Intelligent security management system and method based on big data

By constructing an intelligent security management system based on big data, the problem of insufficient collaborative analysis of multi-source heterogeneous data in traditional security systems has been solved. This enables intelligent management of the entire process of security events, improves the perception capability and decision-making accuracy of the security system, reduces the false alarm rate, and ensures the credibility of alarm information.

CN120875587BActive Publication Date: 2025-12-16WUHAN CITY VOCATIONAL COLLEGE +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511390501.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-26
Publication Date
2025-12-16
Estimated Expiration
2045-09-26

AI Technical Summary

Technical Problem

Traditional security systems lack collaborative analysis mechanisms for multi-source heterogeneous data, resulting in severe information silos, high false alarm rates, difficulty in achieving autonomous learning and forward-looking prediction, and an inability to transform from passive response to proactive early warning.

Method used

A big data-based intelligent security management system is constructed. It receives real-time data streams from multiple heterogeneous security data sources in parallel, extracts feature indicators, calculates instantaneous signal-to-noise ratio and historical alarm accuracy, uses a multimodal collaborative rule base for real-time reasoning and credibility adjustment, generates high-credibility feature combinations, performs saliency verification with historical databases, and finally generates disposal instructions.

Benefits of technology

It enables intelligent management of the entire security incident process, improves the coverage and sensitivity of perception, reduces false alarm and missed alarm rates, improves the accuracy and robustness of risk identification, ensures the credibility of alarm information, and achieves seamless connection from risk perception to emergency response.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120875587B_ABST
    Figure CN120875587B_ABST
Patent Text Reader

Abstract

The application provides a kind of big data-based intelligent security management system and method, it is related to intelligent security technical field, the application first on the basis of multidimensional environment perception, introduce independent reliability calculation model, for each characteristic index is endowed with a comprehensive reliability evaluation value that can reflect both current environmental conditions and can reflect its historical performance, then, multimodal collaborative rule base and the real-time inference mechanism based thereon can simulate the thinking mode of human experts, in-depth mining the internal relationship between different characteristic indexes, and accordingly adjust the preliminary reliability, improve the accuracy of risk identification under complex scene, second, through the significance verification based on causal association strength, can effectively distinguish real security threat and accidental abnormal fluctuation, finally, by mapping matching the verification result with preset strategy library, automatically, quickly generate disposal instruction, realize the automatic closed-loop management from risk perception to emergency response.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of intelligent security and protection, and particularly relates to an intelligent security and protection management system and method based on big data. BACKGROUND

[0002] At present, the demand for social public safety is increasing, and the intelligent upgrading of security and protection management systems has become an inevitable trend to protect key infrastructure, commercial sites and residential communities. The traditional security and protection system usually relies on single or limited types of sensors for isolated event monitoring, and its data processing method is mostly simple rule judgment based on fixed thresholds, which leads to significant limitations of the system. For multi-source security and protection systems, there is a lack of effective collaborative analysis mechanism between multi-source heterogeneous data, and the massive information generated by each data source cannot be deeply fused and correlated, resulting in a serious information island phenomenon. Due to environmental interference, equipment errors or accidental factors, the false alarm rate is high, and a large number of false alarms not only consume valuable security resources, but also may cause real threats to be submerged in frequent false alarms. In addition, the judgment of potential risks in traditional systems is usually lagging and dependent on human experience, lacking the ability of autonomous learning and forward-looking prediction based on historical big data, and it is difficult to realize the transformation from passive response to active early warning. In order to overcome these defects, the industry has gradually explored the use of big data and artificial intelligence technology to improve the accuracy and reliability of security and protection management. However, existing solutions mostly focus on deep model optimization of single data stream or simple data splicing at the decision-making level, and have not yet formed a complete method of real-time unified credibility assessment of multi-modal data, cross-validation and significance decision based on historical evidence.

[0003] Therefore, it is necessary to provide an intelligent security and protection management system and method based on big data to solve the above technical problems. SUMMARY

[0004] To solve the above technical problems, the present application provides an intelligent security and protection management system and method based on big data, which achieves the beneficial effects of real-time unified credibility assessment of multi-modal data and cross-validation and significance decision based on historical evidence.

[0005] The present application provides an intelligent security and protection management method based on big data, comprising:

[0006] S1: parallelly receiving real-time data streams from multiple heterogeneous security and protection data sources, and extracting feature indicators of each real-time data stream;

[0007] S2: calculating the instantaneous signal-to-noise ratio of each feature indicator, and based on historical security and protection big data, obtaining the alarm accuracy of each feature indicator corresponding to the security and protection data source in the same period in history, and calculating the independent credibility of each feature indicator based on the instantaneous signal-to-noise ratio and the alarm accuracy;

[0008] S3: Input all feature indicators and their independent credibility into a pre-built multimodal collaborative rule base for real-time reasoning to obtain a list of credibility adjustment instructions;

[0009] S4: Adjust the independent credibility of each feature indicator based on the credibility adjustment instruction list to obtain the comprehensive credibility of each feature indicator;

[0010] S5: Based on the comprehensive credibility, generate a high credibility feature combination, and perform saliency verification between the high credibility feature combination and a pre-built historical feature fragment database to obtain the verification results;

[0011] S6: Map and match the verification results with the pre-built security strategy library to obtain the risk event type and risk level, and generate handling instructions based on the risk event type and risk level.

[0012] Preferably, in step S1, the feature indicators include the rate of change of personnel density extracted from the video data stream, the abnormal sound intensity value extracted from the audio data stream, and the vibration intensity extracted from the vibration sensor data stream.

[0013] Preferably, in step S2, the formula for calculating the independence confidence level is:

[0014] ;

[0015] in, For independent credibility, For instantaneous signal-to-noise ratio, The maximum signal-to-noise ratio of the system. To improve alarm accuracy, This is the preset weight adjustment factor.

[0016] Preferably, in step S3, the rules in the multimodal collaborative rule base are defined using production rule notation, and the defined rules include:

[0017] Each rule consists of a condition part and an execution part;

[0018] The condition part is the logical combination relationship between different feature indicators, and the execution part is the instruction to adjust the credibility of specific feature indicators;

[0019] The adjustment instructions include increasing credibility, decreasing credibility, and assigning a new value to credibility.

[0020] Preferably, the rules in the multimodal collaborative rule base include supporting rules, contradictory rules, and derived rules, wherein the rule content includes:

[0021] The supported rule is to increase the credibility of another feature indicator when one feature indicator appears;

[0022] The contradictory rule states that when one feature indicator appears, the credibility of the other feature indicator is reduced.

[0023] The derivation rule generates a new credibility of a high-risk event when multiple feature indicators appear simultaneously.

[0024] Preferably, the rules in the multimodal collaborative rule base are automatically generated after analyzing historical security big data through an association rule mining algorithm.

[0025] Preferably, in step S5, the high credibility feature combination is a set composed of all feature indicators whose overall credibility is greater than a preset credibility threshold.

[0026] Preferably, in step S5, the significance verification step includes:

[0027] From the pre-built historical feature fragment database, retrieve all historical feature fragments that contain feature indexes that are completely consistent with the current high-confidence feature combination, and in which the comprehensive confidence level of each feature index is greater than the preset confidence level threshold, and combine them into a historical feature fragment set.

[0028] The proportion of historical feature fragments in the statistical feature fragment set that are marked as real security events is used as the causal association strength of the current high-confidence feature combination;

[0029] The strength of the causal association is compared with a preset significance threshold to obtain the verification results.

[0030] Preferably, in step S6, the security strategy library is a mapping table that defines the correspondence between different verification results and risk event types, risk levels, and handling instructions.

[0031] This invention provides an intelligent security management system based on big data, applied to an intelligent security management method based on big data, comprising:

[0032] The feature index extraction module is used to receive real-time data streams from multiple heterogeneous security data sources in parallel and extract feature indicators from each real-time data stream.

[0033] The independent credibility calculation module is used to calculate the instantaneous signal-to-noise ratio of each feature indicator, and based on historical security big data, obtain the alarm accuracy rate of the security data source corresponding to each feature indicator in the same historical period, and calculate the independent credibility of each feature indicator based on the instantaneous signal-to-noise ratio and alarm accuracy rate.

[0034] The multimodal collaborative reasoning module is used to input all feature indicators and their independent credibility into a pre-built multimodal collaborative rule base for real-time reasoning to obtain a list of credibility adjustment instructions.

[0035] The credibility adjustment module is used to adjust the independent credibility of each feature indicator based on the credibility adjustment instruction list to obtain the comprehensive credibility of each feature indicator.

[0036] The feature combination saliency verification module is used to generate high-confidence feature combinations based on comprehensive confidence, and to perform saliency verification between the high-confidence feature combinations and a pre-built historical feature fragment database to obtain the verification results.

[0037] The strategy mapping and instruction generation module is used to map and match the verification results with the pre-built security strategy library to obtain the risk event type and risk level, and generate disposal instructions based on the risk event type and risk level.

[0038] Compared with related technologies, the intelligent security management system and method based on big data provided by this invention has the following beneficial effects:

[0039] This invention constructs an intelligent analysis and decision-making framework that deeply integrates real-time multimodal sensing data with historical security big data. This framework enables intelligent management of the entire process of security incidents, from perception and analysis to handling. First, by receiving and processing real-time data streams from various heterogeneous data sources such as video, audio, and vibration sensors in parallel, and extracting key feature indicators, the foundation for multi-dimensional environmental perception is laid. This allows the system to capture various characteristic signals of potential threats, avoiding the perception blind spots or false alarms that may exist with single sensors, and improving the coverage and perception sensitivity of security monitoring. Secondly, an independent credibility calculation model is introduced, which dynamically weights and fuses the instantaneous signal-to-noise ratio (SNR), reflecting real-time data quality, with the historical alarm accuracy rate, representing the long-term reliability of the data source. This assigns each feature indicator a comprehensive credibility evaluation value that reflects both the current environmental conditions and its historical performance. This mechanism enables the system to intelligently identify and weigh the value of different data sources, effectively filtering unreliable data caused by factors such as momentary equipment failures and brief environmental interference. This provides a more solid and accurate data foundation for subsequent high-level decision-making. Furthermore, the constructed multimodal collaborative rule base and the real-time reasoning mechanism based on it can simulate the thinking patterns of human experts, deeply exploring the inherent support, contradictions, or... The system derives relationships and dynamically adjusts and optimizes the initial credibility accordingly. This process represents a leap from judging isolated data to fusing related information, enabling the system to identify complex event patterns that cannot be detected by a single indicator. This improves the accuracy and robustness of risk identification in complex scenarios. Next, by generating high-credibility feature combinations based on comprehensive credibility, and further verifying them against a pre-built database of historical feature fragments based on the strength of causal relationships, this method compares the current real-time situation with historical experience, effectively distinguishing between real security threats and accidental abnormal fluctuations. This verification process, driven by historical big data, reduces the system's false alarm and false negative rates, ensuring the high credibility of alarm information. Finally, by mapping and matching the verification results with a pre-set strategy library, the system can automatically and quickly generate handling instructions that precisely correspond to the type and level of risk events. This achieves seamless integration and automated closed-loop management from risk perception to emergency response. This not only improves emergency response speed and reduces the workload of security personnel, but more importantly, it enhances the efficiency and reliability of the overall security management system through scientific and precise decision support. Attached Figure Description

[0040] Figure 1 This is a flowchart of an intelligent security management method based on big data according to the present invention;

[0041] Figure 2 This is a module structure diagram of an intelligent security management system based on big data according to the present invention. Detailed Implementation

[0042] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, only the parts relevant to the invention are shown in the drawings, not all structures. Moreover, unless otherwise specified, the embodiments and features described herein can be combined with each other.

[0043] It should also be noted that, for ease of description, the accompanying drawings show only the parts relevant to the invention and not all of them. Before discussing exemplary embodiments in more detail, it should be mentioned that some exemplary embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts describe operations (or steps) as being processed sequentially, many of these operations can be performed in parallel, concurrently, or simultaneously. Furthermore, the order of the operations can be rearranged. The process can be terminated when its operation is completed, but it may also have additional steps not included in the drawings. The process may correspond to a method, function, procedure, subroutine, subprogram, etc.

[0044] Example 1

[0045] A big data-based intelligent security management method, in its specific implementation process, such as... Figure 1 As shown, a flowchart of a big data-based intelligent security management method according to the present invention is illustrated, including:

[0046] Step S1: Receive real-time data streams from multiple heterogeneous security data sources in parallel and extract the characteristic indicators of each real-time data stream.

[0047] Specifically, in step S1, the feature indicators include the rate of change of personnel density extracted from the video data stream, the abnormal sound intensity value extracted from the audio data stream, and the vibration intensity extracted from the vibration sensor data stream.

[0048] In the specific implementation process, firstly, multiple types of sensor devices deployed in different physical locations simultaneously collect video surveillance data, audio monitoring data, and vibration sensing data to form a multi-source heterogeneous real-time security data stream. These data streams are transmitted in parallel to the central processing system through dedicated communication protocols and data interfaces. The system allocates an independent data receiving thread for each data stream to ensure high concurrency processing capabilities and avoid data blocking. Subsequently, feature index extraction is performed on each real-time data stream. For example, for the video data stream, a background subtraction algorithm combined with pixel statistics methods is used to calculate the rate of change of the pixel area occupied by moving targets between consecutive frames, thereby obtaining... For the personnel density change rate characteristic index, the audio data stream is converted from the time domain signal to the frequency domain signal using short-time Fourier transform. Then, the spectral energy is integrated within a pre-defined abnormal sound intensity frequency band to obtain the abnormal sound intensity value characteristic index. For the vibration sensor data stream, the vibration intensity characteristic index is quantified by calculating the root mean square value of the time domain signal within a fixed time window. All these characteristic index extraction processes are completed within a unified time window to ensure timing alignment. Finally, the system outputs a set of multi-dimensional characteristic indicators including personnel density change rate, abnormal sound intensity value, and vibration intensity to provide standardized data input for subsequent processing stages.

[0049] Step S2: Calculate the instantaneous signal-to-noise ratio of each feature indicator, and based on historical security big data, obtain the alarm accuracy rate of the security data source corresponding to each feature indicator in the same historical period. Calculate the independent credibility of each feature indicator based on the instantaneous signal-to-noise ratio and alarm accuracy rate.

[0050] Specifically, in step S2, the formula for calculating the independence confidence level is:

[0051]

[0052] in, For independent credibility, For instantaneous signal-to-noise ratio, The maximum signal-to-noise ratio of the system. To improve alarm accuracy, This is the preset weight adjustment factor.

[0053] In the specific implementation process, the instantaneous signal-to-noise ratio (SNR) is first calculated for three characteristic indicators: the rate of change in personnel density extracted from the video data stream, the abnormal sound intensity value extracted from the audio data stream, and the vibration intensity extracted from the vibration sensor data stream. The instantaneous SNR quantifies the current signal quality by calculating the ratio of the power of the characteristic indicator signal to the background noise power. The system's maximum SNR is pre-defined as the highest SNR level achievable under ideal operating conditions through long-term monitoring of each data source and is set as a system constant. Simultaneously, the system analyzes historical security big data. For each characteristic indicator's corresponding security data source, it first determines the historical time period corresponding to the current moment, exemplified by the same workday, etc. The system identifies holiday types and time periods, then calculates the proportion of confirmed real alarm events among all alarm records from this data source within the same historical time period as the alarm accuracy rate for that period. Finally, the system uses an independent credibility calculation formula to weight and fuse the instantaneous signal-to-noise ratio with the alarm accuracy rate for the same historical period. The weight adjustment factor is a preset value used to dynamically adjust the relative importance of real-time signal quality and historical reliability in credibility assessment. The independent credibility value calculated by this formula reflects both the signal quality of the characteristic indicators at the current moment and incorporates the reliability assessment of the data source in the historical performance of the same period, providing a standardized credibility input with quantitative evaluation for subsequent multimodal collaborative inference.

[0054] Step S3: Input all feature indicators and their independent credibility into the pre-built multimodal collaborative rule base for real-time reasoning to obtain a list of credibility adjustment instructions.

[0055] Specifically, in step S3, the rules in the multimodal collaborative rule base are defined using production rule notation, and the defined rules include:

[0056] Each rule consists of a condition part and an execution part;

[0057] The condition part is the logical combination relationship between different feature indicators, and the execution part is the instruction to adjust the credibility of specific feature indicators;

[0058] The adjustment instructions include increasing credibility, decreasing credibility, and assigning a new value to credibility.

[0059] Specifically, the rules include:

[0060] The supported rule is to increase the credibility of another feature indicator when one feature indicator appears;

[0061] The contradictory rule states that when one feature indicator appears, the credibility of the other feature indicator is reduced.

[0062] The derivation rule generates a new credibility of a high-risk event when multiple feature indicators appear simultaneously.

[0063] Specifically, the rules in the multimodal collaborative rule base are automatically generated after analyzing historical security big data through an association rule mining algorithm.

[0064] In the specific implementation process, each feature indicator and its independent credibility are input into a pre-built multimodal collaborative rule base for real-time reasoning. This pre-built multimodal collaborative rule base is defined using a production rule notation method. Each rule consists of a clearly defined condition part and an execution part. The condition part defines the complex logical combination relationship between multiple feature indicators. For example, when the rate of change of personnel density extracted from the video data stream exceeds a preset personnel density change threshold and the abnormal sound intensity value extracted from the audio data stream also exceeds a preset sound intensity threshold, or when the vibration intensity extracted from the vibration sensor data stream increases sharply but the rate of change of personnel density shows no personnel activity, the execution part precisely specifies the instruction to be triggered to adjust the credibility of specific feature indicators when the conditions are met, including increasing credibility, decreasing credibility, and assigning a new value to credibility. The rule types in the rule base include supporting rules, contradictory rules, and derived rules. For example, when the rate of change of personnel density extracted from the video data stream exceeds a preset personnel density change threshold and the abnormal sound intensity value extracted from the audio data stream also exceeds a preset sound intensity threshold, the execution instruction is to increase the credibility of these two feature indicators. This is a typical example. The system employs several rules to reinforce the credibility of mutually corroborating features. Conversely, when a surge in vibration intensity coincides with the absence of personnel activity, the execution instruction reduces the credibility of the personnel density change rate indicator. This contradictory rule weakens the credibility of logically inconsistent features. More complex derivative rules stipulate that when a specific combination of three feature indicators, such as abnormal sound intensity and vibration intensity at a specific frequency, simultaneously meets the conditions, the execution instruction not only adjusts the credibility of these original features but also generates a new synthetic event credibility value representing a "high-risk intrusion attempt." These rules are not manually preset but automatically generated after analyzing historical security big data using an association rule mining algorithm. The algorithm first extracts frequently occurring feature indicator combination patterns from historical events, then calculates the correlation strength between these patterns and real security events, and finally converts strong correlation patterns into production rules stored in the rule base. During real-time inference, the current feature indicators and credibility are matched with the rule conditions. For all successfully matched rules, the system executes the corresponding credibility adjustment instruction and outputs a credibility adjustment instruction list, providing a dynamic adjustment basis for subsequent steps.

[0065] Step S4: Adjust the independent credibility of each feature indicator based on the credibility adjustment instruction list to obtain the comprehensive credibility of each feature indicator.

[0066] In the specific implementation process, the credibility adjustment instruction list is first logically sorted and conflict detected to ensure that the execution order of the instructions conforms to the preset priority strategy. For example, the new event credibility instructions generated by the derived rules are executed first, followed by the adjustment instructions of supporting rules and contradictory rules, to avoid data state chaos caused by improper execution order. Then, each adjustment instruction is executed precisely. If the instruction type is to increase credibility, a preset fixed increment value or a proportionally increased value will be added to the current independent credibility of the corresponding feature indicator. If the instruction type is to decrease credibility, the credibility of the corresponding feature indicator will be reduced according to a preset decay coefficient or a fixed step size. If the instruction type is to assign a new value, the credibility of the feature indicator will be directly reset to the target value specified in the instruction. During the execution of each instruction, the system will check in real time whether the adjusted credibility value exceeds the system's allowed effective range of 0 to 1. For results that exceed the range, the system will automatically truncate them to the boundary value to ensure data validity. After all adjustment instructions have been executed, the final credibility value of each feature indicator after dynamic adjustment is used as its comprehensive credibility output, providing a data foundation for the subsequent steps to generate high-credibility feature combinations.

[0067] Step S5: Based on the overall credibility, generate a high credibility feature combination, and perform saliency verification between the high credibility feature combination and the pre-built historical feature fragment database to obtain the verification results.

[0068] Specifically, in step S5, the high credibility feature combination is a set composed of all feature indicators whose overall credibility is greater than a preset credibility threshold.

[0069] Specifically, in step S5, the significance verification steps include:

[0070] From the pre-built historical feature fragment database, retrieve all historical feature fragments that contain feature indexes that are completely consistent with the current high-confidence feature combination, and in which the comprehensive confidence level of each feature index is greater than the preset confidence level threshold, and combine them into a historical feature fragment set.

[0071] The proportion of historical feature fragments in the statistical feature fragment set that are marked as real security events is used as the causal association strength of the current high-confidence feature combination;

[0072] The strength of the causal association is compared with a preset significance threshold to obtain the verification results.

[0073] In the specific implementation process, firstly, based on the comprehensive credibility of each feature indicator, it is compared one by one with a preset credibility threshold to filter out all feature indicators whose comprehensive credibility values ​​exceed the credibility threshold. These filtered high-credibility indicators are then combined into a feature set representing the current significant abnormal pattern, i.e., a high-credibility feature combination. Subsequently, this feature combination is subjected to in-depth saliency verification with a pre-constructed historical feature fragment database. The saliency verification process is as follows: firstly, all historical data fragments containing feature indicators that are completely consistent with the current high-credibility feature combination and whose historical comprehensive credibility values ​​for each feature indicator are all greater than the same credibility threshold are accurately retrieved from the historical database. These fragments are then aggregated to form a historical feature set. The system first generates a feature fragment set. Then, it performs statistical analysis on the event labeling status of each historical data fragment in the feature fragment set, calculating the proportion of historical fragments explicitly marked as real security events to the total number of fragments in the set. This proportion is defined as the causal correlation strength of the current high-confidence feature combination. Finally, it compares the calculated causal correlation strength with a preset significance threshold. If the causal correlation strength reaches or exceeds the significance threshold, a verification result is generated indicating that the pattern represented by the current feature combination has a high probability of real event occurrence in history. If the causal correlation strength is lower than the significance threshold, a verification result is generated indicating that the current pattern may be a random fluctuation or a false alarm, providing a data foundation for subsequent analysis.

[0074] Step S6: Map and match the verification results with the pre-built security strategy library to obtain the risk event type and risk level, and generate handling instructions based on the risk event type and risk level.

[0075] Specifically, in step S6, the security strategy library is a mapping table that defines the correspondence between different verification results and risk event types, risk levels, and handling instructions.

[0076] In the specific implementation process, the verification results are used as the core input and precisely mapped and matched with a pre-built security strategy library. This security strategy library is essentially a structured multi-dimensional mapping table that fully defines the correspondence between different verification results and specific risk event types, detailed risk levels, and executable handling instructions. After inputting the verification results into the pre-built security strategy library, the system first parses the specific content of the verification results. If the verification results indicate that the causal correlation strength of the current high-confidence feature combination exceeds a preset significance threshold, the system determines it as a valid security threat event. Subsequently, based on the specific numerical range of the verification result, the system performs a precise search and match in the mapping table of the security strategy library. The mapping table is pre-set with risk event types corresponding to different intensity ranges, for example, including but not limited to illegal intrusion, fire alarms, etc. Equipment malfunctions and their subdivided risk levels, for example, including but not limited to high-risk, medium-risk, and low-risk levels; after determining the final risk event type and risk level based on the matching results, the system automatically triggers the generation process of the corresponding handling instructions in the mapping table. These handling instructions include, but are not limited to, sending graded alarm information to the monitoring center, automatically dispatching the nearest security personnel to the incident location, activating the emergency response plan to lock access control equipment in the relevant area, activating on-site audible and visual alarm devices, and linking the fire protection system to enter standby mode. The entire mapping and matching process uses a real-time query mechanism to ensure response speed. The generation of all handling instructions strictly follows the standardized process predefined in the strategy library. Finally, the system outputs a set of standardized handling instructions that meet actual security needs, completing a complete intelligent decision-making closed loop from multimodal data analysis to security response execution.

[0077] The working principle of the intelligent security management method based on big data provided by this invention is as follows:

[0078] This invention constructs an intelligent security decision-making framework based on multi-source heterogeneous data fusion and historical big data. The core of this framework involves receiving real-time data streams from heterogeneous data sources such as video, audio, and vibration sensors in parallel, and extracting feature indicators such as personnel density change rate, abnormal sound intensity, and vibration intensity. First, the instantaneous signal-to-noise ratio of each feature indicator is calculated, and then combined with the historical alarm accuracy rate from the same period to generate an independent credibility score through a weighted fusion formula. This quantifies the real-time quality and historical reliability of the data source. Subsequently, all feature indicators and their independent credibility scores are input into a pre-constructed multimodal collaborative rule base for real-time inference. This rule base adopts a production rule structure and includes support rules for resolving conflicts. The system employs three rule types: shield rules, derived rules, and related rules. These rules are automatically generated from historical big data using association rule mining algorithms. They can dynamically adjust the credibility relationships between feature indicators, obtain comprehensive credibility after adjustment, and select high-credibility feature combinations. Then, the combination is compared with a historical feature fragment database for saliency verification. By retrieving historical fragments that match completely, the proportion of real events is statistically analyzed to obtain the causal association strength, which is then compared with a saliency threshold to generate verification results. Finally, the verification results are matched with a mapping table in the security strategy library to automatically generate specific handling instructions for different risk types and levels, thereby achieving closed-loop management from multimodal perception to intelligent decision-making.

[0079] Example 2

[0080] A big data-based intelligent security management system is applied to a big data-based intelligent security management method. In its specific implementation, for example... Figure 2 As shown, it illustrates a modular structure diagram of a big data-based intelligent security management system according to the present invention, including:

[0081] The feature index extraction module 100 is used to receive real-time data streams from multiple heterogeneous security data sources in parallel and extract feature indicators from each real-time data stream.

[0082] The independent credibility calculation module 200 is used to calculate the instantaneous signal-to-noise ratio of each feature indicator, and based on historical security big data, obtain the alarm accuracy rate of the security data source corresponding to each feature indicator in the same historical period, and calculate the independent credibility of each feature indicator based on the instantaneous signal-to-noise ratio and alarm accuracy rate.

[0083] The multimodal collaborative reasoning module 300 is used to input all feature indicators and their independent credibility into a pre-built multimodal collaborative rule base for real-time reasoning to obtain a list of credibility adjustment instructions.

[0084] The credibility adjustment module 400 is used to adjust the independent credibility of each feature indicator based on the credibility adjustment instruction list to obtain the comprehensive credibility of each feature indicator.

[0085] The feature combination saliency verification module 500 is used to generate high-confidence feature combinations based on comprehensive confidence, and to perform saliency verification between the high-confidence feature combinations and a pre-built historical feature fragment database to obtain the verification results.

[0086] The strategy mapping and instruction generation module 600 is used to map and match the verification results with the pre-built security strategy library to obtain the risk event type and risk level, and generate disposal instructions based on the risk event type and risk level.

[0087] The working principle of the intelligent security management system based on big data provided by this invention is as follows:

[0088] First, the feature extraction module 100 synchronously receives real-time streaming data from heterogeneous data sources such as video, audio, and vibration sensors, and uses feature extraction algorithms to calculate three key indicators: personnel density change rate, abnormal sound intensity value, and vibration intensity. Next, the independent credibility calculation module 200 performs quality assessment on these feature indicators, calculating the instantaneous signal-to-noise ratio to reflect the real-time data quality, and simultaneously querying a historical database to obtain the historical alarm accuracy rate of the same data source during the same time period as a reliability reference. Finally, a weighted fusion formula is used to output the independent credibility of each feature. The multimodal collaborative reasoning module 300 inputs the above indicators and credibility data into a pre-generated rule base for real-time matching. This rule base contains supporting rules, contradictory rules, and derived rules obtained through big data mining. When real-time data meets the rule conditions, corresponding credibility adjustment instructions are automatically generated. The credibility adjustment module 400 executes these instructions to dynamically correct the independent credibility, and obtains a more accurate comprehensive credibility by adding, reducing or resetting operations. The feature combination saliency verification module 500 selects high credibility feature combinations based on the adjusted credibility and performs pattern matching with the historical feature fragment database. It counts the proportion of similar patterns in history that are finally confirmed as real events as the causal correlation strength of the current event. Finally, the strategy mapping and instruction generation module 600 inputs the verification results obtained by comparing the correlation strength value with the preset threshold into the strategy mapping table, automatically matches the corresponding risk type, risk level and disposal instructions, and completes the complete technical closed loop from multimodal data perception to intelligent decision output.

[0089] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the process.Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0090] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, including read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-Erasable Programmable Read-Only Memory (EEPROM), compactdisc read-only memory (CD-ROM) or other optical disc storage, disk storage, magnetic tape storage, or any other computer-readable medium capable of carrying or storing data.

[0091] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

Claims

1. A smart security management method based on big data, characterized in that, The intelligent security management method includes the following steps: S1: Receives real-time data streams from multiple heterogeneous security data sources in parallel and extracts the characteristic metrics of each real-time data stream; S2: Calculate the instantaneous signal-to-noise ratio of each feature indicator, and based on historical security big data, obtain the alarm accuracy rate of the security data source corresponding to each feature indicator in the same historical period, and calculate the independent credibility of each feature indicator based on the instantaneous signal-to-noise ratio and alarm accuracy rate. S3: Input all feature indicators and their independent credibility into a pre-built multimodal collaborative rule base for real-time reasoning to obtain a list of credibility adjustment instructions; S4: Adjust the independent credibility of each feature indicator based on the credibility adjustment instruction list to obtain the comprehensive credibility of each feature indicator; S5: Based on the comprehensive credibility, generate a high credibility feature combination, and perform saliency verification between the high credibility feature combination and a pre-built historical feature fragment database to obtain the verification results; S6: Map and match the verification results with the pre-built security strategy library to obtain the risk event type and risk level, and generate handling instructions based on the risk event type and risk level.

2. The intelligent security management method based on big data according to claim 1, characterized in that, In step S1, the feature indicators include the rate of change of personnel density extracted from the video data stream, the abnormal sound intensity value extracted from the audio data stream, and the vibration intensity extracted from the vibration sensor data stream.

3. The intelligent security management method based on big data according to claim 2, characterized in that, In step S2, the formula for calculating the independence confidence level is: ; in, For independent credibility, For instantaneous signal-to-noise ratio, The maximum signal-to-noise ratio of the system. To improve alarm accuracy, This is the preset weight adjustment factor.

4. The intelligent security management method based on big data according to claim 3, characterized in that, In step S3, the rules in the multimodal collaborative rule base are defined using production rule notation, and the defined rules include: Each rule consists of a condition part and an execution part; The condition part is the logical combination relationship between different feature indicators, and the execution part is the instruction to adjust the credibility of specific feature indicators; The adjustment instructions include increasing credibility, decreasing credibility, and assigning a new value to credibility.

5. The intelligent security management method based on big data according to claim 4, characterized in that, The rules in the multimodal collaborative rule base include supporting rules, contradictory rules, and derived rules, wherein the rule content includes: The supported rule is to increase the credibility of another feature indicator when one feature indicator appears; The contradictory rule states that when one feature indicator appears, the credibility of the other feature indicator is reduced. The derivation rule generates a new credibility of a high-risk event when multiple feature indicators appear simultaneously.

6. The intelligent security management method based on big data according to claim 5, characterized in that, The rules in the multimodal collaborative rule base are automatically generated after analyzing historical security big data using an association rule mining algorithm.

7. The intelligent security management method based on big data according to claim 6, characterized in that, In step S5, the high credibility feature combination is a set of all feature indicators whose overall credibility is greater than a preset credibility threshold.

8. The intelligent security management method based on big data according to claim 7, characterized in that, In step S5, the significance verification steps include: From the pre-built historical feature fragment database, retrieve all historical feature fragments that contain feature indexes that are completely consistent with the current high-confidence feature combination, and in which the comprehensive confidence level of each feature index is greater than the preset confidence level threshold, and combine them into a historical feature fragment set. The proportion of historical feature fragments in the statistical feature fragment set that are marked as real security events is used as the causal association strength of the current high-confidence feature combination; The strength of the causal association is compared with a preset significance threshold to obtain the verification results.

9. The intelligent security management method based on big data according to claim 8, characterized in that, In step S6, the security strategy library is a mapping table that defines the correspondence between different verification results and risk event types, risk levels, and handling instructions.

10. A big data-based intelligent security management system, characterized in that, The intelligent security management system, applicable to any one of claims 1 to 9, comprises: The feature index extraction module is used to receive real-time data streams from multiple heterogeneous security data sources in parallel and extract feature indicators from each real-time data stream. The independent credibility calculation module is used to calculate the instantaneous signal-to-noise ratio of each feature indicator, and based on historical security big data, obtain the alarm accuracy rate of the security data source corresponding to each feature indicator in the same historical period, and calculate the independent credibility of each feature indicator based on the instantaneous signal-to-noise ratio and alarm accuracy rate. The multimodal collaborative reasoning module is used to input all feature indicators and their independent credibility into a pre-built multimodal collaborative rule base for real-time reasoning to obtain a list of credibility adjustment instructions. The credibility adjustment module is used to adjust the independent credibility of each feature indicator based on the credibility adjustment instruction list to obtain the comprehensive credibility of each feature indicator. The feature combination saliency verification module is used to generate high-confidence feature combinations based on comprehensive confidence, and to perform saliency verification between the high-confidence feature combinations and a pre-built historical feature fragment database to obtain the verification results. The strategy mapping and instruction generation module is used to map and match the verification results with the pre-built security strategy library to obtain the risk event type and risk level, and generate disposal instructions based on the risk event type and risk level.

Citation Information

Patent Citations

  • Multi-state distributed passive sensing monitoring method, device and equipment for power distribution cable network

    CN116027146A

  • Multi-modal data fusion method and device and computer equipment

    CN120597187A