Network security early warning method and system based on artificial intelligence
By using an AI-based cybersecurity early warning system that combines historical events and real-world scenario information to dynamically adjust warning values, the system solves the problem of traditional methods being unable to cope with complex attacks, and achieves accurate assessment and effective protection of coal enterprise networks.
Patent Information
- Application Number
- CN202511130540.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-13
- Publication Date
- 2025-11-07
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional cybersecurity early warning methods are insufficient to respond to new and complex cyberattacks in a timely and effective manner. Cybersecurity threats to coal enterprises are becoming increasingly serious, affecting production and information security.
An AI-based cybersecurity early warning system is adopted. By collecting and analyzing historical cybersecurity events, and combining information from actual application scenarios and coal production parameters, the system dynamically adjusts early warning values and uses AI to quickly learn and adapt to new attack patterns to identify potential risks.
It enables comprehensive, dynamic, and accurate assessment and early warning of the cybersecurity status of coal enterprises, better responding to new types of cyberattacks, providing timely security protection, and ensuring stable production.
Smart Images

Figure CN120915539A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security early warning, in particular to a network security early warning method and system based on artificial intelligence. BACKGROUND
[0002] In the daily operation of coal enterprises, network security problems are increasingly prominent. With the rapid development of information technology, various aspects of production and management of coal enterprises are highly dependent on network systems. However, the openness and complexity of network environment make coal enterprises face many network security threats, such as hacker attacks, virus infections, data leaks, etc. These security threats not only may cause production interruption of enterprises, resulting in huge economic losses, but also may endanger the business secrets and customer information security of enterprises. Traditional network security early warning methods are often based on rules and feature matching, which are difficult to achieve timely and effective early warning for new and complex network attacks.
[0003] Therefore, it is necessary to design a network security early warning method and system based on artificial intelligence to solve the problems existing in the current technology. SUMMARY
[0004] In view of this, the present application proposes a network security early warning method and system based on artificial intelligence, aiming to analyze and process massive network data in real time, accurately identify potential network security threats, and realize effective early warning of network security of coal enterprises.
[0005] In one aspect, the present application proposes a network security early warning system based on artificial intelligence, comprising: The acquisition module is configured to determine a coal production area to be monitored, collect historical network security events of the coal production area to be monitored, and analyze the historical network security events. Based on the analysis result, an initial network security early warning value of the coal production area to be monitored is determined. The judgment module is configured to collect actual application scenario information of the coal production area to be monitored, and determine whether to adjust the initial network security early warning value according to the actual application scenario information. The adjustment module is configured to, when it is determined to adjust the initial network security early warning value, collect coal production parameters and network running parameters of the coal production area to be monitored, determine an adjustment coefficient of the initial network security early warning value based on the coal production parameters and network running parameters, and obtain a final network security early warning value. The early warning module is configured to determine a security early warning level of the coal production area to be monitored according to the final network security early warning value.
[0006] Further, when the historical network security events are analyzed and the initial network security early warning value of the coal production area to be monitored is determined based on the analysis result, the method comprises: analyzing the historical network security events to obtain network security vulnerability types, security event occurrence frequencies and security event severities of the coal production area to be monitored; determining a basic network security early warning value of the coal production area to be monitored based on the security vulnerability types, the security event occurrence frequencies and the security event severities; collecting production stage information of the coal production area to be monitored to obtain a network dependence degree corresponding to each production stage information, and determining whether to optimize the basic network security early warning value according to the network dependence degree; if yes, determining an optimization coefficient of the basic network security early warning value according to the network dependence degree, and obtaining the initial network security early warning value.
[0007] Further, the security vulnerability types comprise physical layer security vulnerabilities, network layer security vulnerabilities, transmission layer security vulnerabilities and application layer security vulnerabilities.
[0008] Further, when it is determined whether to optimize the basic network security early warning value according to the network dependence degree, the method comprises: comparing the network dependence degree with a network dependence degree threshold value, and determining whether to optimize the basic network security early warning value according to a comparison result; when the network dependence degree is within the network dependence degree threshold value, it is determined that the basic network security early warning value is not optimized; when the network dependence degree is outside the network dependence degree threshold value, it is determined that the basic network security early warning value is optimized.
[0009] Further, when the optimization coefficient of the basic network security early warning value is determined according to the network dependence degree, and the initial network security early warning value is obtained, the method comprises: obtaining a center value of the network dependence degree threshold value, calculating a difference value between the network dependence degree and the center value, and recording the difference value as a dependence degree difference value; obtaining an absolute value of the dependence degree difference value, and recording the absolute value as an absolute dependence degree difference value; comparing the absolute dependence degree difference value with a first absolute dependence degree difference value and a second absolute dependence degree difference value, and determining the optimization coefficient according to a comparison result; wherein the first absolute dependence degree difference value is smaller than the second absolute dependence degree difference value; when the absolute dependence degree difference value is smaller than or equal to the first absolute dependence degree difference value, the optimization coefficient is determined as a first optimization coefficient; determining the optimization coefficient as a second optimization coefficient when the absolute dependence degree difference value is greater than the first absolute dependence degree difference value and less than or equal to the second absolute dependence degree difference value; determining the optimization coefficient as a third optimization coefficient when the absolute dependence degree difference value is greater than the second absolute dependence degree difference value; multiplying the optimization coefficient and the basic network security early warning value to obtain a product value as the initial network security early warning value.
[0010] Further, when determining whether to adjust the initial network security early warning value according to the actual application scenario information, the method comprises: extracting features of the actual application scenario information to obtain a plurality of actual application scenario feature values; obtaining an actual application scenario standard value corresponding to each actual application scenario feature value; comparing the actual application scenario feature value with the corresponding actual application scenario standard value, and determining whether to adjust the initial network security early warning value according to the comparison result; if there is an actual application scenario feature value greater than or equal to the corresponding actual application scenario standard value, it is determined that the initial network security early warning value is adjusted; otherwise, it is determined that the initial network security early warning value is not adjusted.
[0011] Further, when determining the adjustment coefficient of the initial network security early warning value based on the coal production parameters and the network running parameters to obtain the final network security early warning value, the method comprises: analyzing the coal production parameters to obtain real-time coal production indexes; analyzing the network running parameters to obtain real-time network performance indexes; determining a correlation coefficient of the real-time coal production indexes and the real-time network performance indexes; comparing the correlation coefficient with historical data to determine the adjustment coefficient according to the comparison result; when there is a historical correlation coefficient identical to the correlation coefficient in the historical data, taking a historical adjustment coefficient corresponding to the historical correlation coefficient as the adjustment coefficient; when there is no historical correlation coefficient identical to the correlation coefficient in the historical data, determining the adjustment coefficient according to the correlation coefficient; multiplying the adjustment coefficient and the initial network security early warning value to obtain a product value as the final network security early warning value.
[0012] Further, when determining the adjustment coefficient according to the correlation coefficient, the method comprises: The correlation coefficient is compared with a first correlation coefficient and a second correlation coefficient, and the adjustment coefficient is determined according to the comparison result; wherein the first correlation coefficient is less than the second correlation coefficient; When the correlation coefficient is less than or equal to the first correlation coefficient, the adjustment coefficient is determined as a first adjustment coefficient; When the correlation coefficient is greater than the first correlation coefficient and less than or equal to the second correlation coefficient, the adjustment coefficient is determined as a second adjustment coefficient; When the correlation coefficient is greater than the second correlation coefficient, the adjustment coefficient is determined as a third adjustment coefficient.
[0013] Further, when determining the security warning level of the coal production area to be monitored according to the final network security warning value, comprising: Setting a security warning range, wherein the security warning range includes a first range, a second range and a third range; When the final network security warning value falls within the first range, the security warning level is determined as a first level; When the final network security warning value falls within the second range, the security warning level is determined as a second level; When the final network security warning value falls within the third range, the security warning level is determined as a third level.
[0014] Compared with the prior art, the beneficial effects of the present application are that the network security warning system based on artificial intelligence provided by the present application can use artificial intelligence technology to comprehensively, dynamically and accurately evaluate and warn the security status of the network of a coal enterprise. By collecting historical network security events to determine an initial warning value, the historical security situation of the network of the coal enterprise is considered, providing a basis for subsequent warning. Combined with actual application scene information to determine whether to adjust the warning value, the warning is more in line with the actual network usage status of the enterprise. And the adjustment coefficient is determined according to the coal production parameters and network operation parameters, further comprehensively considering the correlation factors of coal production and network operation, making the warning value more scientific and accurate. It can be understood that the system can better cope with new and complex network attacks. In the face of constantly changing network security threats, artificial intelligence technology can quickly learn and adapt to new attack patterns, identify potential security risks in a timely manner, and thus provide more effective network security protection for coal enterprises.
[0015] In another aspect, the present application also provides a network security warning method based on artificial intelligence, comprising the following steps: S100: determine a coal production area to be monitored, collect historical network security events of the coal production area to be monitored, and analyze the historical network security events, determine an initial network security warning value of the coal production area to be monitored based on the analysis result; S200: collect actual application scenario information of the coal production area to be monitored, and determine whether to adjust the initial network security warning value according to the actual application scenario information; S300: when it is determined to adjust the initial network security warning value, collect coal production parameters and network running parameters of the coal production area to be monitored, determine an adjustment coefficient of the initial network security warning value based on the coal production parameters and the network running parameters, and obtain a final network security warning value; S400: determine a security warning level of the coal production area to be monitored according to the final network security warning value.
[0016] It can be understood that the network security warning method and system based on artificial intelligence have the same beneficial effects, which will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS
[0017] Various other advantages and benefits will become apparent to those of ordinary skill in the art upon reading the following detailed description of the preferred embodiments. The drawings are included only to illustrate preferred embodiments of the application and do not imply any limitation of the application. Moreover, in the entire drawings, the same reference numerals refer to the same components. In the drawings: Figure 1 The structure block diagram of the network security warning system based on artificial intelligence provided by the embodiment of the application is shown in the figure; Figure 2 The flowchart of the network security warning method based on artificial intelligence provided by the embodiment of the application is shown in the figure. DETAILED DESCRIPTION
[0018] Exemplary embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments described herein. On the contrary, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art. It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0019] Referring to Figure 1 As shown in the figure, in some embodiments of the present application, the present embodiment provides a network security warning system based on artificial intelligence, comprising: The collection module is configured to determine a coal production area to be monitored, collect historical network security events of the coal production area to be monitored, and analyze the historical network security events, determine an initial network security early warning value of the coal production area to be monitored based on the analysis result; The judgment module is configured to collect actual application scene information of the coal production area to be monitored, and determine whether to adjust the initial network security early warning value according to the actual application scene information; The adjustment module is configured to, when it is determined to adjust the initial network security early warning value, collect coal production parameters and network operation parameters of the coal production area to be monitored, determine an adjustment coefficient of the initial network security early warning value based on the coal production parameters and the network operation parameters, and obtain a final network security early warning value; The early warning module is configured to determine a security early warning level of the coal production area to be monitored according to the final network security early warning value.
[0020] It can be understood that the network security early warning system based on artificial intelligence provided by the embodiment can use artificial intelligence technology to comprehensively, dynamically and accurately evaluate and early warn the security status of the network of the coal enterprise. The initial early warning value is determined by collecting historical network security events, which considers the historical security situation of the network of the coal enterprise and provides a basis for subsequent early warning. Whether to adjust the early warning value is determined in combination with the actual application scene information, so that the early warning is more in line with the actual network use status of the enterprise. The adjustment coefficient is determined according to the coal production parameters and the network operation parameters, which further comprehensively considers the associated factors of coal production and network operation, so that the early warning value is more scientific and accurate. It can be understood that the system can better cope with new and complex network attacks. In the face of constantly changing network security threats, artificial intelligence technology can quickly learn and adapt to new attack patterns, identify potential security risks in a timely manner, and thus provide more effective network security protection for the coal enterprise.
[0021] Specifically, when the historical network security events are analyzed and the initial network security early warning value of the coal production area to be monitored is determined based on the analysis result, the following steps are included: The historical network security events are analyzed to obtain the network security vulnerability type, the security event occurrence frequency and the security event severity of the coal production area to be monitored; The basis network security early warning value of the coal production area to be monitored is determined based on the security vulnerability type, the security event occurrence frequency and the security event severity; The production stage information of the coal production area to be monitored is collected, the network dependence degree corresponding to each production stage information is obtained, and whether to optimize the basis network security early warning value is determined according to the network dependence degree; If yes, an optimization coefficient of the basic network security early warning value is determined according to the network dependence degree, and the initial network security early warning value is obtained.
[0022] It can be understood that the basic network security early warning value is set by comprehensively considering factors such as historical network security vulnerabilities, event occurrence frequency and severity of the coal production area to be monitored, forming a preliminary and objective early warning reference value. On this basis, the basic early warning value is optimized in combination with the network dependence degree corresponding to the production stage, so that the initial early warning value is more suitable for the actual coal production. In different production stages, the network dependence degree of coal enterprises is different. For example, when the degree of automation production is high, increasing the early warning value can prevent risks; for links with small network dependence, reducing the early warning value can avoid resource waste. This optimization mechanism makes the early warning value more targeted and practical, provides a reliable basis for subsequent early warning work, and helps coal enterprises to timely respond to network security threats in different stages and ensure the stability of production and network systems. At the same time, determining the early warning value based on multiple factors reflects the scientificity and flexibility of the system, which can adapt to complex and variable production environments and network security situations.
[0023] Specifically, the security vulnerability types include physical layer security vulnerabilities, network layer security vulnerabilities, transmission layer security vulnerabilities, and application layer security vulnerabilities.
[0024] In the embodiment, the calculation steps of the basic network security early warning value are as follows: first, different types of security vulnerabilities are assigned weight values. The physical layer is assigned a weight value of 0.3 because it affects the physical connection and equipment security of the network; the network layer is assigned a weight value of 0.25 because it involves critical links; the transmission layer is assigned a weight value of 0.2 because it is related to data transmission; and the application layer is assigned a weight value of 0.15 because it affects the running of application programs. Then, quantitative values are determined according to the frequency and severity of security events. The frequency is classified according to the number of times per month, with 0-2 times as low frequency, a quantitative value of 0.2; 3-5 times as medium frequency, a quantitative value of 0.5; and 6 times or more as high frequency, a quantitative value of 0.8. The severity is classified as mild, moderate and severe, with a quantitative value of 0.3, 0.6 and 0.9 respectively. Next, the scores of each type of security vulnerability are calculated by multiplying the weight value of the security vulnerability by the product of the quantitative value of the corresponding security event frequency and the quantitative value of the severity. For example, the score of the physical layer security vulnerability = physical layer weight value x physical layer event frequency quantitative value x physical layer event severity quantitative value. Finally, the scores of each type of security vulnerability are added to obtain the basic network security early warning value. This calculation method considers multiple factors, making the early warning value more scientific and reasonable, and accurately reflecting the network security situation of the coal production area, providing support for early warning and prevention work.
[0025] Specifically, when determining whether to optimize the basic network security early warning value according to the network dependence degree, the following steps are included: The network dependence degree is compared with a network dependence degree threshold value, and whether to optimize the basic network security early warning value is determined according to the comparison result. determining not to optimize the basic network security early warning value when the network dependency degree is within the network dependency degree threshold value; determining to optimize the basic network security early warning value when the network dependency degree is outside the network dependency degree threshold value.
[0026] It can be understood that the network dependency degree is an important indicator for measuring the degree of network dependence in the coal production stage, and the network dependency degree can be obtained in various ways. On the one hand, the coal production process can be analyzed in detail to sort out the role of the network in each production link. For example, in the automatic mining link of coal, if a large number of network-controlled mechanical equipment is used for mining, transportation and monitoring, the network dependency degree of this link is relatively high; while in some traditional manual operation links, such as simple coal sorting work, the network dependency degree is relatively low. On the other hand, the network dependency degree can be determined by collecting data of coal production equipment. The number and type of equipment connected to the network and relying on the network for data transmission and instruction reception are counted. The more the number of equipment and the more critical the type, the higher the network dependency degree of the production stage. The frequency and flow of network data transmission during equipment operation can also be analyzed. The network dependency degree of the production stage with frequent and large flow of data transmission will also be correspondingly improved.
[0027] Specifically, when the network dependency degree is determined to determine the optimization coefficient of the basic network security early warning value, and the initial network security early warning value is obtained, it includes: obtaining the center value of the network dependency degree threshold value, calculating the difference between the network dependency degree and the center value, and recording it as the dependency degree difference; obtaining the absolute value of the dependency degree difference, recording it as the absolute dependency degree difference; comparing the absolute dependency degree difference with the first absolute dependency degree difference and the second absolute dependency degree difference, and determining the optimization coefficient according to the comparison result; wherein the first absolute dependency degree difference is less than the second absolute dependency degree difference; when the absolute dependency degree difference is less than or equal to the first absolute dependency degree difference, determining the optimization coefficient as the first optimization coefficient; when the absolute dependency degree difference is greater than the first absolute dependency degree difference and less than or equal to the second absolute dependency degree difference, determining the optimization coefficient as the second optimization coefficient; when the absolute dependency degree difference is greater than the second absolute dependency degree difference, determining the optimization coefficient as the third optimization coefficient; the product value of the optimization coefficient and the basic network security early warning value is taken as the initial network security early warning value.
[0028] It can be understood that the first optimization coefficient is less than the second optimization coefficient, which is less than the third optimization coefficient. When the absolute difference between the network dependency degree and the network dependency degree threshold center value is small, it means that the network dependency degree of the current production stage is close to the expected normal dependency degree, and a smaller first optimization coefficient is used to fine-tune the basic network security warning value, which can avoid excessive adjustment to deviate from the actual situation. When the absolute difference is in the middle range, it means that the network dependency degree deviates from the normal situation to a certain extent, and needs to be adjusted more significantly, so the second optimization coefficient is used. When the absolute difference is large, it means that the network dependency degree of the current production stage deviates significantly from the normal expectation, and may face higher network security risks, so the largest third optimization coefficient is used to increase the initial network security warning value, so as to more effectively prevent potential network security threats. This way of determining the optimization coefficient according to the absolute dependency degree difference, further enhances the accuracy and adaptability of the system warning, so that the warning value can be dynamically adjusted according to the change of the network dependency degree of the coal production stage, better guaranteeing the safe and stable operation of the network system of the coal enterprise, and helping the smooth progress of the coal production. At the same time, this dynamic adjustment mechanism also reflects the good adaptability of the system to the complex and changeable coal production environment and network security situation, and can provide reliable network security warning service for coal enterprises in different production scenarios.
[0029] Specifically, when judging whether to adjust the initial network security warning value according to the actual application scene information, the method comprises: performing feature extraction on the actual application scene information to obtain a plurality of actual application scene feature values; obtaining an actual application scene standard value corresponding to each actual application scene feature value; comparing the actual application scene feature value with the corresponding actual application scene standard value, and judging whether to adjust the initial network security warning value according to the comparison result; if the actual application scene feature value is greater than or equal to the corresponding actual application scene standard value, it is determined that the initial network security warning value is adjusted; otherwise, it is determined that the initial network security warning value is not adjusted.
[0030] In the embodiment, the actual application scene characteristic values include coal production scale, network access traffic and the like. The coal production scale characteristic value is measured according to daily output and monthly output, and the larger the scale, the higher the network data processing pressure and security risk can be. The network access traffic characteristic value is determined by monitoring data inflow and outflow, and high traffic can mean attack or leakage risk. Each characteristic value has a corresponding standard value, such as a coal production scale standard value determined according to historical average scale, a network access traffic standard value set by analyzing normal traffic fluctuation range, and an external network attack threat standard value referring to industry security standards and past attack situations. Comparing the characteristic values with the standard values, if the characteristic values are greater than or equal to the standard values, it means that the scene has factors affecting network security, and the warning value needs to be adjusted, such as when the coal production scale characteristic value exceeds the standard value or the network access traffic abnormally increases beyond the standard value. If all characteristic values are less than the standard values, the scene is relatively safe and no adjustment is needed. This comparison method makes the network security warning fit the actual production of coal enterprises, can timely discover risks and adjust the warning, improves the security and reliability of the system, and comprehensively considers different characteristic values, which also reflects the comprehensiveness and scientificity of the system and can better cope with complex network security situations.
[0031] Specifically, when determining the adjustment coefficient of the initial network security warning value based on the coal production parameters and the network operation parameters to obtain the final network security warning value, the method comprises: analyzing the coal production parameters to obtain real-time coal production indexes; analyzing the network operation parameters to obtain real-time network performance indexes; determining a correlation coefficient of the real-time coal production indexes and the real-time network performance indexes; comparing the correlation coefficient with historical data to determine the adjustment coefficient according to the comparison result; when there is a historical correlation coefficient identical to the correlation coefficient in the historical data, taking a historical adjustment coefficient corresponding to the historical correlation coefficient as the adjustment coefficient; when there is no historical correlation coefficient identical to the correlation coefficient in the historical data, determining the adjustment coefficient according to the correlation coefficient; taking a product value of the adjustment coefficient and the initial network security warning value as the final network security warning value.
[0032] It can be understood that the real-time coal production indicators include coal production, gas concentration, carbon monoxide concentration, dust concentration, roadway temperature and humidity, etc. These indicators can directly reflect the actual situation of coal production, for example, sudden changes in coal production may mean adjustment of production process or equipment failure, and abnormalities in environmental indicators such as gas concentration, carbon monoxide concentration and dust concentration may indicate potential safety hazards. Real-time network performance indicators include network bandwidth utilization, network delay, packet loss rate, etc., which reflect the running status of the network. High network bandwidth utilization may cause network congestion, and increases in network delay and packet loss rate will affect the stability and real-time performance of data transmission.
[0033] It can be understood that the specific steps of determining the correlation coefficient between real-time coal production indicators and real-time network performance indicators are as follows: first, establish a real-time coal production and network performance indicator dataset. Collect real-time coal production indicators such as coal production and gas concentration, and real-time network performance indicators such as network bandwidth utilization and network delay data within a certain period of time, ensure the accuracy and completeness of the data, and provide a reliable basis for subsequent analysis. Then, standardize the collected data. Due to the large difference in dimensions and value ranges of different indicators, in order to eliminate their influence on the calculation of the correlation coefficient, the Z-score standardization method can be used to convert the data into standard normal distribution data. Then, select an appropriate correlation analysis method. The grey correlation analysis method can be used, which has low requirements for sample size and regularity and small calculation amount, and can calculate the grey correlation coefficient between each real-time coal production indicator and network performance indicator. The Pearson correlation coefficient method can also be used to analyze the linear correlation degree between the two. In combination with multiple methods, the correlation coefficient can be determined more comprehensively and accurately. Finally, the calculated correlation coefficients are comprehensively evaluated. The results of different methods can be weighted and averaged, or adjusted according to experience and needs to obtain the final correlation coefficient. This comprehensive method can accurately reflect the actual correlation between coal production and network operation, and provide a reliable basis for determining the adjustment coefficient and network security warning value.
[0034] Specifically, when the correlation coefficient is used to determine the adjustment coefficient, it includes: comparing the correlation coefficient with a first correlation coefficient and a second correlation coefficient, and determining the adjustment coefficient according to the comparison result; wherein the first correlation coefficient is less than the second correlation coefficient; when the correlation coefficient is less than or equal to the first correlation coefficient, the adjustment coefficient is determined as a first adjustment coefficient; when the correlation coefficient is greater than the first correlation coefficient and less than or equal to the second correlation coefficient, the adjustment coefficient is determined as a second adjustment coefficient; when the correlation coefficient is greater than the second correlation coefficient, the adjustment coefficient is determined as a third adjustment coefficient.
[0035] It can be understood that the first adjustment coefficient is less than the second adjustment coefficient, which is less than the third adjustment coefficient. When the correlation coefficient is small, it means that the real-time coal production index and the real-time network performance index are weakly correlated, and a smaller first adjustment coefficient is used to adjust the initial network security warning value by a smaller amplitude to maintain the basic matching of the warning value and the actual situation. When the correlation coefficient is in the middle range, it means that there is a certain correlation between the two, which needs to be adjusted more greatly, so the second adjustment coefficient is used. When the correlation coefficient is large, it means that the real-time coal production index and the real-time network performance index are closely related, and a larger third adjustment coefficient is used to improve the final network security warning value, so as to more effectively prevent potential network security threats. This way of determining the adjustment coefficient according to the correlation coefficient, further improves the accuracy and effectiveness of the system warning, so that the warning value can be dynamically adjusted according to the correlation between coal production and network operation, better adapt to the complex and changeable production environment and network security situation of coal enterprises, and provide stronger guarantee for the stable operation of the network system of coal enterprises. At the same time, this fine adjustment mechanism also reflects the scientificity and flexibility of the system, which can provide accurate network security warning service for coal enterprises in different production scenarios and help the continuous and efficient production of coal enterprises.
[0036] Specifically, according to the final network security warning value, the safety warning level of the coal production area to be monitored is determined, comprising: setting a safety warning range, wherein the safety warning range includes a first range, a second range and a third range; when the final network security warning value falls within the first range, the safety warning level is determined to be the first level; when the final network security warning value falls within the second range, the safety warning level is determined to be the second level; when the final network security warning value falls within the third range, the safety warning level is determined to be the third level.
[0037] It can be understood that the first range is 0 to 30% of the maximum network security warning value, the second range is 30% to 70%, and the third range is 70% to 100%. Different security warning levels correspond to different network security risk levels and countermeasures. When in the first level, it indicates that the network security status of the coal production area to be monitored is good and the risk is low, and the existing protection measures can be maintained, and routine monitoring and inspection can be performed. When in the second level, it means that the network of the region has certain security risks, and relevant personnel should strengthen real-time monitoring, investigate hidden dangers, and develop plans in advance to prevent risks from expanding. When in the third level, it indicates that the network of the region is facing high risks and may be attacked or have an accident, and the emergency response mechanism needs to be started immediately, and emergency measures such as strengthening protection, limiting access, and blocking abnormal traffic are taken to ensure the safe and stable operation of the network system and avoid affecting coal production. By comparing the final warning value with different ranges to determine the warning level, the network security status of the coal enterprise can be clearly indicated, and corresponding measures can be taken according to the level to effectively prevent and respond to network security threats and ensure the smooth progress of coal production.
[0038] Referring to Figure 2 In some embodiments of the present application, the present embodiment provides an artificial intelligence-based network security warning method, comprising the following steps: S100: determining a coal production area to be monitored, collecting historical network security events of the coal production area to be monitored, and analyzing the historical network security events, and determining an initial network security warning value of the coal production area to be monitored based on the analysis result; S200: collecting actual application scenario information of the coal production area to be monitored, and determining whether to adjust the initial network security warning value according to the actual application scenario information; S300: when it is determined that the initial network security warning value is adjusted, collecting coal production parameters and network operation parameters of the coal production area to be monitored, determining an adjustment coefficient of the initial network security warning value based on the coal production parameters and the network operation parameters, and obtaining a final network security warning value; S400: determining a security warning level of the coal production area to be monitored according to the final network security warning value.
[0039] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system or a computer program product. Therefore, the present application can be in the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can be in the form of a computer program product implemented on one or more computer usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer usable program code.
[0040] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart or flowsheet block or blocks. Figure 1 one or more flowcharts and / or blocks Figure 1 means for functionally implementing the steps listed in the flowchart
[0041] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart or flowsheet block or blocks. Figure 1 one or more flowcharts and / or blocks Figure 1 means for functionally implementing the steps listed in the flowchart
[0042] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart or flowsheet block or blocks. Figure 1 one or more flowcharts and / or blocks Figure 1 means for functionally implementing the steps listed in the flowchart
[0043] Finally, it should be noted that the above-mentioned embodiments are merely intended for describing the technical solutions of the present application, but not for limiting thereof. Although the present application is described in detail with reference to the above embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or equivalent replaced without departing from the spirit and scope of the present application, and any modification or equivalent replacement without departing from the spirit and scope of the present application should be covered in the protection scope of the claims of the present application.
Claims
1. An artificial intelligence-based network security early warning system, characterized in that, The method comprises the following steps: a collection module is configured to determine a coal production area to be monitored, collect historical network security events of the coal production area to be monitored, and analyze the historical network security events, and determine an initial network security warning value of the coal production area to be monitored based on the analysis result; a judgment module is configured to collect actual application scene information of the coal production area to be monitored, and determine whether to adjust the initial network security warning value according to the actual application scene information; an adjustment module is configured to collect coal production parameters and network operation parameters of the coal production area to be monitored when it is determined to adjust the initial network security warning value, determine an adjustment coefficient of the initial network security warning value based on the coal production parameters and the network operation parameters, and obtain a final network security warning value; a warning module is configured to determine a security warning level of the coal production area to be monitored according to the final network security warning value. 2.The artificial intelligence-based network security early warning system according to claim 1, characterized in that, When the historical network security events are analyzed and the initial network security warning value of the coal production area to be monitored is determined based on the analysis result, the method comprises the following steps: the historical network security events are analyzed to obtain network security vulnerability types, security event occurrence frequencies and security event severities of the coal production area to be monitored; a basic network security warning value of the coal production area to be monitored is determined based on the security vulnerability types, the security event occurrence frequencies and the security event severities; production stage information of the coal production area to be monitored is collected to obtain a network dependence degree corresponding to each production stage information, and it is determined whether to optimize the basic network security warning value according to the network dependence degree; if yes, an optimization coefficient of the basic network security warning value is determined according to the network dependence degree, and the initial network security warning value is obtained. 3.The AI-based cyber security early warning system of claim 2, wherein, The security vulnerability types comprise physical layer security vulnerabilities, network layer security vulnerabilities, transmission layer security vulnerabilities and application layer security vulnerabilities. 4.The AI-based cyber security early warning system of claim 2, wherein, When it is determined whether to optimize the basic network security warning value according to the network dependence degree, the method comprises the following steps: the network dependence degree is compared with a network dependence degree threshold value, and it is determined whether to optimize the basic network security warning value according to the comparison result; when the network dependence degree is within the network dependence degree threshold value, it is determined not to optimize the basic network security warning value; when the network dependence degree is outside the network dependence degree threshold value, it is determined to optimize the basic network security warning value. 5.The artificial intelligence-based network security early warning system according to claim 4, characterized in that, When the optimization coefficient of the basic network security warning value is determined according to the network dependence degree, and the initial network security warning value is obtained, the method comprises the following steps: a center value of the network dependence degree threshold value is obtained, a difference between the network dependence degree and the center value is calculated, and is recorded as a dependence degree difference value; an absolute value of the dependence degree difference value is obtained, and is recorded as an absolute dependence degree difference value; The absolute dependence degree difference value is compared with a first absolute dependence degree difference value and a second absolute dependence degree difference value, and the optimization coefficient is determined according to a comparison result; wherein the first absolute dependence degree difference value is less than the second absolute dependence degree difference value; When the absolute dependence degree difference value is less than or equal to the first absolute dependence degree difference value, the optimization coefficient is determined as a first optimization coefficient; When the absolute dependence degree difference value is greater than the first absolute dependence degree difference value and less than or equal to the second absolute dependence degree difference value, the optimization coefficient is determined as a second optimization coefficient; When the absolute dependence degree difference value is greater than the second absolute dependence degree difference value, the optimization coefficient is determined as a third optimization coefficient; A product value of the optimization coefficient and the base network security early warning value is taken as the initial network security early warning value. 6.The AI-based cyber security early warning system of claim 5, wherein, When determining whether to adjust the initial network security early warning value according to the actual application scenario information, comprising: Feature extraction is performed on the actual application scenario information to obtain a plurality of actual application scenario feature values; An actual application scenario standard value corresponding to each actual application scenario feature value is obtained; The actual application scenario feature value is compared with the corresponding actual application scenario standard value, and whether to adjust the initial network security early warning value is determined according to the comparison result; If there is an actual application scenario feature value greater than or equal to the corresponding actual application scenario standard value, it is determined to adjust the initial network security early warning value; Otherwise, it is determined not to adjust the initial network security early warning value. 7.The AI-based cyber security early warning system of claim 6, wherein, When determining the adjustment coefficient of the initial network security early warning value based on the coal production parameters and the network running parameters to obtain the final network security early warning value, comprising: The coal production parameters are analyzed to obtain real-time coal production indexes; The network running parameters are analyzed to obtain real-time network performance indexes; A correlation coefficient of the real-time coal production indexes and the real-time network performance indexes is determined; The correlation coefficient is compared with historical data, and the adjustment coefficient is determined according to the comparison result; When there is a historical correlation coefficient identical to the correlation coefficient in the historical data, a historical adjustment coefficient corresponding to the historical correlation coefficient is taken as the adjustment coefficient; When there is no historical correlation coefficient identical to the correlation coefficient in the historical data, the adjustment coefficient is determined according to the correlation coefficient; A product value of the adjustment coefficient and the initial network security early warning value is taken as the final network security early warning value. 8.The AI-based cyber security early warning system of claim 7, wherein, When the adjustment coefficient is determined according to the correlation coefficient, comprising: The correlation coefficient is compared with a first correlation coefficient and a second correlation coefficient, and the adjustment coefficient is determined according to a comparison result; wherein the first correlation coefficient is less than the second correlation coefficient; When the correlation coefficient is less than or equal to the first correlation coefficient, the adjustment coefficient is determined as a first adjustment coefficient; When the correlation coefficient is greater than the first correlation coefficient and less than or equal to the second correlation coefficient, the adjustment coefficient is determined as a second adjustment coefficient; When the correlation coefficient is greater than the second correlation coefficient, the adjustment coefficient is determined as a third adjustment coefficient. 9.The AI-based cyber security early warning system of claim 8, wherein, When the final network security early warning value falls into the first range, the safety early warning level is determined as a first level. When the final network security early warning value falls into the second range, the safety early warning level is determined as a second level. When the final network security early warning value falls into the third range, the safety early warning level is determined as a third level. When the final network security early warning value falls into the third range, the safety early warning level is determined as a third level. The method comprises: 10.A method for network security early warning based on artificial intelligence, applied to the network security early warning system based on artificial intelligence according to any one of claims 1-9, characterized in that, determining a coal production area to be monitored, collecting historical network security events of the coal production area to be monitored, and analyzing the historical network security events, and determining an initial network security early warning value of the coal production area to be monitored based on the analysis result; collecting actual application scenario information of the coal production area to be monitored, and determining whether to adjust the initial network security early warning value based on the actual application scenario information; when it is determined to adjust the initial network security early warning value, collecting coal production parameters and network operation parameters of the coal production area to be monitored, determining an adjustment coefficient of the initial network security early warning value based on the coal production parameters and the network operation parameters, and obtaining a final network security early warning value; determining a safety early warning level of the coal production area to be monitored based on the final network security early warning value.