Network security multi-mode intelligent detection method and device, equipment and storage medium
By collecting and fusing multimodal data from the power system network boundary, generating comprehensive risk results and triggering a blocking sandbox mechanism, the problem of limited detection capabilities and delayed response in power system network boundary security management is solved, enabling real-time defense and efficient response to complex threats.
Patent Information
- Application Number
- CN202511460714.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-14
- Publication Date
- 2025-11-14
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Power system network boundary security management suffers from limited detection capabilities, cumbersome response processes, and difficulty in effectively resisting complex network attacks. Traditional detection engines lack real-time proactive detection capabilities and automated responses, leading to the spread of security threats and losses.
The system collects static characteristic data, dynamic network traffic data, and time-series behavior pattern data from network boundary devices. Through multimodal fusion analysis, it generates comprehensive risk results, triggers a preset blocking sandbox mechanism, and conducts simulation verification to achieve real-time blocking operations.
It enables accurate identification and proactive defense against complex network threats, improves the accuracy and comprehensiveness of network security threat detection, meets the requirements of second-level response, and reduces the loss of security incidents and the risk of misoperation.
Smart Images

Figure CN120956524A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security management technology, and more specifically, to a network security multimodal intelligent detection method, apparatus, device, and storage medium. Background Technology
[0002] Driven by the powerful wave of digitalization, the stable operation of power systems increasingly relies on efficient network boundary security. As a critical line of defense for information exchange within the power system, the security of the network boundary has risen to an unprecedented strategic level. However, current power system network boundary security management faces numerous severe challenges, and traditional technologies are proving inadequate in addressing increasingly complex cybersecurity threats.
[0003] Network boundary security management tools for power systems generally rely heavily on manual log auditing and post-event analysis, lacking real-time proactive detection capabilities. Once an unauthorized external connection incident occurs, administrators must spend a significant amount of time manually sifting through massive amounts of logs to pinpoint the source of the problem. This excessively long response time falls far short of the stringent compliance requirements for "second-level blocking" in power system security protection. During this prolonged response delay, security threats have ample time to spread unchecked within the power system's network, severely jeopardizing the safe and stable operation of the power system and potentially leading to catastrophic consequences such as critical data breaches, equipment malfunctions, or even widespread power outages.
[0004] Existing detection engines for power system network boundary security management mostly rely on a single data source, such as simple IP blacklists or device signature matching. When faced with complex attack methods such as masquerading as legitimate power devices and using covert communication channels, these traditional detection engines prove inadequate. Taking malicious USB drives as an example, attackers can bypass whitelist detection by forging VID / PID, and traditional engines, lacking behavioral analysis capabilities, struggle to identify their abnormal behavior. This allows malicious USB drives to easily infiltrate the power system's internal network, posing a serious threat to power system security.
[0005] Furthermore, most power system network security management systems separate detection, alarm, and blocking functions, requiring manual confirmation before execution. This not only significantly increases the risk of misoperation but also leads to a substantial extension of the risk window. When high-risk devices are detected, the unauthorized connection may continue for several minutes while the administrator manually issues the blocking command, leaving attackers with an opportunity to cause incalculable losses, such as power data tampering and unplanned generator outages.
[0006] In summary, traditional network boundary security management methods for power systems suffer from prominent problems such as limited detection capabilities and cumbersome response processes, making them difficult to effectively defend against new types of network attacks. Summary of the Invention
[0007] The problem solved by this invention is one or more of the aforementioned related technical problems.
[0008] To address the aforementioned issues, this invention provides a network security multimodal intelligent detection method, apparatus, device, and storage medium.
[0009] In a first aspect, the present invention provides a network security multimodal intelligent detection method, applied to a power system, the detection method comprising: Collect static characteristic data, dynamic network traffic data, and time-series behavior pattern data of network boundary devices in the power system; The static feature data, the dynamic network traffic data, and the time-series behavior pattern data are subjected to multimodal fusion analysis to generate a comprehensive risk result; Based on the comprehensive risk results, determine whether to trigger the preset blocking sandbox mechanism; When the preset blocking sandbox mechanism is triggered, a preset verification process is initiated. Simulation verification is performed based on the comprehensive risk results, the dynamic network traffic data, and the time-series behavior pattern data to obtain verification results. Real-time blocking operations are then performed based on the verification results to ensure network boundary security.
[0010] Optionally, the static feature data includes device fingerprint data; the step of performing multimodal fusion analysis on the static feature data, the dynamic network traffic data, and the time-series behavioral pattern data to generate a comprehensive risk result includes: Based on a preset device library, the device fingerprint data is evaluated to obtain first risk data; Based on a preset traffic baseline model, the second risk data is obtained by identifying the dynamic network traffic data. Based on a preset risk prediction model, the probability of future behavioral risks is obtained from the time-series behavioral pattern data. The comprehensive risk result is obtained based on the first risk data, the first risk data, and the probability of future behavior risk.
[0011] Optionally, the second risk data, obtained by identifying based on the dynamic network traffic data according to the preset traffic baseline model, includes: Feature extraction is performed on the dynamic network traffic data to obtain traffic feature data, and the traffic feature data is divided to obtain time-series traffic data within a preset time window; A multidimensional traffic baseline model is constructed based on historical normal traffic data, and the time-series traffic data within the preset event window is compared with the multidimensional traffic baseline model to obtain multiple corresponding deviation data. The second risk data is determined based on the deviation data described above.
[0012] Optionally, determining the second risk data based on each of the deviation data includes: A multi-dimensional comprehensive score is obtained based on preset weight data and each deviation data; The abnormal traffic type is determined based on the multi-dimensional comprehensive score and the preset threshold, and the second risk data is determined based on the abnormal traffic type.
[0013] Optionally, the time-series behavioral pattern data includes operational behavior data, network connection behavior data, time-series feature data, and contextual information; the step of obtaining the future behavioral risk probability based on the time-series behavioral pattern data using a preset risk prediction model includes: A time-series data sample is generated based on the operational behavior data, the network connection behavior data, the temporal feature data, and the context information; The time-series data sample is input into the risk prediction model to obtain the probability of future behavior risk; The risk prediction model is based on a long short-term memory network.
[0014] Optionally, the network security multimodal intelligent detection method further includes: Obtain current traffic pattern data and device behavior sequence; Based on the comprehensive risk results, current traffic pattern data, device behavior sequences, and historical data, an optimized detection strategy is obtained through a preset reinforcement learning model.
[0015] Optionally, the optimized detection strategy obtained based on the comprehensive risk results, current traffic pattern data, device behavior sequences, and historical data through a preset reinforcement learning model includes: Construct the reinforcement learning model and initialize it. The reward value is determined based on the comprehensive risk results, the current traffic pattern data, the device behavior sequence, and the historical data. The policy gradient is determined based on the reward value, and the policy network parameters of the reinforcement learning model are updated according to the policy gradient to maximize the expected cumulative reward. The optimized detection strategy is determined based on the updated strategy network parameters.
[0016] Secondly, the present invention provides a network security multimodal intelligent detection device, applied to a power system, the detection device comprising: The acquisition unit is used to acquire static characteristic data, dynamic network traffic data, and time-series behavior pattern data of network boundary devices in the power system. The analysis unit is used to perform multimodal fusion analysis on the static feature data, the dynamic network traffic data, and the time-series behavior pattern data to generate a comprehensive risk result; The processing unit is used to determine whether to trigger the preset blocking sandbox mechanism based on the comprehensive risk result; The processing unit is also used to initiate a preset verification process when the preset blocking sandbox mechanism is triggered, to perform simulation verification based on the comprehensive risk result, the dynamic network traffic data and the time-series behavior pattern data, to obtain the verification result, and to perform real-time blocking operation based on the verification result to ensure network boundary security.
[0017] Thirdly, the present invention provides a network security multimodal intelligent detection device, including a memory and a processor; the memory is used to store a computer program; the processor is used to implement the network security multimodal intelligent detection method as described in the first aspect when the computer program is executed.
[0018] Fourthly, the present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the network security multimodal intelligent detection method as described in the first aspect.
[0019] The beneficial effects of the network security multimodal intelligent detection method, device, system, and storage medium of the present invention are: First, static characteristic data, dynamic network traffic data, and time-series behavioral pattern data of network boundary devices are collected. Static characteristic data typically includes hardware model, firmware version, and firewall rules. Dynamic network traffic data includes protocol type (HTTP / DNS), traffic peaks, and abnormal data packets (such as malformed packets). Time-series behavioral pattern data records the temporal characteristics of device behavior, such as administrator login frequency, session duration, and data packet transmission cycle. This process provides the data foundation for subsequent processing.
[0020] Using algorithms such as deep learning and machine learning, feature extraction and correlation analysis are performed on data from different modalities. For example, by combining static feature data of devices (such as device model) with dynamic network traffic data (such as the special protocols used), it can be determined whether a device is performing operations inconsistent with its normal functions; at the same time, by comparing time-series behavioral pattern data (such as abnormally frequent file access) with historical behavioral patterns, potential abnormal behaviors can be identified. Through cross-validation and deep fusion of multimodal data, a comprehensive risk result is generated to comprehensively assess the security risk level of network boundary devices.
[0021] Based on the generated comprehensive risk results, they are compared with preset risk thresholds. When the comprehensive risk result reaches or exceeds the preset threshold, a high security threat is identified, triggering a preset blocking sandbox mechanism. This mechanism acts like a "virtual isolation zone," isolating potentially vulnerable devices or network connections within the sandbox before formal blocking operations, preventing the potential threat from spreading throughout the network. Within the sandbox environment, suspicious activities are comprehensively simulated by combining the comprehensive risk results with dynamic network traffic data and temporal behavior pattern data. For example, based on high-risk areas indicated by the comprehensive risk results, the system focuses on analyzing abnormal traffic patterns in dynamic network traffic data (such as sudden large-volume access, frequent connection attempts from specific IPs) and abnormal operation sequences in temporal behavior pattern data (such as file access behavior following multiple failed login attempts within a short period). Through simulation verification, verification results are obtained. If malicious attack behavior is confirmed, the corresponding network connections or device operations are blocked in real time based on the results, such as cutting off connections from malicious IPs or preventing devices from performing suspicious operations, thereby effectively protecting the network boundary from security threats.
[0022] Therefore, this invention overcomes the limitations of traditional single-data source detection by collecting and fusing multimodal data such as static features, dynamic network traffic, and temporal behavior patterns. Through collaborative detection from multiple dimensions, including device attributes, traffic characteristics, and behavioral patterns, it can accurately identify complex threats such as malicious attacks disguised as legitimate devices and covert channel communications. It effectively prevents malicious USB drives from forging VID / PIDs to bypass detection, significantly improving the accuracy and comprehensiveness of network security threat detection. In terms of response mechanisms, this invention constructs an automated and intelligent real-time protection system, completely changing the lagging mode of traditional manual log auditing. The entire process, from data collection and risk analysis to blocking and handling, can be completed within seconds, meeting the stringent security requirements of "second-level blocking," achieving proactive defense against network attacks, and significantly reducing the losses caused by security incidents. In terms of functional architecture, this invention innovatively integrates detection, analysis, verification, and blocking functions. Through a preset blocking sandbox mechanism and simulated verification process, it ensures the accuracy of blocking while reducing manual intervention. When a risk warning is triggered, the system automatically isolates suspicious objects in the sandbox environment for verification, avoiding misjudgments and delays in handling caused by manual operation, and significantly improving the reliability and response efficiency of network security management. Furthermore, based on continuous analysis and machine learning of time-series behavioral pattern data, the system can deeply mine historical patterns and potential trends in device behavior, and combine these with comprehensive risk assessment results to achieve risk prediction. For recurring security incidents, such as employees repeatedly accessing unauthorized devices, the system can proactively issue warnings or implement pre-blocking measures, promoting a shift in network security protection from passive response to proactive defense, and effectively reducing the probability of similar security incidents recurring. Attached Figure Description
[0023] Figure 1 This is a flowchart illustrating a network security multimodal intelligent detection method according to an embodiment of the present invention; Figure 2 This is a schematic diagram of the structure of a network security multimodal intelligent detection device according to an embodiment of the present invention; Figure 3 This is a schematic diagram of a network security multimodal intelligent detection device according to an embodiment of the present invention. Detailed Implementation
[0024] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Although some embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the present invention. It should be understood that the accompanying drawings and embodiments of the present invention are for illustrative purposes only and are not intended to limit the scope of protection of the present invention.
[0025] It should be understood that the various steps described in the method embodiments of the present invention may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this respect.
[0026] The term "comprising" and its variations as used herein are open-ended, meaning "including but not limited to"; the term "based on" means "at least partially based on"; the term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments"; and the term "optionally" means "optional embodiments". Definitions of other terms will be given in the following description. It should be noted that the concepts of "first," "second," etc., mentioned in this invention are used only to distinguish different devices, modules, or units, and are not intended to limit the order of functions performed by these devices, modules, or units or their interdependencies.
[0027] It should be noted that the terms "a" and "a plurality of" used in this invention are illustrative rather than restrictive. Those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0028] The names of the messages or information exchanged between the multiple devices in the embodiments of the present invention are for illustrative purposes only and are not intended to limit the scope of these messages or information.
[0029] Existing network boundary security detection solutions generally lack the ability to learn from and analyze historical data, making it impossible to predict potential risks and leading to frequent recurring security incidents in power systems. For example, if a power company employee repeatedly plugs into the same unauthorized device, the system can only passively intercept it, making it difficult to proactively alert or block it. This leaves the power system's security protection in a reactive state, unable to effectively curb the recurrence of security incidents, and severely restricts the improvement of the power system's network security protection level.
[0030] To address the problems existing in the aforementioned related technologies, embodiments of the present invention provide a network security multimodal intelligent detection method, device, system, and storage medium.
[0031] like Figure 1 As shown in the figure, an embodiment of the present invention provides a network security multimodal intelligent detection method applied to a power system. The detection method includes: Step S100: Collect static characteristic data, dynamic network traffic data, and time-series behavior pattern data of the network boundary devices in the power system.
[0032] Specifically, network boundary devices in power systems typically include routers, firewalls, switches, and USB devices, which often have specific model numbers, serial numbers, and other identification features.
[0033] Static characteristic data: Collects unique identification information of network boundary devices, including but not limited to: Device physical identification: MAC address, VID (vendor ID) / PID (product ID) of USB devices, hardware serial number, and other immutable physical characteristics; Software characteristics: driver signature hash value, firmware version, digital certificate (such as TLS certificate); Network configuration: IP address (when statically assigned), list of open ports, etc. The above data is captured in real time by a lightweight agent (embedded in the device driver or network interface card) to capture the initialization information when the device connects.
[0034] Dynamic network traffic data generally includes: protocol resolution (DNS query records, HTTP request headers, ICMP payloads); traffic statistics (request frequency, such as DNS requests / second), packet size distribution, session duration); and abnormal characteristics (non-standard port communication, unidirectional large-volume transmission, etc.). The data is typically collected in real-time using traffic mirroring technology or deep packet inspection (DPI) tools (such as Suricata). This traffic characteristic data reflects the network's communication status and traffic trends, providing raw data support for subsequent traffic anomaly detection and security event analysis. Furthermore, various application layer protocols contained in the network traffic, such as IEC 61850 and Modbus TCP / IP protocols commonly used in power systems, are extracted to identify specific content and instructions. Analysis is then conducted to determine whether these protocol interactions conform to the normal communication flow of power system services and whether there are any abnormal commands or data transmissions. For example, for the IEC 61850 protocol, the GOOSE (General Object-Oriented Substation Event) messages in its messages are checked to ensure they conform to predefined formats and semantics, preventing maliciously tampered or forged protocol messages from entering the power system network.
[0035] Timing-based behavioral pattern data typically includes file operation behaviors: access path (e.g., C:\Windows\System32), file type (e.g., .exe and .dll); network connection behaviors: connection target IP / domain name, protocol type, connection frequency; and timing characteristics: operation interval time (e.g., interval between two writes < 1 second), burst operation chains, etc. It is generally collected through kernel-level monitoring tools (e.g., Windows ETW, Linux Auditd) recording system calls.
[0036] At the network boundary of the power system, the behavior of internal and external users accessing network resources through boundary devices is recorded. Information such as the network address accessed, access time, access frequency, and data transmission volume are collected to form time-series data of user network access behavior. Analyzing user access behavior patterns identifies abnormal access behaviors, such as unauthorized external access, abnormal access times by internal users, or frequent access to sensitive resources, thereby providing a basis for preventing network intrusion and data leakage.
[0037] Step S200: Perform multimodal fusion analysis on the static feature data, the dynamic network traffic data, and the time-series behavior pattern data to generate a comprehensive risk result.
[0038] In some embodiments, the collected data is first preprocessed. For static feature data, the hardware information (such as model and configuration), software version, system settings, and other static feature data of network boundary devices are standardized. For example, the device model is converted into a unified encoding format, and the software version is normalized.
[0039] For dynamic network traffic data: Feature extraction and normalization are performed on real-time captured network traffic data (such as packet size, transmission rate, source / destination IP address, port number, etc.). For example, statistical features such as the number of packets per second and the average packet size are calculated, and these feature values are normalized to the range [0, 1].
[0040] For time-series behavioral pattern data: Device behavior logs (such as login attempts, file access, network connections, etc.) are serialized in chronological order. For example, timestamps are used to sort behavioral events, and features such as frequency and interval of behavioral sequences are extracted.
[0041] The preprocessed static feature data, dynamic network traffic data, and temporal behavior pattern data are then fused into a unified feature space. This fusion process can be achieved through feature concatenation, for example, concatenating the static feature vector, dynamic traffic feature vector, and temporal behavior feature vector into a single feature vector. Alternatively, deep learning fusion methods can be used, such as using a convolutional neural network (CNN) to process the static feature data and a recurrent neural network (RNN) to process the temporal behavior pattern data, then inputting these features along with the dynamic network traffic data into a fully connected layer for fusion.
[0042] Finally, a risk assessment is performed on the fused feature vector using machine learning or deep learning models. For example, models such as Support Vector Machines (SVM), Random Forests, or Neural Networks can be used to train a risk assessment model based on historical data to score the current fused feature vector and generate a comprehensive risk result. The comprehensive risk result can be a risk level (e.g., low, medium, high) or a risk probability value (e.g., a value between 0 and 1).
[0043] In some preferred embodiments, risk assessments can be performed on static feature data, dynamic network traffic data, and time-series behavior pattern data using different evaluation methods to obtain corresponding risk data. These risk data are then combined with weighted data to obtain a comprehensive risk result. For example, a risk score (risk data) can be generated by comparing the static feature data with a pre-defined device library. Then, dynamic network traffic data and time-series behavior pattern data can be processed based on a set model to obtain corresponding risk scores (risk data). Finally, the three risk scores are fused using weighted fusion to obtain a comprehensive risk result.
[0044] By integrating static, dynamic, and time-series data, the accuracy of threat identification is significantly improved. For example, traditional methods might allow a USB drive to bypass a whitelist by forging a VID / PID, but behavioral time-series analysis can capture such abnormal operations. Furthermore, this fusion process can comprehensively assess the security status of the network boundary from multiple perspectives, avoiding the bias that can result from a single data modality.
[0045] Step S300: Determine whether to trigger the preset blocking sandbox mechanism based on the comprehensive risk results.
[0046] Specifically, a risk threshold can be set based on network security needs and historical data (e.g., a risk probability value greater than 0.8 or a risk level of "high risk"). This threshold is used to determine whether the current security status of the network boundary has reached a point where further protective measures are needed.
[0047] For example, if the overall risk result is a risk probability value, the preset blocking sandbox mechanism will be triggered when the value exceeds 0.8; if the overall risk result is a risk level, the mechanism will be triggered when the level is "high risk".
[0048] When the overall risk assessment reaches or exceeds a preset risk threshold, a pre-defined blocking sandbox mechanism is automatically triggered. By triggering the blocking sandbox mechanism based on the overall risk assessment, measures can be taken quickly after a potential threat is detected to prevent further spread of the attack and minimize the impact of security incidents on the network perimeter. The blocking sandbox mechanism is a security protection measure used to isolate and analyze suspicious network traffic or behavior to prevent potential threats from further compromising the network perimeter.
[0049] Step S400: When the preset blocking sandbox mechanism is triggered, a preset verification process is started. Simulation verification is performed based on the comprehensive risk results, the dynamic network traffic data, and the time-series behavior pattern data to obtain the verification results. Real-time blocking operations are then performed based on the verification results to ensure network boundary security.
[0050] Specifically, when the blocking sandbox mechanism is triggered, a preset verification process is automatically initiated. The main purpose of the verification process is to further analyze and confirm suspicious network traffic or behavior in order to avoid false alarms.
[0051] The verification process may include the following steps: performing in-depth analysis on suspicious network traffic packets to check whether they contain malicious code or attack characteristics (such as SQL injection, cross-site scripting attacks, etc.).
[0052] Simulate device behavior in a sandbox environment and observe whether it exhibits abnormal behavior. For example, simulate login attempts and file access behavior under attack and compare them with normal behavior patterns.
[0053] By combining comprehensive risk assessment results, dynamic network traffic data, and time-series behavioral pattern data, a comprehensive correlation analysis is conducted on suspicious activities. For example, it analyzes whether abnormal traffic is associated with abnormal behavior patterns of devices.
[0054] In the sandbox environment, suspicious activities are simulated and verified based on comprehensive risk results, dynamic network traffic data, and time-series behavioral pattern data.
[0055] For example, based on the high-risk areas indicated by the comprehensive risk results, we should focus on analyzing abnormal traffic patterns in dynamic network traffic data (such as sudden large-volume access, frequent connection attempts from specific IPs) and abnormal operation sequences in time-series behavior pattern data (such as file access behavior immediately following multiple failed login attempts in a short period of time).
[0056] Based on the simulation results, if malicious behavior or security threats are confirmed, a real-time blocking operation will be automatically executed.
[0057] Real-time blocking operations may include: Disconnecting network connections: Cutting off network connections with suspicious IP addresses to prevent further attacks. Blocking device operation: Preventing devices from performing suspicious operations, such as blocking file access or program execution. Logging: Recording detailed information about the verification process and blocking operations in a log for subsequent auditing and analysis.
[0058] By initiating a verification process and conducting simulated verification, suspicious activities can be analyzed and confirmed in depth, avoiding blocking measures based solely on preliminary detection results and effectively reducing false alarm rates. For example, through deep packet inspection and behavioral simulation analysis, it can be confirmed whether traffic or behavior is truly malicious, avoiding unnecessary blocking operations due to misjudgments of normal network activity.
[0059] Simultaneously, by isolating and analyzing suspicious activities through a sandbox mechanism, it is possible to effectively respond to new and complex cyberattack methods and enhance the security protection capabilities of the network perimeter. For example, for unknown malware or zero-day attacks, the sandbox environment can provide a secure analysis environment to help detect and block potential threats.
[0060] Finally, real-time blocking operations enable rapid response to security threats, reducing the time attacks spend impacting network boundaries and improving the response efficiency of network security protection. For example, after detecting high-risk behavior, the system can complete verification and execute blocking operations within seconds, effectively preventing the further development of the attack.
[0061] In summary, by using a blocking sandbox mechanism and verification process based on comprehensive risk results, security threats can be blocked in a timely and accurate manner, the false alarm rate can be reduced, the protection capability of the network boundary can be enhanced, the security response efficiency can be improved, and detailed information can be provided for security audits, thereby effectively ensuring the security of the network boundary.
[0062] In this embodiment, the network security multimodal intelligent detection method first collects static characteristic data, dynamic network traffic data, and temporal behavior pattern data from network boundary devices. Static characteristic data typically includes hardware model, firmware version, firewall rules, etc.; dynamic network traffic data includes protocol type (HTTP / DNS), traffic peaks, and abnormal data packets (such as malformed packets); and temporal behavior pattern data records the temporal characteristics of device behavior, such as administrator login frequency, session duration, and data packet sending cycle. This process provides the data foundation for subsequent processing.
[0063] Using algorithms such as deep learning and machine learning, feature extraction and correlation analysis are performed on data from different modalities. For example, by combining static feature data of devices (such as device model) with dynamic network traffic data (such as the special protocols used), it can be determined whether a device is performing operations inconsistent with its normal functions; at the same time, by comparing time-series behavioral pattern data (such as abnormally frequent file access) with historical behavioral patterns, potential abnormal behaviors can be identified. Through cross-validation and deep fusion of multimodal data, a comprehensive risk result is generated to comprehensively assess the security risk level of network boundary devices.
[0064] Based on the generated comprehensive risk results, they are compared with preset risk thresholds. When the comprehensive risk result reaches or exceeds the preset threshold, a high security threat is identified, triggering a preset blocking sandbox mechanism. This mechanism acts like a "virtual isolation zone," isolating potentially vulnerable devices or network connections within the sandbox before formal blocking operations, preventing the potential threat from spreading throughout the network. Within the sandbox environment, suspicious activities are comprehensively simulated by combining the comprehensive risk results with dynamic network traffic data and temporal behavior pattern data. For example, based on high-risk areas indicated by the comprehensive risk results, the system focuses on analyzing abnormal traffic patterns in dynamic network traffic data (such as sudden large-volume access, frequent connection attempts from specific IPs) and abnormal operation sequences in temporal behavior pattern data (such as file access behavior following multiple failed login attempts within a short period). Through simulation verification, verification results are obtained. If malicious attack behavior is confirmed, the corresponding network connections or device operations are blocked in real time based on the results, such as cutting off connections from malicious IPs or preventing devices from performing suspicious operations, thereby effectively protecting the network boundary from security threats.
[0065] Therefore, this invention overcomes the limitations of traditional single-data source detection by collecting and fusing multimodal data such as static features, dynamic network traffic, and temporal behavior patterns. Through collaborative detection from multiple dimensions, including device attributes, traffic characteristics, and behavioral patterns, it can accurately identify complex threats such as malicious attacks disguised as legitimate devices and covert channel communications. It effectively prevents malicious USB drives from forging VID / PIDs to bypass detection, significantly improving the accuracy and comprehensiveness of network security threat detection. In terms of response mechanisms, this invention constructs an automated and intelligent real-time protection system, completely changing the lagging mode of traditional manual log auditing. The entire process, from data collection and risk analysis to blocking and handling, can be completed within seconds, meeting the stringent security requirements of "second-level blocking," achieving proactive defense against network attacks, and significantly reducing the losses caused by security incidents. In terms of functional architecture, this invention innovatively integrates detection, analysis, verification, and blocking functions. Through a preset blocking sandbox mechanism and simulated verification process, it ensures the accuracy of blocking while reducing manual intervention. When a risk warning is triggered, the system automatically isolates suspicious objects in the sandbox environment for verification, avoiding misjudgments and delays in handling caused by manual operation, and significantly improving the reliability and response efficiency of network security management. Furthermore, based on continuous analysis and machine learning of time-series behavioral pattern data, the system can deeply mine historical patterns and potential trends in device behavior, and combine these with comprehensive risk assessment results to achieve risk prediction. For recurring security incidents, such as employees repeatedly accessing unauthorized devices, the system can proactively issue warnings or implement pre-blocking measures, promoting a shift in network security protection from passive response to proactive defense, and effectively reducing the probability of similar security incidents recurring.
[0066] Optionally, the static feature data includes device fingerprint data; the step of performing multimodal fusion analysis on the static feature data, the dynamic network traffic data, and the time-series behavioral pattern data to generate a comprehensive risk result includes: Based on a preset device library, the device fingerprint data is evaluated to obtain first risk data; Based on a preset traffic baseline model, the second risk data is obtained by identifying the dynamic network traffic data. Based on a preset risk prediction model, the probability of future behavioral risks is obtained from the time-series behavioral pattern data. The comprehensive risk result is obtained based on the first risk data, the first risk data, and the probability of future behavior risk.
[0067] Specifically, device fingerprint data in static feature data is a unique identifier generated by collecting hardware information (such as CPU model, memory size, hard drive serial number, etc.), software configuration (such as operating system version, installed applications and their version numbers), and network configuration (such as MAC address, IP address, etc.) of the device.
[0068] Optionally, corresponding device fingerprint data can be generated based on the initialization information of each network boundary device, such as the device's initial configuration and system information during installation. USB devices: Vendor ID (VID), Product ID (PID), Device Descriptor, Driver Signature Hash Value; Network devices: MAC Address, IP Address (if statically assigned), Firmware Version; Other devices: Hardware Serial Number, Digital Certificate (such as TLS Certificate), Hardware Configuration Hash Value.
[0069] The above static feature data is combined and hashed (e.g., SHA-256) to generate a unique device fingerprint for subsequent comparison. For example: Device fingerprint data = SHA256(VID=1234, PID=5678, MAC=00:1A:2B:3C:4D:5E).
[0070] The generated device fingerprint data is compared with a pre-defined device database. This database stores fingerprint data of known devices and their corresponding security risk levels or scores. For example, the database might record certain device models that pose a high security risk due to known vulnerabilities. The pre-defined device database includes a whitelist (which can be manually added): This whitelist contains fingerprints of known secure devices, such as enterprise-authorized USB devices (e.g., encrypted USB drives); MAC addresses of internal servers; and hardware driver signatures that have passed security certification. The database also includes a blacklist (which can be dynamically added based on historical security events, such as devices that repeatedly violate security rules): This blacklist records fingerprints of known malicious or high-risk devices, such as the VID / PID of USB devices previously used in attacks; MAC addresses of historically violating devices; and driver hashes of malware signatures.
[0071] If the device fingerprint data exists in the whitelist, it is marked as an "authorized device" and the risk score is set to 0%; if no match is found, it will be queried in the blacklist. If the device fingerprint exists in the blacklist, it is marked as a "high-risk device" and the risk score is set to 100%; if no match is found, it is marked as an "unauthorized device" and the basic risk score (e.g., +30%) is triggered.
[0072] The scoring logic includes: whitelist matching: risk score = 0% (complete trust); Blacklist matching: Risk score = 100% (direct blocking); Unauthorized devices: Risk score = base score (30%) + weighted score of other static features.
[0073] For example: unsigned driver: +20%; device type is "portable WiFi": +15%; firmware version is too old: +10%. However, the total score limit is usually no more than 70% (to avoid premature blocking, it needs to be combined with subsequent dynamic analysis).
[0074] For subsequent handling, the following actions will be taken for unauthorized devices: trigger real-time behavior monitoring (such as recording file operations and network connections); mark the device as "pending verification" and determine the final action based on the final comprehensive risk score.
[0075] As for handling blacklisted devices: immediately block device connections (e.g., close USB ports, discard network traffic); generate a full-screen alert and notify the administrator; record the event to the security log for subsequent auditing and model training.
[0076] Optionally, the second risk data, obtained by identifying based on the dynamic network traffic data according to the preset traffic baseline model, includes: Feature extraction is performed on the dynamic network traffic data to obtain traffic feature data, and the traffic feature data is divided to obtain time-series traffic data within a preset time window; A multidimensional traffic baseline model is constructed based on historical normal traffic data, and the time-series traffic data within the preset event window is compared with the multidimensional traffic baseline model to obtain multiple corresponding deviation data. The second risk data is determined based on the deviation data described above.
[0077] Optionally, determining the second risk data based on each of the deviation data includes: A multi-dimensional comprehensive score is obtained based on preset weight data and each deviation data; The abnormal traffic type is determined based on the multi-dimensional comprehensive score and the preset threshold, and the second risk data is determined based on the abnormal traffic type.
[0078] Specifically, feature extraction is performed on dynamic network traffic data to extract key traffic characteristics, such as packet size, transmission rate, source / destination IP addresses, port numbers, protocol types, and session duration. For example, the following features can be extracted from network traffic: average and standard deviation of packet size, number of packets transmitted per second, distribution of source and destination IP addresses, protocol types used (such as TCP, UDP, HTTP, etc.), and distribution of session duration.
[0079] The extracted traffic characteristic data is divided according to a preset time window to generate time-series traffic data. The time window can be set according to specific needs, such as every minute, every 5 minutes, or every hour.
[0080] Collect historical normal network traffic data. This data should come from periods when the network is operating normally, without any obvious attacks or abnormal behavior. For example, collect network traffic data from 8:00 to 18:00 every day for the past month, assuming that the network is operating normally during this period.
[0081] A multidimensional traffic baseline model is constructed based on historical normal traffic data. This model describes the distribution and patterns of normal traffic across various feature dimensions.
[0082] For example, statistical methods are used to calculate the mean, standard deviation, quantiles, etc., of each feature, forming a multidimensional model describing normal traffic characteristics. This multidimensional traffic baseline model is based on statistical calculations of data packet characteristics at multiple time points. For each time point, data packets are collected, and their characteristic statistics such as mean, standard deviation, and quantiles are calculated. The final model covers these characteristic statistical values from multiple time points. For example, in the baseline model, the average data packet size at a certain time point is 1000 bytes, and the standard deviation is 200 bytes; the mean number of data packets per second is 100, and the standard deviation is 20, etc. A multidimensional traffic baseline model is constructed in this way to describe normal traffic characteristics.
[0083] The current time-series traffic data is compared with the multidimensional traffic baseline model, and the deviation in each feature dimension is calculated.
[0084] For example, if the average packet size within the current time window is 1200 bytes, the deviation from the baseline model's 1000 bytes is z: .
[0085] Similarly, calculate the deviation of other feature dimensions (such as the number of packets per second, IP address distribution, etc.).
[0086] For each time window's traffic data, multiple deviation data points are generated, each corresponding to a feature dimension. For example, for a single time window, the following deviation data might be obtained: packet size deviation: 1; packet quantity deviation: 0.5; IP address distribution deviation: 0.3. Based on preset weights and each deviation data point, a multi-dimensional comprehensive score is calculated. Weights can be allocated according to the importance of each feature. For example, assuming the weight allocation is: packet size weight: 0.4; packet quantity weight: 0.3; IP address distribution weight: 0.3, the comprehensive score calculation formula is: ; The type of abnormal traffic is determined based on a multi-dimensional comprehensive score and a preset threshold. For example, if the threshold is set to 0.5, traffic is considered abnormal when the comprehensive score exceeds 0.5.
[0087] Based on the characteristics of abnormal traffic, determine the type of abnormal traffic. For example, if the packet size deviates significantly, it may be identified as a "large-scale attack"; if the IP address distribution deviates significantly, it may be identified as a "distributed denial-of-service (DDoS) attack".
[0088] Based on the type of abnormal traffic, determine the second risk data. For example, for a "large-scale attack", the second risk data may be "high risk" or a high risk score (such as 0.8); for a "DDoS attack", the second risk data may be "medium risk" or a medium risk score (such as 0.6).
[0089] By extracting features and serializing dynamic network traffic data, we can more accurately capture dynamic changes in traffic. Furthermore, by employing a multi-dimensional traffic baseline model, we can conduct comparative analysis from multiple feature dimensions (such as packet size, quantity, and IP address distribution) to more comprehensively assess the degree of traffic anomalies. The baseline model is built upon historical normal traffic data, enabling it to dynamically adapt to normal changes in network traffic and reduce false alarms caused by normal traffic fluctuations.
[0090] Furthermore, through multi-dimensional analysis and comparison with dynamic baseline models, it is possible to more accurately determine whether traffic is abnormal, thereby reducing the false alarm rate. At the same time, multi-dimensional comprehensive scoring and preset thresholds can quantify abnormal traffic into specific risk scores and further classify it into different types of abnormal traffic.
[0091] In summary, by performing feature extraction, time-series serialization, multi-dimensional baseline model comparison, and comprehensive scoring on dynamic network traffic data, we can accurately detect traffic anomalies, provide detailed information on abnormal traffic, reduce false alarm rates, and provide clear evidence for security responses, thereby effectively improving the accuracy and reliability of network security detection.
[0092] It should be noted that the multidimensional traffic baseline model supports online learning or sliding window updates. The output also includes: updated baseline parameters such as the new mean and standard deviation; and a baseline version identifier: a timestamp or version number used to track model iteration status. By regularly updating the baseline model, it can adapt to changes in network traffic over time, maintaining the accuracy and effectiveness of detection.
[0093] Optionally, the time-series behavioral pattern data includes operational behavior data, network connection behavior data, time-series feature data, and contextual information; the step of obtaining the future behavioral risk probability based on the time-series behavioral pattern data using a preset risk prediction model includes: A time-series data sample is generated based on the operational behavior data, the network connection behavior data, the temporal feature data, and the context information; The time-series data sample is input into the risk prediction model to obtain the probability of future behavior risk; wherein the risk prediction model is constructed based on a long short-term memory network.
[0094] In some embodiments, file operation behavior (operation behavior data) typically includes the number of file read / write operations, access path (such as system directory), and file type (executable file, document, etc.); network connection behavior (network connection behavior data) typically includes the target IP / domain name, protocol type (HTTP / DNS / ICMP), and connection frequency; operation timing characteristics (timing characteristic data) typically include operation interval time (such as the interval between two writes) and frequency changes (such as burst operations); context information typically includes device type (USB flash drive / portable WiFi), user permissions (ordinary user / administrator), etc.
[0095] Time series data samples are generated by aggregating data within a time window (e.g., every minute).
[0096] Normalize numerical features (such as request frequency) using Min-Max or Z-score; and divide continuous behavior sequences into fixed-length time steps (such as a window of 10 minutes).
[0097] The labeled data includes: positive samples: sequences containing historical high-risk behaviors (such as malicious file writing, covert communication); negative samples: normal operation sequences (such as regular file access, legitimate network connection).
[0098] Risk prediction model (LSTM model) architecture and training process: Input layer: Receives time series data in the shape of (time step, feature dimension), for example: time step = 10 (10-minute window); feature dimension = 8 (8 features such as number of file operations, network request frequency, etc.).
[0099] LSTM layer: number of hidden units = 64, activation function = tanh; stack 2 layers of LSTM to enhance feature extraction capability.
[0100] Fully connected layer: Output dimension = 1 (risk probability), activation function = sigmoid.
[0101] The loss function chosen is binary cross-entropy. Optimizer: Adam, learning rate = 0.001, weight decay = 1e-4 (to prevent overfitting).
[0102] Risk probability prediction and dynamic decision-making: Real-time collection of equipment behavior data, generating time series according to time windows; standardized data is then input into a trained LSTM model. The model output value ∈ [0,1] represents the risk probability in the next time window (e.g., the next 10 minutes). For example, an output probability of 0.85 indicates a risk probability of 85%.
[0103] By comprehensively analyzing various behavioral data and leveraging the powerful predictive capabilities of the LSTM model, it is possible to more accurately determine whether behavior is abnormal, thereby reducing the false alarm rate. In other words, the risk prediction model comprehensively considers operational behavior data, network connection behavior data, temporal feature data, and contextual information, enabling a more comprehensive assessment of behavioral risk. The future behavioral risk probability output by the risk prediction model provides security personnel with risk warning information, facilitating proactive measures to prevent security incidents. Specifically, the LSTM network can effectively capture long-term dependencies in temporal behavioral patterns and identify complex changes in behavioral patterns. By inputting temporal behavioral pattern data into the LSTM model, the risk probability of future behavior can be dynamically predicted, allowing for the early detection of potential security threats. Furthermore, the LSTM model has adaptive learning capabilities, continuously updating and optimizing model parameters based on new temporal behavioral pattern data to adapt to the ever-changing security environment.
[0104] In summary, by utilizing Long Short-Term Memory (LSTM) networks to construct a risk prediction model, and combining it with operational behavior data, network connection behavior data, temporal feature data, and contextual information, long-term dependencies can be effectively captured, the risk probability of future behaviors can be dynamically predicted, multiple behavioral data can be integrated, the false alarm rate can be reduced, and risk warnings can be provided to security personnel, thereby significantly improving the accuracy and foresight of network security detection.
[0105] Optionally, the network security multimodal intelligent detection method further includes: Obtain current traffic pattern data and device behavior sequence; Based on the comprehensive risk results, current traffic pattern data, device behavior sequences, and historical data, an optimized detection strategy is obtained through a preset reinforcement learning model.
[0106] Optionally, the optimized detection strategy obtained based on the comprehensive risk results, current traffic pattern data, device behavior sequences, and historical data through a preset reinforcement learning model includes: Construct the reinforcement learning model and initialize it. The reward value is determined based on the comprehensive risk results, the current traffic pattern data, the device behavior sequence, and the historical data. The policy gradient is determined based on the reward value, and the policy network parameters of the reinforcement learning model are updated according to the policy gradient to maximize the expected cumulative reward. The optimized detection strategy is determined based on the updated strategy network parameters.
[0107] Specifically, state space construction and model initialization: The state space of the reinforcement learning model is defined, including the following elements: a. Real-time comprehensive risk score (comprehensive risk result); b. Current traffic pattern characteristics (current traffic pattern data), including protocol type distribution and Z-score value (deviation degree) of traffic deviation from the baseline; c. Device behavior sequence label, identified by the high-risk operation chain output by the LSTM model; d. Historical data, including the false alarm rate, false negative rate and average response latency of the past N blocking events. Reward Value Calculation: Based on real-time handling results and historical feedback data, the reward value R is calculated using the following formula: ; in, For false alarm rate, The false negative rate, To respond to the delay, , , These are the corresponding weighting coefficients, which can be dynamically adjusted according to the business scenario.
[0108] Policy gradient algorithm update: Using the Proximal Policy Optimization (PPO) algorithm, perform the following operations: Sample batch data from the experience playback buffer, including state. ,action ,award Next state ; Calculate the dominance function A( The policy network parameters are updated to maximize the expected cumulative reward based on the gradient of the target policy; the value function network is updated simultaneously to minimize the mean square error between the predicted and target values. Dynamic deployment of detection strategies: Determining the final optimized detection strategy may include adjusting traffic monitoring thresholds and updating device behavior rules. For example: adjusting the threshold for risk scoring to trigger sandbox verification; updating the firewall blocking rule base, adding or deleting blocking policies for specific IPs / ports; optimizing the sandbox verification process, and increasing monitoring dimensions for new attack behaviors (such as memory malware injection); Closed-loop feedback and continuous optimization: Record the actual effect data after each strategy adjustment and store it in the historical database; periodically retrain the reinforcement learning model to ensure adaptation to changes in the network environment and new attack methods.
[0109] In some specific embodiments, such as detecting a suspected DDoS attack, The real-time handling process includes: automatically blocking the attack source IP in 0.8 seconds (without timeout); and sandbox verification confirming that the attack traffic contains malicious payloads.
[0110] Reward Calculation: Successful blocking: +10; Response delay: 0.8 seconds (<1 second), no penalty; Sandbox verification successful: +15; Total reward value: R=10+15=25.
[0111] In some embodiments, the system is given a negative reward when the false alarm rate is too high: Reward calculation: R = −20 (false alarm penalty weight β is relatively high).
[0112] Strategy Update: The model reduces its reliance on static features (such as device type) and increases the decision weight of dynamic traffic analysis.
[0113] Policy Deployment: The risk scoring threshold was increased from 60% to 70% to reduce false blocking; the default blocking of ordinary USB drives was removed from the firewall rules.
[0114] Results Verification: The false alarm rate decreased by 15% in the next cycle, and the reward value increased to R=+10.
[0115] By constructing a reinforcement learning model and dynamically optimizing the detection strategy using a policy gradient algorithm, intelligent adjustment of network security detection strategies is achieved. Its core advantage lies in the model's ability to dynamically adjust the detection strategy based on the real-time state of the network, such as comprehensive risk outcomes, traffic patterns, and device behavior sequences, thereby improving detection accuracy and adaptability. This not only enables the detection strategy to cope with rapid changes in the network environment but also ensures high efficiency in long-term operation by maximizing expected cumulative rewards. Simultaneously, the model integrates multiple data modalities to comprehensively assess the network state, effectively reducing false positive and false negative rates. Furthermore, its adaptive learning capability allows it to continuously update and optimize strategies to adapt to evolving network attack methods, providing long-term security for the network perimeter.
[0116] like Figure 2 As shown in the figure, an embodiment of the present invention provides a network security multimodal intelligent detection device, applied to a power system. The detection device includes: The acquisition unit is used to acquire static characteristic data, dynamic network traffic data, and time-series behavior pattern data of network boundary devices in the power system. The analysis unit is used to perform multimodal fusion analysis on the static feature data, the dynamic network traffic data, and the time-series behavior pattern data to generate a comprehensive risk result; The processing unit is used to determine whether to trigger the preset blocking sandbox mechanism based on the comprehensive risk result; The processing unit is also used to initiate a preset verification process when the preset blocking sandbox mechanism is triggered, to perform simulation verification based on the comprehensive risk result, the dynamic network traffic data and the time-series behavior pattern data, to obtain the verification result, and to perform real-time blocking operation based on the verification result to ensure network boundary security.
[0117] like Figure 3 As shown in the figure, an embodiment of the present invention provides a network security multimodal intelligent detection device, including a memory and a processor; the memory is used to store a computer program; the processor is used to implement the network security multimodal intelligent detection method as described above when the computer program is executed.
[0118] Alternatively, a network security multimodal intelligent detection device includes a memory and a processor coupled to the memory; the memory is configured to store a computer program; the processor is configured to perform the following operations when the computer program is executed: Collect static characteristic data, dynamic network traffic data, and time-series behavior pattern data of network boundary devices; The static feature data, the dynamic network traffic data, and the time-series behavior pattern data are subjected to multimodal fusion analysis to generate a comprehensive risk result; Based on the comprehensive risk results, determine whether to trigger the preset blocking sandbox mechanism; When the preset blocking sandbox mechanism is triggered, a preset verification process is initiated. Simulation verification is performed based on the comprehensive risk results, the dynamic network traffic data, and the time-series behavior pattern data to obtain verification results. Real-time blocking operations are then performed based on the verification results to ensure network boundary security.
[0119] This invention provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the network security multimodal intelligent detection method described above.
[0120] Alternatively, a non-volatile computer-readable storage medium storing a computer program that, when executed by a processor, causes the processor to perform the following operations: Collect static characteristic data, dynamic network traffic data, and time-series behavior pattern data of network boundary devices; The static feature data, the dynamic network traffic data, and the time-series behavior pattern data are subjected to multimodal fusion analysis to generate a comprehensive risk result; Based on the comprehensive risk results, determine whether to trigger the preset blocking sandbox mechanism; When the preset blocking sandbox mechanism is triggered, a preset verification process is initiated. Simulation verification is performed based on the comprehensive risk results, the dynamic network traffic data, and the time-series behavior pattern data to obtain verification results. Real-time blocking operations are then performed based on the verification results to ensure network boundary security.
[0121] The present invention describes a network security multimodal intelligent detection device that can serve as a server or client of the present invention, which is an example of a hardware device that can be applied to various aspects of the present invention. The network security multimodal intelligent detection device is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The network security multimodal intelligent detection device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0122] The network security multimodal intelligent detection device includes a computing unit, which can perform various appropriate actions and processes based on a computer program stored in read-only memory (ROM) or a computer program loaded from a storage unit into random access memory (RAM). The RAM can also store various programs and data required for device operation. The computing unit, ROM, and RAM are interconnected via a bus. Input / output (I / O) interfaces are also connected to the bus.
[0123] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc. In this application, the units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of the embodiments of the present invention according to actual needs. Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated units can be implemented in hardware or as software functional units.
[0124] While the present invention has been disclosed above, its scope of protection is not limited thereto. Those skilled in the art can make various changes and modifications without departing from the spirit and scope of the present invention, and all such changes and modifications will fall within the scope of protection of the present invention.
Claims
1. A multimodal intelligent detection method for network security, characterized in that, Applied to power systems, the detection method includes: Collect static characteristic data, dynamic network traffic data, and time-series behavior pattern data of network boundary devices in the power system; The static feature data, the dynamic network traffic data, and the time-series behavior pattern data are subjected to multimodal fusion analysis to generate a comprehensive risk result; Based on the comprehensive risk results, determine whether to trigger the preset blocking sandbox mechanism; When the preset blocking sandbox mechanism is triggered, a preset verification process is initiated. Simulation verification is performed based on the comprehensive risk results, the dynamic network traffic data, and the time-series behavior pattern data to obtain the verification results. Real-time blocking operations are then performed based on the verification results to ensure network boundary security.
2. The network security multimodal intelligent detection method according to claim 1, characterized in that, The static feature data includes device fingerprint data; the multimodal fusion analysis of the static feature data, the dynamic network traffic data, and the time-series behavioral pattern data to generate a comprehensive risk result includes: Based on a preset device library, the device fingerprint data is evaluated to obtain first risk data; Based on a preset traffic baseline model, the second risk data is obtained by identifying the dynamic network traffic data. Based on a preset risk prediction model, the probability of future behavioral risks is obtained from the time-series behavioral pattern data. The comprehensive risk result is obtained based on the first risk data, the first risk data, and the probability of future behavior risk.
3. The network security multimodal intelligent detection method according to claim 2, characterized in that, The second risk data, obtained by identifying risks based on the preset traffic baseline model and the dynamic network traffic data, includes: Feature extraction is performed on the dynamic network traffic data to obtain traffic feature data, and the traffic feature data is divided to obtain time-series traffic data within a preset time window; A multidimensional traffic baseline model is constructed based on historical normal traffic data, and the time-series traffic data within the preset event window is compared with the multidimensional traffic baseline model to obtain multiple corresponding deviation data. The second risk data is determined based on the deviation data described above.
4. The network security multimodal intelligent detection method according to claim 3, characterized in that, The determination of the second risk data based on each of the deviation data includes: A multi-dimensional comprehensive score is obtained based on preset weight data and each deviation data; The abnormal traffic type is determined based on the multi-dimensional comprehensive score and the preset threshold, and the second risk data is determined based on the abnormal traffic type.
5. The network security multimodal intelligent detection method according to claim 2, characterized in that, The time-series behavioral pattern data includes operational behavior data, network connection behavior data, time-series feature data, and contextual information; the process of obtaining the future behavioral risk probability based on the time-series behavioral pattern data using a preset risk prediction model includes: A time-series data sample is generated based on the operational behavior data, the network connection behavior data, the temporal feature data, and the context information; The time-series data sample is input into the risk prediction model to obtain the probability of future behavior risk; The risk prediction model is based on a long short-term memory network.
6. The network security multimodal intelligent detection method according to claim 1, characterized in that, The network security multimodal intelligent detection method also includes: Obtain current traffic pattern data and device behavior sequence; Based on the comprehensive risk results, current traffic pattern data, device behavior sequences, and historical data, an optimized detection strategy is obtained through a preset reinforcement learning model.
7. The network security multimodal intelligent detection method according to claim 6, characterized in that, The optimized detection strategy, based on the comprehensive risk results, current traffic pattern data, device behavior sequences, and historical data, is obtained through a preset reinforcement learning model, including: Construct the reinforcement learning model and initialize it. The reward value is determined based on the comprehensive risk results, the current traffic pattern data, the device behavior sequence, and the historical data. The policy gradient is determined based on the reward value, and the policy network parameters of the reinforcement learning model are updated according to the policy gradient to maximize the expected cumulative reward. The optimized detection strategy is determined based on the updated strategy network parameters.
8. A network security multimodal intelligent detection device, characterized in that, The detection device, applied to power systems, includes: The acquisition unit is used to acquire static characteristic data, dynamic network traffic data, and time-series behavior pattern data of network boundary devices in the power system. The analysis unit is used to perform multimodal fusion analysis on the static feature data, the dynamic network traffic data, and the time-series behavior pattern data to generate a comprehensive risk result; The processing unit is used to determine whether to trigger the preset blocking sandbox mechanism based on the comprehensive risk result; The processing unit is also used to initiate a preset verification process when the preset blocking sandbox mechanism is triggered, to perform simulation verification based on the comprehensive risk result, the dynamic network traffic data and the time-series behavior pattern data, to obtain the verification result, and to perform real-time blocking operation based on the verification result to ensure network boundary security.
9. A network security multimodal intelligent detection device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the network security multimodal intelligent detection method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, which, when executed by a processor, implements the network security multimodal intelligent detection method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Network security protection method and system
CN117879970A
Edge side terminal security threat analysis and evaluation method
CN119089449A
Autonomous security risk sensing system and method based on digital twin industrial control network
CN120281563A
Financial digital intelligent management system
CN120492020A
Network security multi-mode intelligent detection system and method
CN120498904A
Cited By
Network security protection method, system, device, medium and product
CN121418201A
Self-adaptive risk defense method and device, equipment and medium
CN121418207A