Dynamic security protection system and method for special communication network of smart city

Through the dynamic security protection system of the perception layer, decision layer and evolution layer, known and unknown threats in the smart city's dedicated communication network can be identified and defended in real time, solving the problems of insufficient unknown threat detection capabilities and inability to dynamically adjust protection measures in existing technologies, and achieving effective defense and rapid response to potential threats.

CN120811784AActive Publication Date: 2025-10-17北京智慧城市网络有限公司
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511300242.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-12
Publication Date
2025-10-17
Estimated Expiration
2045-09-12

AI Technical Summary

Technical Problem

Existing smart city dedicated communication networks lack the ability to proactively detect unknown threats, and existing security protection measures cannot be dynamically adjusted, resulting in slow response speeds and an inability to respond to new attack methods in a timely manner.

Method used

A dynamic security protection system with perception layer, decision layer and evolution layer is used. Through pre-trained anomaly capture model and security risk identification model, it collects and analyzes multi-source network data in real time, identifies known and unknown threats, and dynamically updates the model to adapt to changes in the network environment.

Benefits of technology

It effectively identifies and defends against potential security threats, reduces the risk of unknown attacks, improves the system's response speed and adaptability, and enables continuous learning and evolution based on the latest execution results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120811784A_ABST
    Figure CN120811784A_ABST
Patent Text Reader

Abstract

The invention discloses a dynamic security protection system and method for a special communication network of a smart city, and the system comprises a sensing layer which is used for collecting and preprocessing various network data related to the special communication network of the smart city through a pre-trained anomaly capture model, and obtaining multi-source private network data; the decision-making layer is used for inputting the multi-source private network data into a pre-trained security risk identification model and outputting a decision-making result corresponding to the multi-source private network data; the execution layer is used for executing the strategy template of the decision-making result to obtain an execution result when the decision-making result indicates that the known threat or the potential unknown threat exists in the smart city special communication network; and the evolution layer is used for feeding back the execution result to the perception layer and the decision-making layer so as to dynamically update a pre-trained anomaly capture model and a pre-trained security risk identification model respectively. Therefore, by adopting the embodiment of the invention, unknown threats can be detected, and the threats can be effectively coped with when facing new attack means.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and in particular to a dynamic security protection system and method for a smart city special communication network. BACKGROUND

[0002] In the construction of smart cities, the city network infrastructure usually adopts a networking mode combining public networks and special networks. The public network mainly refers to the public communication network constructed by telecom operators, such as 4G, 5G, etc., which provides communication services for a wide range of users; the special network is a special communication network constructed by government departments to ensure the security and confidentiality of information, serving key fields such as government, public security, and public utilities.

[0003] In related technologies, the special network usually adopts an independent physical or logical communication channel to enhance the security of the network. In terms of information security, the smart city special communication network adopts traditional security protection measures such as firewalls, intrusion detection systems (IDS), and antivirus software.

[0004] On the one hand, the existing technology mainly focuses on the defense against known threats, lacking the ability to actively detect unknown threats. On the other hand, most existing security protection measures are based on static rules and cannot be dynamically adjusted according to changes in the network environment and the evolution of threat situations, resulting in the need for manual rule updates when facing new attack methods, slow response speed, and the inability to respond to threats in a timely and effective manner. SUMMARY

[0005] The embodiments of the present application provide a dynamic security protection system and method for a smart city special communication network. In order to have a basic understanding of some aspects of the disclosed embodiments, a brief summary is given below. This summary is not a general review, nor does it determine the key / important components or delineate the protection scope of these embodiments. Its only purpose is to present some concepts in a simple form as a prelude to the detailed description that follows.

[0006] In a first aspect, the embodiments of the present application provide a dynamic security protection system for a smart city special communication network, the system comprising: a perception layer, a decision layer, an execution layer, and an evolution layer; The perception layer is configured to collect and preprocess a plurality of network data related to the smart city special communication network through a pre-trained anomaly capture model to obtain multi-source special network data. The decision layer is configured to input the multi-source special network data into a pre-trained security risk identification model to output a decision result corresponding to the multi-source special network data; the pre-trained security risk identification model is obtained based on historical multi-source data and known attack patterns. an execution layer configured to execute the policy template of the decision result to obtain an execution result when the decision result indicates that there is a known threat or a potential unknown threat in the smart city special communication network; an evolution layer configured to feed back the execution result to the perception layer and the decision layer to respectively dynamically update the pre-trained anomaly capturing model and the pre-trained security risk identification model.

[0007] Optionally, a plurality of network data related to the smart city special communication network is collected and pre-processed to obtain multi-source special network data, including: targeting the smart city special communication network; collecting and standardizing, from the cybersecurity equipment and the security perception management platform, at least network traffic, network attack events, and host controlled events related to the target as first network data according to a preset period; collecting and standardizing, from the host class, the network device class, and the application program class in the network infrastructure of the target, at least fault data, alarm data, logs, and terminal detection data as second network data according to a preset period; collecting and standardizing, from the terminal class equipment and the external platform connected to the target, actual business scenario data as third network data according to a preset period; obtaining and standardizing, from the external threat intelligence platform, global threat intelligence information as fourth network data; performing data correlation analysis on the first network data, the second network data, the third network data, and the fourth network data to obtain situation data; inputting the situation data into the pre-trained anomaly capturing model to capture abnormal data and abnormal patterns in the situation data, and outputting multi-source special network data corresponding to the situation data.

[0008] Optionally, the data correlation analysis on the first network data, the second network data, the third network data, and the fourth network data to obtain situation data includes: associating the network attack events in the first network data with the alarm data in the second network data based on timestamps and event types to identify existing attack paths; associating the network traffic data in the first network data with the actual business scenario data in the third network data to analyze the relationship between traffic anomalies and business activities; associating the fault data in the second network data with the threat intelligence information in the fourth network data to identify known threats; analyzing detailed information of the host controlled events through the host controlled events in the first network data and the log data in the second network data to determine the behavior patterns of the controlled hosts; Correlate the terminal detection data in the third network data with the threat intelligence information in the fourth network data to identify threat information faced by the terminal device; Correlate the network traffic data in the first network data with the global threat intelligence information in the fourth network data to analyze whether there is a known threat feature in the traffic; Integrate all the results obtained by the above correlation to obtain a unified situation data set.

[0009] Optionally, the pre-trained anomaly capturing model includes a feature extraction layer, an anomaly pattern analysis layer, a severity quantification layer, a context information acquisition layer, and a data output layer. Input the situation data into the pre-trained anomaly capturing model to output multi-source special network data corresponding to the situation data, including: The feature extraction layer extracts network traffic features, network attack event features, host controlled event features, terminal detection data features, and threat intelligence information features existing in the situation data to obtain a multi-source feature set; The anomaly pattern analysis layer performs anomaly pattern analysis on the multi-source feature set to identify anomaly patterns of the smart city special communication network; the anomaly patterns at least include abnormal behaviors in network attack events, abnormal behaviors in host controlled events, abnormal behaviors in terminal devices, and abnormal information in threat intelligence; The severity quantification layer quantifies the severity of each anomaly pattern; The context information acquisition layer acquires network devices, terminal devices, and business systems involved in each anomaly pattern to obtain context information; The data output layer outputs each anomaly pattern, the severity of each anomaly pattern, and the context information as multi-source special network data corresponding to the situation data.

[0010] Optionally, the pre-trained anomaly capturing model is generated according to the following steps, including: Collect historical multi-source data from the smart city special communication network; Perform data cleaning and data normalization on the historical multi-source data; Perform data correlation analysis on the normalized historical multi-source data to obtain historical situation data; Determine known historical normal behaviors and related data sets thereof, and historical anomaly patterns and related data sets thereof corresponding to the historical multi-source data; Label the known historical normal behaviors and related data sets thereof, and the historical anomaly patterns and related data sets thereof in the historical situation data to obtain a first model training sample; the related data sets of the historical anomaly patterns include historical severity and historical context information; Create an anomaly capturing model using a neural network; The first model training sample is input into the anomaly capture model, and a first model loss value is output; in the case that the first model loss value reaches a minimum, a pre-trained anomaly capture model is generated.

[0011] Optionally, the multi-source private network data includes each abnormal mode, severity of each abnormal mode, and context information; the pre-trained security risk identification model includes a feature extraction layer, a parameter quantization layer, a weighted summation layer, an abnormal mode marking layer, a strategy template acquisition layer, and a decision result output layer; The multi-source private network data is input into the pre-trained security risk identification model, and a decision result corresponding to the multi-source private network data is output, including: The feature extraction layer maps each abnormal mode to a discrete code, normalizes the severity of each abnormal mode to the interval of 0-1, and converts the context information of each abnormal mode into an embedded vector to obtain a unified target feature vector; The parameter quantization layer quantizes the asset importance score, the current threat occurrence probability, and the potential harm degree based on the target feature vector; The weighted summation layer performs weighted summation on the asset importance score, the current threat occurrence probability, and the potential harm degree to obtain a comprehensive risk score of each abnormal mode; The abnormal mode marking layer marks each abnormal mode as a high-risk known threat when the comprehensive risk score is greater than the upper limit value of a preset risk threshold interval; or marks each abnormal mode as a medium-risk known threat when the comprehensive risk score is within the preset risk threshold interval; or marks each abnormal mode as a potential unknown threat when the comprehensive risk score is less than the lower limit value of the preset risk threshold interval and the similarity between each abnormal mode and a known attack mode is greater than a preset difference threshold; The strategy template acquisition layer obtains a target strategy template corresponding to the high-risk known threat or the medium-risk known threat or the potential unknown threat from a mapping relationship between pre-established threat categories and strategy templates, as the decision result corresponding to the multi-source private network data; The decision result output layer outputs the decision result corresponding to the multi-source private network data.

[0012] Optionally, the target strategy template corresponding to the high-risk known threat is composed of an immediate blocking strategy, an isolation strategy, and a forensics strategy; the target strategy template corresponding to the medium-risk known threat is composed of a flow limiting strategy, an alarm strategy, and a patch pushing strategy; and the target strategy template corresponding to the unknown threat is composed of a sandbox deep analysis strategy and a behavior monitoring strategy; wherein, The asset importance score The calculation formula is:

[0013] Wherein, and is the weight coefficient, which is used to adjust the impact of context information and severity on the asset importance score. is the embedding vector of the context information in the target feature vector, is the normalized result of the severity of the abnormal pattern in the target feature vector; Current threat probability The calculation formula is:

[0014] in, and Is the weight coefficient, used to adjust the impact of abnormal patterns and severity on the probability of threat occurrence, is the discrete encoding of the abnormal pattern in the target feature vector, is the normalized result of the severity of the abnormal pattern in the target feature vector, It is the Sigmoid function, which is used to map the calculation results to the range of 0-1; Potential harm It can be calculated by the following formula:

[0015] in, and is a weight coefficient used to adjust the impact of context information and severity on the potential harm degree. is the embedding vector of the context information in the target feature vector, is the normalized result of the severity of the abnormal pattern in the target feature vector.

[0016] Optionally, follow these steps to generate a pre-trained security risk identification model, including: Collect historical multi-source data from the smart city’s dedicated communication network; Perform data cleaning and data normalization on historical multi-source data; Perform data correlation analysis on normalized historical multi-source data to obtain historical situation data; Input historical situation data into a pre-trained anomaly capture model, and output historical multi-source private network data corresponding to the historical situation data; For historical multi-source private network data, each historical abnormal pattern is marked with a known attack pattern, and each historical abnormal pattern is marked with a historical threat category and a historical policy template to obtain a second model training sample; Use neural networks to create a security risk identification model; The second model training sample is input into the security risk identification model, and a second model loss value is output; and in a case where the second model loss value reaches a minimum, a pre-trained security risk identification model is generated.

[0017] Optionally, the execution result includes execution time, an executed policy template, an execution result, a network state after execution, and a security result. The pre-trained anomaly capturing model and the pre-trained security risk identification model are dynamically updated, including: The execution time, the executed policy template, the execution result, the network state after execution, and the security result are associated with the multi-source private network data as data labels, and an incremental data set is obtained. The pre-trained anomaly capturing model and the pre-trained security risk identification model are fine-tuned using the incremental data set, so as to dynamically update the pre-trained anomaly capturing model and the pre-trained security risk identification model.

[0018] In a second aspect, the embodiments of the present application provide a dynamic security protection method for a smart city private communication network, including: A plurality of network data related to the smart city private communication network is collected and preprocessed by the pre-trained anomaly capturing model, and multi-source private network data is obtained; The multi-source private network data is input into the pre-trained security risk identification model, and a decision result corresponding to the multi-source private network data is output; the pre-trained security risk identification model is obtained based on historical multi-source data and known attack modes; When the decision result indicates that there is a known threat or a potential unknown threat in the smart city private communication network, a policy template of the decision result is executed, and an execution result is obtained; According to the execution result, the pre-trained anomaly capturing model and the pre-trained security risk identification model are dynamically updated.

[0019] The technical scheme provided by the embodiments of the present application can include the following beneficial effects: In the embodiments of the present application, on the one hand, the perception layer can fit the multi-source private network data using the pre-trained anomaly capturing model, and the multi-source private network data has related parameter information of unknown threats. The decision layer can input these multi-source private network data into the security risk identification model, which is trained based on historical data and known attack modes, and can effectively identify abnormal data and abnormal patterns. The smart city private communication network can defend against potential security threats, thereby reducing the risk of unknown attacks. On the other hand, the evolution layer feeds back the execution result to the perception layer and the decision layer, and dynamically updates the anomaly capturing model and the security risk identification model. The feedback mechanism enables the system to continuously learn and evolve according to the latest execution result, so as to adapt to the changing network environment.

[0020] It should be understood that the general description above and the detailed description below are only exemplary and explanatory, and are not restrictive of the present application. BRIEF DESCRIPTION OF DRAWINGS

[0021] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and serve to explain the principles of the present application, in which, like reference numerals designate corresponding parts throughout the several views.

[0022] Figure 1 is a system architecture schematic diagram of a dynamic security protection system of a smart city special communication network provided by an embodiment of the present application; Figure 2 is a multi-source special network data fitting schematic diagram provided by an embodiment of the present application; Figure 3 is a model structure schematic diagram of a pre-trained anomaly capture model provided by an embodiment of the present application; Figure 4 is a model structure schematic diagram of a pre-trained security risk identification model provided by an embodiment of the present application; Figure 5 is a flow schematic diagram of a dynamic security protection method of a smart city special communication network provided by an embodiment of the present application; Figure 6 is a process schematic block diagram of a dynamic security protection process of a smart city special communication network provided by an embodiment of the present application; Figure 7 is a flow schematic diagram of a model training method of an anomaly capture model provided by an embodiment of the present application; Figure 8 is a flow schematic diagram of a model training method of a security risk identification model provided by an embodiment of the present application. DETAILED DESCRIPTION

[0023] The following description and drawings are illustrative of specific embodiments of the present application and are not intended to limit the scope of the present application.

[0024] It should be clear that the described embodiments are only some of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of protection of the present application.

[0025] The following description refers to the accompanying drawings. Unless otherwise indicated, the same numbers in different drawings indicate the same or similar elements. The implementations described in the following example embodiments are not meant to represent all implementations consistent with the present application. Rather, they are merely examples of systems and methods consistent with some aspects of the present application as detailed in the appended claims.

[0026] In the description of the present application, it should be understood that the terms "first", "second" and the like are only used for descriptive purposes and cannot be understood as indicating or implying relative importance. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to the specific circumstances. In addition, in the description of the present application, "a plurality of" means two or more, unless otherwise specified. The association relationship of the associated objects is described, which means that there can be three relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after it.

[0027] At present, the private network usually adopts independent physical or logical communication channels to enhance the security of the network. In terms of information security, the smart city special communication network adopts traditional security protection measures such as firewall, intrusion detection system (IDS), antivirus software, etc.

[0028] The inventors of the present application noticed that, on the one hand, the prior art mainly focuses on the defense of known threats, and lacks the active detection ability of unknown threats. On the other hand, most of the existing security protection measures are based on static rules, which cannot be dynamically adjusted according to the changes of network environment and the evolution of threat situation, resulting in the need for manual updating of rules when facing new attack methods, slow response speed, and inability to respond to threats in time and effectively.

[0029] In order to solve the problems in the prior art, the present application provides a dynamic security protection system and method for smart city special communication network to solve the problems existing in the above related technical problems. In the embodiments of the present application, on the one hand, the perception layer can fit the multi-source private network data by using the pre-trained anomaly capture model, and the multi-source private network data contains the related parameter information of unknown threats. The decision layer can input these multi-source private network data into the security risk identification model, which is trained based on historical data and known attack patterns, and can effectively identify abnormal data and abnormal patterns, so that the smart city special communication network can defend against potential security threats, thereby reducing the risk of unknown attacks. On the other hand, the evolution layer feeds back the execution results to the perception layer and the decision layer, and dynamically updates the anomaly capture model and the security risk identification model. The feedback mechanism enables the system to continuously learn and evolve according to the latest execution results to adapt to the changing network environment, which will be described in detail below using exemplary embodiments.

[0030] Please refer to Figure 1FIG. 1 shows a structural diagram of a dynamic security protection system of a smart city special communication network according to an example embodiment of the present application. The dynamic security protection system of the smart city special communication network includes a perception layer, a decision layer, an execution layer, and an evolution layer. The perception layer, the decision layer, the execution layer, and the evolution layer are communicatively connected.

[0031] The perception layer is configured to collect and preprocess various network data related to the smart city special communication network by using a pre-trained anomaly capturing model to obtain multi-source special network data. In some embodiments of the present application, the specific process of collecting and preprocessing various network data related to the smart city special communication network to obtain multi-source special network data includes: taking the smart city special communication network as a target; collecting and standardizing at least network traffic, network attack events, and host controlled events related to the target as first network data from the network security equipment and the security perception management platform according to a preset period; collecting and standardizing at least fault data, alarm data, logs, and terminal detection data from the host class, the network device class, and the application program class in the network infrastructure of the target as second network data according to a preset period; collecting and standardizing actual business scenario data from the terminal class devices and the external platform connected to the target as third network data according to a preset period; obtaining and standardizing global threat intelligence information from the external threat intelligence platform as fourth network data; performing data correlation analysis on the first network data, the second network data, the third network data, and the fourth network data to obtain situation data; and inputting the situation data into the pre-trained anomaly capturing model to capture abnormal data and abnormal patterns in the situation data and output multi-source special network data corresponding to the situation data.

[0032] The network security equipment is a device used to protect the security of network and information systems. The security perception management platform is a platform that centrally manages security devices and monitors the security status of the network. Network traffic is the amount of data transmitted through the network, including the size and number of transmitted data packets. Network attack events are malicious attack behaviors against network systems, such as DDoS attacks, port scanning, etc. Host controlled events refer to events where a host is controlled by malicious software or accessed without authorization. Fault data is data generated when a network device or host fails. Alarm data is alarm information generated when a security system detects potential threats or abnormal behaviors. Logs are recorded information generated during the operation of a system, application program, or network device. Terminal detection data is data collected during security detection of terminal devices. Actual business scenario data is data directly related to smart city business, such as traffic flow, public security monitoring data, etc. The external threat intelligence platform is a platform that provides global network security threat information. Global threat intelligence information is information about network security threats obtained from external platforms.

[0033] For example, in the case that the communication network service dedicated for the smart city serves the traffic management system of the smart city, the network traffic can be a video stream captured by a traffic camera. The network attack event can be an attempt to illegally access the traffic management system. The host controlled event can be that a traffic control server is infected by malicious software. The fault data can be a traffic signal failure report. The alarm data can be an alarm including abnormal traffic flow detection. The log can be an operation log recording the traffic management system. The terminal detection data can be related to a security check on a traffic monitoring device. The actual business scenario data can be information including real-time traffic flow information. The global threat intelligence information can be new network attack intelligence for the traffic management system.

[0034] For example Figure 2 As shown, Figure 2 is a multi-source private network data fitting schematic diagram provided by the present application, which can be based on an equal protection device, a security perception management platform, a host type, a network device type and an application type, a terminal type device and an external platform, and an external threat intelligence platform, and is divided into four paths to collect first network data, second network data, third network data and fourth network data. Finally, the first network data, the second network data, the third network data and the fourth network data can be associated and analyzed, and a multi-source private network data can be obtained by combining a pre-trained abnormality capture model.

[0035] In some embodiments of the present application, the specific process of data association analysis of the first network data, the second network data, the third network data and the fourth network data to obtain the situation data includes: based on the time stamp and the event type, the network attack event in the first network data is associated with the alarm data in the second network data to identify the existing attack path; the network traffic data in the first network data is associated with the actual business scenario data in the third network data to analyze the relationship between traffic anomaly and business activity; the fault data in the second network data is associated with the threat intelligence information in the fourth network data to identify the known threats; the host controlled event in the first network data and the log data in the second network data are used to analyze the detailed information of the host controlled event to determine the behavior pattern of the controlled host; the terminal detection data in the third network data is associated with the threat intelligence information in the fourth network data to identify the threat information faced by the terminal device; the network traffic data in the first network data is associated with the global threat intelligence information in the fourth network data to analyze whether there is a known threat feature in the traffic; all the results obtained by the above association are integrated to obtain a unified situation data set.

[0036] In one possible implementation, based on the timestamp and the event type, the network attack events in the first network data are associated with the alarm data in the second network data to identify the attack path. The network traffic data in the first network data is associated with the actual business scenario data in the third network data to analyze the relationship between the traffic anomaly and the business activity. The failure data in the second network data is associated with the threat intelligence information in the fourth network data to identify the known threat. The host controlled event in the first network data and the log data in the second network data are analyzed to determine the behavior pattern of the controlled host. The terminal detection data in the third network data is associated with the threat intelligence information in the fourth network data to identify the threat faced by the terminal device. The network traffic data in the first network data is associated with the global threat intelligence information in the fourth network data to analyze whether there is a feature of the known threat in the traffic.

[0037] For example, the traffic management system of a smart city suffers from a network attack. At this time, the network attack event in the first network data records the behavior of the attacker trying to illegally access the traffic management system. The alarm data in the second network data shows the abnormal login attempt detected by the system. Through data association, the attack path is identified, which shows that the system is entered through a known vulnerability. The network traffic data in the first network data shows an abnormal traffic peak. The actual business scenario data in the third network data shows the normal traffic pattern of the traffic management system. Through data association, it can be found that the abnormal traffic is irrelevant to a specific business activity (such as traffic flow monitoring during rush hour), thereby confirming the traffic anomaly. The failure data in the second network data shows the abnormal behavior of the system during the attack. The threat intelligence information in the fourth network data provides detailed information about the vulnerability. Through data association, it can be identified that this is a known threat.

[0038] For example Figure 3 As shown, the pre-trained anomaly capture model includes a feature extraction layer, an anomaly pattern analysis layer, a severity quantification layer, a context information acquisition layer, and a data output layer.

[0039] In some embodiments of the present application, the specific process of inputting the situation data into the pre-trained anomaly capture model and outputting the multi-source special network data corresponding to the situation data includes: the feature extraction layer extracts the network traffic features, network attack event features, host controlled event features, terminal detection data features, and threat intelligence information features existing in the situation data to obtain a multi-source feature set; the anomaly pattern analysis layer performs anomaly pattern analysis on the multi-source feature set to identify the anomaly patterns of the smart city special communication network; the anomaly patterns at least include abnormal behaviors in network attack events, abnormal behaviors in host controlled events, abnormal behaviors in terminal devices, and abnormal information in threat intelligence; the severity quantification layer quantifies the severity of each anomaly pattern; the context information acquisition layer acquires the network devices, terminal devices, and business systems involved in each anomaly pattern to obtain context information; and the data output layer outputs each anomaly pattern, the severity of each anomaly pattern, and the context information as the multi-source special network data corresponding to the situation data.

[0040] In some embodiments of the present application, the specific process of generating the pre-trained anomaly capture model includes: collecting historical multi-source data from the smart city special communication network; performing data cleaning and data normalization on the historical multi-source data; performing data correlation analysis on the normalized historical multi-source data to obtain historical situation data; determining the known historical normal behaviors and their related data sets, historical anomaly patterns and their related data sets corresponding to the historical multi-source data; marking the known historical normal behaviors and their related data sets, historical anomaly patterns and their related data sets on the historical situation data to obtain a first model training sample; the related data set of the historical anomaly pattern includes historical severity and historical context information; creating an anomaly capture model using a neural network; inputting the first model training sample into the anomaly capture model to output a first model loss value; and generating the pre-trained anomaly capture model when the first model loss value reaches a minimum.

[0041] The decision layer is configured to input the multi-source special network data into the pre-trained security risk identification model and output decision results corresponding to the multi-source special network data; and the pre-trained security risk identification model is obtained based on historical multi-source data and known attack patterns. The multi-source special network data includes each anomaly pattern, the severity of each anomaly pattern, and context information.

[0042] For example Figure 4 As shown, the pre-trained security risk identification model includes a feature extraction layer, a parameter quantification layer, a weighted summation layer, an anomaly pattern marking layer, a strategy template acquisition layer, and a decision result output layer.

[0043] In some embodiments of the present application, the specific process of inputting the multi-source private network data into the pre-trained security risk identification model and outputting the decision results corresponding to the multi-source private network data includes: the feature extraction layer maps each abnormal mode to a discrete code, normalizes the severity of each abnormal mode to the interval of 0-1, and converts the context information of each abnormal mode into an embedding vector to obtain a unified target feature vector; the parameter quantization layer quantizes the asset importance score, the current threat occurrence probability and the potential harm degree based on the target feature vector; the weighted summation layer performs weighted summation on the asset importance score, the current threat occurrence probability and the potential harm degree to obtain a comprehensive risk score of each abnormal mode; the abnormal mode marking layer marks each abnormal mode as a high-risk known threat when the comprehensive risk score is greater than the upper limit value of the preset risk threshold interval; or marks each abnormal mode as a medium-risk known threat when the comprehensive risk score is within the preset risk threshold interval; or marks each abnormal mode as a potential unknown threat when the comprehensive risk score is less than the lower limit value of the preset risk threshold interval and the similarity between each abnormal mode and the known attack mode is greater than the preset difference threshold; the strategy template acquisition layer acquires the target strategy template corresponding to the high-risk known threat or the medium-risk known threat or the potential unknown threat from the mapping relationship between the pre-established threat categories and the strategy templates as the decision results corresponding to the multi-source private network data; and the decision result output layer outputs the decision results corresponding to the multi-source private network data.

[0044] Among them, the target strategy template corresponding to the high-risk known threat is composed of the immediate blocking strategy, the isolation strategy and the evidence collection strategy, the target strategy template corresponding to the medium-risk known threat is composed of the flow limiting strategy, the alarm strategy and the patch pushing strategy, and the target strategy template corresponding to the unknown threat is composed of the sandbox deep analysis strategy and the behavior monitoring strategy.

[0045] Among them, the asset importance score is calculated by the following formula:

[0046] Among them, and are weight coefficients for adjusting the influence of the context information and the severity on the asset importance score, is the embedding vector of the context information in the target feature vector, is the normalized result of the severity of the abnormal mode in the target feature vector; The calculation formula of the current threat occurrence probability is as follows:

[0047] Among them, and is a weight coefficient, used to adjust the influence of abnormal patterns and severity on the probability of threat occurrence, is a discrete encoding of abnormal patterns in the target feature vector, is the standardized result of the severity of abnormal patterns in the target feature vector, is a Sigmoid function, used to map the calculation result to the 0-1 interval; Potential harm degree It can be calculated by the following formula:

[0048] wherein, and is a weight coefficient, used to adjust the influence of context information and severity on the potential harm degree, is an embedding vector of context information in the target feature vector, is the standardized result of the severity of abnormal patterns in the target feature vector.

[0049] In some embodiments of the present application, the specific process of generating the pre-trained security risk identification model includes: collecting historical multi-source data from the smart city special communication network; data cleaning and data normalization are performed on the historical multi-source data; data correlation analysis is performed on the normalized historical multi-source data to obtain historical situation data; the historical situation data is input into the pre-trained anomaly capture model to output the historical multi-source special network data corresponding to the historical situation data; the historical multi-source special network data is marked with known attack patterns, each historical abnormal pattern, and the historical threat category and historical strategy template of each historical abnormal pattern to obtain a second model training sample; a neural network is used to create a security risk identification model; the second model training sample is input into the security risk identification model to output a second model loss value; and the pre-trained security risk identification model is generated when the second model loss value reaches a minimum.

[0050] wherein, the execution layer, for executing the strategy template of the decision result when the decision result indicates that there is a known threat or a potential unknown threat in the smart city special communication network, obtaining an execution result; wherein, the decision result is a conclusion about the network security situation obtained after the decision layer analyzes the multi-source special network data, including the identification and evaluation of threats. The strategy template is a pre-defined security response measure to deal with a specific type or level of threat identified. The known threat is a network attack or security vulnerability that has been identified and has corresponding defense measures. The potential unknown threat is a new type of network attack or security vulnerability that has not been widely identified or does not have known defense measures. The execution result is the result after the execution layer implements the strategy template, including whether the threat is successfully prevented, whether the system is restored to normal, etc.

[0051] In one possible implementation, the execution layer receives the analysis results from the decision layer, including the identified known threats and potential unknown threats. According to the threat types and severity in the decision results, the execution layer selects the corresponding policy template from the policy library. The execution layer implements specific security measures according to the selected policy template, such as blocking malicious IPs, isolating infected hosts, issuing security patches, etc. The execution layer monitors the effect of policy execution to ensure that the measures are correctly implemented. After execution is completed, the execution results are recorded, including the successfully prevented threats, issues that need further processing, etc. The execution results are fed back to the evolution layer for further optimization of the model and updating of the policy template.

[0052] The evolution layer is configured to feed back the execution results to the perception layer and the decision layer to dynamically update the pre-trained anomaly capture model and the pre-trained security risk identification model, respectively.

[0053] The execution results include the execution time, the executed policy template, the execution result, the network state after execution, and the security result. The execution time is the specific time point of executing the security policy. The policy template is a pre-defined security response measure for dealing with a specific type of threat. The execution result is the result after implementing the policy template, such as success, failure, or partial success. The network state after execution is the current state of the network after executing the policy, which can include traffic, connection state, etc. The security result is an evaluation of the network security situation after executing the policy, such as whether the threat has been eliminated. The incremental data set is a data set containing newly collected data and execution results, which is used for model updating.

[0054] In some embodiments of the present application, the specific process of dynamically updating the pre-trained anomaly capture model and the pre-trained security risk identification model includes: associating the execution time, the executed policy template, the execution result, the network state after execution, and the security result as data labels with the multi-source private network data to obtain an incremental data set; and using the incremental data set to fine-tune the pre-trained anomaly capture model and the pre-trained security risk identification model to dynamically update the pre-trained anomaly capture model and the pre-trained security risk identification model.

[0055] In one possible implementation, the execution layer records the execution time (16:25:54), the executed policy template (traffic cleaning), the execution result (partial success), the network state after execution (traffic reduction of 20%), and the security result (attack not completely blocked). These execution data are associated with the multi-source private network data (such as network traffic data, alarm data, etc.) to form an incremental data set. The pre-trained anomaly capture model and the security risk identification model are fine-tuned using the incremental data set to identify the characteristics of this new type of DDoS attack. The model parameters are updated to enable more accurate identification and evaluation of this new type of attack.

[0056] In the embodiments of the present application, on the one hand, the perception layer can fit the multi-source private network data by using the pre-trained anomaly capture model, the multi-source private network data has related parameter information of unknown threats, and the decision layer can input these multi-source private network data into a security risk identification model, which is trained based on historical data and known attack patterns, so as to effectively identify abnormal data and abnormal patterns, so that the smart city private communication network can defend against potential security threats, thereby reducing the risk of unknown attacks. On the other hand, the evolution layer feeds back the execution result to the perception layer and the decision layer, and dynamically updates the anomaly capture model and the security risk identification model. The feedback mechanism enables the system to continuously learn and evolve according to the latest execution results to adapt to the changing network environment.

[0057] Please refer to Figure 5 A flowchart of a dynamic security protection method for a smart city private communication network is provided for the embodiments of the present application. As shown in the figure, the method of the embodiments of the present application can include the following steps: S101, acquiring and preprocessing a plurality of network data related to the smart city private communication network by using a pre-trained anomaly capture model to obtain multi-source private network data; In some embodiments of the present application, the smart city private communication network is taken as the target; at least network traffic, network attack events, and host controlled events related to the target are collected and standardized from the equal protection equipment and the security perception management platform as the first network data according to a preset period; at least fault data, alarm data, logs, and terminal detection data are collected and standardized from the host class, network equipment class, and application program class in the network infrastructure of the target as the second network data according to a preset period; actual business scenario data is collected and standardized from the terminal class equipment and external platforms connected to the target as the third network data according to a preset period; global threat intelligence information is obtained and standardized from the external threat intelligence platform as the fourth network data; the first network data, the second network data, the third network data, and the fourth network data are subjected to data correlation analysis to obtain situation data; and the situation data is input into the pre-trained anomaly capture model to capture abnormal data and abnormal patterns in the situation data, and the multi-source private network data corresponding to the situation data is output.

[0058] S102, inputting the multi-source private network data into a pre-trained security risk identification model to output decision results corresponding to the multi-source private network data; the pre-trained security risk identification model is obtained based on historical multi-source data and known attack patterns; S103, when the decision results indicate that there are known threats or potential unknown threats in the smart city private communication network, executing a strategy template of the decision results to obtain execution results; S104, according to the execution result, dynamically updating the pre-trained anomaly capture model and the pre-trained security risk identification model respectively.

[0059] The execution result includes execution time, executed policy template, execution result, network state after execution, and security result.

[0060] In some embodiments of the present application, the specific process of dynamically updating the pre-trained anomaly capture model and the pre-trained security risk identification model according to the execution result includes: associating the execution time, the executed policy template, the execution result, the network state after execution, and the security result with the multi-source private network data as data labels to obtain an incremental data set; and fine-tuning the pre-trained anomaly capture model and the pre-trained security risk identification model using the incremental data set to dynamically update the pre-trained anomaly capture model and the pre-trained security risk identification model.

[0061] For example Figure 6 As shown, Figure 6 is a process schematic block diagram of a dynamic security protection process of a smart city special communication network provided by the present application. The smart city special communication network is taken as the target; at least including network traffic, network attack events, and host controlled events related to the target are collected and standardized from the equal protection equipment and the security perception management platform according to a preset period as first network data; at least including fault data, alarm data, logs, and terminal detection data are collected and standardized from the host class, network equipment class, and application program class in the network infrastructure of the target according to a preset period as second network data; actual business scenario data are collected and standardized from the terminal class equipment and external platforms connected to the target according to a preset period as third network data; global threat intelligence information is obtained and standardized from the external threat intelligence platform as fourth network data; the first network data, the second network data, the third network data, and the fourth network data are subjected to data correlation analysis to obtain situation data; the situation data is input into a pre-trained anomaly capture model to capture abnormal data and abnormal patterns in the situation data, and multi-source private network data corresponding to the situation data is output. The multi-source private network data is input into a pre-trained security risk identification model, and decision results corresponding to the multi-source private network data are output; the pre-trained security risk identification model is obtained based on historical multi-source data and known attack patterns; when the decision results indicate that there is a known threat or a potential unknown threat in the smart city special communication network, a policy template of the decision results is executed to obtain execution results; according to the execution results, the pre-trained anomaly capture model and the pre-trained security risk identification model are dynamically updated respectively.

[0062] In the embodiments of the present application, on the one hand, the pre-trained anomaly capture model can fit the multi-source private network data. The multi-source private network data has relevant parameter information of unknown threats. These multi-source private network data can be input into the security risk identification model. The model is trained based on historical data and known attack patterns, and can effectively identify abnormal data and abnormal patterns, so that the smart city private communication network can defend against potential security threats, thereby reducing the risk of unknown attacks. On the other hand, the execution result can dynamically update the anomaly capture model and the security risk identification model. The feedback mechanism enables the system to continuously learn and evolve according to the latest execution results to adapt to the changing network environment.

[0063] See Figure 7 A method flowchart of an anomaly capture model training method is provided for the embodiments of the present application. As shown in the figure, the method of the embodiments of the present application can include the following steps: S201, collecting historical multi-source data from the smart city private communication network; S202, data cleaning and data normalization of the historical multi-source data; S203, data correlation analysis of the normalized historical multi-source data to obtain historical situation data; S204, determining the known historical normal behavior and its related data set, historical abnormal mode and its related data set corresponding to the historical multi-source data; S205, marking the known historical normal behavior and its related data set, historical abnormal mode and its related data set on the historical situation data to obtain the first model training sample; the related data set of the historical abnormal mode includes historical severity and historical context information; S206, creating an anomaly capture model using a neural network; S207, inputting the first model training sample into the anomaly capture model to output the first model loss value; in the case that the first model loss value reaches the minimum, a pre-trained anomaly capture model is generated.

[0064] In some embodiments, in the case that the first model loss value does not reach the minimum, the step of inputting the first model training sample into the anomaly capture model is continued until the first model loss value reaches the minimum.

[0065] In the embodiments of the present application, on the one hand, the pre-trained anomaly capture model can fit the multi-source private network data. The multi-source private network data has relevant parameter information of unknown threats. These multi-source private network data can be input into the security risk identification model. The model is trained based on historical data and known attack patterns, and can effectively identify abnormal data and abnormal patterns, so that the smart city private communication network can defend against potential security threats, thereby reducing the risk of unknown attacks. On the other hand, the execution result can dynamically update the anomaly capture model and the security risk identification model. The feedback mechanism enables the system to continuously learn and evolve according to the latest execution results to adapt to the changing network environment.

[0066] See Figure 8 A method flowchart of a security risk identification model training method is provided for the embodiments of the present application. As shown in the figure, the method of the embodiments of the present application can include the following steps: S301, collecting historical multi-source data from the smart city private communication network; S302, data cleaning and data normalization are performed on the historical multi-source data; S303, data correlation analysis is performed on the normalized historical multi-source data to obtain historical situation data; S304, input the historical situation data into the pre-trained anomaly capture model to output the historical multi-source private network data corresponding to the historical situation data; S305, for the historical multi-source private network data, mark each historical abnormal mode and mark the historical threat category and historical strategy template of each historical abnormal mode using known attack patterns to obtain second model training samples; S306, create a security risk identification model using a neural network; S307, input the second model training samples into the security risk identification model to output a second model loss value; in the case where the second model loss value reaches the minimum, a pre-trained security risk identification model is generated.

[0067] In some embodiments, in the case where the second model loss value does not reach the minimum, the step of inputting the second model training samples into the security risk identification model is continued until the second model loss value reaches the minimum.

[0068] In the embodiments of the present application, on the one hand, the pre-trained anomaly capture model can fit the multi-source private network data, the multi-source private network data has related parameter information of unknown threats, and the multi-source private network data can be input into the security risk identification model. The model is trained based on historical data and known attack patterns, can effectively identify abnormal data and abnormal patterns, enables the smart city private communication network to defend against potential security threats, thereby reducing the risk of unknown attacks. On the other hand, the execution result can dynamically update the anomaly capture model and the security risk identification model. The feedback mechanism enables the system to continuously learn and evolve according to the latest execution results to adapt to the changing network environment.

[0069] A person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiments can be completed by a computer program instructing related hardware. The program for dynamic security protection of the smart city private communication network can be stored in a computer readable storage medium. When the program is executed, it can include the processes of the above-mentioned embodiments. The storage medium of the program for dynamic security protection of the smart city private communication network can be a disk, an optical disk, a read-only memory, a random access memory, etc.

[0070] The above only discloses the preferred embodiments of the present application, and of course cannot limit the scope of the rights of the present application. Therefore, equivalent changes made according to the claims of the present application are still within the scope of the present application.

Claims

1. A dynamic security protection system for a smart city dedicated communication network, characterized in that: The system includes: a perception layer, a decision layer, an execution layer, and an evolution layer; The perception layer is used to collect and pre-process various network data related to the smart city dedicated communication network through a pre-trained anomaly capture model to obtain multi-source private network data; The decision layer is used to input the multi-source private network data into a pre-trained security risk identification model and output a decision result corresponding to the multi-source private network data; the pre-trained security risk identification model is obtained based on historical multi-source data and known attack patterns; The execution layer is configured to execute the policy template of the decision result to obtain an execution result when the decision result indicates that a known threat or a potential unknown threat exists in the smart city dedicated communication network; The evolution layer is used to feed back the execution results to the perception layer and the decision layer, so as to dynamically update the pre-trained anomaly capture model and the pre-trained security risk identification model respectively.

2. The system according to claim 1, wherein: The method collects and pre-processes various network data related to the smart city private communication network to obtain multi-source private network data, including: Targeting the smart city dedicated communication network; Collecting and standardizing at least network traffic, network attack events, and host controlled events related to the target from the security protection equipment and the security perception management platform according to a preset period as first network data; Collecting and standardizing at least fault data, alarm data, logs, and terminal detection data from the host class, network device class, and application class in the target network infrastructure according to a preset period as second network data; Collecting and standardizing actual business scenario data from terminal devices and external platforms connected to the target as third network data according to a preset period; Obtain and standardize global threat intelligence information from external threat intelligence platforms as the fourth network data; Performing data correlation analysis on the first network data, the second network data, the third network data, and the fourth network data to obtain situation data; The situation data is input into the pre-trained anomaly capture model to capture abnormal data and abnormal patterns in the situation data, and multi-source private network data corresponding to the situation data is output.

3. The system according to claim 2, characterized in that Performing data association analysis on the first network data, the second network data, the third network data, and the fourth network data to obtain situation data includes: Correlating the network attack events in the first network data with the alarm data in the second network data based on the timestamp and the event type to identify an existing attack path; Correlating the network traffic data in the first network data with the actual business scenario data in the third network data to analyze the relationship between traffic anomalies and business activities; Correlating the fault data in the second network data with the threat intelligence information in the fourth network data to identify known threats; Analyzing detailed information of the host controlled events in the first network data and log data in the second network data to determine a behavior pattern of the controlled host; Associating the terminal detection data in the third network data with the threat intelligence information in the fourth network data to identify threat information faced by the terminal device; Correlating network traffic data in the first network data with global threat intelligence information in the fourth network data to analyze whether there are characteristics of known threats in the traffic; All the results obtained from the above associations are integrated to obtain a unified situation data set.

4. The system according to claim 2, wherein: The pre-trained anomaly capture model includes a feature extraction layer, anomaly pattern analysis layer, severity quantification layer, context information acquisition layer, and data output layer; Inputting the situation data into the pre-trained anomaly capture model and outputting multi-source private network data corresponding to the situation data includes: The feature extraction layer extracts network traffic features, network attack event features, host controlled event features, terminal detection data features, and threat intelligence information features present in the situation data to obtain a multi-source feature set; The abnormal pattern analysis layer uses the multi-source feature set to perform abnormal pattern analysis to identify abnormal patterns of the smart city dedicated communication network; the abnormal patterns include at least abnormal behaviors in network attack events, abnormal behaviors in host-controlled events, abnormal behaviors in terminal devices, and abnormal information in threat intelligence; The severity quantification layer quantifies the severity of each abnormal pattern; The context information acquisition layer acquires the network devices, terminal devices, and business systems involved in each abnormal pattern to obtain context information; The data output layer outputs each abnormal pattern, the severity of each abnormal pattern, and context information as multi-source private network data corresponding to the situation data.

5. The system according to claim 1, wherein: Follow these steps to generate a pre-trained anomaly catching model, including: Collect historical multi-source data from the smart city’s dedicated communication network; Performing data cleaning and data normalization on the historical multi-source data; Perform data correlation analysis on normalized historical multi-source data to obtain historical situation data; Determining known historical normal behaviors and their associated data sets, and historical abnormal patterns and their associated data sets corresponding to the historical multi-source data; For the historical situation data, mark known historical normal behaviors and their related data sets, historical abnormal patterns and their related data sets to obtain first model training samples; the related data sets of historical abnormal patterns include historical severity and historical context information; Use neural networks to create anomaly capture models; The first model training sample is input into the anomaly capture model, and a first model loss value is output; when the first model loss value reaches the minimum, a pre-trained anomaly capture model is generated.

6. The system according to claim 1, wherein: The multi-source private network data includes each abnormal pattern, the severity of each abnormal pattern, and contextual information; the pre-trained security risk identification model includes a feature extraction layer, a parameter quantization layer, a weighted summation layer, an abnormal pattern marking layer, a policy template acquisition layer, and a decision-making result output layer; Inputting the multi-source private network data into a pre-trained security risk identification model and outputting a decision result corresponding to the multi-source private network data includes: The feature extraction layer maps each abnormal pattern into a discrete code, normalizes the severity of each abnormal pattern to a range of 0-1, and performs embedding vector conversion on the context information of each abnormal pattern to obtain a unified target feature vector; The parameter quantification layer quantifies the asset importance score, the current threat probability and the potential harm degree based on the target feature vector; The weighted summation layer performs weighted summation on the asset importance score, the current threat occurrence probability, and the potential harm degree to obtain a comprehensive risk score for each abnormal pattern; The abnormal pattern marking layer marks each abnormal pattern as a high-risk known threat when the comprehensive risk score is greater than the upper limit of the preset risk threshold interval; or marks each abnormal pattern as a medium-risk known threat when the comprehensive risk score is within the preset risk threshold interval; or marks each abnormal pattern as a potential unknown threat when the comprehensive risk score is less than the lower limit of the preset risk threshold interval and the similarity between each abnormal pattern and a known attack pattern is greater than a preset difference threshold; The policy template acquisition layer obtains the target policy template corresponding to the high-risk known threat, the medium-risk known threat, or the potential unknown threat from the pre-established mapping relationship between the threat category and the policy template, as the decision result corresponding to the multi-source private network data; The decision result output layer outputs the decision results corresponding to the multi-source private network data.

7. The system according to claim 6, characterized in that The target policy template corresponding to the high-risk known threat is composed of an immediate blocking strategy, an isolation strategy, and an evidence collection strategy. The target policy template corresponding to the medium-risk known threat is composed of a current limiting strategy, an alarm strategy, and a patch push strategy. The target policy template corresponding to the unknown threat is composed of a sandbox deep analysis strategy and a behavior monitoring strategy. The asset importance score The calculation formula is: in, and is the weight coefficient, which is used to adjust the impact of context information and severity on the asset importance score. is the embedding vector of the context information in the target feature vector, is the normalized result of the severity of the abnormal pattern in the target feature vector; The probability of the current threat occurring The calculation formula is: in, and Is the weight coefficient, used to adjust the impact of abnormal patterns and severity on the probability of threat occurrence, is the discrete encoding of the abnormal pattern in the target feature vector, is the normalized result of the severity of the abnormal pattern in the target feature vector, It is the Sigmoid function, which is used to map the calculation results to the range of 0-1; The potential hazard It can be calculated by the following formula: in, and is a weight coefficient used to adjust the impact of context information and severity on the potential harm degree. is the embedding vector of the context information in the target feature vector, is the normalized result of the severity of the abnormal pattern in the target feature vector.

8. The system according to claim 1, wherein: Follow these steps to generate a pre-trained security risk identification model, including: Collect historical multi-source data from the smart city’s dedicated communication network; Performing data cleaning and data normalization on the historical multi-source data; Perform data correlation analysis on normalized historical multi-source data to obtain historical situation data; Inputting the historical situation data into the pre-trained anomaly capture model, and outputting historical multi-source private network data corresponding to the historical situation data; For the historical multi-source private network data, each historical abnormal pattern is marked with a known attack pattern, and a historical threat category and a historical policy template are marked for each historical abnormal pattern to obtain a second model training sample; Use neural networks to create a security risk identification model; The second model training sample is input into the security risk identification model, and a second model loss value is output; when the second model loss value reaches the minimum, a pre-trained security risk identification model is generated.

9. The system according to claim 1, wherein: The execution result includes the execution time, the executed policy template, the execution result, the network status after execution and the security result; The dynamically updating of the pre-trained anomaly capture model and the pre-trained security risk identification model includes: Associating the execution time, executed policy template, execution result, network status after execution, and security result as data tags with the multi-source private network data to obtain an incremental data set; The incremental data set is used to fine-tune the pre-trained anomaly capture model and the pre-trained security risk identification model to dynamically update the pre-trained anomaly capture model and the pre-trained security risk identification model.

10. A dynamic security protection method for a smart city dedicated communication network implemented by the system according to any one of claims 1 to 9, characterized in that: The method comprises: Through the pre-trained anomaly capture model, various network data related to the smart city private communication network are collected and pre-processed to obtain multi-source private network data; Inputting the multi-source private network data into a pre-trained security risk identification model and outputting a decision result corresponding to the multi-source private network data; the pre-trained security risk identification model is obtained by training based on historical multi-source data and known attack patterns; When the decision result indicates that a known threat or a potential unknown threat exists in the smart city dedicated communication network, executing the policy template of the decision result to obtain an execution result; According to the execution results, the pre-trained anomaly capture model and the pre-trained security risk identification model are dynamically updated respectively.

Citation Information

Patent Citations

  • Active defense system and method for unknown threats

    CN116760636A

  • Network information security protection system

    CN118353702A

  • Network security evaluation system and method based on dynamic attack and defense game model

    CN119544307A

  • Network risk assessment method and system based on multi-modal data pre-training model

    CN119814354A

  • Active defense system and method for unknown threat

    US20250286906A1