Heterogeneous network security defense system and method based on artificial intelligence

By constructing a heterogeneous network security defense system based on artificial intelligence, featuring full-dimensional perception, cognitive enhancement, intelligent decision-making, and adaptive execution, the system addresses the problem of insufficient adaptability of traditional defense systems to complex and ever-changing network attacks. It achieves efficient dynamic defense and cross-domain collaboration, thereby enhancing the overall network security defense capability.

CN120934883APending Publication Date: 2025-11-11ZHONGTONG SERVICE WANGYING TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202511244076.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-02
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Traditional network security defense systems are poorly adaptable to complex and ever-changing network attacks, lack intelligent decision-making and adaptive adjustment capabilities, struggle to form a unified defense force, and have insufficient cross-domain collaboration capabilities.

Method used

A defense system based on artificial intelligence, consisting of a full-dimensional perception layer, a cognitive enhancement layer, an intelligent decision-making layer, an adaptive execution layer, and a cross-domain collaboration layer, is constructed through technologies such as four-dimensional spatiotemporal feature fusion, adversarial feature purification, hypergraph modeling, causal reasoning, incomplete information game model, and blockchain notarization. This system enables dynamic adjustment and cross-domain collaboration.

Benefits of technology

It significantly improves the accuracy of identifying complex and ever-changing threats, realizes the transformation from passive defense to active defense, enhances the adaptability of network attacks and overall defense capabilities, and ensures security information sharing and collaborative defense between different network domains.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934883A_ABST
    Figure CN120934883A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and particularly discloses a heterogeneous network security defense system and method based on artificial intelligence, and the system comprises a full-dimensional perception layer which is used for obtaining original data of heterogeneous network security through a hardware-level data collection and protocol self-adaption technology; the cognitive enhancement layer is used for undertaking the output of the full-dimensional perception layer and optimizing the threat identification precision through four-dimensional spatial-temporal feature fusion and antagonism feature purification; the intelligent decision-making layer is used for accurately depicting a complex attack mode through hypergraph modeling and causal reasoning based on output of the cognitive enhancement layer; according to the method, through integration of four-dimensional spatial-temporal feature fusion and antagonistic feature purification technologies, the identification precision of complex and variable threats in a heterogeneous network is remarkably improved, especially for unknown or variable attack means; by means of hypergraph modeling and causal reasoning technologies, a complex attack mode is accurately described, an optimal defense action sequence is automatically generated, and conversion from passive defense to active defense is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security technology, specifically relating to a heterogeneous network security defense system and method based on artificial intelligence. Background Technology

[0002] In today's digital and networked era, the rapid development of information technology has driven the widespread application of heterogeneous networks. Heterogeneous networks, as complex network environments constructed from different technical architectures, equipment from different vendors, and different communication protocols, have become a critical infrastructure supporting the operation of modern society. Their high complexity and diversity not only promote the extensive sharing and efficient interaction of information resources but also provide a powerful impetus for the digital transformation of various industries.

[0003] However, with the continuous advancement of network technology, the cybersecurity challenges faced by heterogeneous networks are becoming increasingly severe. Traditional network security defense systems are mostly based on fixed rules and static defense strategies. While these can be effective against known attack patterns, they fall short in dealing with new, complex, and ever-changing cyberattacks. Traditional defense strategies have poor adaptability and struggle to adapt to rapidly changing cyberattack methods. Once attack methods change, existing defense strategies may become ineffective or even completely fail. Furthermore, insufficient cross-domain collaboration capabilities are a major weakness of traditional defense systems. In heterogeneous network environments, security information between different network domains is difficult to share and coordinate effectively, limiting overall defense capabilities and preventing the formation of a unified defensive force.

[0004] Therefore, it is necessary to propose a heterogeneous network security defense system and method based on artificial intelligence to solve the problem that traditional defense strategies in existing technologies rely on fixed rules and static defense strategies, lack the ability of intelligent decision-making and adaptive adjustment, resulting in limited defense effectiveness.

[0005] The information disclosed above in this background section is only for enhancing the understanding of the background section of this invention, and therefore may include prior art that is not known to those skilled in the art. Summary of the Invention

[0006] The purpose of this invention is to provide a heterogeneous network security defense system and method based on artificial intelligence to solve the problems mentioned in the background art.

[0007] To achieve the above objectives, the present invention provides the following technical solution:

[0008] A heterogeneous network security defense system based on artificial intelligence includes:

[0009] The full-dimensional perception layer is used to acquire raw data on heterogeneous network security through hardware-level data acquisition and protocol adaptive technology;

[0010] The cognitive enhancement layer is used to receive the output of the full-dimensional perception layer and optimize the threat identification accuracy through four-dimensional spatiotemporal feature fusion and adversarial feature purification.

[0011] The intelligent decision-making layer is used to accurately characterize complex attack patterns based on the output of the cognitive enhancement layer through hypergraph modeling and causal reasoning.

[0012] An adaptive execution layer is used to respond to the instructions of the intelligent decision-making layer and to optimize the adaptability of the defense strategy by using an incomplete information game model and chaos engineering injection.

[0013] The cross-domain collaboration layer is used to build a trusted defense ecosystem based on protocol-independent middleware through cross-domain blockchain notarization and digital twin verification, and to manage the entire lifecycle of the defense strategy.

[0014] Preferably, the full-dimensional perception layer includes the following collaborative modules:

[0015] The protocol adaptive traffic mirroring module is used to dynamically adjust the sampling rate using reinforcement learning and activate the full traffic capture mode when abnormal traffic characteristics are detected to obtain metadata of heterogeneous network security.

[0016] Hardware-level device fingerprint collectors are used to construct a multi-dimensional profile of device identity by comparing firmware hash values ​​and analyzing electromagnetic radiation spectrum through convolutional neural networks, thus forming device-level trust anchors.

[0017] The user behavior gene library is used to generate individualized behavioral feature sequences using the LSTM-Transformer hybrid model to establish a user behavior baseline.

[0018] The electromagnetic side channel analysis module is used to identify the time-space-frequency domain coupling characteristics of the device's radiation pattern using a spatiotemporal convolutional neural network.

[0019] An environment-aware adaptive module is used to aggregate multi-node environment parameters based on the device-level trust anchor point using the following federated learning formula, and dynamically adjust the adopted strategy.

[0020]

[0021] In the formula, w t For the weight of the global environment, Let n be the local environment weight of the k-th node. k Let n be the number of data points in the k-th node, and n be the total number of data points in all nodes.

[0022] A data freshness evaluator is used to calculate the timeliness weight of data using a decay factor based on information entropy and time.

[0023] Preferably, the cognitive enhancement layer receives the output of the full-dimensional perception layer and extracts data value through the following techniques:

[0024] A spatiotemporal feature fusion engine is used to integrate time-space-protocol-semantic dimension data based on the aforementioned metadata using four-dimensional tensor modeling technology to construct a multimodal situation map;

[0025] An adversarial feature cleaner is used to eliminate data contamination and enhance coupling features based on the time-space-frequency domain coupled features by integrating GAN noise filtering and graph attention anomaly detection;

[0026] The semantic transformation hub module is used to map heterogeneous data to a unified semantic embedding space based on the behavioral features through cross-protocol knowledge distillation technology, so as to provide standardized input for the intelligent decision-making layer.

[0027] Preferably, the intelligent decision-making layer constructs a multimodal threat cognition architecture based on the output of the cognitive enhancement layer, including:

[0028] The dynamic graph neural network submodule is used to construct the device interaction relationship topology based on the multimodal situation map through hypergraph modeling technology, and combine it with the subgraph-level anomaly detection algorithm to accurately characterize complex attack patterns.

[0029] The meta-reinforcement learning threat detection engine is used to identify zero-shot attack patterns based on the multimodal situation map using the MAML framework, and to quickly adapt to new threat features through few-shot learning.

[0030] The causal reasoning auxiliary module is used to construct an attack path prediction matrix based on a structural causal model and output an attack success probability distribution map.

[0031] Structural causal model inference formula:

[0032]

[0033] In the formula, P(Y|X) is the conditional probability of Y given X, and Z is the latent hidden variable;

[0034] A multimodal attention fusion unit is used to integrate visual features, temporal features, and graph structure features using a Transformer encoder architecture, and combine natural language processing to understand and analyze attack feature behavior.

[0035] The adaptive knowledge distillation module is used to migrate attack patterns in digital twin environments to real network defense models through a teacher-student network architecture.

[0036] Preferably, the adaptive execution layer responds to the instructions of the intelligent decision-making layer, including:

[0037] A game theory-driven defense strategy generator is used to calculate the Nash equilibrium strategy based on the attack success probability distribution map, using an incomplete information random game model, and generate an optimal defense action sequence that includes a firewall rule reorganization sequence and access control list change instructions.

[0038] The formula for solving Nash equilibrium based on incomplete information stochastic game models:

[0039]

[0040] In the formula, u i (s i ,s -i For player i in strategy s i Other player strategies -i The effect of s i Let ' be a possible strategy for player i, and s be... i Let i be player i's current strategy;

[0041] Zero Trust Execution Framework is used to integrate continuous authentication with attribute-based dynamic permission allocation mechanisms for least privilege access control.

[0042] A dynamic micro-segmentation controller is used to perform least privilege isolation of business traffic using a hypergraph segmentation algorithm;

[0043] A defense strategy optimizer is used to find the optimal solution for Poate based on the multi-objective particle swarm optimization algorithm, considering business continuity, system entropy increase, defense cost, and attack blocking rate.

[0044] A chaos engineering injector is used to periodically inject controlled disturbances into the network to verify system resilience and optimize the adaptability of the defense strategy.

[0045] Preferably, the cross-domain collaboration layer is executed through protocol-independent middleware, including:

[0046] A multi-protocol instruction conversion gateway is used to perform cross-domain adaptation of the intelligent decision-making layer instructions through a built-in semantic mapping table of 20+ industrial protocols.

[0047] The blockchain evidence storage chain is used to record the history of changes to the defense strategy, the evidence chain for tracing the source of attacks, and the instruction execution log, thereby constructing an immutable audit trail.

[0048] The digital twin verification sandbox is used to form a closed loop of "strategy generation - simulation verification - deployment optimization" through real-time simulation and dynamic evaluation of the attack surface of the defense strategy.

[0049] A heterogeneous network security defense method based on artificial intelligence includes:

[0050] Step 1: Implement full-dimensional data collection through self-organizing edge probes to construct a three-dimensional situation matrix containing traffic metadata, device fingerprint features, and user behavior trajectories;

[0051] Step 2: Based on the three-dimensional situation matrix, feature optimization is performed using a spatiotemporal adversarial training framework, and a feature quality assessment report containing noise robustness indicators is generated.

[0052] Step 3: Construct a cross-domain knowledge graph based on the optimized features, share information across devices and domains through a federated learning framework, and use a hypergraph attention network to mine hidden attack association patterns.

[0053] Step 4: Generate a defense action space in a deep reinforcement learning model using the attack association pattern, and optimize the defense strategy by combining Monte Carlo tree search with defense cost-benefit analysis.

[0054] Step 5: Based on the optimized defense strategy, execute cross-domain translation of defense instructions through protocol-independent middleware, and synchronously update the SDN flow table and device configuration;

[0055] Step 6: Establish a defense effect feedback loop and continuously optimize the feature extraction and strategy generation process based on the online meta-learning mechanism.

[0056] Preferably, in step three, the cross-domain defense capability is optimized by performing the following operations based on the optimized features:

[0057] Construct a device relationship hypergraph and use a high-order graph attention network to detect abnormal communication subgraphs, revealing potential attack paths;

[0058] The causal discovery algorithm is applied to identify the key decision nodes of the attack path, providing data support for attack early warning and defense decisions;

[0059] Using contrastive learning methods, historical attack patterns are mapped to a new threat feature space to identify and respond to emerging attack types.

[0060] By generating a heatmap of attack success probability, we can guide the dynamic allocation of defense resources and optimize defense effectiveness in different network environments.

[0061] Preferably, in step four, the following defense strategy optimization is performed based on the attack pattern:

[0062] A defense effectiveness evaluation system is constructed based on the indicators of the defense strategy to comprehensively evaluate the effectiveness of the defense strategy.

[0063] A hierarchical reinforcement learning architecture is adopted, which decomposes the global policy into sub-policies at the network layer, host layer, and application layer, and enables each layer to work together.

[0064] Stress tests were conducted in a digital twin environment to verify the robustness of the defense strategy under various hybrid attack scenarios;

[0065] By generating confidence intervals for the defense strategy, decision support is provided for human intervention.

[0066] Preferably, in step five, the following defense instructions are transmitted and executed based on the optimized defense strategy:

[0067] The unified defense strategy is converted into a specific protocol instruction set by a semantic parser, and corresponding formatting and protocol adaptation operations are performed according to the target network protocol.

[0068] The distribution process of the defense strategy is executed using blockchain smart contract technology, while implementing an anti-tampering mechanism.

[0069] Implement traffic shaping for time-sensitive networks by classifying and prioritizing traffic through network configuration and bandwidth management.

[0070] Compared with the prior art, the beneficial effects of the present invention are:

[0071] This invention significantly improves the accuracy of identifying complex and ever-changing threats in heterogeneous networks by integrating four-dimensional spatiotemporal feature fusion and adversarial feature purification technologies, particularly for unknown or variant attack methods, achieving more efficient detection and identification. Utilizing hypergraph modeling and causal reasoning techniques, it accurately characterizes complex attack patterns and automatically generates optimal defense action sequences, realizing a shift from passive to active defense. Through incomplete information game theory models and chaotic engineering injection technology, it dynamically adjusts defense strategies to adapt to constantly changing network attack landscapes, effectively resisting various new and complex network attacks. Furthermore, based on protocol-independent middleware, it constructs a trusted defense ecosystem for cross-domain blockchain notarization and digital twin verification, enabling secure information sharing and collaborative defense between different network domains, significantly enhancing overall defense capabilities. Attached Figure Description

[0072] Figure 1 This is a framework diagram of the artificial intelligence-based heterogeneous network security defense system of the present invention;

[0073] Figure 2 This is a flowchart of the artificial intelligence-based heterogeneous network security defense method of the present invention. Detailed Implementation

[0074] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0075] Example 1:

[0076] Please see Figure 1 As shown, an artificial intelligence-based heterogeneous network security defense system includes:

[0077] The full-dimensional perception layer is used to acquire raw data on heterogeneous network security through hardware-level data acquisition and protocol adaptive technology;

[0078] The full-dimensional perception layer includes the following collaborative modules:

[0079] The protocol adaptive traffic mirroring module is used to dynamically adjust the sampling rate using reinforcement learning and activate the full traffic capture mode when abnormal traffic characteristics are detected to obtain metadata of heterogeneous network security.

[0080] Hardware-level device fingerprint collectors are used to construct a multi-dimensional profile of device identity by comparing firmware hash values ​​and analyzing electromagnetic radiation spectrum through convolutional neural networks, thus forming device-level trust anchors.

[0081] The user behavior gene library is used to generate individualized behavioral feature sequences using the LSTM-Transformer hybrid model to establish a user behavior baseline.

[0082] The electromagnetic side channel analysis module is used to identify the time-space-frequency domain coupling characteristics of the device's radiation pattern using a spatiotemporal convolutional neural network.

[0083] The environment-aware adaptive module is used to aggregate multi-node environment parameters based on device-level trust anchors and dynamically adjust the adopted strategy using the following federated learning formula.

[0084] A data freshness evaluator is used to calculate the timeliness weight of data using a decay factor based on information entropy and time.

[0085] Furthermore, this all-dimensional perception layer accurately acquires raw security data from heterogeneous networks through hardware-level data acquisition and protocol adaptation technologies, enabling multi-dimensional security protection such as dynamic traffic monitoring, device identification, user behavior analysis, and radiation pattern recognition. Through the synergistic effect of technologies such as reinforcement learning, convolutional neural networks, and federated learning, the system's responsiveness and real-time performance to security threats are improved, while ensuring the timeliness and reliability of data, thus enhancing the intelligence and adaptability of network security protection.

[0086] The cognitive enhancement layer is used to receive the output of the full-dimensional perception layer and optimize the threat identification accuracy through four-dimensional spatiotemporal feature fusion and adversarial feature purification.

[0087] The cognitive enhancement layer receives the output from the full-dimensional perception layer and extracts data value through the following technologies:

[0088] The spatiotemporal feature fusion engine is used to integrate time-space-protocol-semantic dimension data based on metadata and employ four-dimensional tensor modeling technology to construct a multimodal situation map;

[0089] An adversarial feature cleaner is used to eliminate data contamination and strengthen coupled features based on time-space-frequency domain coupled features by integrating GAN noise filtering and graph attention anomaly detection.

[0090] The semantic transformation hub module is used to map heterogeneous data to a unified semantic embedding space based on behavioral features and through cross-protocol knowledge distillation technology, providing standardized input for the intelligent decision-making layer.

[0091] Furthermore, the cognitive enhancement layer improves the accuracy of threat identification and the usability of data through four-dimensional spatiotemporal feature fusion and adversarial feature purification technology. The spatiotemporal feature fusion engine integrates multi-dimensional data to construct a multimodal situation map, providing comprehensive security situation awareness; the adversarial feature purifier eliminates data pollution and strengthens key information features, improving data quality; the semantic conversion hub module standardizes heterogeneous data through cross-protocol knowledge distillation, providing accurate input for the subsequent intelligent decision-making layer, enhancing the system's intelligent decision-making capabilities and anti-interference ability.

[0092] The intelligent decision-making layer is used to accurately characterize complex attack patterns based on the output of the cognitive enhancement layer through hypergraph modeling and causal reasoning.

[0093] The intelligent decision-making layer, based on the output of the cognitive enhancement layer, constructs a multimodal threat cognition architecture, including:

[0094] The dynamic graph neural network submodule is used to construct the device interaction relationship topology based on multimodal situational maps and through hypergraph modeling technology, and to accurately characterize complex attack patterns by combining subgraph-level anomaly detection algorithms.

[0095] The meta-reinforcement learning threat detection engine is used for zero-shot attack pattern recognition based on multimodal situational maps and the MAML framework, and can quickly adapt to new threat features through few-shot learning.

[0096] The causal reasoning auxiliary module is used to construct an attack path prediction matrix based on a structural causal model and output an attack success probability distribution map.

[0097] A multimodal attention fusion unit is used to integrate visual features, temporal features, and graph structure features using a Transformer encoder architecture, and combine natural language processing to understand and analyze attack feature behavior.

[0098] The adaptive knowledge distillation module is used to migrate attack patterns in digital twin environments to real network defense models through a teacher-student network architecture.

[0099] Furthermore, the intelligent decision-making layer enhances the accuracy of identifying and responding to complex attack patterns through a multimodal threat cognition architecture. The dynamic graph neural network submodule accurately characterizes attack patterns in device interactions through hypergraph modeling and anomaly detection techniques; the meta-reinforcement learning engine achieves zero-shot attack pattern recognition, rapidly adapting to new threats; the causal reasoning module constructs an attack path prediction matrix, providing accurate analysis of attack success probabilities; the multimodal attention fusion unit deeply analyzes attack behavior by integrating different types of features; and the adaptive knowledge distillation module migrates defense strategies from the digital twin environment to the real network, enhancing the system's adaptability and defense capabilities. Overall, the intelligent decision-making layer effectively improves the detection, prediction, and response capabilities to complex attacks.

[0100] An adaptive execution layer is used to respond to instructions from the intelligent decision-making layer, and utilizes incomplete information game model and chaos engineering to optimize the adaptability of the defense strategy.

[0101] The adaptive execution layer responds to instructions from the intelligent decision-making layer, including:

[0102] A game theory-driven defense strategy generator is used to calculate the Nash equilibrium strategy based on the attack success probability distribution map and an incomplete information stochastic game model, and generate the optimal defense action sequence including firewall rule reorganization sequence and access control list change instructions.

[0103] Zero Trust Execution Framework is used to integrate continuous authentication with attribute-based dynamic permission allocation mechanisms for least privilege access control.

[0104] A dynamic micro-segmentation controller is used to perform least privilege isolation of business traffic using a hypergraph segmentation algorithm;

[0105] A defense strategy optimizer is used to find the optimal solution for Poate based on the multi-objective particle swarm optimization algorithm, considering business continuity, system entropy increase, defense cost, and attack blocking rate.

[0106] Chaos engineering injectors are used to periodically inject controlled disturbances into networks to verify system resilience and optimize the adaptability of defense strategies.

[0107] Furthermore, the adaptive execution layer enhances the flexibility and adaptability of the defense strategy by responding to instructions from the intelligent decision-making layer. A game theory-driven defense strategy generator calculates the optimal defense action sequence based on the attack success probability distribution map, enhancing the intelligence of the defense response; the zero-trust execution framework strengthens least privilege access control, ensuring system security; the dynamic micro-segmentation controller achieves business traffic isolation through a hypergraph segmentation algorithm, improving security; the defense strategy optimizer finds the optimal solution among multiple objectives, ensuring the effectiveness and cost control of the system's defense; and the chaos engineering injector verifies system resilience through periodic perturbations, continuously optimizing the adaptability of the defense strategy. Overall, the adaptive execution layer improves the system's dynamic defense capabilities and continuous resilience, ensuring the ability to cope with complex and unknown attacks.

[0108] The cross-domain collaboration layer is used for protocol-agnostic middleware to build a trusted defense ecosystem through cross-domain blockchain notarization and digital twin verification, and to manage the entire lifecycle of defense strategies.

[0109] The cross-domain collaboration layer is executed through protocol-independent middleware, including:

[0110] A multi-protocol command conversion gateway is used to perform cross-domain adaptation of intelligent decision-making layer commands through a built-in semantic mapping table of 20+ industrial protocols.

[0111] The blockchain evidence storage chain is used to record the history of defense strategy changes, attack tracing evidence chains, and command execution logs, thus constructing an immutable audit trail.

[0112] The digital twin verification sandbox is used to form a closed loop of "strategy generation - simulation verification - deployment optimization" through real-time simulation of defense strategies and dynamic evaluation of the attack surface.

[0113] Furthermore, the cross-domain collaboration layer constructs a trusted defense ecosystem through protocol-agnostic middleware, enhancing the transparency and traceability of defense strategies. The multi-protocol command conversion gateway achieves cross-domain adaptation, ensuring the compatibility of intelligent decision-making layer commands across different protocol environments; the blockchain evidence storage chain records defense strategy changes, attack tracing, and command execution history, providing an immutable audit trail and enhancing the credibility of defense strategies; the digital twin verification sandbox, through real-time simulation and dynamic attack surface assessment, forms a closed loop of strategy generation, simulation verification, and deployment optimization, ensuring the effectiveness and continuous optimization of defense strategies. Overall, the cross-domain collaboration layer provides strong support for the full lifecycle management of defense strategies, improving system security and trustworthiness.

[0114] Example 2:

[0115] Please see Figure 2 As shown, an artificial intelligence-based heterogeneous network security defense method includes:

[0116] Step 1: Implement full-dimensional data collection through self-organizing edge probes to construct a three-dimensional situation matrix containing traffic metadata, device fingerprint features, and user behavior trajectories;

[0117] Step 2: Based on the three-dimensional situation matrix, feature optimization is performed using a spatiotemporal adversarial training framework, and a feature quality assessment report containing noise robustness indicators is generated.

[0118] Step 3: Construct a cross-domain knowledge graph based on the optimized features, share information across devices and domains through a federated learning framework, and use a hypergraph attention network to mine hidden attack association patterns.

[0119] Step 4: Generate a defense action space in the deep reinforcement learning model using attack correlation patterns, and optimize the defense strategy by combining Monte Carlo tree search with defense cost-benefit analysis.

[0120] Step 5: Based on the optimized defense strategy, execute cross-domain translation of defense commands through protocol-independent middleware, and synchronously update SDN flow tables and device configurations;

[0121] Step 6: Establish a defense effect feedback loop and continuously optimize the feature extraction and strategy generation process based on the online meta-learning mechanism.

[0122] In step three, the cross-domain defense capability is optimized based on the optimized features by performing the following operations:

[0123] Construct a device relationship hypergraph and use a high-order graph attention network to detect abnormal communication subgraphs, revealing potential attack paths;

[0124] The causal discovery algorithm is used to identify key decision nodes in the attack path, providing data support for attack early warning and defense decisions.

[0125] Using contrastive learning methods, historical attack patterns are mapped to a new threat feature space to identify and respond to emerging attack types.

[0126] By generating a heatmap of attack success probability, we can guide the dynamic allocation of defense resources and optimize defense effectiveness in different network environments.

[0127] Furthermore, this optimization scheme effectively detects abnormal communication subgraphs and reveals potential attack paths by constructing a device relationship hypergraph and applying a high-order graph attention network, thereby enhancing cross-domain defense capabilities. Causal discovery algorithms help identify key decision nodes in attack paths, providing accurate data support for attack warnings and defense decisions. Contrastive learning methods combine historical attack patterns with new threat characteristics to identify emerging attack types, enhancing the defense's ability to respond to new threats. In addition, generating a heatmap of attack success probabilities helps dynamically allocate defense resources, thereby optimizing defense effectiveness in different network environments and improving overall security and defense efficiency.

[0128] In step four, the following defense strategies are optimized based on the attack pattern:

[0129] A defense effectiveness evaluation system is constructed based on the indicators of defense strategies to comprehensively evaluate the effectiveness of defense strategies.

[0130] A hierarchical reinforcement learning architecture is adopted, which decomposes the global policy into sub-policies at the network layer, host layer, and application layer, and enables each layer to work together.

[0131] Stress tests were conducted in a digital twin environment to verify the robustness of the defense strategy under various hybrid attack scenarios;

[0132] By generating confidence intervals for defense strategies, decision support is provided for human intervention.

[0133] Furthermore, this optimized defense strategy scheme comprehensively evaluates the effectiveness of the defense strategy by constructing a defense performance evaluation system, ensuring the effectiveness of the defense measures. The hierarchical reinforcement learning architecture decomposes the global strategy into multiple hierarchical sub-strategies, which work collaboratively at different levels, thereby improving the overall defense effect. Stress testing in a digital twin environment verifies the robustness of the defense strategy under various hybrid attack scenarios, ensuring its adaptability and stability in real-world environments. Simultaneously, by generating confidence intervals for the defense strategy, it provides decision support for human intervention, helping the defense team more accurately determine the level of trust in strategy execution and the need for adjustments, further enhancing the intelligence and flexibility of the defense.

[0134] In step five, the following defense instructions are transmitted and executed based on the optimized defense strategy:

[0135] A semantic parser converts a unified defense strategy into a specific protocol instruction set and performs corresponding formatting and protocol adaptation operations according to the target network protocol.

[0136] The process of distributing defense strategies is executed using blockchain smart contract technology, while simultaneously implementing anti-tampering mechanisms;

[0137] Implement traffic shaping for time-sensitive networks by classifying and prioritizing traffic through network configuration and bandwidth management.

[0138] Furthermore, this defense command delivery and execution scheme uses a semantic parser to convert the optimized defense strategy into a specific protocol instruction set, achieving precise strategy execution and network protocol adaptation. Blockchain smart contract technology ensures the distribution process of the defense strategy has an tamper-proof mechanism, improving the security and transparency of strategy execution. Time-Sensitive Networking (TSN) traffic shaping optimizes bandwidth management and network configuration through traffic classification and priority control, effectively reducing the traffic pressure from attacks and ensuring efficient and stable network operation. These measures collectively enhance the execution accuracy, security, and network robustness of the defense strategy.

[0139] Application Example: Heterogeneous Network Security Defense Practices of a Large Manufacturing Enterprise

[0140] A large manufacturing company with operations spanning multiple sectors, including production, supply chain management, product development, and customer service, possesses a complex heterogeneous network environment. This environment includes network equipment from different vendors, various operating systems, diverse industrial control systems, and IoT devices. As digital transformation deepens, the security threats faced by the company are becoming increasingly complex and diverse, rendering traditional cybersecurity defense systems inadequate.

[0141] I. Application of the technical solution of this invention

[0142] In order to enhance the company's cybersecurity protection capabilities, the company decided to adopt the present invention "A Heterogeneous Cybersecurity Defense System and Method Based on Artificial Intelligence" to build its cybersecurity defense system.

[0143] (1) Deployment of the full-dimensional perception layer

[0144] Hardware-level data acquisition: Deploy self-organizing edge probes at key network nodes to collect multi-dimensional data such as network traffic, device status, and user behavior in real time through hardware-level data acquisition technology.

[0145] Protocol Adaptive Technology: Utilizing the protocol adaptive traffic mirroring module, the sampling rate is dynamically adjusted according to network traffic characteristics to ensure that the full traffic capture mode can be quickly activated when abnormal traffic is detected, and detailed metadata can be obtained.

[0146] (2) Implementation of the cognitive enhancement layer

[0147] Four-dimensional spatiotemporal feature fusion: Based on the collected metadata, four-dimensional tensor modeling technology is used to integrate time, space, protocol and semantic dimension data to construct a multimodal situation map and improve the accuracy of threat identification.

[0148] Adversarial feature cleanup: By integrating GAN noise filtering and graph attention anomaly detection techniques, noise and contamination in the data are eliminated, key information features are enhanced, and data quality is improved.

[0149] (3) Application of intelligent decision-making layer

[0150] Hypergraph Modeling and Causal Inference: Based on a multimodal situational awareness map, hypergraph modeling technology is used to construct the topology of device interaction relationships. Combined with subgraph-level anomaly detection algorithms, complex attack patterns are accurately characterized. Simultaneously, causal inference technology is used to construct an attack path prediction matrix, outputting an attack success probability distribution map.

[0151] Zero-sample attack pattern identification: Employing the MAML framework for zero-sample attack pattern identification, the system can quickly adapt to new threat characteristics and ensure that it can maintain a high level of defense against unknown attacks.

[0152] (4) Adaptive execution layer optimization

[0153] Game theory-driven defense strategy generation: Based on the attack success probability distribution map, the Nash equilibrium strategy is calculated using an incomplete information stochastic game model, and the optimal defense action sequence including firewall rule reorganization sequence and access control list change instructions is generated.

[0154] Chaos engineering injection: Periodically inject controlled disturbances into the network to verify system resilience, and optimize defense strategies based on test results to improve the system's adaptability and robustness to complex attacks.

[0155] (5) Construction of cross-domain collaboration layer

[0156] Multi-protocol command conversion: Through the multi-protocol command conversion gateway, cross-domain adaptation of intelligent decision-making layer commands in different protocol environments is achieved, ensuring that defense strategies can be effectively executed in the entire heterogeneous network environment.

[0157] Blockchain Evidence Storage and Digital Twin Verification: Utilizing a blockchain evidence storage chain to record the history of defense strategy changes, attack tracing evidence chains, and command execution logs, an immutable audit trail is constructed. Simultaneously, a digital twin verification sandbox is used for real-time simulation of defense strategies and dynamic assessment of the attack surface, forming a closed loop of "strategy generation - simulation verification - deployment optimization."

[0158] II. Application Effects

[0159] By implementing the technical solution of this invention, this large manufacturing enterprise significantly improved its heterogeneous network security defense capabilities. The system can perceive changes in the network environment in real time, automatically identify and respond to various complex attacks, effectively reducing the probability of network security incidents. Simultaneously, the establishment of a cross-domain collaborative defense mechanism enables effective sharing and collaboration of security information between different departments and network domains, further enhancing overall defense capabilities. Furthermore, the full lifecycle management function of the defense strategy ensures the scientific, rational, and effective nature of the defense measures, reduces operational costs, and improves the enterprise's network security protection level.

[0160] Example 3:

[0161] This invention also provides a computer-readable storage medium storing a program for an artificial intelligence-based heterogeneous network security defense system as described above. When executed by a processor, this program implements the various processes of the aforementioned security defense system embodiments and achieves the same technical effects. To avoid repetition, further details are omitted here. The computer-readable storage medium may include, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0162] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Furthermore, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0163] The accompanying drawings of the embodiments disclosed in this invention only involve the structures involved in the embodiments disclosed in this invention. Other structures can refer to general designs. In the absence of conflict, the same embodiment and different embodiments of this invention can be combined with each other.

[0164] The flowchart shown in the attached diagram is for illustrative purposes only and does not necessarily include all content and operations / steps, nor does it necessarily have to be performed in the order described. For example, some operations / steps can be broken down, combined, or partially merged, so the actual execution order may change depending on the actual situation.

[0165] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A heterogeneous network security defense system based on artificial intelligence, characterized in that, include: The full-dimensional perception layer is used to acquire raw data on heterogeneous network security through hardware-level data acquisition and protocol adaptive technology; The cognitive enhancement layer is used to receive the output of the full-dimensional perception layer and optimize the threat identification accuracy through four-dimensional spatiotemporal feature fusion and adversarial feature purification. The intelligent decision-making layer is used to accurately characterize complex attack patterns based on the output of the cognitive enhancement layer through hypergraph modeling and causal reasoning. An adaptive execution layer is used to respond to the instructions of the intelligent decision-making layer and to optimize the adaptability of the defense strategy by using an incomplete information game model and chaos engineering injection. The cross-domain collaboration layer is used to build a trusted defense ecosystem based on protocol-independent middleware through cross-domain blockchain notarization and digital twin verification, and to manage the entire lifecycle of the defense strategy.

2. The heterogeneous network security defense system based on artificial intelligence according to claim 1, characterized in that, The full-dimensional perception layer includes the following collaborative modules: The protocol adaptive traffic mirroring module is used to dynamically adjust the sampling rate using reinforcement learning and activate the full traffic capture mode when abnormal traffic characteristics are detected to obtain metadata of heterogeneous network security. Hardware-level device fingerprint collectors are used to construct a multi-dimensional profile of device identity by comparing firmware hash values ​​and analyzing electromagnetic radiation spectrum through convolutional neural networks, thus forming device-level trust anchors. The user behavior gene library is used to generate individualized behavioral feature sequences using the LSTM-Transformer hybrid model to establish a user behavior baseline. The electromagnetic side channel analysis module is used to identify the time-space-frequency domain coupling characteristics of the device's radiation pattern using a spatiotemporal convolutional neural network. An environment-aware adaptive module is used to aggregate multi-node environment parameters based on the device-level trust anchor point using the following federated learning formula, and dynamically adjust the adopted strategy. In the formula, w t For the weight of the global environment, Let n be the local environment weight of the k-th node. k Let n be the number of data points in the k-th node, and n be the total number of data points in all nodes. A data freshness evaluator is used to calculate the timeliness weight of data using a decay factor based on information entropy and time.

3. The heterogeneous network security defense system based on artificial intelligence according to claim 2, characterized in that, The cognitive enhancement layer receives the output of the full-dimensional perception layer and extracts data value through the following techniques: A spatiotemporal feature fusion engine is used to integrate time-space-protocol-semantic dimension data based on the aforementioned metadata using four-dimensional tensor modeling technology to construct a multimodal situation map; An adversarial feature cleaner is used to eliminate data contamination and enhance coupling features based on the time-space-frequency domain coupled features by integrating GAN noise filtering and graph attention anomaly detection; The semantic transformation hub module is used to map heterogeneous data to a unified semantic embedding space based on the behavioral features through cross-protocol knowledge distillation technology, so as to provide standardized input for the intelligent decision-making layer.

4. The heterogeneous network security defense system based on artificial intelligence according to claim 3, characterized in that, The intelligent decision-making layer, based on the output of the cognitive enhancement layer, constructs a multimodal threat cognition architecture, including: The dynamic graph neural network submodule is used to construct the device interaction relationship topology based on the multimodal situation map through hypergraph modeling technology, and combine it with the subgraph-level anomaly detection algorithm to accurately characterize complex attack patterns. The meta-reinforcement learning threat detection engine is used to identify zero-shot attack patterns based on the multimodal situation map using the MAML framework, and to quickly adapt to new threat features through few-shot learning. The causal reasoning auxiliary module is used to construct an attack path prediction matrix based on a structural causal model and output an attack success probability distribution map. Structural causal model inference formula: In the formula, P(Y|X) is the conditional probability of Y given X, and Z is the latent hidden variable; A multimodal attention fusion unit is used to integrate visual features, temporal features, and graph structure features using a Transformer encoder architecture, and combine natural language processing to understand and analyze attack feature behavior. The adaptive knowledge distillation module is used to migrate attack patterns in digital twin environments to real network defense models through a teacher-student network architecture.

5. A heterogeneous network security defense system based on artificial intelligence according to claim 4, characterized in that, The adaptive execution layer responds to the instructions of the intelligent decision-making layer, including: A game theory-driven defense strategy generator is used to calculate the Nash equilibrium strategy based on the attack success probability distribution map, using an incomplete information random game model, and generate an optimal defense action sequence that includes a firewall rule reorganization sequence and access control list change instructions. The formula for solving Nash equilibrium based on incomplete information stochastic game models: In the formula, u i (s i ,s -i For player i in strategy s i Other player strategies -i The effect of s i Let ' be a possible strategy for player i, and s be... i Let i be player i's current strategy; Zero Trust Execution Framework is used to integrate continuous authentication with attribute-based dynamic permission allocation mechanisms for least privilege access control. A dynamic differential segmentation controller is used to perform least privilege isolation of business traffic using a hypergraph segmentation algorithm; A defense strategy optimizer is used to find the optimal solution for Poate based on the multi-objective particle swarm optimization algorithm, considering business continuity, system entropy increase, defense cost, and attack blocking rate. A chaos engineering injector is used to periodically inject controlled disturbances into the network to verify system resilience and optimize the adaptability of the defense strategy.

6. A heterogeneous network security defense system based on artificial intelligence according to claim 5, characterized in that, The cross-domain collaboration layer is executed through protocol-independent middleware, including: A multi-protocol instruction conversion gateway is used to perform cross-domain adaptation of the intelligent decision-making layer instructions through a built-in semantic mapping table of 20+ industrial protocols. The blockchain evidence storage chain is used to record the history of changes to the defense strategy, the evidence chain for tracing the source of attacks, and the instruction execution log, thereby constructing an immutable audit trail. The digital twin verification sandbox is used to form a closed loop of "strategy generation - simulation verification - deployment optimization" through real-time simulation and dynamic evaluation of the attack surface of the defense strategy.

7. A heterogeneous network security defense method based on artificial intelligence, characterized in that, include: Step 1: Implement full-dimensional data collection through self-organizing edge probes to construct a three-dimensional situation matrix containing traffic metadata, device fingerprint features, and user behavior trajectories; Step 2: Based on the three-dimensional situation matrix, feature optimization is performed using a spatiotemporal adversarial training framework, and a feature quality assessment report containing noise robustness indicators is generated. Step 3: Construct a cross-domain knowledge graph based on the optimized features, share information across devices and domains through a federated learning framework, and use a hypergraph attention network to mine hidden attack association patterns. Step 4: Generate a defense action space in a deep reinforcement learning model using the attack association pattern, and optimize the defense strategy by combining Monte Carlo tree search with defense cost-benefit analysis. Step 5: Based on the optimized defense strategy, execute cross-domain translation of defense instructions through protocol-independent middleware, and synchronously update the SDN flow table and device configuration; Step 6: Establish a defense effect feedback loop and continuously optimize the feature extraction and strategy generation process based on the online meta-learning mechanism.

8. The heterogeneous network security defense method based on artificial intelligence according to claim 7, characterized in that, In step three, the cross-domain defense capability is optimized based on the optimized features by performing the following operations: Construct a device relationship hypergraph and use a high-order graph attention network to detect abnormal communication subgraphs, revealing potential attack paths; The causal discovery algorithm is applied to identify the key decision nodes of the attack path, providing data support for attack early warning and defense decisions; Using contrastive learning methods, historical attack patterns are mapped to a new threat feature space to identify and respond to emerging attack types. By generating a heatmap of attack success probability, we can guide the dynamic allocation of defense resources and optimize defense effectiveness in different network environments.

9. A heterogeneous network security defense method based on artificial intelligence according to claim 8, characterized in that, In step four, the defense strategy is optimized based on the attack pattern as follows: A defense effectiveness evaluation system is constructed based on the indicators of the defense strategy to comprehensively evaluate the effectiveness of the defense strategy. A hierarchical reinforcement learning architecture is adopted, which decomposes the global policy into sub-policies at the network layer, host layer, and application layer, and enables each layer to work together. Stress tests were conducted in a digital twin environment to verify the robustness of the defense strategy under various hybrid attack scenarios; By generating confidence intervals for the defense strategy, decision support is provided for human intervention.

10. A heterogeneous network security defense method based on artificial intelligence according to claim 9, characterized in that, In step five, the following defense instructions are transmitted and executed based on the optimized defense strategy: The unified defense strategy is converted into a specific protocol instruction set by a semantic parser, and corresponding formatting and protocol adaptation operations are performed according to the target network protocol. The distribution process of the defense strategy is executed using blockchain smart contract technology, while implementing an anti-tampering mechanism. Implement traffic shaping for time-sensitive networks by classifying and prioritizing traffic through network configuration and bandwidth management.

Citation Information

Cited By

  • Large model reasoning path optimization method and system based on dynamic entropy perception

    CN121706996A

  • AI-enabled CPU server data security automatic defense strategy generation method

    CN122046350A