according to the total number of the correlation attack modes; The base risk value and the feature data of the correlation attack mode are interactively transmitted, and are used in the process of calculating the correction factor; When the base risk value is updated according to the total number of the correlation attack modes, the correction factor and the total number of the correlation attack modes have a linear growth relationship, and the value range of the correction factor is in a fixed interval; The output data of the correction factor is directly used in the process of updating the base risk value, so as to ensure that the updating result reflects the influence of the total number of the correlation attack modes; When the next security scanning interval is reconfigured, the updated risk value is obtained, the interval adjustment factor is determined according to the updated risk value, and the next security scanning interval is reconfigured, the interval adjustment factor and the updated risk value have an inverse variation relationship, and the value range of the interval adjustment factor is in a fixed interval; The updated risk value data is transmitted into the process of calculating the interval adjustment factor, and is used to generate the next security scanning interval configuration. 2.The smart AI-based security identification method of claim 1, wherein When the monitoring signal is evaluated according to the security judgment benchmark and the standard behavior model library, and it is identified whether there is suspicious abnormal behavior and is labeled, the behavior sequence of all monitoring signals is matched with the standard behavior model library, and the feature intensity of each monitoring signal is compared with the average feature value of the monitoring signal, and it is identified whether there is suspicious abnormal behavior and is labeled according to the matching and comparison results; When the feature intensity of the monitoring signal exceeds the multiple setting value of the average feature value of the monitoring signal, the monitoring signal is identified as suspicious abnormal behavior and is labeled; When the behavior sequence of the monitoring signal does not appear in the standard behavior model library, the monitoring signal is identified as suspicious abnormal behavior and is labeled; The output data of the standard behavior model library is used in the process of comparing the feature intensity, so as to ensure that the labeling result is consistent with the historical normal behavior data. 3.The smart AI-based security identification method of claim 2, wherein, When it is determined whether the suspicious abnormal behavior is a real threat behavior according to the parameter attribute and the behavior mode feature, if the parameter attribute of the suspicious abnormal behavior is inconsistent with the common parameter attribute in the standard behavior model library, the suspicious abnormal behavior is determined as a real threat behavior; The behavior mode feature includes the behavior mode atlas form, and when the behavior mode atlas form of the suspicious abnormal behavior presents a discrete behavior peak value, the suspicious abnormal behavior is determined as a real threat behavior; The parameter attribute data is extracted from the labeling of the suspicious abnormal behavior, and is transmitted to the behavior mode atlas form analysis process, and is used to determine the real threat behavior. 4.The smart AI-based security identification method of claim 3, wherein, When the base risk value is determined based on the threat behavior occurrence frequency, the base risk value is calculated by comprehensively considering the threat behavior occurrence frequency and the deviation degree of the parameter attribute of each real threat behavior from the most similar parameter attribute in the standard behavior model library; The threat behavior occurrence frequency and the parameter attribute deviation data are obtained from the determination result of the real threat behavior, and are used in the process of calculating the base risk value. 5.The smart AI-based security identification method of claim 4, wherein, The classification algorithm is used to classify and analyze all real threat behaviors, and whether there is an associated attack mode is judged according to the classification result, including: the interaction track includes the number of interaction track fluctuations and the change rate of the interaction track; Determine the initial classification boundary through the feature density distribution graph, and set the minimum sample number as a fixed value; Take the feature vector of each real threat behavior as a data point, traverse all data points, and find the point whose data point number in the classification boundary reaches the minimum sample number as the core point; From each core point, check the points in its classification boundary; If the point in the boundary is a core point, expand the category cluster; if the point in the boundary is an edge point, add it to the current category cluster; If a point does not belong to the classification boundary of any core point and cannot form a category cluster, it is marked as an isolated point; When there is a category cluster containing at least two real threat behaviors and the operation type of the real threat behavior is at least two operations, it is determined that the real threat behavior in the category cluster is an associated attack mode; The interaction track data is transmitted from the real threat behavior analysis and used in the feature vector construction process.

6. An intelligent AI security identification system based on the intelligent AI security identification method of any one of claims 1 to 5. It includes: The data collection module is configured to collect historical non-abnormal behavior data to establish a standard behavior model library, collect real-time monitoring data sets, and determine the security scanning interval according to the data size of the real-time monitoring data sets; All monitoring signals are obtained within the security scanning interval, and the average feature value of the monitoring signals is calculated, which is used as the security judgment benchmark; The threat identification module is configured to evaluate the monitoring signals based on the security judgment benchmark and the standard behavior model library, identify whether there is suspicious abnormal behavior, and mark it; When there is suspicious abnormal behavior, the parameter attribute and behavior mode feature of each suspicious abnormal behavior are extracted, and whether the suspicious abnormal behavior is a real threat behavior is determined according to the parameter attribute and behavior mode feature. When it is determined that the suspicious abnormal behavior is a real threat behavior, the basis risk value is determined based on the threat behavior frequency; The attack analysis module is configured to analyze real threat behaviors and identify behavior sequences, operation types and interaction tracks, use classification algorithms to classify and analyze all real threat behaviors, and determine whether there is an associated attack mode according to the classification result; When it is determined that there is an associated attack mode, update the basis risk value according to the characteristics of the associated attack mode to calculate the correction factor, and reconfigure the next security scanning interval; The response execution module is configured to start the protection measures according to the updated risk value, and output the details of the real threat behavior; The log storage module is configured to store threat behavior records; The output of the data collection module is transmitted to the threat identification module, the output of the threat identification module is transmitted to the attack analysis module, and the output of the attack analysis module is transmitted to the response execution module.

Citation Information

Patent Citations

  • Vulnerability and threat scanning method and system based on artificial intelligence

    CN119227089A

  • feature and limit setting for threat detection in an industrial plant control system

    DE102017128693A1