Highway toll threat event prediction and traceability system based on deep learning

By constructing a deep learning-based system for predicting and tracing threat events in highway toll collection, the system addresses the efficiency and security issues of management workflows in highway network toll collection systems. It enables real-time monitoring and rapid response, ensures data security and credibility, accurately traces the root cause of events, and dynamically adjusts resource allocation.

CN121125180APending Publication Date: 2025-12-12JIANGXI PROVINCIAL TRAFFIC MONITORING & COMMAND CENT +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511165188.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-20
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

The highway network toll collection system suffers from several problems, including insufficient efficiency in standardized task assignment and dynamic scheduling of management workflows, uncontrollable network security operations and maintenance, risk of data tampering, and lagging threat perception with difficulty in tracing the source of attacks.

Method used

Construct a highway toll threat event prediction and tracing system based on deep learning, including a network security work management platform, an operation and maintenance service risk management system, and an abnormal event analysis system. Employ boundary protection, threat perception and response technologies, IoT security hardening, disaster recovery and continuous operation and maintenance technologies, combined with intelligent task orchestration, dynamic policy base and knowledge graph, and blockchain evidence storage and tracing to achieve real-time monitoring and rapid response.

Benefits of technology

It enables efficient and visualized network security management, ensuring the security of operation and maintenance services and data flow. It can monitor network security status in real time, respond quickly to emergencies, accurately trace the root cause of incidents, predict high-risk scenarios, and automatically adjust resource configuration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125180A_ABST
    Figure CN121125180A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network security, and particularly relates to a highway toll threat event prediction and traceability system based on deep learning, which comprises a highway networked toll system. The network safety work management platform is used for forming a planned management strategy by combing the existing safety management work flow of the highway networked toll collection system; the network security operation and maintenance service risk management system is used for constructing an expressway network toll collection system operation and maintenance service security risk management system; and the abnormal event analysis system is used for constructing a visual safe brain for abnormal event analysis and prediction and has an event tracing function. According to the invention, an efficient and visual management platform is created to deal with emergency situations and task changes, construct a security risk management system, ensure data security and integrity and construct a security brain for anomaly analysis, so that a manager can monitor the network security state in real time and make a response quickly.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of network security, and particularly relates to a highway toll threat event prediction and tracing system based on deep learning. BACKGROUND

[0002] The highway network toll collection system refers to integrating the toll management of multiple highways in a region into a centralized operation system through unified technical standards and network architecture, realizing unified calculation, splitting and settlement of vehicle tolls; the essence is to reconstruct the traditional toll collection mode through network, intelligence and standardization, realize "one pass, one payment, automatic account allocation", and maximize the network coordination efficiency and economic benefits.

[0003] Problems of the prior art: The existing management workflow of the highway network toll collection system has a serious problem of insufficient task standardization assignment and dynamic scheduling efficiency, and the traditional manual assignment is prone to cause response delay and cannot adapt to emergency situations and task changes; the network security operation has the problems of uncontrollable operation and data tampering risk; in addition, for network threats, threat perception lags behind and attack tracing is difficult. SUMMARY

[0004] The purpose of the present application is to provide a highway toll threat event prediction and tracing system based on deep learning, which can cope with emergency situations and task changes, ensure data security and integrity, and enable management personnel to monitor the network security state in real time and respond quickly.

[0005] The technical solutions adopted by the present application are as follows: The highway toll threat event prediction and tracing system based on deep learning comprises a highway network toll collection system: A network security work management platform forms a planned management strategy by analyzing the existing security management workflow of the highway network toll collection system; A network security operation service risk management system is used to build a highway network toll collection system operation service security risk management system, to ensure the security and credibility of operation service and data flow, and to establish a quantifiable network security risk assessment mechanism by analyzing daily network security operation work; An abnormal event analysis system is used to build a visual security brain for abnormal event analysis and prediction, with event tracing function, so that management personnel can monitor the network security state in real time and respond quickly; The network security work management platform serves as a decision center, receives threat intelligence from the abnormal event analysis system, and generates standardized operation and maintenance tasks and distributes them to the road section sub-centers; the network security operation and maintenance service risk management system serves as an execution and risk control center, dynamically adjusts the priority of operation and maintenance tasks according to the strategy issued by the network security work management platform, and feeds back operation and maintenance operation data to the abnormal event analysis system for behavior baseline modeling; the abnormal event analysis system serves as a perception and tracing center, outputs a visual threat map to the network security work management platform, triggers emergency response tasks, and provides real-time risk indicators for the network security operation and maintenance service risk management system to drive dynamic allocation of operation and maintenance resources.

[0006] The direction of building the network security work management platform includes a network security work management system and a task standardization distribution system and a dynamic adjustment mechanism for establishing network security work management.

[0007] The core technologies for building the network security work management system include boundary protection and access control technology, terminal and data security protection technology, threat perception and response technology, Internet of Things security reinforcement technology, and disaster recovery and continuous operation technology. The boundary protection and access control technology consists of next-generation firewalls and gateways and network access control, wherein the next-generation firewalls and gateways only allow one-way transmission of encrypted data to the internal network, eliminating the risk of two-way access, and the network access control is used for identity authentication and security state checking of terminal devices. The terminal and data security protection technology consists of terminal detection and response and database audit and encryption, wherein terminal detection and response is used to monitor the behavior of toll lane industrial control computers and server terminals, and database audit and encryption is used to prevent tampering and leakage of toll data. The threat perception and response technology consists of a situational awareness platform and vulnerability scanning and penetration testing, wherein the situational awareness platform is used to integrate network security data, realize threat visualization and collaborative disposal, and vulnerability scanning and penetration testing is used to discover system vulnerabilities. The Internet of Things security reinforcement technology consists of terminal security reinforcement and video monitoring data encryption, wherein terminal security reinforcement is used to protect ETC gantry and license plate recognition device Internet of Things terminals, and video monitoring data encryption is used to prevent over-the-air pictures and video streams from being stolen. The disaster recovery and continuous operation technology consists of a remote disaster recovery center and an automated operation platform, wherein the remote disaster recovery center is used to ensure business continuity in the event of extreme failure, and the automated operation platform is used to reduce human operation risks.

[0008] The core technologies for establishing the task standardization distribution system and the dynamic adjustment mechanism for network security work management include intelligent task scheduling and dispatching technology, dynamic strategy library and knowledge graph technology, and elastic evaluation and feedback loop technology. The intelligent task arrangement and scheduling technology is composed of a SOAR platform and a resource portrait and load balancing engine, wherein the SOAR platform is used for event response automation dispatching and execution tracking, and the resource portrait and load balancing engine optimizes task allocation by monitoring the resource states of nodes at all levels in real time; The dynamic policy library and knowledge graph technology is composed of a dynamic policy generation engine and a knowledge graph assisted decision making, wherein the dynamic policy generation engine is used for optimizing the security policy library in combination with threat intelligence and operation and maintenance data, and the knowledge graph assisted decision making is used for correlating historical task data, predicting task execution risks and recommending adjustment schemes; The elastic evaluation and feedback closed loop technology is composed of an elastic evaluation model and a blockchain storage and audit, wherein the elastic evaluation model is used for quantifying task execution effects to support a dynamic adjustment mechanism, and the blockchain storage and audit is used for ensuring that the task execution process is traceable and tamper-proof.

[0009] The directions for establishing the network security operation and maintenance service risk management system include building a multi-role manager classification and hierarchical management method, an operation and maintenance service security risk management system, and a daily network security operation and maintenance quantitative scoring system.

[0010] The core technology for building the multi-role manager classification and hierarchical management method is a unified identity governance platform, a continuous trust evaluation system, a micro-isolation protection system, and a blockchain audit and traceability system; The core technology for establishing the daily network security operation and maintenance quantitative scoring system is an asset exposure management system, a vulnerability full life cycle tracking system, a data security situation awareness system, a terminal security baseline evaluation system, a blockchain audit and traceability system, and a dynamic scoring and closed loop management.

[0011] The core technology for building the operation and maintenance service security risk management system is a blockchain data storage and traceability system, an intelligent contract driven automated response system, a blockchain enabled dynamic risk assessment system, and a modular and scalable architecture design; The blockchain data storage and traceability system is composed of a device operation and maintenance storage chain and a transaction risk traceability platform, wherein the device operation and maintenance storage chain is used for realizing full life cycle traceability of operation and maintenance operations, and the transaction risk traceability platform is used for cross-regional data correlation analysis on toll fee abnormal transactions; The intelligent contract driven automated response system is composed of an elastic risk disposal engine and a dynamic insurance compensation contract, wherein the elastic risk disposal engine is used for automatically executing risk disposal actions according to preset rules, and the dynamic insurance compensation contract is used for realizing automated claims settlement for ETC transaction disputes; and The blockchain-enabled dynamic risk assessment system is composed of a multi-dimensional risk portrait model and an elastic strategy generation engine, wherein the multi-dimensional risk portrait model generates a dynamic risk score by integrating device status, network attacks, and human operation data, and the elastic strategy generation engine dynamically adjusts security strategies based on the risk score. The modular and scalable architecture design is composed of a layered blockchain architecture and a cross-chain collaboration mechanism.

[0012] The directions for establishing the abnormal event analysis system include building a visual security brain and security event traceability function, and establishing a network security threat event prediction model and practical response mechanism.

[0013] The core technology for building the visual security brain and security event traceability function is a global data acquisition layer, an intelligent analysis engine layer, a visualization and traceability layer, and a response and disposal layer. The global data acquisition layer is composed of a distributed probe system and an Internet of Things terminal monitoring gateway, wherein the distributed probe system is used to collect network traffic, terminal logs, and device status data in real time, and the Internet of Things terminal monitoring gateway is used to perform firmware signature verification and port monitoring on ETC gantry and license plate recognition camera devices. The intelligent analysis engine layer is composed of an AI threat detection cluster and an attack chain correlation engine, wherein the AI threat detection cluster analyzes global network data through machine learning to identify advanced persistent threats and unknown attacks, and the attack chain correlation engine is used to correlate discrete events into complete attack paths. The visualization and traceability layer is composed of a three-dimensional situational awareness large screen and a blockchain traceability system, wherein the three-dimensional situational awareness large screen is used to dynamically display the security status of the entire network, and supports drill-down analysis, and the blockchain traceability system stores operation logs based on Hyperledger Fabric, enabling tamper-proof traceability. The response and disposal layer is composed of an automated response work order system and a cross-province collaborative traceability mechanism, wherein the automated response work order system is used to execute blocking strategies for firewalls and EDR devices, and the cross-province collaborative traceability mechanism is used to respond to cross-province attack chains and implement departmental and provincial collaborative traceability.

[0014] The core technology for establishing the network security threat event prediction model and practical response mechanism is a multi-source threat perception system, an intelligent prediction and decision system, a practical response and closed-loop system, and a dynamic optimization and verification system. The multi-source threat perception system is composed of a global data acquisition layer and a threat intelligence federated learning platform, wherein the global data acquisition layer is used to integrate data sources and build a data foundation for the prediction model, and the threat intelligence federated learning platform is used to share desensitized threat features across provinces. The intelligent prediction and decision system is composed of a dynamic risk scoring model and a knowledge graph assisted decision engine, wherein the dynamic risk scoring model predicts threat events according to historical information, and the knowledge graph assisted decision engine is used for associating a historical event library and automatically generating a disposal plan. The actual combat response and closed loop system is composed of an automated combat sand table and a cross-domain collaborative response mechanism, wherein the automated combat sand table is used to automatically simulate an attack chain after receiving a predicted alarm, and the cross-domain collaborative response mechanism is used to collaboratively execute response instructions. The dynamic optimization and verification system is composed of a red-blue confrontation exercise platform and an elastic strategy library, wherein the red-blue confrontation exercise platform is used to generate an attack script to simulate confrontation exercises, and the elastic strategy library triggers strategy reconstruction for new parameters.

[0015] The technical effects achieved by the present application are: An efficient and visual network security work management platform is created, the existing network security management process of the highway networked toll collection system is combed, a classification, grading and time-sharing method is adopted, the daily work process is simplified and visualized, and a standardized management strategy is formed.

[0016] Based on the zero trust mechanism and the blockchain technology, a highway networked toll collection system operation service security risk management system is constructed to ensure the security and credibility of the operation service and data flow; the daily network security operation and maintenance work of the highway networked toll collection system is combed, and a quantifiable network security risk assessment mechanism is established.

[0017] A visual security brain for abnormal event analysis and prediction is constructed, so that the management personnel can monitor the network security state in real time and respond quickly, has a global threat perspective ability, constructs a three-dimensional attack path atlas through distributed probe collection, directly displays the ransomware propagation link or data stealing path, combines the blockchain evidence and micro-isolation strategy, accurately traces the event source, and the threat prediction model can predict high-risk scenes, can combine the simulated attack chain to output a weak point repair priority list, and automatically migrate tasks when predicting resource bottlenecks. BRIEF DESCRIPTION OF DRAWINGS

[0018] Figure 1 It is a system diagram of the highway networked toll collection system provided by the embodiment of the present application. DETAILED DESCRIPTION

[0019] In order to make the purpose and advantages of the present application more clear and understandable, the present application is specifically described below in conjunction with embodiments. It should be understood that the following text is merely used to describe one or several specific embodiments of the present application, and does not strictly limit the specific protection scope requested by the present application.

[0020] The expressway toll threat event prediction and tracing system based on deep learning includes an expressway network toll system, which is internally provided with a network security work management platform, a network security operation service risk management system and an abnormal event analysis system.

[0021] A high-efficiency and visual network security work management platform is constructed, and the research contents include constructing a network security work management system of the expressway network toll system, and the core technologies thereof are as follows: I. Border protection and access control technology 1. Next-generation firewall (NGFW) and gateway Technical function: deploy NGFW at the network exit to realize traffic filtering and intrusion prevention; isolate the toll system from the external network through the gateway to block illegal penetration.

[0022] Operation process: the firewall analyzes the traffic in real time, automatically intercepts SQL injection, DDoS attacks and other threats; the gateway adopts a "ferry mechanism" to allow one-way transmission of encrypted data to the internal network, and eliminates the risk of two-way access.

[0023] 2. Network access control (NAC) Technical function: identity authentication and security state check of terminal equipment to ensure that compliant terminals are accessed.

[0024] Operation process: automatically detect the patch and antivirus software state before terminal access, and isolate and repair non-compliant devices; combine with the 802.1x protocol to realize dynamic permission allocation based on VLAN.

[0025] II. Terminal and data security protection technology 1. Terminal detection and response (EDR) Technical function: monitor the behavior of terminal equipment such as toll lane industrial control computers and servers, and block malicious operations in real time.

[0026] Operation process: deploy a lightweight agent on the lane industrial control computer to collect process and registry behavior and upload to the analysis platform; automatically isolate the terminal and alarm for abnormal operations (such as unauthorized data export).

[0027] 2. Database audit and encryption Technical function: prevent toll data tampering and leakage.

[0028] Operation process: The audit system records all database operations (such as SQL statement execution) and marks high-risk behaviors (such as batch querying user information); SM4 national encryption algorithm is used to encrypt sensitive fields (such as license plates and transaction amounts), and the key is managed uniformly by the provincial center.

[0029] Three, threat perception and response technology 1, situation awareness platform Technical effect: Integrate network security data to realize threat visualization and collaborative disposal.

[0030] Operation process: Collect firewall logs, terminal alarms, and traffic probe data, and generate threat maps through AI algorithms; automatically link the firewall to block attack source IPs and push work orders to road operation personnel for disposal.

[0031] 2, vulnerability scanning and penetration testing Technical effect: Actively discover system vulnerabilities.

[0032] Operation process: Automatically scan fee servers and network devices every month, generate vulnerability reports and repair them in stages (such as high-risk vulnerabilities repaired within 24 hours); hire third parties for penetration testing every quarter to simulate hacker attacks and verify the effectiveness of protection.

[0033] Four, Internet of Things security reinforcement technology 1, terminal security reinforcement Technical effect: Protect ETC gantries, license plate recognition devices, and other Internet of Things terminals.

[0034] Operation process: Add digital signatures to device firmware and refuse unauthorized firmware upgrades; close idle ports (such as Telnet) and only keep necessary communication ports for business.

[0035] 2, video monitoring data encryption Technical effect: Prevent overpass pictures and video streams from being stolen.

[0036] Operation process: Use the national SM9 encryption algorithm to encrypt video streams, and the key is distributed by the provincial center; deploy decryption modules on the edge computing nodes of the toll station, and business systems directly access desensitized data.

[0037] Five, disaster recovery and continuous operation technology 1, off-site disaster recovery center Technical effect: Ensure business continuity in extreme failure.

[0038] Operation process: Incrementally backup transaction data to the local center every day and fully backup to the off-site disaster recovery center every week; in the event of a failure, the disaster recovery system will take over the business within 30 minutes.

[0039] 2, automated operation platform Technical effect: Reduce human operation risk.

[0040] Operation process: Execute scripts to update patches in batches through the bastion host, and audit the whole operation process; use Ansible to automatically inspect the device status and trigger alarms when there is an exception.

[0041] Build an efficient and visual network security work management platform. The research content includes the establishment of a task standardization allocation system and its dynamic adjustment mechanism for network security work management. The core technologies are as follows: I. Intelligent task orchestration and scheduling technology 1. SOAR (Security Orchestration, Automation and Response) platform Technical effect: Standardize security policies and task processes, and realize automatic dispatch and execution tracking of event response.

[0042] Operation process: Task standardization allocation: After the provincial situational awareness platform detects threats (such as abnormal traffic of gantry equipment), SOAR automatically generates a work order and allocates it to the section center or toll station according to the preset rules; Dynamic adjustment: When the same road segment triggers the same type of alarm for 3 times within 24 hours, the task priority is automatically upgraded and the provincial experts are notified to intervene.

[0043] 2. Resource profiling and load balancing engine Technical effect: Real-time monitoring of resource status of nodes at all levels (such as EDR cluster performance, vulnerability scanning progress), and optimization of task allocation.

[0044] Operation process: Through the automatic operation and maintenance platform, the CPU / memory utilization of each toll station server is collected, and the vulnerability scanning task is dynamically allocated to the idle node; During peak period (such as holidays), automatically reduce the resource occupancy ratio of non-critical tasks (such as log auditing) to prioritize the security of transaction systems.

[0045] II. Dynamic policy library and knowledge graph technology 1. Strategy dynamic generation engine Technical effect: Combine threat intelligence and operation data to optimize the security policy library in real time.

[0046] Operation process: Automatically generate reinforcement strategies (such as closing high-risk ports) for new vulnerabilities found in ETC gantry penetration testing and push them to the provincial gantry operation task list; Integrate vulnerability scanning and attack event data every month to update the terminal detection standards of network access control policies.

[0047] 2. Knowledge graph assisted decision-making Technical effect: Correlate historical task data, predict task execution risks and recommend adjustment schemes.

[0048] Operation process: Analyze past disaster switching records, mark sites with success rates below 90%, and automatically allocate additional practice resources; when a new ransomware outbreak occurs, quickly match similar cases, and generate standardized isolation and data recovery processes.

[0049] III. Elasticity evaluation and feedback loop technology 1. Elasticity evaluation model Technical role: Quantify task execution effectiveness to support dynamic adjustment mechanisms.

[0050] Operation process: Define KPIs (such as vulnerability repair timeliness and event response duration), and have the provincial center evaluate each section's score monthly. If the score falls below the threshold, automatically trigger specialized training tasks. After disaster switching drills, dynamically adjust backup frequency based on RTO (Recovery Time Objective) achievement rates.

[0051] 2. Blockchain storage and audit Technical role: Ensure that task execution processes are traceable and tamper-proof.

[0052] Operation process: All security operations (such as policy changes and key updates) are recorded on the blockchain for post-audit purposes. If policy execution deviations are found, automatically freeze accounts and notify superiors for review.

[0053] Based on the above, create an efficient and visual network security work management platform. By analyzing the existing network security management processes of the highway networked toll collection system, using classification, grading, and time-sharing methods, simplify and visualize daily work processes, and form standardized management strategies. At the same time, develop a mechanism to evaluate the capabilities and loads of staff, and build a standardized task allocation system and dynamic adjustment mechanism to respond to emergency situations and task changes.

[0054] Establish and improve the network security operation and maintenance service risk management strategy for the highway networked toll collection system. The research content includes the classification and grading management method of multi-role management personnel under the zero-trust mechanism, and the core technology is as follows: I. Unified identity governance platform (IGA) Operation process Dynamic role mapping: Divide management personnel into four levels: provincial decision-making layer (policy formulation, key management); road operation and maintenance layer (vulnerability repair, event response); toll station operation layer (device inspection, log reporting); outsourced audit layer (penetration testing supervision); Attribute-based (position + business scenario) dynamic generation of minimal permission sets, such as toll station operators only having access to local device management interfaces.

[0055] Multi-factor authentication (MFA) enhancement: When operating critical systems (such as clearing and settlement), iris + dynamic token authentication is required, and the session is re-verified every 15 minutes.

[0056] II. Continuous trust assessment system Operation process Behavior baseline modeling: Through AI analysis of historical operation logs, establish role behavior baseline (e.g. provincial administrator daily strategy modification frequency ≤ 3 times).

[0057] Real-time risk linkage: When the road section operator frequently accesses non-jurisdictional area gantry equipment, the following actions are automatically triggered: downgraded to read-only permission; simultaneously record operation video and push to audit chain.

[0058] III. Micro-isolation protection system Operation process Business domain fine division: Core clearing zone includes settlement database, key management system, limited to above provincial decision layer access; equipment monitoring zone includes gantry control terminal, EDR management terminal, limited to road section operation layer access; log audit zone includes database audit platform, limited to outsourcing audit layer access.

[0059] Dynamic strategy execution: Toll collector operation ETC gantry needs to apply for temporary token first, strategy engine real-time verification, verification content includes device geographic location (GPS positioning), operation time (only limited to white shift period) and associated terminal security state (EDR no alarm).

[0060] IV. Blockchain audit traceability system Operation process Operation evidence: All sensitive operations (such as rate adjustment, key update) are recorded to Hyperledger Fabric chain, including operator digital signature, terminal device fingerprint and network environment hash value.

[0061] Cross-role traceability: If there is a toll data tampering, through blockchain positioning, the traced information includes original operator (road section operator A), permission grantor (provincial administrator B) and operation verification log (outsourcing auditor C).

[0062] Establish and improve the risk management strategy of highway networked toll collection system network security operation and maintenance service, the research content includes building a flexible and expandable operation and maintenance service security risk management system under the blockchain technology, the core technology is as follows: I. Blockchain data evidence and traceability system 1. Device operation evidence chain System function: chain the operation of Internet of Things devices such as ETC gantry and RSU antenna (such as firmware upgrade, maintenance record), realize full life cycle traceability.

[0063] Operation process: After the maintenance personnel pass digital identity authentication, the operation log (including operation time, device fingerprint, GPS positioning) is written into the Hyperledger Fabric consortium chain in real time; the blockchain node synchronously verifies the data hash value, and abnormal operation (such as modifying parameters during unauthorized period) triggers the smart contract alarm.

[0064] 2. Transaction risk traceability platform System function: Cross-regional data correlation analysis on abnormal toll transactions (such as repeated toll deduction, toll evasion behavior).

[0065] Operation process: The toll data of each province is interconnected through cross-chain protocol (such as Cosmos SDK), and the transaction hash value is stored in the main chain; when an anomaly is found, it is traced back to the specific gantry, lane, and operator through timestamp + device ID.

[0066] II. Smart contract-driven automated response system 1. Elastic risk disposal engine System function: Automatically execute risk disposal actions according to preset rules to reduce manual intervention delay.

[0067] Operation process: When the Internet of Things device state monitoring system detects that the RSU antenna failure rate exceeds the threshold (such as 3 communication failures within 10 minutes), the smart contract is automatically triggered, which includes freezing the transaction rights of the device, assigning standby devices to take over the business, and pushing maintenance work orders to the nearest operation and maintenance team.

[0068] 2. Dynamic insurance claim contract System function: Realize automatic claim settlement for ETC transaction disputes.

[0069] Operation process: Compare user complaint data with on-chain transaction records, and after a successful match, call the insurance company API to generate a claim settlement work order, then complete the claim transfer through the on-chain payment channel, and all process data is encrypted and stored in IPFS distributed storage.

[0070] III. Blockchain-enabled dynamic risk assessment system 1. Multi-dimensional risk profiling model System function: Integrate device status, network attacks, human operations, etc. to generate dynamic risk scores.

[0071] Operation process: Collect blockchain evidence data (such as vulnerability repair records, penetration test results) and real-time monitoring data (such as DDoS attack frequency); use federated learning model to train risk assessment algorithm, output 0-100 risk value and graded warning.

[0072] 2. Elastic strategy generation engine System function: Dynamically adjust security policies based on risk scores.

[0073] Operation process: During high-risk periods (such as holiday traffic peaks), automatically increase the EDR detection frequency to 5 times per second, and simultaneously limit the non-critical system bandwidth occupancy rate to ≤20%; during low-risk periods, enable energy-saving mode and close redundant protection nodes.

[0074] Four, modular scalable architecture design 1. Layered blockchain architecture The data layer is used for operation and maintenance logs, transaction record evidence, and supports PBFT / Raft consensus algorithm dynamic switching; the contract layer is used for risk assessment and automatic response to smart contracts, and has a modular contract library, supporting hot plug deployment; the service layer is used for cross-chain gateway, API interface, compatible with Hyperledger / Ant Chain and other mainstream frameworks.

[0075] 2. Cross-chain collaboration mechanism Through the relay chain, data interconnection with provincial clearing systems and third-party payment platforms is realized to ensure that risk disposal strategies are synchronized across the network.

[0076] Establish and improve the risk management strategy for the network security operation and maintenance service of the highway networked toll collection system. The research content includes establishing a safety risk assessment mechanism to quantitatively score the daily network security operation of the system. The core technology is as follows: One, asset exposure management system Operation process Global asset mapping: Through Agent / Sensor, automatically identify the types of devices in the toll network (such as ETC gantry, RSU antenna, lane industrial computer), generate a dynamic asset list, and achieve a coverage rate of over 98%; based on GPS positioning, establish an asset geographic distribution heat map, and mark devices exposed to the public network (such as gantry controllers with Telnet ports not closed).

[0077] Risk quantification scoring: formula: exposure value = (number of high-risk ports x 0.3) + (number of unpatched vulnerabilities x 0.5) + (number of times of illegal external connections x 0.2), scores over 5 automatically trigger rectification work orders.

[0078] Two, vulnerability lifecycle tracking system Operation process Intelligent scanning and priority determination: automatically scan toll servers and network devices every month, and use AI models to determine vulnerability levels (such as Apache vulnerabilities in ETC gantry systems classified as "urgent"); score based on repair time: 10 points for urgent vulnerabilities repaired within 24 hours, minus 1 point per hour for overtime; high-risk vulnerabilities repaired within 72 hours.

[0079] Penetration test verification: If a repaired vulnerability is found to be exploited again in quarterly penetration testing, the vulnerability item score is zero and the responsible person is traced back.

[0080] Three, data security situation awareness system Operation process Sensitive data flow monitoring: Deploy probes in clearing and settlement systems to monitor toll data flow in real time, and mark abnormal operations (such as exporting more than 10,000 license plate information in a day). Scoring rules: encrypted transmission ratio ≥95% gets 10 points, and each 5% reduction deducts 2 points; data leakage events directly deduct 20 points.

[0081] SM algorithm compliance detection: Automatically check whether the province-station communication link uses SM4 / SM9 encryption. If the link does not meet the standard, it is marked as a "major risk" in the scoring.

[0082] Four, terminal security baseline evaluation system Operation process Protection coverage detection: Scan lane industrial computers daily, and count EDR installation rate and virus library update delay time (more than 24 hours is considered invalid). Scoring formula: terminal security score = (number of online protection terminals / total number) x 10, less than 60% triggers network-wide notification.

[0083] Process whitelist control: Establish a process hash library for Linux hosts. Unauthorized processes are started immediately and deduct 5 points, and the terminal is isolated.

[0084] Five, blockchain audit traceability system Operation process Operation behavior evidence: All operation (such as firmware upgrade, policy change) records are recorded in the Fabric consortium chain, including operator digital signature and device fingerprint.

[0085] Responsibility tracing score: When a security incident occurs, locate the specific operation link according to the blockchain log, and associate the history operation deduction record of the responsible person (such as 3 times of un-repaired vulnerabilities deduct 15 points).

[0086] Six, dynamic scoring and closed-loop management Core mechanism Model dynamic iteration: Update scoring weights every quarter according to attack samples (such as ransomware attack frequently, terminal protection weight increases by 30%); Cross-system linkage: When the situation awareness platform detects DDoS attacks, automatically suspend the vulnerability repair score of affected devices.

[0087] Operation process example: Data collection, weight dynamic adjustment by risk assessment model and generation of quantitative score, early warning according to score classification, warning level is divided into high risk (provincial intervention rectification), medium risk (road section sub-center limited repair), low risk (charging station self-treatment), after repair verification, re-input data collection work.

[0088] According to the above content, based on the zero trust mechanism and the block chain technology, the expressway networking charging system operation and maintenance service security risk management system is constructed, and the safety and credibility of operation and maintenance service and data flow are ensured; The daily network security operation and maintenance of the expressway networking charging system is combed, and a set of quantifiable network security risk assessment mechanism is established.

[0089] A visual brain of abnormal event analysis of expressway networking charging system is constructed, and the research contents include construction of visual security brain of abnormal event analysis and security event traceability function, and the core technologies are as follows: I. Global data acquisition layer 1. Distributed probe system Technical effect: Deploy lightweight probes at toll stations, ETC gantries, provincial centers and other nodes to collect network traffic, terminal logs, device status and other data in real time.

[0090] Operation process: gantry layer: probe captures RSU device communication traffic (such as OBU transaction data), identifies abnormal communication mode (such as high-frequency unauthorized access); Toll station layer: collect lane industrial computer process behavior, database operation log, and transmit to provincial center through SM4 encryption; Provincial center: gather all network security data, single-day processing capacity exceeds 10TB.

[0091] 2. Internet of Things terminal monitoring gateway Technical effect: Firmware signature verification and port monitoring for ETC gantries, license plate recognition cameras and other devices.

[0092] Operation process: Real-time verification of device firmware hash value, intercept unsigned upgrade request; Close non-business ports (such as Telnet), only keep necessary communication ports (such as ETC dedicated port 8088).

[0093] II. Intelligent analysis engine layer 1. AI threat detection cluster Technical effect: Analyze all network data through machine learning to identify advanced persistent threats (APT) and unknown attacks.

[0094] Operation process: Build normal behavior baseline (such as ETC gantry daily communication frequency ≤2000 times), deviation more than 30% automatically alarm; Detect ransomware features: encrypted file behavior + abnormal external IP, accuracy ≥95%.

[0095] 2. Attack chain association engine Technical effect: Associate discrete events (such as port scanning, abnormal login) into a complete attack path.

[0096] Operation process: Example attack chain: First, the gantry port scans, exploits industrial computer vulnerabilities, steals database credentials, and then tampers with toll data; automatically generate attack graph, mark key attack nodes (such as C2 server IP) Three, visualization and traceability layer 1. Three-dimensional situational awareness large screen Technical effect: Dynamically display the security status of the entire road network, support drill-down analysis.

[0097] Operation process: Spatial dimension: superimpose the gantry attack heat map on the geographic map, and mark the high-risk sections in red; Time dimension: scroll the timeline to display the attack peak period (such as the DDoS outbreak period during holidays); Asset dimension: click the toll station icon to view vulnerability distribution (such as red for unpatched vulnerabilities > 20%).

[0098] 2. Blockchain traceability system Technical effect: Based on Hyperledger Fabric, record operation logs to achieve tamper-proof traceability.

[0099] Operation process: Record the five elements of key operations: [operator ID] + [device fingerprint] + [GPS coordinates] + [operation content] + [timestamp]; Data tampering event traceability: locate the original operator (A toll station Zhang San), verify the terminal security state (EDR has no alarm) at the time of operation, and backtrack the data flow path (gantry → sub-center → provincial center).

[0100] Four, response and disposal layer 1. Automated response ticket system Technical effect: Link up firewalls, EDRs, and other devices to execute blocking strategies.

[0101] Operation process: When a ransomware outbreak occurs: automatically isolate infected terminals (disconnect within 10 seconds); freeze associated accounts (such as database permissions for operator B); distribute virus-specific tools to terminals on the same section.

[0102] 2. Cross-province collaborative traceability mechanism Technical effect: Respond to cross-province attack chains and achieve department-province joint traceability.

[0103] Operation process: When the attack source IP comes from a neighboring province: automatically generate a joint investigation ticket, synchronize attack fingerprints (such as malware MD5) to the neighboring province's situational platform, and cross-province data comparison confirms the attack path.

[0104] Key scenario operation example: The visualization brain of the abnormal event analysis of the expressway networking toll collection system is constructed, and the research content includes the establishment of a network security threat event prediction model and a practical response mechanism, and the core technology is as follows: I. Multi-source threat perception system 1. Global data acquisition layer System function: Integrate 11 types of data sources such as ETC gantry, toll lane, provincial cloud control platform, etc. to build the data basis of the prediction model.

[0105] Operation process: Real-time collection of device logs (such as gantry vibration sensors), network traffic (firewall DPI deep analysis), user behavior (toll collector operation sequence) and other data, preprocessed by edge computing nodes and uploaded to the provincial center; Use blockchain storage technology to ensure data integrity and tamper resistance, and real-time chain key fields (such as abnormal traffic characteristics).

[0106] 2. Threat intelligence federated learning platform Operation process: Cross-provincial sharing of desensitized threat features (such as new ransomware attack patterns), provincial centers train local models, and only upload model parameters to the central platform for aggregation and optimization to avoid original data leakage.

[0107] II. Intelligent prediction and decision system 1. Dynamic risk scoring model Operation process: Short-term prediction: Based on LSTM algorithm to analyze device failure rate, attack frequency and other indicators within 72 hours, output toll station level risk heat map (such as predicting DDoS attack probability > 85% in the next 2 hours); Long-term prediction: combined with meteorological, holiday traffic data, predict seasonal threats (such as gantry power failure risk in flood season), trigger reinforcement tasks.

[0108] 2. Knowledge graph assisted decision engine Operation process: Correlate historical event library (such as ETC fraud event in a certain province in 2024), automatically generate disposal plan, operation example as follows: When gantry data anomaly is detected, perform historical event library knowledge graph matching, determine 90% similarity with a certain historical event, start anti-fee evasion audit model, and at the same time define as a new threat, and immediately issue a sand table exercise task; Optimize the disposal process dynamically to reduce the false positive rate that requires manual review.

[0109] III. Practical response and closed-loop system 1. Automated combat sand table Operation process: After receiving the prediction alarm, automatically simulate the attack chain (such as ransomware penetration path), and verify the effectiveness of the protection strategy in the virtual environment; Output reinforcement instructions to physical devices: such as predicting the risk of optical cable interruption, switch to 5G backup link in advance.

[0110] 2. Cross-domain collaborative response mechanism Operation process: Vertical coordination: provincial centers issue blocking instructions (such as isolating infected gantries) to section centers, and the status is returned to the blockchain in real time; horizontal coordination: linkage with traffic police and cloud service providers for synchronous disposal (such as attacking IP network ban), response time < 3 minutes.

[0111] Four, dynamic optimization and verification system 1. Red-blue confrontation exercise platform Operation process: automatically generate attack scripts (such as fake OBU signals to deceive) every month, blue team real combat to verify the accuracy of the prediction model, and the results are fed back to the training set iteration; key indicators (such as vulnerability repair time) are included in KPI evaluation, and unqualified sections are automatically allocated for reinforcement.

[0112] 2. Elastic strategy library Operation process: when the prediction false positive rate > 15% or the delay of new threat identification > 1 hour, trigger strategy reconstruction, such as adding ETC transaction fraud detection dimensions and adjusting AI model weight parameters.

[0113] Key scenario operation example According to the above content, a visual security brain for abnormal event analysis and prediction is constructed, which enables management personnel to monitor the network security state in real time and respond quickly, has global threat perspective ability, constructs a three-dimensional attack path map through distributed probe collection, intuitively displays the ransomware propagation link or data theft path, and combines blockchain evidence and micro-isolation strategy to accurately trace the event source; the threat prediction model can predict high-risk scenarios, can output a weak point repair priority list in combination with a simulated attack chain, and automatically migrate tasks when predicting resource bottlenecks.

[0114] The above is only the preferred embodiment of the present application, it should be pointed out that for ordinary skilled in the art, without departing from the principles of the present application, can make a number of improvements and refinements, these improvements and refinements should be considered as the protection scope of the present application. The structures, devices and operation methods not specifically described and explained in the present application, such as no special description and limitation, are implemented according to the conventional means in the art.

Claims

1. A deep learning-based system for predicting and tracing threat events related to highway toll collection, including a highway network toll collection system, characterized in that: The network security management platform develops a planned management strategy by streamlining the existing security management workflows of the highway network toll collection system. The network security operation and maintenance service risk management system is used to build a security risk management system for the operation and maintenance services of the highway network toll collection system, to ensure the security and reliability of operation and maintenance services and data flow, and to establish a set of quantifiable and scoreable network security risk assessment mechanisms by sorting out daily network security operation and maintenance work. An anomaly analysis system is used to build a visual security brain for anomaly analysis and prediction, and also has event tracing functions, enabling managers to monitor network security status in real time and respond quickly. The network security work management platform serves as the decision-making center, receiving threat intelligence from the abnormal event analysis system, generating standardized operation and maintenance tasks, and allocating them to the road segment sub-centers. As the execution and risk control center, the network security operation and maintenance service risk management system relies on the policies issued by the network security work management platform to dynamically adjust the priority of operation and maintenance tasks, and feeds back operation and maintenance data to the abnormal event analysis system for behavioral baseline modeling. As the perception and tracing center, the abnormal event analysis system outputs a visualized threat map to the network security work management platform, triggers emergency response tasks, and provides real-time risk indicators to the network security operation and maintenance service risk management system, driving the dynamic allocation of operation and maintenance resources.

2. The deep learning-based highway toll threat event prediction and tracing system according to claim 1, characterized in that: The direction for building a cybersecurity work management platform includes a cybersecurity work management system and the establishment of a standardized task allocation system and dynamic adjustment mechanism for cybersecurity work management.

3. The deep learning-based highway toll threat event prediction and tracing system according to claim 2, characterized in that: The core technologies for building the network security work management system include boundary protection and access control technology, terminal and data security protection technology, threat perception and response technology, Internet of Things security hardening technology, and disaster recovery and continuous operation and maintenance technology. Boundary protection and access control technology consists of next-generation firewalls and gateways, as well as network access control. The next-generation firewalls and gateways only allow encrypted data to be transmitted unidirectionally to the internal network, eliminating the risk of bidirectional access. Network access control is used to authenticate the identity and check the security status of terminal devices. Terminal and data security protection technology consists of terminal detection and response, as well as database auditing and encryption. Terminal detection and response is used to monitor the behavior of industrial control computers and server terminals in toll lanes, while database auditing and encryption are used to prevent toll data from being tampered with or leaked. Threat perception and response technology consists of a situational awareness platform and vulnerability scanning and penetration testing. The situational awareness platform is used to integrate network-wide security data to achieve threat visualization and collaborative handling, while vulnerability scanning and penetration testing are used to discover system vulnerabilities. The IoT security hardening technology consists of terminal security hardening and video surveillance data encryption. Terminal security hardening is used to protect IoT terminals such as ETC gantries and license plate recognition devices, while video surveillance data encryption is used to prevent the theft of vehicle images and video streams. Disaster recovery and continuous operation and maintenance technology consists of an off-site disaster recovery center and an automated operation and maintenance platform. The off-site disaster recovery center is used to ensure business continuity under extreme failures, while the automated operation and maintenance platform is used to reduce the risks of human operation.

4. The deep learning-based highway toll threat event prediction and tracing system according to claim 1, characterized in that: The core technologies for establishing the standardized task allocation system and dynamic adjustment mechanism for network security work management include intelligent task orchestration and scheduling technology, dynamic policy base and knowledge graph technology, and flexible evaluation and feedback closed-loop technology. The intelligent task orchestration and scheduling technology consists of the SOAR platform and the resource profiling and load balancing engine. The SOAR platform is used for automated event response dispatch and execution tracking, while the resource profiling and load balancing engine optimizes task allocation by monitoring the resource status of nodes at all levels in real time. The dynamic policy library and knowledge graph technology consists of a dynamic policy generation engine and a knowledge graph-assisted decision-making system. The dynamic policy generation engine is used to combine threat intelligence and operational data to optimize the security policy library, while the knowledge graph-assisted decision-making system is used to associate historical task data, predict task execution risks, and recommend adjustment solutions. The flexible assessment and feedback closed-loop technology consists of a flexible assessment model and blockchain evidence storage and auditing. The flexible assessment model is used to quantify the performance of tasks and support the dynamic adjustment mechanism, while blockchain evidence storage and auditing is used to ensure that the task execution process is traceable and tamper-proof.

5. The deep learning-based highway toll threat event prediction and tracing system according to claim 1, characterized in that: The direction for establishing a network security operation and maintenance service risk management system includes building a classification and hierarchical management method for multi-role managers, an operation and maintenance service security risk management system, and establishing a quantitative scoring system for daily network security operation and maintenance.

6. The deep learning-based highway toll threat event prediction and tracing system according to claim 5, characterized in that: The core technologies for constructing the multi-role manager classification and hierarchical management method are a unified identity governance platform, a continuous trust assessment system, a micro-segmentation protection system, and a blockchain audit and traceability system. The core technologies for establishing quantitative scoring of daily network security operations and maintenance include an asset exposure surface management system, a vulnerability lifecycle tracking system, a data security situation awareness system, an endpoint security baseline assessment system, a blockchain audit and tracing system, and dynamic scoring and closed-loop management.

7. The deep learning-based highway toll threat event prediction and tracing system according to claim 5, characterized in that: The core technologies for building the security risk management system for the operation and maintenance service are a blockchain data storage and traceability system, a smart contract-driven automated response system, a blockchain-enabled dynamic risk assessment system, and a modular and scalable architecture design. The blockchain data storage and traceability system consists of an equipment operation and maintenance storage chain and a transaction risk traceability platform. The equipment operation and maintenance storage chain is used to make the operation and maintenance operations traceable throughout their entire lifecycle, while the transaction risk traceability platform is used to conduct cross-regional data correlation analysis on abnormal toll transactions. The smart contract-driven automated response system consists of a resilient risk management engine and a dynamic insurance claims contract. The resilient risk management engine automatically executes risk management actions according to preset rules, while the dynamic insurance claims contract automates claims processing for ETC transaction disputes. The blockchain-enabled dynamic risk assessment system consists of a multi-dimensional risk profile model and an elastic policy generation engine. The multi-dimensional risk profile model generates a dynamic risk score by integrating data on device status, network attacks, and human operations. The elastic policy generation engine dynamically adjusts security policies based on the risk score. The modular and scalable architecture design consists of a layered blockchain architecture and a cross-chain collaboration mechanism.

8. The deep learning-based highway toll threat event prediction and tracing system according to claim 1, characterized in that: The direction for establishing an anomaly analysis system includes building a visual security brain and security incident tracing functions, as well as establishing a network security threat incident prediction model and practical response mechanism.

9. The deep learning-based highway toll threat event prediction and tracing system according to claim 8, characterized in that: The core technologies for building the visualized security brain and security incident tracing function are the full-domain data acquisition layer, the intelligent analysis engine layer, the visualization and tracing layer, and the response and handling layer. The full-domain data acquisition layer consists of a distributed probe system and an IoT terminal monitoring gateway. The distributed probe system is used to collect network traffic, terminal logs, and device status data in real time, while the IoT terminal monitoring gateway is used to perform firmware signature verification and port monitoring on ETC gantry and license plate recognition camera devices. The intelligent analysis engine layer consists of an AI threat detection cluster and an attack chain association engine. The AI ​​threat detection cluster analyzes the entire network data through machine learning to identify advanced persistent threats and unknown attacks, while the attack chain association engine is used to associate discrete events into complete attack paths. The visualization and traceability layer consists of a 3D situational awareness screen and a blockchain traceability system. The 3D situational awareness screen is used to dynamically display the security status of the entire road network and supports drill-down analysis. The blockchain traceability system is based on Hyperledger Fabric's evidence storage operation logs to achieve tamper-proof traceability. The response and handling layer consists of an automated response work order system and a cross-provincial collaborative tracing mechanism. The automated response work order system is used to coordinate with firewalls and EDR devices to execute blocking policies, while the cross-provincial collaborative tracing mechanism is used to deal with cross-provincial attack chains and achieve joint tracing between the Ministry and provinces.

10. The deep learning-based highway toll threat event prediction and tracing system according to claim 8, characterized in that: The core technologies for establishing the network security threat event prediction model and practical response mechanism are a multi-source threat perception system, an intelligent prediction and decision-making system, a practical response and closed-loop system, and a dynamic optimization and verification system. The multi-source threat perception system consists of a global data acquisition layer and a threat intelligence federated learning platform. The global data acquisition layer is used to integrate data sources and build the data foundation for predictive models, while the threat intelligence federated learning platform is used to share de-identified threat features across provinces. The intelligent prediction and decision-making system consists of a dynamic risk scoring model and a knowledge graph-assisted decision-making engine. The dynamic risk scoring model predicts threat events based on historical information, while the knowledge graph-assisted decision-making engine is used to associate with the historical event database and automatically generate contingency plans. The combat response and closed-loop system consists of an automated combat sandbox and a cross-domain collaborative response mechanism. The automated combat sandbox is used to automatically simulate the attack chain after receiving a predictive alarm, and the cross-domain collaborative response mechanism is used to collaboratively execute response commands. The dynamic optimization and verification system consists of a red-blue team exercise platform and an elastic strategy library. The red-blue team exercise platform is used to generate attack scenarios to simulate combat exercises, and the elastic strategy library triggers strategy reconstruction for new parameters.

Citation Information

Cited By

  • Network security operation method based on security policy

    CN121585475A