Intrusion detection alarm noise reduction and priority dynamic sorting method

By combining large language model technology to standardize, deduplicate, and score data in multiple dimensions, the problems of redundant alarms and insufficient priority ranking in intrusion detection systems are solved, thereby improving the efficiency and accuracy of network security operations.

CN120880869AActive Publication Date: 2025-10-31INFORMATION & COMM CO OF STATE GRID SHAANXI ELECTRIC POWER CO LTD

Patent Information

Application Number
CN202511385427.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-26
Publication Date
2025-10-31
Estimated Expiration
2045-09-26

AI Technical Summary

Technical Problem

Existing intrusion detection systems suffer from redundancy, numerous false alarms, insufficient prioritization, and high costs of manual intervention in alarm processing, making them ineffective in dealing with complex cybersecurity environments.

Method used

By combining Large Language Model (LLM) technology, massive alarm data is intelligently processed to perform data standardization, deduplication, semantic vector encoding, noise identification, and multi-dimensional scoring, thereby achieving alarm noise reduction and dynamic priority ranking.

Benefits of technology

Significantly reduces redundant alarms, improves alarm processing efficiency and decision-making accuracy, reduces manual intervention costs, and supports the needs of high-concurrency enterprise applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880869A_ABST
    Figure CN120880869A_ABST
Patent Text Reader

Abstract

The invention discloses an intrusion detection alarm noise reduction and priority dynamic sorting method, which belongs to the technical field of network security, and comprises the following steps: obtaining multi-source original alarm data, and carrying out standardization processing to obtain a standard alarm data set; performing duplicate removal processing on the standard alarm data set to obtain a simplified alarm data set; introducing an attention mechanism into a pre-trained large language model, and encoding the simplified alarm data set to obtain a high-dimensional semantic vector; constructing a noise recognition model based on the dichotomy model; inputting the high-dimensional semantic vector into the trained noise recognition model, and recognizing an effective noise alarm; and constructing a multi-dimensional scoring model, and performing priority ranking on the identified effective noise alarms to obtain a corresponding priority ranking result. The method not only greatly improves the alarm processing efficiency and the decision accuracy, but also reduces the manual intervention cost, supports the high-concurrency and high-availability enterprise-level application requirements, and has wide application prospects and popularization values.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security technology, and in particular relates to a method for noise reduction and dynamic priority ranking of intrusion detection alarms. Background Technology

[0002] With the diversification and increasing complexity of cyberattacks, Intrusion Detection Systems (IDS) play a crucial role in enterprise network security. However, in practical applications, IDS typically generate a large number of alerts, including many redundant, false positives, or low-priority alerts, placing a significant workload on security teams. Traditional alert handling methods mainly rely on rule matching and statistical analysis, but these methods are insufficient to effectively address the current complex network security environment.

[0003] First, traditional methods have significant shortcomings in alarm noise reduction. Due to a lack of understanding of the alarm context, these methods cannot accurately distinguish between valid alarms and noise. For example, some alarms may be frequently triggered due to fluctuations in the network environment, but may not actually pose a threat. In addition, alarm deduplication and merging are inefficient, especially in large-scale network environments, where duplicate alarms may account for more than 60% of the total alarms.

[0004] Secondly, existing methods also face numerous challenges in prioritization. Current prioritization methods are mostly based on static rules or simple feature weight allocation, which cannot dynamically adapt to complex network environments and attack scenarios. For example, some low-threat alerts may become potential threats due to their high correlation with other alerts. In addition, the lack of time-sensitivity analysis may lead to a failure to respond to high-risk events in a timely manner.

[0005] Furthermore, the high cost of manual intervention is another pressing issue. Security teams need to spend a significant amount of time manually filtering and analyzing alerts, reducing response efficiency. Manual intervention is not only time-consuming but also prone to introducing subjective bias, affecting the accuracy of decision-making.

[0006] To address the aforementioned problems in existing technologies, there is an urgent need to propose a method for noise reduction and dynamic priority ranking of intrusion detection alarms. Summary of the Invention

[0007] To address the aforementioned technical problems, this invention proposes an intrusion detection alarm noise reduction and dynamic priority ranking method. This method combines Large Language Model (LLM) technology to intelligently process massive alarm data, achieving efficient noise reduction and dynamic priority ranking, thereby significantly improving security operation efficiency and solving the problems existing in the prior art.

[0008] To achieve the above objectives, this invention provides a method for noise reduction and dynamic priority ranking of intrusion detection alarms, comprising the following steps:

[0009] Acquire raw alarm data from multiple sources and perform standardization processing to obtain a standard alarm dataset;

[0010] The standard alarm dataset is deduplicated to obtain a simplified alarm dataset;

[0011] An attention mechanism is introduced into the pre-trained large language model to encode the simplified alarm dataset and obtain high-dimensional semantic vectors.

[0012] A noise recognition model is constructed based on a binary classification model and then trained.

[0013] The high-dimensional semantic vector is input into the trained noise recognition model to identify valid noise alarms;

[0014] A multi-dimensional scoring model is constructed to prioritize the identified valid noise alarms and obtain the corresponding priority ranking results.

[0015] Optionally, the process of acquiring multi-source raw alarm data and performing standardization processing to obtain a standard alarm dataset includes:

[0016] The timestamps of multi-source raw alarm data are uniformly converted into international standard time format, Internet Protocol addresses are converted into classless inter-domain routing representation, classification encoding is performed on protocol type fields, and a data verification mechanism is introduced to ensure the integrity of data during transmission through hash value comparison and field integrity checks.

[0017] Optionally, the process of deduplicating the standard alarm dataset to obtain a simplified alarm dataset includes:

[0018] For completely duplicate alarm records in the standard alarm dataset, rule matching is used to remove them;

[0019] For similar alarm records in the standard alarm dataset, cosine similarity and Jaccard similarity coefficient are used to calculate the intersection and union ratio between similar alarm records. When the intersection and union ratio exceeds a preset threshold, the similar alarm records are merged into one record.

[0020] Optionally, the process of constructing and training a noise recognition model based on a binary classification model includes:

[0021] The noise recognition model is first trained by introducing a regularization coefficient, and then adversarial training is performed again by adding perturbations based on the results of the first training, finally obtaining the trained noise recognition model.

[0022] Optionally, the process of constructing a multi-dimensional scoring model to prioritize the identified valid noise alarms and obtaining the corresponding priority ranking results includes:

[0023] Threat level, scope of impact, contextual relevance, and time sensitivity are selected as scoring dimensions, and weights are assigned to each scoring dimension to complete the construction of a multi-dimensional scoring model. Based on the multi-dimensional scoring model, effective noise alarms are prioritized to obtain an initial ranking result. The weight allocation of the multi-dimensional scoring model is dynamically adjusted through deep reinforcement learning to optimize the initial ranking result and obtain the final priority ranking result.

[0024] Optionally, it also includes building an interactive dashboard to display the time distribution, geographical distribution, and priority ranking results of valid noise alarms.

[0025] This invention also proposes an alarm noise reduction and dynamic priority ranking system for large-scale intrusion detection, used to implement the method described above. The system includes:

[0026] The data acquisition module is used to acquire raw alarm data from multiple sources and perform standardization processing to obtain a standard alarm dataset.

[0027] The data processing module is used to perform deduplication on the standard alarm dataset to obtain a simplified alarm dataset;

[0028] The data encoding module is used to introduce an attention mechanism into the pre-trained large language model to encode the simplified alarm dataset and obtain high-dimensional semantic vectors.

[0029] The noise recognition module is used to build a noise recognition model based on a binary classification model and train it. The high-dimensional semantic vector is input into the trained noise recognition model to identify valid noise alarms.

[0030] The multi-dimensional scoring module is used to build a multi-dimensional scoring model, prioritize the identified valid noise alarms, and obtain the corresponding priority ranking results.

[0031] The present invention also proposes a computer device, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the method.

[0032] The present invention also proposes a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method.

[0033] The present invention also proposes a computer program product, including a computer program that, when executed by a processor, implements the steps of the method.

[0034] Compared with the prior art, the present invention has the following advantages and technical effects:

[0035] This invention significantly reduces redundant alarms through standardized data formats and deduplication strategies; it generates high-dimensional semantic vectors using a large language model and combines them with an attention mechanism to accurately capture the implicit relationships between alarms; it achieves dynamic weight adjustment through a multi-dimensional scoring model and deep reinforcement learning algorithms to ensure timely responses to high-risk events; and it provides security teams with an intuitive threat view and intelligent recommendation functions through knowledge graphs and a visual interface. The overall solution not only significantly improves alarm processing efficiency and decision-making accuracy but also reduces manual intervention costs, supports the high-concurrency, high-availability requirements of enterprise-level applications, and has broad application prospects and promotional value. Attached Figure Description

[0036] The accompanying drawings, which form part of this application, are used to provide a further understanding of this application. The illustrative embodiments and descriptions of this application are used to explain this application and do not constitute an undue limitation of this application. In the drawings:

[0037] Figure 1 This is a system architecture diagram of an embodiment of the present invention;

[0038] Figure 2 This is a flowchart illustrating the alarm noise reduction process according to an embodiment of the present invention.

[0039] Figure 3 This is a structural diagram of the multi-dimensional scoring model according to an embodiment of the present invention;

[0040] Figure 4 This is an example diagram illustrating the application of knowledge graphs in an embodiment of the present invention. Detailed Implementation

[0041] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. This application will now be described in detail with reference to the accompanying drawings and embodiments.

[0042] It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.

[0043] Example 1

[0044] like Figures 1-2 As shown, this embodiment provides a method for noise reduction and dynamic priority ranking of intrusion detection alarms, wherein:

[0045] Figure 1The diagram illustrates the overall system architecture, including the modular division and interrelationships of the data acquisition layer, data processing layer, analysis and decision-making layer, and user interaction layer. The diagram clearly describes the functional positioning of each module and the data flow path.

[0046] Figure 2 It describes the specific steps from data preprocessing to noise identification, including data standardization, deduplication strategies, semantic vector generation, and the training process of the noise identification model.

[0047] The method specifically includes the following steps:

[0048] Acquire raw alarm data from multiple sources and perform standardization processing to obtain a standard alarm dataset;

[0049] The standard alarm dataset is deduplicated to obtain a simplified alarm dataset;

[0050] An attention mechanism is introduced into the pre-trained large language model to encode the simplified alarm dataset and obtain high-dimensional semantic vectors;

[0051] A noise recognition model is constructed based on a binary classification model and then trained.

[0052] The high-dimensional semantic vector is input into the trained noise recognition model to identify valid noise alarms;

[0053] A multi-dimensional scoring model is constructed to prioritize the identified valid noise alarms and obtain the corresponding priority ranking results.

[0054] The feasible process of acquiring multi-source raw alarm data and standardizing it to obtain a standard alarm dataset includes:

[0055] The timestamps of multi-source raw alarm data are uniformly converted into international standard time format, Internet Protocol addresses are converted into classless inter-domain routing representation, classification encoding is performed on protocol type fields, and a data verification mechanism is introduced to ensure the integrity of data during transmission through hash value comparison and field integrity checks.

[0056] As a specific implementation method, alarm data originates from intrusion detection systems (IDS), security information and event management (SIEM) platforms, firewall logs, and endpoint detection and response (EDR) systems deployed within the enterprise. Data formats include common formats such as JSON, CSV, and Syslog, and multiple protocols such as HTTP, MQTT, and Kafka are supported for data transmission.

[0057] Mapping fields and converting formats for data from different sources is the first step in data standardization. For example, timestamps are standardized to the ISO 8601 format (YYYY-MM-DDTHH:mm:ssZ), and IP addresses are converted to CIDR notation. This involves defining a general data structure. Store alarm information:

[0058] ;

[0059] in, Represents a timestamp. Indicates the source IP address. Indicates the target IP address. Indicates the protocol type. This describes the attack characteristics. To ensure data consistency, this embodiment also introduces a data verification mechanism, which prevents errors during data transmission through hash value comparison and field integrity checks.

[0060] The feasible process of deduplicating the standard alarm dataset to obtain a simplified alarm dataset includes:

[0061] For completely duplicate alarm records in the standard alarm dataset, rule matching is used to remove them; for similar alarm records in the standard alarm dataset, cosine similarity and Jaccard similarity coefficient are used to calculate the intersection and union ratio between similar alarm records. When the intersection and union ratio exceeds a preset threshold, the similar alarm records are merged into one record.

[0062] As a specific implementation method, suppose a company generates approximately 100,000 original alarms per day, of which about 30% are duplicate alarms and 20% are noise alarms. Therefore, data deduplication strategies are an important part of the noise reduction process.

[0063] The deduplication strategy first removes completely duplicate alarm records based on rule matching. For alarms with high similarity, in addition to using cosine similarity, the Jaccard similarity coefficient can also be introduced to calculate the similarity between the two alarm sets. The ratio of the intersection to the union:

[0064] ;

[0065] like If so, the two alarms are considered duplicate records.

[0066] For text fields For example, in "attack feature descriptions," similarity is determined using edit distance (LevenshteinDistance):

[0067] ;

[0068] like If the two text descriptions are similar, then they are considered to be similar.

[0069] Furthermore, missing field completion is also an important step in data preprocessing. This is especially true for missing timestamp fields. The linear interpolation method is used for estimation:

[0070] ;

[0071] in, and These are the most recent times before and after the missing timestamp. For missing numeric fields... For example, the threat level is predicted using the K-Nearest Neighbors (KNN) algorithm:

[0072] ;

[0073] in, For the number of nearest neighbors, For the first The field value of the nearest neighbor.

[0074] The feasible process of introducing an attention mechanism into a pre-trained large language model to encode the simplified alarm dataset and obtain high-dimensional semantic vectors includes:

[0075] Semantic vector generation is a core step in alarm noise reduction. To improve the expressive power of semantic vectors, a pre-trained large language model (such as GPT-4 or BERT) is used to encode the alarm description, generating high-dimensional semantic vectors. To further enhance expressive power, an attention mechanism is introduced to weightedly calculate the importance of different words, generating more accurate semantic vectors. :

[0076] ;

[0077] in, For the first The attention weight of each word, where n is the number of words. This represents the corresponding word vector. The formula for calculating attention weights is as follows:

[0078] ;

[0079] in, For the first The relevance score of each word. Let exp() be the relevance score of the j-th word.

[0080] To further enhance the model's generalization ability, this embodiment also introduces transfer learning technology, using a pre-trained large language model (such as GPT-4 or BERT) as the base model and fine-tuning it on specific tasks.

[0081] A feasible process for constructing and training a noise recognition model based on a binary classification model includes:

[0082] The noise recognition model is first trained by introducing a regularization coefficient, and then adversarial training is performed again by adding perturbations based on the results of the first training, finally obtaining the trained noise recognition model.

[0083] As a specific implementation method, constructing a noise recognition model is a crucial step in the noise reduction process. This embodiment constructs a noise recognition model based on a binary classification model (such as logistic regression or SVM), identifying valid noise alarms based on semantic vectors and other features (such as threat level and frequency of occurrence). A regularization term is introduced during model training to prevent overfitting, and the loss function is:

[0084] ;

[0085] in, For loss function, This is the weight vector of the model. For bias terms, The total number of training samples. For the first The index of each training sample. For the first The true labels of each training sample For the first The feature vectors of each training sample For the model to predict the first The probability that a sample is a positive class. The regularization coefficient is . Weight vector of Norm squared.

[0086] Furthermore, adversarial training is used to enhance model robustness by adding perturbations during training. From the input data, the trained noise recognition model is finally obtained:

[0087] ;

[0088] in, For the input data after adding perturbation, The original input data, The amplitude of the disturbance. ( ) is a sign function. loss function For input data gradient, This is the loss function.

[0089] The feasible process of constructing a multi-dimensional scoring model to prioritize identified valid noise alarms and obtain the corresponding priority ranking results includes:

[0090] Threat level, scope of impact, contextual relevance, and time sensitivity are selected as scoring dimensions, and weights are assigned to each scoring dimension to complete the construction of a multi-dimensional scoring model. Based on the multi-dimensional scoring model, effective noise alarms are prioritized to obtain an initial ranking result. The weight allocation of the multi-dimensional scoring model is dynamically adjusted through deep reinforcement learning to optimize the initial ranking result and obtain the final priority ranking result. Figure 3 The paper demonstrates the components of a multi-dimensional scoring model and its weight adjustment mechanism, highlighting the role of deep reinforcement learning algorithms in dynamically adjusting weights.

[0091] As a specific implementation method, this embodiment defines a multi-dimensional scoring model that comprehensively considers the following four dimensions:

[0092] Threat Level: The severity of the threat as determined by analysis of historical data;

[0093] Scope of impact: The importance and coverage of the attacked assets;

[0094] Contextual relevance: Calculate the correlation between alarms using semantic vectors generated by a large language model;

[0095] Time sensitivity: based on the time distribution of alarm occurrences and the attack window period;

[0096] The weighting formula is:

[0097] ;

[0098] in, For comprehensive scoring, For the weights of each dimension, The weights for each rating dimension, Threat level rating, To score the scope of influence, Score the context relevance. A time sensitivity score is given.

[0099] Reinforcement learning-based weight adjustment is the core of dynamic priority ranking. This embodiment uses Deep Reinforcement Learning (DRL) to dynamically adjust the weights. The state space is defined. Action space and reward function :

[0100] state space This includes the priority distribution of current alarms and historical data feedback;

[0101] Action space This includes actions to adjust the weights of each dimension;

[0102] reward function Defined as:

[0103] ;

[0104] in, The total reward value, For the first The performance improvement after weight adjustment This represents the total number of weight adjustments.

[0105] Policy optimization is performed using a Deep Q-Network (DQN), with the objective function being:

[0106] ;

[0107] in, For loss function, These are the parameters of the current Q-network. For the parameters of the target network, As a discount factor, This is the current state. In the state The following actions were taken. To perform the action The instant reward obtained afterward To perform the action The next state after that, For the current Q network in state Take action below of Value estimation, For the target network in state Take action below Q-value estimation, In the state Below, the target network estimates the maximum Q-value for all possible actions. To replay from the experience pool The expectation of the empirical sample randomly sampled in the middle.

[0108] Implementable methods also include constructing an interactive dashboard that displays the time distribution, geographical distribution, and priority ranking results of valid noise alarms.

[0109] As a specific implementation method, this embodiment designs an interactive dashboard to display the real-time distribution and priority ranking results of alarms. The dashboard includes the following modules:

[0110] Alarm list module: Displays alarm information in order of priority, and supports keyword search and filtering functions.

[0111] Timeline View Module: Displays the time distribution of alarm occurrences in a timeline format, making it easier to identify abnormal periods.

[0112] Heatmap module: Displays the geographical distribution of alarms to help identify high-risk areas.

[0113] Use ECharts or D3.js to implement dynamic chart rendering, ensuring the smoothness and scalability of the interface.

[0114] Furthermore, to enhance the user experience, this embodiment also introduces a voice interaction function, allowing users to query specific alarms or perform operations via voice commands.

[0115] Furthermore, it also includes intelligent recommendation functionality, which enhances the accuracy of the recommendation system by introducing a knowledge graph. Figure 4 This diagram describes how knowledge graphs connect alerts with other relevant information (such as vulnerability databases and asset inventories) to generate precise action recommendations. It illustrates the core role of knowledge graphs in intelligent recommendation functionality.

[0116] By constructing a knowledge graph in the cybersecurity field and linking alerts with other relevant information, such as vulnerability databases and asset inventories, more accurate handling recommendations can be generated. The formal description of the recommendation strategy is as follows:

[0117] ;

[0118] in, As a recommendation, For effective alarm collection, This is a reasoning function based on a knowledge graph.

[0119] This embodiment proposes an alarm noise reduction and dynamic priority ranking method for large-scale intrusion detection systems. By combining Large Language Model (LLM) technology, an intelligent and efficient alarm processing framework is constructed. This method comprehensively optimizes key aspects of the traditional alarm processing flow, from data preprocessing and semantic analysis to noise identification and dynamic priority ranking.

[0120] This embodiment significantly improves the efficiency and accuracy of network security operations by combining Large Language Modeling (LLM) technology and advanced machine learning algorithms. In enterprise network security protection, Intrusion Detection Systems (IDS) typically generate a large number of redundant, false alarms, or low-priority alerts. This not only increases the workload of the security team but may also lead to high-risk events being overlooked. To address this issue, this embodiment significantly reduces the number of invalid alerts through intelligent noise reduction technology, thus laying the foundation for subsequent processing.

[0121] Specifically, this embodiment utilizes data preprocessing, semantic analysis, and noise identification to effectively reduce alarm density. Experimental results show that after noise reduction, the effective alarm ratio increases from 10% to 70% of the original data, significantly improving alarm processing efficiency. Furthermore, methods such as cosine similarity, Jaccard coefficient, and edit distance are used to deduplicate and similar alarms, further reducing the number of redundant alarms and significantly alleviating the workload of the security team. The noise-reduced alarm data is not only more refined but also provides higher-quality input for subsequent prioritization.

[0122] In prioritizing alerts, traditional methods often rely on static rules or simple feature weight allocation, making it difficult to dynamically adapt to complex network environments and attack scenarios. This embodiment introduces a multi-dimensional scoring model that comprehensively considers multiple dimensions such as threat level, impact scope, contextual relevance, and time sensitivity to ensure a comprehensive assessment of the importance of each alert. Simultaneously, deep reinforcement learning (DRL) is used to dynamically adjust the weights of each dimension, enabling the system to continuously optimize the priority ranking strategy based on real-time network conditions and historical data feedback. Compared to traditional static rule methods, the accuracy of the priority ranking model is improved by 17%, reaching 92%, thus ensuring timely responses to high-risk events. This dynamic adaptability makes the system more reliable in the face of diverse attacks.

[0123] To further improve decision-making accuracy, this embodiment fully leverages the powerful semantic understanding and contextual reasoning capabilities of large language models to deeply uncover the implicit relationships between alerts. For example, seemingly independent alerts may belong to the same attack chain. This correlation analysis helps security teams more accurately identify potential threats and avoid overlooking key information. By using an attention mechanism to weight the importance of different words, more accurate semantic vectors are generated, further enhancing the model's generalization and expressive capabilities. Furthermore, adversarial training and regularization techniques enhance the robustness of the noise recognition model, making it more stable in the face of diverse attacks, thereby improving the overall accuracy of decision-making.

[0124] In practical applications, this embodiment significantly reduces the need for manual intervention through automated noise reduction and intelligent recommendation functions. User feedback shows that the work efficiency of security analysts has increased by approximately 40%. Specifically, the intelligent recommendation strategies generated by LLM assist security teams in quickly formulating response plans, thereby improving the overall efficiency of security operations. Furthermore, by reducing false positive rates, this embodiment reduces resource waste caused by false positives, further optimizing operating costs. This efficient and automated processing method provides strong support for enterprise cybersecurity operations.

[0125] Example 2

[0126] Based on the same general inventive concept, this invention also provides an alarm noise reduction and dynamic priority ranking system for large-scale intrusion detection. The system provided by this invention is described below, and the system described below can be referred to in conjunction with the method described above. The system includes:

[0127] The data acquisition module is used to acquire raw alarm data from multiple sources and perform standardization processing to obtain a standard alarm dataset.

[0128] The data processing module is used to perform deduplication on the standard alarm dataset to obtain a simplified alarm dataset;

[0129] The data encoding module is used to introduce an attention mechanism into the pre-trained large language model to encode the simplified alarm dataset and obtain high-dimensional semantic vectors.

[0130] The noise recognition module is used to build a noise recognition model based on a binary classification model and train it. The high-dimensional semantic vector is input into the trained noise recognition model to identify valid noise alarms.

[0131] The multi-dimensional scoring module is used to build a multi-dimensional scoring model, prioritize the identified valid noise alarms, and obtain the corresponding priority ranking results.

[0132] It should be understood that the alarm noise reduction and dynamic priority ranking system for large-scale intrusion detection provided in this embodiment of the invention has all the advantages of the method provided in the above embodiments.

[0133] Example 3

[0134] This embodiment also discloses a computer device, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of the method described in Embodiment 1.

[0135] Example 4

[0136] This embodiment also discloses a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the method described in Embodiment 1.

[0137] Example 5

[0138] This embodiment also discloses a computer program product, including a computer program that, when executed by a processor, implements the steps of the method described in Embodiment 1.

[0139] The above are merely preferred embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for noise reduction and dynamic priority ranking of intrusion detection alarms, characterized in that, Includes the following steps: Acquire raw alarm data from multiple sources and perform standardization processing to obtain a standard alarm dataset; The standard alarm dataset is deduplicated to obtain a simplified alarm dataset; An attention mechanism is introduced into the pre-trained large language model to encode the simplified alarm dataset and obtain high-dimensional semantic vectors; A noise recognition model is constructed based on a binary classification model and then trained. The high-dimensional semantic vector is input into the trained noise recognition model to identify valid noise alarms; A multi-dimensional scoring model is constructed to prioritize the identified valid noise alarms and obtain the corresponding priority ranking results.

2. The method according to claim 1, characterized in that, The process of acquiring raw alarm data from multiple sources and performing standardization processing to obtain a standard alarm dataset includes: The timestamps of multi-source raw alarm data are uniformly converted into international standard time format, Internet Protocol addresses are converted into classless inter-domain routing representation, classification encoding is performed on protocol type fields, and a data verification mechanism is introduced to ensure the integrity of data during transmission through hash value comparison and field integrity checks.

3. The method according to claim 1, characterized in that, The process of deduplicating the standard alarm dataset to obtain a simplified alarm dataset includes: For completely duplicate alarm records in the standard alarm dataset, rule matching is used to remove them; For similar alarm records in the standard alarm dataset, cosine similarity and Jaccard similarity coefficient are used to calculate the intersection and union ratio between similar alarm records. When the intersection and union ratio exceeds a preset threshold, the similar alarm records are merged into one record.

4. The method according to claim 1, characterized in that, The process of building and training a noise recognition model based on a binary classification model includes: The noise recognition model is first trained by introducing a regularization coefficient, and then adversarial training is performed again by adding perturbations based on the results of the first training, finally obtaining the trained noise recognition model.

5. The method according to claim 1, characterized in that, The process of constructing a multi-dimensional scoring model, prioritizing the identified valid noise alarms, and obtaining the corresponding priority ranking results includes: Threat level, scope of impact, contextual relevance, and time sensitivity are selected as scoring dimensions, and weights are assigned to each scoring dimension to complete the construction of a multi-dimensional scoring model. Based on the multi-dimensional scoring model, effective noise alarms are prioritized to obtain an initial ranking result. The weight allocation of the multi-dimensional scoring model is dynamically adjusted through deep reinforcement learning to optimize the initial ranking result and obtain the final priority ranking result.

6. The method according to claim 1, characterized in that, It also includes building an interactive dashboard, which displays the time distribution, geographical distribution, and priority ranking results of valid noise alarms.

7. An alarm noise reduction and dynamic priority ranking system for large-scale intrusion detection, characterized in that, The system for implementing the method according to any one of claims 1-6 comprises: The data acquisition module is used to acquire raw alarm data from multiple sources and perform standardization processing to obtain a standard alarm dataset. The data processing module is used to perform deduplication on the standard alarm dataset to obtain a simplified alarm dataset; The data encoding module is used to introduce an attention mechanism into the pre-trained large language model to encode the simplified alarm dataset and obtain high-dimensional semantic vectors. The noise recognition module is used to build a noise recognition model based on a binary classification model and train it. The high-dimensional semantic vector is input into the trained noise recognition model to identify valid noise alarms. The multi-dimensional scoring module is used to build a multi-dimensional scoring model, prioritize the identified valid noise alarms, and obtain the corresponding priority ranking results.

8. A computer device comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the steps of the method according to any one of claims 1-6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the steps of the method according to any one of claims 1-6.

10. A computer program product, comprising a computer program, characterized in that, When executed by a processor, the computer program implements the steps of the method according to any one of claims 1-6.

Citation Information

Patent Citations

  • Network security early warning method and system based on artificial intelligence

    CN120342671A

  • Substation remote fault early warning system and method based on deep learning

    CN120412250A

  • Anomaly Detection Systems And Methods

    US20220327108A1

  • Automatic Alert Dispositioning using Artificial Intelligence

    US20240177094A1

Cited By

  • Alarm noise reduction method based on cooperation of large model and reinforcement learning and related equipment

    CN121350017A

  • Alarm noise reduction method based on large model and reinforcement learning cooperation and related equipment

    CN121350017B