Emergency management information distribution supervision method and system based on network security

By combining a multi-objective risk factor assessment model with adaptive thresholds and game theory mechanisms, the problems of a single risk assessment model and inflexible strategy adjustment in information distribution for cybersecurity emergency management are solved. This enables dynamic optimization of the information distribution process and security situation monitoring, thereby improving the efficiency and security of emergency management.

CN120934852APending Publication Date: 2025-11-11CHENGDU INST OF URBAN SAFETY & EMERGENCY MANAGEMENT
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511165948.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-20
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing technologies in cybersecurity emergency management information distribution use a single risk assessment model, which fails to fully consider the interaction and coupling relationships between various risk factors. The information distribution strategy lacks flexibility and dynamism, making it difficult to adapt to complex and ever-changing network environments, thus affecting the efficiency and security of emergency management information distribution.

Method used

A multi-objective risk factor assessment model is used to extract multi-dimensional risk factors from information distribution-related data. The strategy is dynamically adjusted by combining adaptive thresholds and game theory mechanisms. A comprehensive situation dataset is generated through data fusion and situation visualization engine for real-time monitoring and strategy optimization.

Benefits of technology

It enables a comprehensive reflection of the risk situation in the information distribution process, dynamically adjusts strategies to adapt to complex network environments, improves the efficiency and security of emergency management information distribution, and provides comprehensive and intuitive regulatory basis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934852A_ABST
    Figure CN120934852A_ABST
Patent Text Reader

Abstract

The invention discloses an emergency management information distribution supervision method and system based on network security. The method comprises the following steps: extracting multi-dimensional risk factors related to information distribution through a multi-target risk factor evaluation model, and processing the multi-dimensional risk factors through a self-adaptive threshold and game theory mechanism; fusing the processed risk factor data and real-time state data by a data fusion and situation visualization engine to form a comprehensive situation data set; potential risks are evaluated based on the data set, a distribution strategy is dynamically optimized through an adaptive threshold value and a game theory mechanism according to an evaluation result, and then a data fusion and situation visualization engine monitors in real time and converts data into a visual situation chart. The system comprises six units which are connected in sequence and work cooperatively. According to the method and the system, through multi-target risk assessment, dynamic strategy optimization and data fusion visualization, the security, the efficiency and the supervision intuition of information distribution are improved, and the method and the system are suitable for a network security emergency management information distribution supervision scene.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security emergency management information, and in particular to a method and system for monitoring and distributing emergency management information based on network security. Background Technology

[0002] In today's era of rapid development in network technology, cybersecurity incidents are frequent, making the security, timeliness, and accuracy of information distribution during emergency management increasingly critical. The handling of various emergency incidents relies on efficient information transmission; however, information distribution faces multiple risks, including unreliable information sources, vulnerable transmission links, and security vulnerabilities in terminal devices. These intertwined risk factors can lead to delays or errors in emergency decision-making. To address these issues, there is an urgent need to develop an information distribution and monitoring method and system capable of comprehensively assessing multi-objective risks, dynamically adjusting monitoring strategies, integrating multi-source data, and achieving situational visualization, thereby ensuring the orderly conduct of cybersecurity emergency management.

[0003] Existing technologies have significant shortcomings in the supervision of information distribution for cybersecurity emergency management. On the one hand, risk assessment models are relatively simplistic, often analyzing isolated risk factors without fully considering the interactions and coupling relationships between them. This leads to discrepancies between risk assessment results and actual conditions, making it difficult to comprehensively reflect the security situation during information distribution. On the other hand, information distribution strategies lack flexibility and dynamism, mostly relying on fixed thresholds or preset rules for regulation. They fail to incorporate game theory mechanisms to consider the strategy choices and payoff balances of various participants. Faced with complex and ever-changing network environments, these strategies struggle to quickly adapt and optimize, impacting the efficiency and security of emergency management information distribution. Summary of the Invention

[0004] In order to overcome the shortcomings and deficiencies of existing technologies, this invention provides a method and system for the distribution and supervision of emergency management information based on network security.

[0005] The technical solution adopted in this invention is an emergency management information distribution and supervision method based on network security, characterized by comprising the following steps:

[0006] Step S1: Extract multi-dimensional risk factors from information distribution-related data generated during network security emergency management using a multi-objective risk factor assessment model. The multi-dimensional risk factors include information source credibility, transmission link stability, receiving terminal security, information content confidentiality level, and distribution timeliness requirements.

[0007] Step S2 involves inputting the extracted multi-dimensional risk factors into an adaptive threshold and game theory mechanism. This mechanism dynamically adjusts the initial threshold corresponding to each risk factor and simultaneously constructs a set of game strategies among the participants in information distribution. The set of game strategies includes the distribution strategy of the information sender, the verification strategy of the receiver, and the regulation strategy of the regulator.

[0008] Step S3: Use the data fusion and situation visualization engine to fuse the risk factor data and real-time status data in the information distribution process after the adaptive threshold and game theory mechanism are processed to form a comprehensive situation dataset after the fusion of multi-source heterogeneous data.

[0009] Step S4: Based on the comprehensive situation dataset, the potential risks in the information distribution process are quantitatively assessed using a multi-objective risk factor assessment model to generate risk assessment results. The quantitative assessment involves the weight allocation and interaction analysis of each risk factor.

[0010] Step S5: Based on the risk assessment results, the adaptive threshold and game theory mechanism are restarted to dynamically optimize the information distribution strategy, including adjusting the information transmission path, changing the encryption method, and updating the verification rules.

[0011] Step S6: The data fusion and situation visualization engine monitors the optimized information distribution process in real time, integrates and processes the monitored data, and transforms it into a visual situation chart to supervise the entire process of information distribution for cybersecurity emergency management.

[0012] Furthermore, in step S2, when the adaptive threshold and game theory mechanism dynamically adjust the initial threshold, the risk impact coefficient from the multi-objective risk factor assessment model is introduced to construct the threshold adjustment model: Among them, T adj T represents the adjusted threshold. init α represents the initial threshold, n represents the number of risk factors, and α represents the initial threshold. i R represents the influence weight of the i-th risk factor. i Let represent the quantified value of the i-th risk factor; simultaneously, when constructing the Boyi strategy set, considering the real-time requirements of information distribution in cybersecurity emergency management, define Boyi... Payoff function: Among them, U j Let β represent the payoff of the j-th participant, m represent the number of strategies, and β represent the payoff of the j-th participant. k S represents the weight of the k-th strategy. jk Let C represent the payoff value of the j-th participant using the k-th strategy. jk This represents the cost of the j-th participant adopting the k-th strategy.

[0013] Furthermore, in step S3, when the data fusion and situation visualization engine perform fusion processing, a hierarchical fusion strategy is adopted, combining the credibility assessment results of each data point from the multi-objective risk factor assessment model. First, primary fusion is performed on similar data to eliminate data redundancy, and then advanced fusion is performed on different types of data to generate a comprehensive situation dataset. During this process, a data fusion weight model is constructed. Among them, W ij γ represents the fusion weight of the j-th data in the i-th data category, p represents the number of data types, and γ i C represents the importance coefficient of the i-th data category. ij Let represent the confidence value of the j-th data point in the i-th data category; simultaneously, to ensure the timeliness of the fused data, a time decay factor is introduced to establish a data timeliness correction model: Among them, D′ ij D represents the value of the j-th data in the i-th data group after correction. ij λ represents the original data value, t represents the time decay coefficient, and t represents the time decay coefficient. ij This indicates the time interval between data generation and fusion.

[0014] Furthermore, in step S4, when the multi-objective risk factor assessment model performs quantitative assessment, it comprehensively considers the dynamic change characteristics of each risk factor, constructs a risk assessment matrix, and obtains the quantitative value of each potential risk through matrix operations; the risk assessment model is defined as follows: Where R represents the overall risk quantification value, r represents the number of risk categories, t represents the number of sub-risks under each risk category, and θ q δ represents the weight of the q-th type of risk. s F represents the weight of the s-th sub-risk under the q-th risk class. qs Let C represent the product of the probability of occurrence and the degree of impact of the s-th sub-risk under the q-th risk category; simultaneously, to reflect the interaction between risk factors, a coupling coefficient is introduced to establish a risk coupling model: C ab =μ×(R) a ×R b ) / (R a +R b ), where C ab R represents the degree of coupling between risk factor a and risk factor b, μ represents the coupling coefficient, and R represents the coupling coefficient. a R b These represent the quantitative values ​​of the a-th and b-th risk factors, respectively.

[0015] Furthermore, in step S5, when the adaptive threshold and game theory mechanism dynamically optimize the information distribution strategy, the risk assessment results from step S4 are used as a basis. When the risk quantification value exceeds the set range, the strategy optimization process is automatically triggered; the strategy optimization objective function is constructed as follows: Where O represents the target value, v represents the number of policies to be optimized, and ξ u L represents the optimization weight of the u-th strategy. u Let represent the loss value of the u-th strategy; simultaneously, combining the strategy choices of the participating agents in game theory, a strategy choice probability model is established: Among them, P jk U represents the probability that the j-th participant chooses the k-th strategy, η represents the sensitivity coefficient for strategy selection, and U jk Let m represent the payoff value of the j-th participant using the k-th strategy, and m represent the number of strategies.

[0016] Furthermore, in step S6, when the data fusion and situation visualization engine performs real-time monitoring, the monitoring data is segmented according to the time series, each segment is independently fused and analyzed, and then the results of each segment are integrated; a segmented fusion model for monitoring data is constructed: Among them, F t This represents the fusion result of the t-th data segment, where n is the fusion result. t ζ represents the number of data points in the t-th segment. l M represents the weight of the l-th data point in the y-th segment. tl This represents the value of the l-th monitoring data in segment t; simultaneously, in the process of converting it into a visual situation chart, considering the decision-making needs of cybersecurity emergency management, a chart parameter mapping model is established: Among them, V p This represents the value of the p-th chart parameter, κ represents the mapping coefficient, s represents the number of data dimensions, and φ q D represents the mapping weight of the q-th data dimension. pq This represents the value of the q-th data dimension corresponding to the p-th chart parameter.

[0017] Further, step S3 includes the following sub-steps: S3.1, Data Acquisition Sub-step: Real-time acquisition of various types of data during the information distribution process is achieved through monitoring devices deployed at each node of the network. The types of data acquired include information transmission rate, packet loss rate, node load, and information encryption status. Data sampling is performed at preset time intervals during the acquisition process to ensure the continuity and representativeness of the data; S3.2, Data Classification Sub-step: The acquired data is classified according to its source, type, and associated risk factors. Data belonging to the same information distribution link are marked as belonging to the same category, and independent data subsets are established for data related to different risk factors. Automatic classification is performed during the classification process based on the characteristic values ​​of the data. The data is categorized, allowing for manual correction of the classification results; S3.3, Data Association Analysis sub-step, performs association analysis on the categorized data to uncover the inherent connections between different data. By analyzing the data's timestamps, transmission path identifiers, and node ID information, the correspondence between data and information distribution events is determined, and a data association graph is established to provide a basis for subsequent fusion processing; S3.4, Multi-Source Fusion sub-step, based on the data association graph, uses a weighted average method to fuse multi-source data, assigning different weights according to the data's credibility and importance. During the fusion process, abnormal data is identified and filtered, and the fused data is organized into a structured comprehensive situational dataset and stored in a designated database.

[0018] Further, step S4 includes the following sub-steps: S4.1, Risk Factor Weight Determination Sub-step: Based on the multi-objective risk factor assessment model, the weight of each risk factor is determined using the analytic hierarchy process (AHP). A judgment matrix is ​​constructed, and the maximum eigenvalue and corresponding eigenvector of the matrix are calculated. The eigenvector is used as the weight value of each risk factor. During the weight determination process, experts in the field of cybersecurity emergency management are invited to conduct a consistency check on the judgment matrix; S4.2, Risk Quantification Sub-step: Each risk factor is quantified according to a preset quantification standard, transforming qualitatively described risk factors into quantitative values. For directly measurable risk factors, calculations are performed using collected actual data. For risk factors that are difficult to measure directly, historical data is considered. Historical data and expert experience are used to estimate the quantitative values ​​of each risk factor; S4.3, the comprehensive risk assessment sub-step, involves weighted summation of the quantitative values ​​of each risk factor with their corresponding weights to obtain the overall risk quantitative value in the information distribution process. Simultaneously, the contribution of each risk factor is analyzed to determine the primary and secondary risk factors, generating a risk assessment report. The report includes the quantitative results of each risk factor, the overall risk value, and the risk level classification; S4.4, the assessment result verification sub-step, compares and verifies the risk assessment results with the risk situations in historical cases, calculates the degree of deviation between the assessment results and the actual risk, and adjusts the parameters of the multi-objective risk factor assessment model based on the degree of deviation to improve the accuracy of subsequent risk assessments.

[0019] Further, step S5 includes the following sub-steps: S5.1, Strategy optimization trigger judgment sub-step, which compares the risk assessment result obtained in step S4 with the adaptive threshold. When the overall risk quantification value exceeds the upper limit of the adaptive threshold, the strategy optimization process is triggered. When the overall risk quantification value is lower than the lower limit of the adaptive threshold, the current information distribution strategy remains unchanged. When the overall risk quantification value is within the adaptive threshold range, some high-risk links are fine-tuned. S5.2, Optimization scheme generation sub-step, which generates multiple information distribution strategy optimization schemes based on the triggered optimization level and the strategy set of each participating entity in the game theory mechanism. The optimization schemes include transmission path change schemes, encryption algorithm upgrade schemes, and verification streams. The process is simplified, with each scheme clearly defined in terms of specific implementation steps and expected effects; S5.3, the scheme evaluation and selection sub-step, uses a multi-objective decision-making method to evaluate the generated optimized schemes. Evaluation indicators include the degree of risk reduction, implementation cost, and impact on information distribution efficiency. The optimal optimized scheme is selected based on the evaluation results, taking into full account the actual needs and resource constraints of network security emergency management during the selection process; S5.4, the strategy execution and feedback sub-step, applies the selected optimized scheme to the information distribution process, monitors the effects of strategy execution in real time, collects relevant data on information distribution, calculates the risk quantification value after strategy execution, and feeds the results back to the adaptive threshold and game theory mechanism to provide a basis for the next strategy optimization.

[0020] A network security-based emergency management information distribution and monitoring system includes:

[0021] The multi-dimensional risk factor extraction unit is used to extract multi-dimensional risk factors from data related to the distribution of network security emergency management information through a multi-objective risk factor assessment model. This unit is connected to the network data acquisition device and receives the collected raw data.

[0022] The dynamic threshold adjustment and game strategy construction unit is connected to the output of the multi-dimensional risk factor extraction unit. It receives the extracted multi-dimensional risk factors and uses them to dynamically adjust the initial threshold and construct a set of game strategies through adaptive threshold and game theory mechanism.

[0023] The multi-source data fusion and situation dataset generation unit has its input end connected to the output end of the dynamic threshold adjustment and game strategy construction unit to receive processed risk factor data. At the same time, it is connected to the real-time status monitoring device to receive information and distribute real-time status data, which is used to fuse and process the received data to generate a comprehensive situation dataset.

[0024] The risk quantification assessment unit is connected to the output of the multi-source data fusion and situation dataset generation unit at its input end. It receives the comprehensive situation dataset and is used to quantify potential risks and generate risk assessment results through a multi-objective risk factor assessment model.

[0025] The information distribution strategy dynamic optimization unit has its input connected to the output of the risk quantification assessment unit and the output of the dynamic threshold adjustment and game strategy construction unit, respectively. It receives the risk assessment results and the game strategy set, and is used to dynamically optimize the information distribution strategy based on the risk assessment results.

[0026] The real-time monitoring and visualization unit has its input ends connected to the output ends of the dynamic optimization unit for the distribution strategy and the multi-source data fusion and situation dataset generation unit, respectively. It receives the optimized strategy information and the comprehensive situation dataset, and uses it to monitor the information distribution process in real time and convert the data into a visual situation chart. This unit is connected to a display device to display the visual chart.

[0027] Beneficial Effects: This invention proposes a method and system for monitoring and distributing emergency management information based on network security. It comprehensively assesses multi-dimensional risk factors related to information distribution through a multi-objective risk factor assessment model, fully considering the interactions and coupling relationships between various risk factors. This solves the problem of biased results caused by the single risk assessment model and lack of comprehensive consideration of the correlation between risk factors in existing technologies, and can comprehensively reflect the security situation during the information distribution process. By utilizing adaptive thresholds and game theory mechanisms, it can dynamically adjust thresholds and optimize distribution strategies. Combined with the strategy choices and benefit balance of various participating entities, it overcomes the shortcomings of existing technologies, such as lack of flexibility and dynamism in strategy adjustment and difficulty in adapting to complex network environments, thus improving the efficiency and security of emergency management information distribution. Simultaneously, the data fusion and situation visualization engine realizes multi-source data fusion and situation visualization, providing comprehensive and intuitive evidence for supervision and ensuring the orderly conduct of network security emergency management work. Attached Figure Description

[0028] Figure 1 This is a flowchart of the method steps of the present invention;

[0029] Figure 2 This is a diagram showing the system unit composition of the present invention. Detailed Implementation

[0030] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. The application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0031] like Figure 1As shown, the emergency management information distribution and supervision method based on network security includes the following steps:

[0032] Step S1: Extract multi-dimensional risk factors from information distribution-related data generated during network security emergency management using a multi-objective risk factor assessment model. The multi-dimensional risk factors include information source credibility, transmission link stability, receiving terminal security, information content confidentiality level, and distribution timeliness requirements.

[0033] Specifically, the multi-objective risk factor assessment model, when extracting multi-dimensional risk factors, involves technical parameters covering the scoring range of information source credibility, the fluctuation coefficient of transmission link stability, vulnerability detection indicators of receiving terminal security, the classification standards of information content confidentiality levels, and the time interval for distribution timeliness requirements. These parameters collectively constitute the foundation of a comprehensive risk assessment. Their significance lies in capturing potential security risks during information distribution from multiple perspectives, providing accurate initial data support for subsequent processing and supervision, ensuring the comprehensiveness and relevance of the risk assessment, and avoiding regulatory oversights due to insufficient consideration of a single factor.

[0034] In practice, the credibility score of information sources is set between 0 and 100 points. This is achieved through quantitative scoring of the information publisher's historical behavior records and qualification certifications. For example, information sources certified by authoritative institutions initially receive a score of 80 points, with 5-30 points deducted depending on the extent of any information distortion. The stability fluctuation coefficient of the transmission link is represented by the change in the hourly packet loss rate, with normal fluctuations controlled within 0.5%. A fluctuation coefficient exceeding 1% is considered unstable. Vulnerability detection indicators for receiving terminal security include system patch update status and firewall configuration level. Terminals with delayed system patch updates exceeding 7 days are considered to have medium-to-high risk vulnerabilities. Information content is classified into four levels: Top Secret, Confidential, Secret, and Public. Different levels correspond to different distribution scopes and encryption requirements; for example, Top Secret information is only accessible to specific core personnel. The time interval for distribution timeliness is set according to the urgency of the emergency. Information distribution for particularly urgent events must be completed within 10 minutes, while general emergencies can be completed within 30 minutes. Through these specific parameter settings and implementation methods, multi-dimensional risk factors are extracted.

[0035] Step S2 involves inputting the extracted multi-dimensional risk factors into an adaptive threshold and game theory mechanism. This mechanism dynamically adjusts the initial threshold corresponding to each risk factor and simultaneously constructs a set of game strategies among the participants in information distribution. The set of game strategies includes the distribution strategy of the information sender, the verification strategy of the receiver, and the regulation strategy of the regulator.

[0036] Specifically, in the adaptive threshold and game theory mechanism, the initial threshold setting is related to the characteristics of each risk factor, including the minimum acceptable score for the credibility of the information source, the critical fluctuation coefficient for the stability of the transmission link, the number of vulnerabilities that the receiving terminal can tolerate, the minimum encryption strength corresponding to the confidentiality level of the information content, and the maximum allowable delay time for distribution. The significance of these parameters lies in providing clear judgment criteria for handling risk factors. The construction of the game strategy set considers the interests and behavioral logic of all parties involved in information distribution. By clarifying the strategy choices of each party, it provides an interactive framework for dynamic adjustment and optimization, ensuring that in a complex information distribution environment, the needs of all parties can be balanced, achieving effective supervision and control.

[0037] In practice, the minimum acceptable score for the credibility of the information source is 60 points. When the credibility score of the extracted information source is lower than this value, a further verification process is triggered. The critical fluctuation coefficient for transmission link stability is set at 1.5%. When the fluctuation coefficient exceeds this value, the adaptive threshold mechanism starts to dynamically adjust the threshold. The adjustment range is calculated based on the proportion exceeding the threshold. For example, if the proportion exceeds 20%, the subsequent critical fluctuation coefficient will be temporarily lowered by 10%. The number of vulnerabilities that the receiving terminal can tolerate is 2. When 3 or more unpatched vulnerabilities are detected in the terminal, a terminal security hardening prompt is initiated. Among the minimum encryption strengths corresponding to the information content's confidentiality level, top-secret information requires the use of a 256-bit AES encryption algorithm, and confidential information requires the use of a 128-bit AES encryption algorithm. The maximum allowable delay time for distribution varies depending on the confidentiality level. The maximum delay for secret information is no more than 15 minutes, and the maximum delay for public information is no more than 60 minutes. In the set of game strategies, the information sender's distribution strategies include direct distribution, encrypted distribution, and forwarding via intermediate nodes, while the receiver's verification strategies include identity verification and information integrity verification, and the regulator's control strategies include suspending distribution and adjusting transmission paths. Through the interaction and adjustment of the strategies of all parties, the initial threshold can be dynamically optimized and the strategy can be adaptively selected.

[0038] Step S3: Use the data fusion and situation visualization engine to fuse the risk factor data and real-time status data in the information distribution process after the adaptive threshold and game theory mechanism are processed to form a comprehensive situation dataset after the fusion of multi-source heterogeneous data.

[0039] Specifically, the data fusion and situation visualization engine involves technical parameters such as data fusion accuracy, data transmission rate, and situation chart update frequency when processing data. Data fusion accuracy is measured by the deviation rate between the fused data and the original data. Data transmission rate affects the efficiency of real-time data acquisition and processing, while the update frequency of situation charts relates to whether regulators can promptly grasp the latest information distribution status. Its significance lies in integrating scattered and heterogeneous risk factor data and real-time status data into a unified and coherent comprehensive situation dataset, eliminating data redundancy and conflicts. Simultaneously, by presenting this data visually, regulators can intuitively understand the overall situation of information distribution, improving the efficiency and accuracy of supervision.

[0040] In the specific implementation process, the deviation rate of data fusion accuracy is controlled within 3%. Weighted average method is used to fuse similar data. For example, the transmission link fluctuation coefficient collected from different monitoring points is calculated and fused according to the credibility weight of each monitoring point (e.g., the weight of the main monitoring point is 0.6, and the weight of the auxiliary monitoring point is 0.4). The data transmission rate is required to be no less than 10Mbps to ensure that real-time status data can be transmitted to the engine for processing in a timely manner. When the transmission rate is lower than 5Mbps, the data compression transmission mode is activated to reduce the amount of data to ensure transmission continuity. The update frequency of the situation chart is set to once every 30 seconds. For information distribution processes with higher risk levels, the update frequency is increased to once every 10 seconds. During the fusion processing, the risk factor data, after being processed by adaptive thresholds and game theory mechanisms, is first standardized to ensure that it is consistent with the format of real-time status data (such as real-time transmission rate, terminal online status, etc.). Then, the data association algorithm is used to identify the correlation between the data, such as associating the credibility data of a specific information source with the transmission link data of the information sent by that information source. Finally, the data is integrated to form a comprehensive situational dataset containing information on information sources, transmission links, receiving terminals, content confidentiality levels, distribution timeliness, and other aspects. This dataset is stored in a high-performance database to provide data support for subsequent assessment and monitoring.

[0041] Step S4: Based on the comprehensive situation dataset, the potential risks in the information distribution process are quantitatively assessed using a multi-objective risk factor assessment model to generate risk assessment results. The quantitative assessment involves the weight allocation and interaction analysis of each risk factor.

[0042] Specifically, when using a multi-objective risk factor assessment model for quantitative evaluation, technical parameters are involved, including the weighting coefficients of each risk factor, the range of risk occurrence probabilities, and the grading standards for the degree of risk impact. The weighting coefficients reflect the importance of different risk factors in the overall risk assessment, while the probability of risk occurrence and the degree of impact jointly determine the quantitative value of an individual risk factor. The significance of these parameters lies in transforming qualitative risk descriptions into quantitative assessment results through scientific quantification, enabling the comparison and synthesis of the impacts of different risk factors. This allows for an accurate grasp of the main risk points and overall risk level in the information distribution process, providing a reliable basis for subsequent strategy optimization.

[0043] In the specific implementation process, the weight coefficients of each risk factor are determined through expert scoring and the analytic hierarchy process. The weight coefficient for the credibility of the information source is set to 0.25, the weight coefficient for the stability of the transmission link is set to 0.2, the weight coefficient for the security of the receiving terminal is set to 0.2, the weight coefficient for the confidentiality level of the information content is set to 0.15, and the weight coefficient for the timeliness requirement of distribution is set to 0.2. The probability of risk occurrence ranges from 0 to 1, with the most likely risk ranging from 0.8 to 1, the most likely risk ranging from 0.5 to 0.7, the least likely risk ranging from 0.2 to 0.4, and the almost impossible risk ranging from 0 to 0.1. The degree of risk impact is divided into four levels: minor, moderate, severe, and catastrophic, corresponding to quantitative values ​​of 1, 2, 3, and 4, respectively. In the quantitative assessment, the probability of risk occurrence is first calculated based on the actual data of each risk factor. For example, the probability of risk occurrence for a transmission link is calculated by the ratio of the number of times the transmission link is interrupted to the total transmission time in the past 24 hours. Then, the quantitative value of the impact of each risk factor is determined by combining the classification standard of risk impact. For example, when the information content is classified as top secret, the quantitative value of the impact of its leakage is 4. Next, the probability of risk occurrence is multiplied by the quantitative value of the impact to obtain the quantitative value of a single risk factor. Finally, each quantitative value is multiplied by its corresponding weight coefficient and summed to generate the overall risk assessment result. At the same time, the weight and quantitative value of each risk factor are analyzed to determine the top three risk factors that contribute the most to the overall risk and are identified as key focus areas.

[0044] Step S5: Based on the risk assessment results, the adaptive threshold and game theory mechanism are restarted to dynamically optimize the information distribution strategy, including adjusting the information transmission path, changing the encryption method, and updating the verification rules.

[0045] Specifically, when dynamically optimizing information distribution strategies using adaptive thresholds and game theory mechanisms, technical parameters such as the trigger threshold for strategy adjustments, the implementation cost of different strategies, and the response time of strategy adjustments are involved. The trigger threshold determines the risk level at which strategy optimization is initiated, the implementation cost reflects the resource consumption of different strategies, and the response time reflects the timeliness of strategy adjustments. The significance of these parameters lies in ensuring that strategy optimization can be implemented quickly at the appropriate time and at a reasonable cost. By adjusting information transmission paths, encryption methods, and verification rules, the risks in the information distribution process are reduced, and the efficiency and security of information distribution are improved, enabling the information distribution process to adapt to constantly changing risk situations.

[0046] In practice, the trigger threshold for strategy adjustment is set at 80 points (out of 100) of the overall risk assessment result. When the overall risk assessment result exceeds this value, the strategy optimization process is initiated immediately. The implementation costs of different strategies vary. For example, the cost of changing the transmission path includes the testing fee for the new path and the node coordination fee. It is estimated that the cost of a single change is about 500 yuan, while the cost of upgrading the encryption algorithm is mainly the software upgrade fee, which is about 300 yuan per time. The response time for strategy adjustment is required to be completed within 5 minutes, and the time interval from the start of the optimization process to the implementation of the new strategy shall not exceed this time. During dynamic optimization, the main causes of increased risk are first identified based on the risk assessment results generated in step S4. For example, if the decline in transmission link stability is the main risk point, then adjusting the information transmission path is given priority. Then, effective strategies targeting the cause are selected from the set of game strategies, such as switching to a backup transmission link or increasing link redundancy. The implementation cost and expected risk reduction of each strategy are calculated. Next, the acceptance and execution cost of different strategies by each participating party are analyzed through game theory mechanisms, such as the degree of cooperation of the information receiver in switching the transmission path and the difficulty of supervision by the regulator for the new strategy. Finally, the optimal strategy is selected and implemented by comprehensively considering the cost, risk reduction effect, and acceptance of all parties. For example, after determining to switch to a backup transmission link, a path adjustment instruction is immediately sent to the relevant nodes, the encryption method is updated to a higher level algorithm, and the verification frequency of the receiving terminal is increased from once per hour to once every 30 minutes.

[0047] Step S6: The data fusion and situation visualization engine monitors the optimized information distribution process in real time, integrates and processes the monitored data, and transforms it into a visual situation chart to supervise the entire process of information distribution for cybersecurity emergency management.

[0048] Specifically, the data fusion and situational visualization engine involves technical parameters such as the sampling frequency of monitoring data, data storage capacity, resolution of visualization charts, and display parameters during real-time monitoring and visualization. The sampling frequency determines the density and timeliness of the monitoring data; the data storage capacity ensures the retention and traceability of historical data; and the resolution and display parameters of the visualization charts affect the regulatory personnel's understanding and judgment of the information. Its significance lies in the ability to promptly identify new risks and anomalies through continuous monitoring of the optimized information distribution process, while presenting monitoring results in an intuitive and visual way. This enables regulatory personnel to quickly grasp the dynamic changes in information distribution, take timely countermeasures, and ensure the continuous security and efficiency of the information distribution process.

[0049] In practice, the sampling frequency of monitoring data is set to once per second. For the distribution of key information, the sampling frequency is increased to five times per second to capture more subtle changes. The data storage capacity is configured to 10TB, and a cyclic overwrite method is used to ensure that at least 30 days of monitoring data are retained to meet the needs of historical query and analysis. The resolution of the visualization charts is 1920×1080 pixels, and the color coding in the charts follows a unified standard, such as green indicating a normal state (risk value 0-30 points), yellow indicating a warning state (risk value 31-60 points), and red indicating a dangerous state (risk value 61-100 points). The axis scales of the curves and bars in the charts are accurate to two decimal places to ensure the accuracy of data display. During real-time monitoring, the engine continuously receives various data from the optimized information distribution process, including new transmission rates, data packet integrity, and terminal response times. This data is then fused in real-time, removing outliers (such as data exceeding the normal range by more than 10 times) and supplementing missing values ​​(using linear interpolation). The fused data is then categorized and organized according to time series and risk categories, transforming it into various visual charts such as line graphs (showing risk value trends), bar charts (comparing the quantitative values ​​of different risk factors), and network topology diagrams (displaying transmission paths and node status). Finally, these charts are pushed to the monitoring center's display screen in real-time, with an automatic alarm function set up. When a certain indicator exceeds a preset safety range, the corresponding area in the chart will flash and emit an audible alert, reminding regulators to pay attention and take timely action.

[0050] 2. The method according to claim 1, characterized in that, in step S2, when the adaptive threshold and game theory mechanism dynamically adjust the initial threshold, the risk impact coefficient in the multi-objective risk factor assessment model is introduced to construct a threshold adjustment model: Among them, T adj T represents the adjusted threshold. init α represents the initial threshold, n represents the number of risk factors, and α represents the initial threshold.i R represents the influence weight of the i-th risk factor. i Let represent the quantified value of the i-th risk factor; simultaneously, when constructing the Boyi strategy set, considering the real-time requirements of information distribution in cybersecurity emergency management, define Boyi... Payoff function: Among them, U j Let β represent the payoff of the j-th participant, n represent the number of strategies, and β represent the payoff of the j-th participant. k S represents the weight of the k-th strategy. jk Let C represent the payoff value of the j-th participant using the k-th strategy. jk This represents the cost of the j-th participant adopting the k-th strategy.

[0051] Specifically, the risk impact coefficient in the multi-objective risk factor assessment model introduced when dynamically adjusting the initial threshold using adaptive threshold and game theory mechanisms includes technical parameters such as the range of risk impact weights and the calculation standard for risk factor quantification values. The risk impact weights are determined based on the importance of each risk factor in information distribution supervision, ranging from 0.1 to 0.5; a larger value indicates a more significant impact of the risk factor on threshold adjustment. The risk factor quantification value is determined comprehensively based on the probability of risk occurrence and the scope of impact, ranging from 0 to 10. The significance of this threshold adjustment model is that it allows the threshold to flexibly change according to the actual risk situation, avoiding the problem of fixed thresholds being difficult to adapt to complex network environments. Simultaneously, the strategy weights in the game payoff function are set based on the effectiveness and feasibility of strategy implementation, ranging from 0 to 1. The payoff and cost values ​​of the strategy are derived from historical data and actual testing. The payoff value reflects the degree of risk reduction and efficiency improvement brought about by the strategy implementation, while the cost value includes resource consumption and time investment. The significance of this function is to provide a quantitative basis for participating entities to select the optimal strategy, ensuring that the strategy selection is both in line with their own interests and guarantees the security and efficiency of overall information distribution. In practice, the weights and quantifications of each risk factor are first calculated based on the actual data of the risk factors, and then substituted into the threshold adjustment model to obtain the adjusted threshold. For the game payoff function, the payoff and cost values ​​of different strategies of each participant are collected, and the payoff of each strategy is calculated in combination with the strategy weights. Based on this, the participants are guided to choose strategies. In this way, the initial threshold is dynamically adjusted and the game strategy set is effectively constructed, so that the whole mechanism can better cope with various risk situations in information distribution in cybersecurity emergency management.

[0052] 3. The method according to claim 1, characterized in that, in step S3, when data fusion and situation visualization engine perform fusion processing, a hierarchical fusion strategy is adopted by combining the credibility assessment results of each data from the multi-objective risk factor assessment model. First, primary fusion is performed on similar data to eliminate data redundancy, and then advanced fusion is performed on different types of data to generate a comprehensive situation dataset; in this process, a data fusion weight model is constructed: Among them, W ij γ represents the fusion weight of the j-th data in the i-th data category, p represents the number of data types, and γ i C represents the importance coefficient of the i-th data category. ij Let represent the confidence value of the j-th data point in the i-th data category; simultaneously, to ensure the timeliness of the fused data, a time decay factor is introduced to establish a data timeliness correction model: Among them, D′ ij D represents the value of the j-th data in the i-th data group after correction. ij λ represents the original data value, t represents the time decay coefficient, and t represents the time decay coefficient. ij This indicates the time interval between data generation and fusion.

[0053] Specifically, the layered fusion strategy employed when integrating data with the situation visualization engine involves technical parameters such as the criteria for classifying data importance coefficients, evaluation indicators for data credibility values, and rules for setting time decay coefficients. The data importance coefficient is determined based on the criticality of the data for information distribution and supervision; the coefficient for core data is set at 0.6-0.8, and the coefficient for auxiliary data is set at 0.2-0.4. The data credibility value is obtained through evaluation of multiple aspects, including the reliability of the data source and the stability of the transmission process, and ranges from 0 to 1, with higher values ​​indicating more reliable data. The time decay coefficient is set according to the timeliness requirements of the data; for data with high real-time requirements, the coefficient is set at 0.05-0.1, and for data with lower real-time requirements, the coefficient is set at 0.01-0.03. The significance of the data fusion weight model lies in scientifically allocating the weights of each data point in the fusion process, ensuring that the fusion result better reflects the true situation; the significance of the data timeliness correction model lies in eliminating the interference of outdated data on the fusion result, ensuring the timeliness and accuracy of the data. During implementation, preliminary fusion is first performed on similar data. The fusion weights of each data point are calculated according to a data fusion weighting model, and the weighted sum is used to obtain the preliminary fusion result. Then, advanced fusion is performed on different types of data. Simultaneously, a data timeliness correction model is applied to correct the data, and the corrected data is integrated to form a comprehensive situational awareness dataset. Through this layered fusion and correction process, data redundancy and conflicts are effectively eliminated, data quality and usability are improved, and reliable data support is provided for subsequent risk assessment and regulatory decisions.

[0054] 4. The method according to claim 1, characterized in that, in step S4, when the multi-objective risk factor assessment model performs quantitative assessment, it comprehensively considers the dynamic change characteristics of each risk factor, constructs a risk assessment matrix, and obtains the quantitative value of each potential risk through matrix operations; defining the risk assessment model: Where R represents the overall risk quantification value, r represents the number of risk categories, t represents the number of sub-risks under each risk category, and θ q δ represents the weight of the q-th type of risk. s F represents the weight of the s-th sub-risk under the q-th risk class. qs Let C represent the product of the probability of occurrence and the degree of impact of the s-th sub-risk under the q-th risk category; simultaneously, to reflect the interaction between risk factors, a coupling coefficient is introduced to establish a risk coupling model: C ab =μ×(R) a ×R b ) / (R a +R b ), where C ab R represents the degree of coupling between risk factor a and risk factor b, μ represents the coupling coefficient, and R represents the coupling coefficient. a R b These represent the quantitative values ​​of the a-th and b-th risk factors, respectively.

[0055] Specifically, when using the multi-objective risk factor assessment model for quantitative assessment, the number of risk categories is determined based on the actual risk scenarios of information distribution in cybersecurity emergency management, generally divided into 5-8 categories, with 3-5 sub-risks under each category. Risk weights are determined through a combination of expert review and statistical analysis, with both category risk weights and sub-risk weights ranging from 0 to 1, and the sum of the weights of all sub-risks within the same category being 1. The probability of risk occurrence is calculated based on the historical frequency of risk occurrence and the current network environment, ranging from 0 to 1. The quantitative value of the impact is set according to the scope and extent of damage to information distribution after the risk occurs: 1 for minor impact, 2 for moderate impact, 3 for severe impact, and 4 for catastrophic impact. The significance of the risk assessment model lies in comprehensively and accurately calculating the overall risk quantification value, providing a basis for identifying major risks. The coupling coefficient in the risk coupling model is set according to the degree of correlation between risk factors, ranging from 0 to 1, and is used to measure the additional risks generated by the interaction of different risk factors. Its significance lies in considering the mutual influence between risk factors, making the risk assessment results more consistent with reality. In practice, the risk categories and sub-risks are first determined, and their respective weights are calculated. Then, based on actual data, the probability of occurrence and the degree of impact of each sub-risk are obtained and substituted into the risk assessment model to obtain the overall risk quantification value. At the same time, the coupling degree between each risk factor is calculated, and the impact of risk coupling is analyzed. In this way, the potential risks in the information distribution process are quantitatively assessed, providing accurate risk basis for subsequent strategy optimization.

[0056] 5. The method according to claim 1, characterized in that, in step S5, when the adaptive threshold and game theory mechanism dynamically optimize the information distribution strategy, the risk assessment result of step S4 is used as the basis, and when the risk quantification value exceeds the set range, the strategy optimization process is automatically triggered; a strategy optimization objective function is constructed: Where O represents the target value, v represents the number of policies to be optimized, and ξ u L represents the optimization weight of the u-th strategy. u Let represent the loss value of the u-th strategy; simultaneously, combining the strategy choices of the participating agents in game theory, a strategy choice probability model is established: Among them, P jk U represents the probability that the j-th participant chooses the k-th strategy, η represents the sensitivity coefficient for strategy selection, and U jk Let m represent the payoff value of the j-th participant using the k-th strategy, and m represent the number of strategies.

[0057] Specifically, when adaptive thresholding and game theory mechanisms dynamically optimize information distribution strategies, the number of strategies to be optimized is determined based on the number of risk points in the information distribution process, typically 3-5. Optimization weights are set according to the strategy's contribution to risk reduction, ranging from 0 to 1, with higher contributions resulting in higher weights. Loss values ​​include resource waste and efficiency reduction caused by strategy implementation, calculated through actual measurements. The objective function of strategy optimization clarifies the direction of strategy optimization, achieving maximum risk reduction with minimal loss. The sensitivity coefficient in the strategy selection probability model is set based on the participants' sensitivity to strategy returns, ranging from 0.5 to 2; a higher sensitivity coefficient indicates a stronger reaction to changes in returns. The strategy's return value is calculated based on the degree of risk reduction and efficiency improvement after strategy implementation. The significance of this model lies in quantifying the probability of participants choosing each strategy, providing a scientific basis for optimal strategy selection. During implementation, when the risk quantification value exceeds the set range, the strategy optimization process is initiated. This process identifies the strategy to be optimized, its laboratory, and optimization weights. The objective function is then used to calculate the optimization target value for each strategy combination, and the strategy combination with the smallest target value is selected. Simultaneously, the probability of each participating entity selecting different strategies is calculated using a strategy selection probability model. After comprehensive consideration, the final optimized strategy is determined and implemented. This method enables dynamic optimization of the information distribution strategy, allowing the strategy to be adjusted in a timely manner according to changes in risk, thus ensuring the security and efficiency of information distribution.

[0058] 6. The method according to claim 1, characterized in that, in step S6, when the data fusion and situation visualization engine performs real-time monitoring, the monitoring data is segmented according to the time series, each segment of data is independently fused and analyzed, and then the results of each segment are integrated; a segmented fusion model of monitoring data is constructed: Among them, F t This represents the fusion result of the t-th data segment, where n is the fusion result. t ζ represents the number of data points in the t-th segment. l M represents the weight of the l-th data point in the t-th segment. tl This represents the value of the l-th monitoring data in segment t; simultaneously, in the process of converting it into a visual situation chart, considering the decision-making needs of cybersecurity emergency management, a chart parameter mapping model is established: Among them, V p This represents the value of the p-th chart parameter, κ represents the mapping coefficient, s represents the number of data dimensions, and φ q D represents the mapping weight of the q-th data dimension. pq This represents the value of the q-th data dimension corresponding to the p-th chart parameter.

[0059] Specifically, when the data fusion and situation visualization engine processes monitoring data in time-series segments, the number of data points in each segment is determined based on the data collection frequency and monitoring cycle, typically containing 30-50 data points per segment. Data weights are set according to the importance and reliability of the data, with key data receiving a weight of 0.6-0.8 and ordinary data receiving a weight of 0.2-0.4. The significance of the segmented data fusion model lies in improving the accuracy of data fusion, reducing errors caused by excessive data volume through segmentation, and facilitating the analysis and comparison of data from different time periods. In the chart parameter mapping model, the mapping coefficients are set based on the correlation between the data and the chart parameters, ranging from 0.5 to 1.5; the data dimension mapping weights are determined based on the influence of each data dimension on the chart parameters, with values ​​ranging from 0 to 1. The significance of this model is to transform complex data into chart parameters that meet decision-making needs, making the visualized charts more intuitively reflect the actual situation of information distribution. In practice, the monitoring data is divided into several segments according to the time series. For each segment, a fusion result is calculated based on its data weight, and then the results from each segment are integrated. When converting the data into a visual situation chart, the data is transformed into chart parameters based on the mapping weights and coefficients of the data dimensions, generating charts that meet the decision-making needs of cybersecurity emergency management. This approach ensures the accuracy of data fusion while enabling the visual charts to provide regulators with clear and intuitive information, improving the efficiency and quality of regulatory work.

[0060] 7. The method according to claim 1, characterized in that step S3 includes the following sub-steps: S3.1, a data acquisition sub-step, in which various types of data during the information distribution process are collected in real time by monitoring devices deployed at each node of the network. The types of data collected include information transmission rate, data packet loss rate, node load, and information encryption status. Data sampling is performed at preset time intervals during the acquisition process to ensure the continuity and representativeness of the data; S3.2, a data classification sub-step, in which the collected data is classified according to source, type, and associated risk factors. Data belonging to the same information distribution link are marked as the same category, and independent data subsets are established for data related to different risk factors. During the classification process, data is classified according to the data... The feature values ​​are automatically classified, while allowing manual correction of the classification results; S3.3, Data Association Analysis Sub-step, performs association analysis on the classified data to explore the inherent connections between different data. By analyzing the timestamps, transmission path identifiers, and node IDs of the data, the correspondence between the data and information distribution events is determined, and a data association graph is established to provide a basis for subsequent fusion processing; S3.4, Multi-source Fusion Sub-step, based on the data association graph, uses a weighted average method to fuse multi-source data. Different weights are assigned according to the credibility and importance of the data. Abnormal data is identified and filtered during the fusion process. The fused data is organized into a structured comprehensive situation dataset and stored in a designated database.

[0061] Specifically, step S3 involves several technical parameters, including the data collection time interval, data sampling ratio, data feature value extraction dimensions, and data association analysis matching threshold. The data collection time interval is set according to the real-time requirements of information distribution, generally 1-5 seconds; for high-priority information distribution, the time interval is shortened to 0.5 seconds. The data sampling ratio is set at 20%-30% to ensure data representativeness while reducing data processing volume. The data feature value extraction dimensions include 8-10 dimensions such as data format, source identifier, and timestamp, providing a comprehensive basis for data classification. The data association analysis matching threshold is set at 80%, meaning that when the feature value matching degree of two data points reaches or exceeds this threshold, a correlation is determined to exist. The significance of these steps lies in transforming scattered raw data into a structured, comprehensive situational dataset through systematic collection, classification, association, and fusion, providing a high-quality data foundation for subsequent risk assessment. In the specific implementation process, the data acquisition sub-step collects data at set time intervals through monitoring equipment deployed on network nodes and samples it proportionally; the data classification sub-step automatically classifies the data based on the extracted multi-dimensional feature values, allowing for manual correction; the data association analysis sub-step constructs a data association map based on matching thresholds and by analyzing information such as timestamps and transmission path identifiers; the multi-source fusion sub-step assigns weights according to data credibility and importance, filters out abnormal data after weighted fusion, and forms and stores a comprehensive situational dataset. The sub-steps are closely linked to ensure the consistency and effectiveness of data processing.

[0062] 8. The method according to claim 1, characterized in that step S4 includes the following sub-steps: S4.1, risk factor weight determination sub-step, based on a multi-objective risk factor assessment model, the weight of each risk factor is determined using the analytic hierarchy process (AHP), by constructing a judgment matrix, calculating the maximum eigenvalue and corresponding eigenvector of the matrix, and using the eigenvector as the weight value of each risk factor; during the weight determination process, experts in the field of cybersecurity emergency management are invited to conduct consistency checks on the judgment matrix; S4.2, risk quantification sub-step, each risk factor is quantified according to a preset quantification standard, converting the qualitatively described risk factors into quantitative values; for directly measurable risk factors, calculations are performed using collected actual data; for risk factors that are difficult to measure directly... Risk factors are estimated by combining historical data and expert experience to obtain the quantitative value of each risk factor; S4.3, the comprehensive risk assessment sub-step, the quantitative value of each risk factor is weighted and summed with its corresponding weight to obtain the overall risk quantitative value in the information distribution process. At the same time, the contribution of each risk factor is analyzed to determine the primary and secondary risk factors, and a risk assessment report is generated. The report includes the quantitative results of each risk factor, the overall risk value, and the risk level classification; S4.4, the assessment result verification sub-step, the risk assessment results are compared and verified with the risk situation in historical cases, the degree of deviation between the assessment results and the actual risk is calculated, and the parameters of the multi-objective risk factor assessment model are adjusted according to the degree of deviation to improve the accuracy of subsequent risk assessments.

[0063] Specifically, step S4 involves several technical parameters, including the order of the judgment matrix, the allowable deviation value for consistency testing, the grading range for risk factor quantification, and the tolerance for deviation in the verification of assessment results. The order of the judgment matrix corresponds to the number of risk factors, typically 5-8. The allowable deviation value for consistency testing is set at 0.1; the judgment matrix passes the test when the calculated consistency ratio is less than this value. The grading range for risk factor quantification is determined based on risk characteristics, such as 0-20 for low risk, 21-40 for low-to-medium risk, 41-60 for medium risk, 61-80 for medium-to-high risk, and 81-100 for high risk. The tolerance for deviation in the verification of assessment results is set at 10%, meaning that the assessment is considered valid when the deviation between the assessment results and the actual risk falls within this range. These parameters are significant in standardizing the risk assessment process and ensuring the scientific validity and reliability of the assessment results. In implementation, the risk factor weight determination sub-step constructs a judgment matrix of the appropriate order, calculates eigenvalues ​​and eigenvectors to obtain weights, and performs consistency checks. The risk quantification sub-step transforms qualitative risks into quantitative values; risks that can be directly measured are calculated based on actual data, while those that are difficult to measure directly are estimated by combining historical data and expert experience. The risk comprehensive assessment sub-step obtains the overall risk value through weighted summation, analyzes the contribution of each factor, and classifies risk levels. The assessment result verification sub-step compares the assessment results with historical cases, calculates the degree of deviation, and adjusts model parameters when the deviation exceeds the tolerance. Each sub-step is progressively advanced, gradually improving the risk assessment process.

[0064] 9. The method according to claim 1, characterized in that step S5 includes the following sub-steps: S5.1, a strategy optimization trigger judgment sub-step, comparing the risk assessment result obtained in step S4 with an adaptive threshold; when the overall risk quantification value exceeds the upper limit of the adaptive threshold, triggering the strategy optimization process; when the overall risk quantification value is lower than the lower limit of the adaptive threshold, maintaining the current information distribution strategy unchanged; when the overall risk quantification value is within the adaptive threshold range, fine-tuning some links with higher risks; S5.2, an optimization scheme generation sub-step, generating multiple information distribution strategy optimization schemes based on the triggered optimization level and the strategy set of each participating entity in the game theory mechanism, including transmission path change schemes and encryption algorithms. The upgrade plan and simplified verification process are outlined, with each plan specifying concrete implementation steps and expected results. Step S5.3, the plan evaluation and selection sub-step, employs a multi-objective decision-making method to evaluate the generated optimized plans. Evaluation indicators include risk reduction, implementation cost, and impact on information distribution efficiency. The optimal optimized plan is selected based on the evaluation results, taking into full account the actual needs and resource constraints of cybersecurity emergency management. Step S5.4, the strategy execution and feedback sub-step, applies the selected optimized plan to the information distribution process, monitors the effects of strategy execution in real time, collects relevant information distribution data, calculates the risk quantification value after strategy execution, and feeds the results back to the adaptive threshold and game theory mechanism to provide a basis for the next strategy optimization.

[0065] Specifically, step S5 involves technical parameters including the upper and lower limits of the adaptive threshold, the number of optimization schemes, the weights of evaluation indicators for multi-objective decision-making, and the monitoring frequency of strategy execution effectiveness. The upper limit of the adaptive threshold is set at 80 points of the overall risk quantification value, and the lower limit at 30 points. The number of optimization schemes is determined based on the complexity of the risk, typically 3-5. In multi-objective decision-making, the weights of the evaluation indicators for risk reduction, implementation cost, and efficiency impact are set at 0.5, 0.3, and 0.2, respectively. The monitoring frequency for strategy execution effectiveness is once per minute to ensure timely understanding of strategy implementation. These parameters provide clear triggering conditions, evaluation standards, and monitoring basis for strategy optimization, making the optimization process evidence-based and improving the adaptability and effectiveness of the strategy. In practice, the strategy optimization trigger judgment sub-step compares the risk assessment results with the adaptive threshold, and triggers different levels of optimization or maintains the current strategy based on the results; the optimization scheme generation sub-step combines the game strategy set to generate multiple schemes containing specific implementation steps for the triggered optimization level; the scheme evaluation and selection sub-step evaluates and selects the optimal scheme based on the set indicator weights using a multi-objective decision-making method; the strategy execution and feedback sub-step applies the selected scheme, collects data according to the monitoring frequency to calculate the risk value, and feeds it back to the relevant mechanism for the next optimization. The sub-steps form a closed loop, realizing the dynamic adjustment and continuous optimization of the strategy.

[0066] The multi-objective risk factor assessment model is the core tool in this invention for comprehensively assessing various risks in the distribution of information for cybersecurity emergency management. Specifically, it comprehensively considers multiple dimensions of risk factors, including information source credibility, transmission link stability, receiving terminal security, information content confidentiality level, and distribution timeliness requirements. These factors are quantitatively assessed using scientific methods to derive an overall risk quantification value. To implement this model, the weight coefficients of each risk factor are first determined using expert scoring and the analytic hierarchy process (AHP). For example, the weight coefficient for information source credibility is set to 0.25, and the weight coefficient for transmission link stability is set to 0.2. Then, each risk factor is quantified according to a preset quantitative standard, transforming qualitative descriptions into quantitative values. Directly measurable risk factors are calculated based on actual data, while those difficult to measure are estimated using historical data and expert experience. Finally, the quantified values ​​of each risk factor are weighted and summed with their corresponding weights to obtain the overall risk quantification value. Simultaneously, the contribution of each risk factor is analyzed to identify the main risk factors. The model aims to accurately identify potential risks in the information distribution process, providing a reliable basis for subsequent strategy optimization. Its significance lies in changing the limitations of existing risk assessment models that focus only on isolated factors and are singular. It can comprehensively and accurately reflect the security situation in the information distribution process, providing a scientific risk assessment basis for the supervision of information distribution in cybersecurity emergency management, and ensuring that the supervision work is more targeted and effective.

[0067] The adaptive threshold and game theory mechanism are the key mechanisms in this invention for dynamically adjusting thresholds and optimizing information distribution strategies. Specifically, this includes dynamically adjusting the initial thresholds corresponding to each risk factor, and constructing a set of game strategies among the participants in information distribution. This set of strategies includes the distribution strategy of the information sender, the verification strategy of the receiver, and the control strategy of the regulator. In implementing this mechanism, the adaptive threshold part adjusts the initial threshold based on the risk impact coefficients derived from the multi-objective risk factor assessment model. For example, the critical fluctuation coefficient for transmission link stability is set to 1.5%. When the fluctuation coefficient exceeds this value, the threshold is dynamically adjusted according to the excess proportion. The game theory part considers the interests and behavioral logic of each participant, defines a game payoff function, calculates the payoffs of each participant using different strategies, and uses this as a basis to guide strategy selection. The mechanism enables thresholds to be flexibly adjusted according to actual risk conditions, and allows information distribution strategies to be dynamically optimized by combining the strategy choices and benefit balance of all parties. Its significance lies in overcoming the shortcomings of existing technologies that rely on fixed thresholds or preset rules for strategy adjustments and lack dynamism and flexibility. It enables information distribution to better adapt to complex and ever-changing network environments, improves the efficiency and security of information distribution, and ensures the smooth progress of information distribution in network security emergency management.

[0068] The data fusion and situation visualization engine is a crucial tool in this invention for processing data and displaying the regulatory situation. Specifically, it fuses multi-source, heterogeneous risk factor data and real-time status data during information distribution to form a comprehensive situation dataset, and then transforms the processed data into visualized situation charts. To implement this engine, firstly, monitoring devices deployed at various network nodes collect various types of data in real time, including information transmission rates and packet loss rates. Then, the collected data is categorized according to source, type, and associated risk factors, uncovering the inherent connections between different data points and establishing a data correlation graph. Next, a weighted average method is used to fuse multi-source data, assigning different weights based on data credibility and importance, filtering out abnormal data, and forming a comprehensive situation dataset. Finally, the fused data is transformed into visualized charts such as line charts, bar charts, and network topology diagrams, and updated in real time according to a set update frequency. The engine's function is to integrate scattered and heterogeneous data into unified and intuitive information, providing regulators with comprehensive and clear regulatory basis. Its significance lies in solving the problems of data dispersion and lack of intuitiveness in existing technologies, enabling regulators to quickly grasp the dynamic changes in information distribution, take timely countermeasures, improve the efficiency and accuracy of regulatory work, and provide strong technical support for the supervision of information distribution in cybersecurity emergency management.

[0069] like Figure 2 As shown, the emergency management information distribution and monitoring system based on network security includes:

[0070] The multi-dimensional risk factor extraction unit is used to extract multi-dimensional risk factors from data related to the distribution of network security emergency management information through a multi-objective risk factor assessment model. This unit is connected to the network data acquisition device and receives the collected raw data.

[0071] The dynamic threshold adjustment and game strategy construction unit is connected to the output of the multi-dimensional risk factor extraction unit. It receives the extracted multi-dimensional risk factors and uses them to dynamically adjust the initial threshold and construct a set of game strategies through adaptive threshold and game theory mechanism.

[0072] The multi-source data fusion and situation dataset generation unit has its input end connected to the output end of the dynamic threshold adjustment and game strategy construction unit to receive processed risk factor data. At the same time, it is connected to the real-time status monitoring device to receive information and distribute real-time status data, which is used to fuse and process the received data to generate a comprehensive situation dataset.

[0073] The risk quantification assessment unit is connected to the output of the multi-source data fusion and situation dataset generation unit at its input end. It receives the comprehensive situation dataset and is used to quantify potential risks and generate risk assessment results through a multi-objective risk factor assessment model.

[0074] The information distribution strategy dynamic optimization unit has its input connected to the output of the risk quantification assessment unit and the output of the dynamic threshold adjustment and game strategy construction unit, respectively. It receives the risk assessment results and the game strategy set, and is used to dynamically optimize the information distribution strategy based on the risk assessment results.

[0075] The real-time monitoring and visualization unit has its input ends connected to the output ends of the dynamic optimization unit for the distribution strategy and the multi-source data fusion and situation dataset generation unit, respectively. It receives the optimized strategy information and the comprehensive situation dataset, and uses it to monitor the information distribution process in real time and convert the data into a visual situation chart. This unit is connected to a display device to display the visual chart.

[0076] This invention relates to a network security-based emergency management information distribution and supervision method and system, which demonstrates significant advantages in risk assessment. Through a multi-objective risk factor assessment model, it comprehensively considers multiple risk factors involved in information distribution, such as the credibility of information sources and the stability of transmission links. It deeply analyzes the interactions and coupling relationships between these factors, overcoming the limitations of existing risk assessment models that focus only on isolated factors. This approach more comprehensively and accurately reflects the security situation during information distribution and effectively solves the problem of discrepancies between assessment results and actual conditions.

[0077] Its advantages are equally prominent at the strategy optimization level. Leveraging adaptive thresholds and game theory mechanisms, thresholds can be dynamically adjusted based on risk assessment results. Simultaneously, by considering the strategy choices and payoff balances of participating entities such as information senders, receivers, and regulators, information distribution strategies can be flexibly optimized. This feature overcomes the shortcomings of existing technologies that rely on fixed thresholds or preset rules for strategy adjustments, lacking dynamism and flexibility. It enables information distribution to better adapt to complex and ever-changing network environments, improving distribution efficiency and security.

[0078] Furthermore, its advantages in data processing and regulatory visualization cannot be overlooked. The data fusion and situational visualization engine can effectively integrate multi-source heterogeneous data, eliminating redundancy and consolidating valuable information, while transforming the processed data into intuitive and visual situational charts. This provides comprehensive and clear evidence for regulatory work, solving the problems of data fragmentation and lack of intuitiveness in existing technologies, and helping relevant personnel to more efficiently carry out information distribution and regulatory work related to cybersecurity emergency management.

[0079] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "set," "install," "connect," "link," and "fix" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal communication between two components. Those skilled in the art will understand the specific meaning of the above terms in this invention based on the specific circumstances.

[0080] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various equivalent changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A method for monitoring and distributing emergency management information based on network security, characterized in that, include: Step S1: Extract multi-dimensional risk factors from information distribution-related data generated during network security emergency management using a multi-objective risk factor assessment model. These multi-dimensional risk factors include information source credibility, transmission link stability, receiving terminal security, information content confidentiality level, and distribution timeliness requirements. Step S2: Input the extracted multi-dimensional risk factors into an adaptive threshold and game theory mechanism. This mechanism dynamically adjusts the initial threshold corresponding to each risk factor and constructs a set of game strategies among the information distribution participants. This set of game strategies includes the information sender's distribution strategy, the receiver's verification strategy, and the regulator's control strategy. Step S3: Utilize a data fusion and situation visualization engine to analyze the risk factor data processed by the adaptive threshold and game theory mechanism, as well as the data generated during information distribution. The real-time status data is fused to form a comprehensive situation dataset after multi-source heterogeneous data fusion; Step S4, based on the comprehensive situation dataset, the potential risks in the information distribution process are quantitatively assessed through a multi-objective risk factor assessment model to generate risk assessment results. The quantitative assessment involves the weight allocation and interaction analysis of each risk factor; Step S5, based on the risk assessment results, the adaptive threshold and game theory mechanism are restarted to dynamically optimize the information distribution strategy, including adjusting the information transmission path, changing the encryption method, and updating the verification rules; Step S6, the data fusion and situation visualization engine monitors the optimized information distribution process in real time, fuses the monitored data, and transforms it into a visualized situation chart to monitor the entire process of information distribution for network security emergency management.

2. The emergency management information distribution and supervision method based on network security according to claim 1, characterized in that, In step S2, when the adaptive threshold and game theory mechanism dynamically adjust the initial threshold, the risk impact coefficient from the multi-objective risk factor assessment model is introduced to construct the threshold adjustment model: Among them, T adj T represents the adjusted threshold. init α represents the initial threshold, n represents the number of risk factors, and α represents the initial threshold. i R represents the influence weight of the i-th risk factor. i Let represent the quantified value of the i-th risk factor; simultaneously, when constructing the Boyi strategy set, considering the real-time requirements of information distribution in cybersecurity emergency management, define Boyi... Payoff function: Among them, U j Let β represent the payoff of the j-th participant, m represent the number of strategies, and β represent the payoff of the j-th participant. k S represents the weight of the k-th strategy. jk Let C represent the payoff value of the j-th participant using the k-th strategy. jk This represents the cost of the j-th participant adopting the k-th strategy.

3. The emergency management information distribution and supervision method based on network security according to claim 1, characterized in that, In step S3, when data fusion and situation visualization engine perform fusion processing, a hierarchical fusion strategy is adopted, combining the credibility assessment results of each data point from the multi-objective risk factor assessment model. First, primary fusion is performed on similar data to eliminate data redundancy; then, advanced fusion is performed on different types of data to generate a comprehensive situation dataset. During this process, a data fusion weight model is constructed. Among them, W ij γ represents the fusion weight of the j-th data in the i-th data category, p represents the number of data types, and γ i C represents the importance coefficient of the i-th data category. ij This represents the confidence value of the j-th data point in the i-th data category; simultaneously, a time decay factor is introduced to establish a data timeliness correction model: Among them, D′ ij D represents the value of the j-th data in the i-th data group after correction. ij λ represents the original data value, t represents the time decay coefficient, and t represents the time decay coefficient. ij This indicates the time interval between data generation and fusion.

4. The emergency management information distribution and supervision method based on network security according to claim 1, characterized in that, In step S4, when the multi-objective risk factor assessment model performs quantitative assessment, it comprehensively considers the dynamic change characteristics of each risk factor, constructs a risk assessment matrix, and obtains the quantitative value of each potential risk through matrix operations; the risk assessment model is defined as follows: Where R represents the overall risk quantification value, r represents the number of risk categories, t represents the number of sub-risks under each risk category, and θ q δ represents the weight of the q-th type of risk. s F represents the weight of the s-th sub-risk under the q-th risk class. qs Let C represent the product of the probability of occurrence and the degree of impact of the s-th sub-risk under the q-th risk category; simultaneously, to reflect the interaction between risk factors, a coupling coefficient is introduced to establish a risk coupling model: C ab =μ×(R) a ×R b ) / (R a +R b ), where C ab R represents the degree of coupling between risk factor a and risk factor b, μ represents the coupling coefficient, and R represents the coupling coefficient. a R b These represent the quantitative values ​​of the a-th and b-th risk factors, respectively.

5. The emergency management information distribution and supervision method based on network security according to claim 1, characterized in that, In step S5, when the adaptive threshold and game theory mechanism dynamically optimize the information distribution strategy, the risk assessment results of step S4 are used as the basis. When the risk quantification value exceeds the set range, the strategy optimization process is automatically triggered. Construct the policy optimization objective function: Where O represents the target value, v represents the number of policies to be optimized, and ξ u L represents the optimization weight of the u-th strategy. u Let represent the loss value of the u-th strategy; simultaneously, combining the strategy choices of the participating agents in game theory, a strategy choice probability model is established: Among them, P jk U represents the probability that the j-th participant chooses the k-th strategy, η represents the sensitivity coefficient for strategy selection, and U jk Let m represent the payoff value of the j-th participant using the k-th strategy, and m represent the number of strategies.

6. The emergency management information distribution and supervision method based on network security according to claim 1, characterized in that, In step S6, when the data fusion and situation visualization engine performs real-time monitoring, the monitoring data is segmented according to the time series, each segment is independently fused and analyzed, and then the results of each segment are integrated; a segmented fusion model for monitoring data is constructed. Among them, F t This represents the fusion result of the t-th data segment, where n is the fusion result. t ζ represents the number of data points in the t-th segment. l M represents the weight of the l-th data point in the t-th segment. tl This represents the value of the l-th monitoring data in segment t; simultaneously, in the process of converting it into a visual situation chart, considering the decision-making needs of cybersecurity emergency management, a chart parameter mapping model is established: Among them, V p This represents the value of the p-th chart parameter, κ represents the mapping coefficient, s represents the number of data dimensions, and φ q D represents the mapping weight of the q-th data dimension. pq This represents the value of the q-th data dimension corresponding to the p-th chart parameter.

7. The emergency management information distribution and supervision method based on network security according to claim 1, characterized in that, Step S3 includes the following sub-steps: S3.1, real-time collection of various types of data during the information distribution process by monitoring devices deployed at each node of the network. The types of data collected include information transmission rate, data packet loss rate, node load and information encryption status. Data sampling is performed at preset time intervals during the collection process to ensure the continuity and representativeness of the data. S3.2 The collected data is classified according to its source, type, and associated risk factors. Data belonging to the same information distribution chain are marked as belonging to the same category. Data related to different risk factors are established as independent data subsets. During the classification process, automatic classification is performed based on the data's feature values, while allowing manual correction of the classification results. S3.3 Correlation analysis is performed on the classified data to uncover the inherent connections between different data. By analyzing the data's timestamps, transmission path identifiers, and node IDs, the correspondence between data and information distribution events is determined, and a data correlation graph is established to provide a basis for subsequent fusion processing. S3.4 Based on the data correlation graph, a weighted average method is used to fuse multi-source data. Different weights are assigned according to the data's credibility and importance. Abnormal data is identified and filtered during the fusion process. The fused data is then organized into a structured comprehensive situational dataset and stored in a designated database.

8. The emergency management information distribution and supervision method based on network security according to claim 1, characterized in that, Step S4 includes the following sub-steps: S4.1, Based on the multi-objective risk factor assessment model, the weight of each risk factor is determined by the analytic hierarchy process. By constructing a judgment matrix, the maximum eigenvalue of the matrix and the corresponding eigenvector are calculated. The eigenvector is used as the weight value of each risk factor. During the weight determination process, experts in the field of cybersecurity emergency management are invited to conduct a consistency check on the judgment matrix. S4.2 Quantify each risk factor according to the preset quantitative standard, and convert the qualitatively described risk factors into quantitative values. For directly measurable risk factors, calculate using the collected actual data. For risk factors that are difficult to measure directly, estimate by combining historical data and expert experience to obtain the quantitative value of each risk factor. S4.3, the quantitative values ​​of each risk factor are weighted and summed with their corresponding weights to obtain the overall risk quantitative value in the information distribution process. At the same time, the contribution of each risk factor is analyzed to determine the primary and secondary risk factors and generate a risk assessment report. The report includes the quantitative results of each risk factor, the overall risk value, and the risk level classification. S4.4 compares and verifies the risk assessment results with the risk situations in historical cases, calculates the degree of deviation between the assessment results and the actual risks, and adjusts the parameters of the multi-objective risk factor assessment model according to the degree of deviation to improve the accuracy of subsequent risk assessments.

9. The emergency management information distribution and supervision method based on network security according to claim 1, characterized in that, Step S5 includes the following sub-steps: S5.1, compare the risk assessment result obtained in step S4 with the adaptive threshold. When the overall risk quantification value exceeds the upper limit of the adaptive threshold, trigger the strategy optimization process. When the overall risk quantification value is lower than the lower limit of the adaptive threshold, maintain the current information distribution strategy unchanged. When the overall risk quantification value is within the adaptive threshold range, make fine adjustments to some links with higher risks. S5.2 Based on the triggered optimization level and combined with the strategy set of each participating entity in the game theory mechanism, a variety of information distribution strategy optimization schemes are generated. The optimization schemes include transmission path change schemes, encryption algorithm upgrade schemes, and verification process simplification schemes. Each scheme specifies the specific implementation steps and expected effects. S5.

3. A multi-objective decision-making method is used to evaluate the generated optimization scheme. The evaluation indicators include the degree of risk reduction, implementation cost and impact on information distribution efficiency. The optimal optimization scheme is selected based on the evaluation results. The selection process fully considers the actual needs and resource constraints of network security emergency management. S5.4 applies the selected optimization scheme to the information distribution process, monitors the effect of the strategy in real time, collects relevant data on information distribution, calculates the risk quantification value after the strategy is executed, and feeds the results back to the adaptive threshold and game theory mechanism to provide a basis for the next strategy optimization.

10. An emergency management information distribution and monitoring system based on network security, characterized in that, include: The multi-dimensional risk factor extraction unit is used to extract multi-dimensional risk factors from data related to the distribution of network security emergency management information through a multi-objective risk factor assessment model. This unit is connected to the network data acquisition device and receives the collected raw data. The dynamic threshold adjustment and game strategy construction unit is connected to the output of the multi-dimensional risk factor extraction unit. It receives the extracted multi-dimensional risk factors and uses them to dynamically adjust the initial threshold and construct a set of game strategies through adaptive threshold and game theory mechanism. The multi-source data fusion and situation dataset generation unit has its input end connected to the output end of the dynamic threshold adjustment and game strategy construction unit to receive processed risk factor data. At the same time, it is connected to the real-time status monitoring device to receive information and distribute real-time status data, which is used to fuse and process the received data to generate a comprehensive situation dataset. The risk quantification assessment unit is connected to the output of the multi-source data fusion and situation dataset generation unit at its input end. It receives the comprehensive situation dataset and is used to quantify potential risks and generate risk assessment results through a multi-objective risk factor assessment model. The information distribution strategy dynamic optimization unit has its input connected to the output of the risk quantification assessment unit and the output of the dynamic threshold adjustment and game strategy construction unit, respectively. It receives the risk assessment results and the game strategy set, and is used to dynamically optimize the information distribution strategy based on the risk assessment results. The real-time monitoring and visualization unit has its input ends connected to the output ends of the dynamic optimization unit for the distribution strategy and the multi-source data fusion and situation dataset generation unit, respectively. It receives the optimized strategy information and the comprehensive situation dataset, and uses it to monitor the information distribution process in real time and convert the data into a visual situation chart. This unit is connected to a display device to display the visual chart.

Citation Information

Cited By

  • Evolvable credible cloud level computing system and method based on game optimization

    CN121644230A