Smart city redundancy security defense system

By combining real-time data collection and dynamic risk assessment with automated switching control, the problems of assessment lag and blind switching in smart city systems have been solved, achieving seamless switching and high-reliability business continuity, and improving the security and availability of the system.

CN121125226APending Publication Date: 2025-12-12XINJIANG YUNENG HIGH-TECH INFORMATION CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511290338.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-10
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

Smart city core business systems face problems such as delayed assessment, blind switching, and lack of a unified view. Traditional security defense and disaster recovery backup solutions cannot effectively cope with complex network attacks and hardware failures, resulting in delayed risk assessment, high error switching rate, and scattered information that makes decision-making difficult.

Method used

The system employs a data acquisition module to collect security situation awareness and business impact parameters in real time, a risk assessment and analysis module to evaluate risk levels based on dynamic calculation formulas, and a security switchover control module to automatically trigger seamless switchover to the redundant backup system. The system also provides visualization and alerts through the monitoring center.

Benefits of technology

It enables real-time, accurate quantitative assessment of the security risks and availability of the main system, automated switching decisions, ensures seamless business flow switching, reduces the risk of service interruption and data loss, and improves the system's high reliability and business continuity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125226A_ABST
    Figure CN121125226A_ABST
Patent Text Reader

Abstract

The invention discloses a smart city redundancy security defense system and method. The system comprises a data acquisition module, a redundant backup system, a risk assessment analysis module, a safety switching control module, a data storage module and a supervision center. The data acquisition module acquires security situation awareness parameters and service influence parameters of the main system in real time; the risk assessment analysis module assesses the security risk level and the availability state of the main system in real time by using a calculation formula and combining with a weight adaptive adjustment mechanism; the safety switching control module automatically triggers switching when a preset switching condition is met; the data storage module records whole-process data, and the supervision center provides risk thermodynamic diagrams, backup states and hierarchical alarm visualization; according to the invention, the dynamic quantitative evaluation of the security risk of the core business system of the smart city and the high-reliability automatic fault switching and recovery are realized, and the overall toughness and business continuity of the system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of system vulnerability detection and protection, and specifically discloses a redundant security defense system for a smart city. BACKGROUND

[0002] With the in-depth development of smart city construction, its core business system carries a large amount of key data and important services, and puts forward unprecedentedly high requirements for the security, availability and continuity of the system. These systems are facing increasingly complex and frequent network attacks, hardware and software failures, human operation errors and other threats. Once service interruption or data leakage occurs, it will cause great social influence and economic loss; the traditional security defense and disaster recovery backup scheme has the following technical defects:

[0003] 1. Evaluation lag: traditional monitoring only collects basic performance indicators such as CPU and bandwidth, lacks correlation and quantification of security threats and business impact, and leads to a 3-5 hour lag in risk assessment compared to actual threats;

[0004] 2. Switching blindness: master-slave switching relies on manual experience or fixed thresholds, such as CPU occupancy greater than 90%, and in complex attack scenarios, the misconnection rate is as high as 42%;

[0005] 3. Lack of unified view and decision support: information such as security posture, system performance, backup status is scattered, lacks integrated analysis and visual display, and is not conducive to managers to fully understand the system state and make optimal decisions.

[0006] Although the prior art introduces a redundancy mechanism, it does not solve the core problems of dynamic risk quantification and adaptive switching decision.

[0007] Therefore, it is necessary to invent a redundant security defense system for a smart city to solve the above problems. SUMMARY

[0008] To overcome the aforementioned shortcomings of existing technologies, this invention provides a smart city redundant security defense system. The data acquisition module collects security situation awareness parameters and business impact parameters of the main system in real time using lightweight probes and network sensors. The risk assessment and analysis module, based on a preset security threat model and performance thresholds, utilizes a unique dynamic calculation formula combined with a weighted adaptive adjustment mechanism to assess the main system's security risk level and availability status in real time. When preset switching conditions are met, the security switching control module automatically triggers a seamless switching process including transaction freezing, two-phase commit consistency verification, data synchronization, traffic switching, and basic service verification testing. This securely and reliably switches the business flow to a functionally equivalent, data-synchronized redundant backup system. The system also supports health checks, gray-scale rollback, and parallel operation verification processes after the main system is repaired. The data storage module records all process data, and the monitoring center provides risk heatmaps, backup status, and hierarchical alarm visualization, effectively solving the problems mentioned in the background technology.

[0009] To achieve the above objectives, the present invention provides the following technical solution: a smart city redundant security defense system, specifically comprising:

[0010] Data acquisition module: Real-time acquisition of security situation awareness parameters and business impact parameters of core smart city business systems;

[0011] Redundant backup system: includes at least one backup subsystem that is functionally equivalent to and synchronized with the main system;

[0012] Risk assessment and analysis module: Receives data from the data acquisition module and dynamically assesses the security risk level and availability status of the main system based on preset security threat models and performance thresholds;

[0013] Security handover control module: When the security risk level or availability status index of the main system assessed by the risk assessment and analysis module meets the handover conditions, the security handover protocol is automatically triggered to seamlessly switch business traffic and control.

[0014] Data storage module: records monitoring data from the data acquisition module, assessment results from the risk assessment and analysis module, switching operations from the security switching control module, and the operating status of the redundant backup system after switching.

[0015] Supervision Center: Visualizes the main system risk heat map, backup system readiness status, and switchover event alarms.

[0016] Based on the above embodiments, the security situation awareness parameters include the main system's vulnerability CVSS score, current attack frequency, data sensitivity coefficient, and defense blocking rate;

[0017] The business impact parameters include redundancy coverage, fault recovery time, primary and backup data difference, total duration of unplanned faults, number of degraded services, total number of critical services, and total runtime.

[0018] Based on the above embodiments, the risk assessment and analysis module performs the following specific analysis process:

[0019] The system receives security situation awareness parameters and business impact parameters from the data acquisition module in real time.

[0020] The main system's security risk value is dynamically calculated based on the security risk level calculation formula.

[0021] The availability status value of the main system is dynamically calculated based on the availability status index calculation formula.

[0022] Assess risk levels and system availability based on security risk values ​​and availability status values;

[0023] A risk assessment report is generated by combining the preset risk level and availability status.

[0024] Based on the above embodiments, the formula for calculating the security risk value is as follows: In the formula, R represents the system security risk value, and V... max The highest vulnerability CVSS score, A f A represents the actual attack frequency. max D represents the highest attack frequency in history. s R is the data sensitivity coefficient. b To defend against blocking rate, W v W a W d and W r These are the weighting coefficients.

[0025] Based on the above embodiments, the specific method for assessing risk level and system availability is as follows:

[0026] Risk level assessment:

[0027] When the safety risk value R∈[0, 0.3), it is considered no risk; when the safety risk value R∈[0.3, 0.6), it is considered low risk; when the safety risk value R∈[0.6, 0.8), it is considered medium risk; and when the safety risk value R∈[0.8, 1), it is considered high risk.

[0028] System availability assessment:

[0029] Availability is considered excellent when the availability status index A ∈ (0.9, 1], good when the availability status index A ∈ (0.7, 0.9], acceptable when the availability status index A ∈ (0.6, 0.7], and vulnerable when the availability status index A ∈ [0, 0.6].

[0030] Based on the above embodiments, the formula for calculating the availability status index is: A = α·A c +β·R e +γ·D h -δ·S p In the formula, α, β, γ, and δ are weighting coefficients, A c R represents the percentage of non-failure time. e D is the redundancy efficiency coefficient. h For the data health index, S p The penalty coefficient for service degradation.

[0031] Based on the above embodiments, the specific switching process of the safety switching control module is as follows:

[0032] Real-time acquisition of security risk levels and availability status assessed by the risk assessment and analysis module;

[0033] When the switching conditions are met, freeze the main system's business flows and start transaction consistency verification;

[0034] Synchronize unfinished transactions to the redundant backup system;

[0035] Switch DNS resolution and load balancing to the redundant backup system;

[0036] Perform basic service verification tests to verify service integrity;

[0037] Release business flows to the redundant backup system and record the switchover timestamp.

[0038] Based on the above embodiments, the switching process of the security switching control module also includes switching back the redundant backup system to the main system, and the specific switching process is as follows:

[0039] Perform a health check after the main system is repaired;

[0040] Incremental synchronous redundancy system runtime data;

[0041] A canary phase switch will be implemented, transferring 10% of the business traffic to the main system.

[0042] After a full switch, both systems will run in parallel.

[0043] After verifying that the main system's SLA compliance rate meets the standard, shut down the business flow of the redundant system.

[0044] Based on the above embodiments, the switching condition is to satisfy any of the following conditions:

[0045] Safety risk level ≥ Medium risk lasting 5 minutes;

[0046] Availability status index ≤ qualified level for 10 minutes;

[0047] Critical service degradation rate ≥ 40%;

[0048] The difference between the primary and backup data exceeds the threshold and cannot be repaired within 30 seconds.

[0049] The technical effects and advantages of this invention are as follows:

[0050] 1. Dynamic Risk Assessment System: By integrating multi-dimensional security posture parameters and business impact parameters, the system uses calculation formulas to achieve real-time and accurate quantitative assessment of the main system's security risks and availability status. This avoids the limitations of traditional qualitative or simple threshold judgments and provides a scientific and objective basis for switching decisions.

[0051] 2. Intelligent and automated switching decision-making and execution: Based on accurate risk level and availability status assessment results, the system automatically triggers preset switching conditions without manual intervention, significantly improving decision response speed; Seamless switching process: Through steps such as transaction freezing, two-phase commit + MVCC snapshot to ensure strong consistency, incremental synchronization, DNS / load balancing switching, and basic service verification testing, the system achieves a smooth, lossless, and reliable switching of business flows from the primary system to the backup system, minimizing or even eliminating service interruption time and data loss risks;

[0052] 3. High reliability and business continuity assurance: The built-in transaction consistency verification mechanism and basic service verification testing greatly reduce the risk of failures introduced during the switching process itself. After the main system is repaired, it must go through multiple steps such as strict health checks, incremental synchronization, gray-scale switching, parallel operation, and SLA compliance verification to finally complete the switchback, ensuring that the main system is fully restored to stability before carrying all business and preventing secondary failures. Attached Figure Description

[0053] The present invention will be further described with reference to the accompanying drawings, but the embodiments in the drawings do not constitute any limitation on the present invention. For those skilled in the art, other drawings can be obtained based on the following drawings without creative effort.

[0054] Figure 1 This is a schematic diagram of the overall structure of the present invention.

[0055] Figure 2 This is a schematic diagram of the overall process of the present invention. Detailed Implementation

[0056] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0057] This invention provides a smart city redundant security defense system, comprising the following modules: a data acquisition module, a redundant backup system, a risk assessment and analysis module, a security switching control module, a data storage module, and a monitoring center;

[0058] like Figure 1 As shown, the data storage module is connected to the data acquisition module, the risk assessment and analysis module, and the security switching control module, respectively. The monitoring center is connected to the data acquisition module and the redundant backup system, respectively. The data acquisition module and the risk assessment and analysis module are connected, the risk assessment module is connected to the security switching control module, and the security switching control module is connected to the redundant backup system.

[0059] Please see Figure 2 As shown, the overall workflow of this invention is as follows:

[0060] The data acquisition module collects security situation awareness parameters and business impact parameters of the core business systems of the smart city in real time.

[0061] In the preferred technical solution of this application, the security situation awareness parameters include the vulnerability CVSS score of the main system, the current attack frequency, the data sensitivity coefficient, and the defense blocking rate; the business impact parameters include redundancy coverage, fault recovery time, main and backup data difference, total duration of unplanned faults, number of degraded services, total number of critical services, and total runtime.

[0062] It should be further explained that the data acquisition module collects security parameters in real time through lightweight probes and network traffic sensors deployed in the core business system, such as Fluentd log collector and SuricataIDS; security situation awareness parameters are synchronized to the central server every 2 seconds via the Syslog protocol; and business impact parameters are pulled from the service governance platform, such as Nacos, at a frequency of 1Hz via a RESTful API.

[0063] The risk assessment and analysis module receives data from the data acquisition module and dynamically assesses the security risk level and availability of the main system based on a preset security threat model and performance threshold.

[0064] In the preferred embodiment of this application, the risk assessment and analysis module performs the following specific analysis process:

[0065] The system receives security situation awareness parameters and business impact parameters from the data acquisition module in real time.

[0066] The main system's security risk value is dynamically calculated based on the security risk level calculation formula.

[0067] The availability status value of the main system is dynamically calculated based on the availability status index calculation formula.

[0068] Assess risk levels and system availability based on security risk values ​​and availability status values;

[0069] A risk assessment report is generated by combining the preset risk level and availability status.

[0070] In a preferred embodiment of this application, the formula for calculating the security risk value is as follows: In the formula, R represents the system security risk value, and V... max The highest vulnerability CVSS score, A f A represents the actual attack frequency. max D represents the highest attack frequency in history. s R is the data sensitivity coefficient. b To defend against blocking rate, W v W a W d and W r These are the weighting coefficients.

[0071] It should be further noted that the vulnerability exposure coefficient E i Data sensitivity coefficient D s Defense Interception Rate R b The value range is [0,1], and the larger the value, the greater the degree of exposure, sensitivity, and defense blocking capability.

[0072] Furthermore, the weighting coefficient W v W a W d and W r Based on a combination of historical data fitting and expert experience calibration, in the preferred technical solution of this application, the weighting coefficient W... v =0.4, weighting coefficient W a =0.3, weighting coefficient W d =0.2 and weighting coefficient W r =0.1; Data sensitivity coefficient D s The data is dynamically assigned values ​​according to the data classification strategy, with a range of [0,1]. The higher the confidentiality, the larger the value. The specific value is determined according to the data classification strategy: Public data = 0.2, Internal data = 0.5, Confidential data = 0.8, Top secret data = 1.0.

[0073] In a preferred embodiment of this application, the formula for calculating the availability status index is: A = α·A c +β·R e +γ·D h -δ·S p In the formula, A represents the system availability state value, and α, β, γ, and δ are weighting coefficients. c R represents the percentage of non-failure time. e D is the redundancy efficiency coefficient. h For the data health index, S p The penalty coefficient for service degradation.

[0074] Furthermore, the proportion of non-failure time A c The calculation formula is: In the formula, T u T represents the total duration of unplanned failures. t Total runtime; Redundancy efficiency coefficient R e The calculation formula is: In the formula, C r For redundant coverage, T r For fault recovery time, η is the weighting coefficient, and k is the response time sensitivity coefficient; Data Health Index D h The calculation formula is: In the formula, ΔD is the difference between the primary and backup data, and D is the difference between the primary and backup data. t The tolerance threshold for differences; the service degradation penalty coefficient S. p The calculation formula is: N in the formula d The number of critical services to be degraded is defined as follows: when the response latency is greater than 2 seconds or the error rate is greater than 5%, it is considered a service degradation. N c This represents the total number of critical services.

[0075] Furthermore, the weighting coefficients α, β, γ, and δ are adaptively adjusted according to the actual scenario: during major events, α = 0.6, β = 0.25, γ = 0.1, and δ = 0.05; during normal operation, α = 0.5, β = 0.3, γ = 0.15, and δ = 0.05; and during post-disaster reconstruction, α = 0.4, β = 0.35, γ = 0.2, and δ = 0.05.

[0076] Furthermore, the value of the recovery time sensitivity coefficient k follows the rule of k = 0.3 × (1 - C r Tolerance threshold for difference D t = 0.1% × total database capacity.

[0077] In the preferred embodiment of this application, the specific method for assessing the risk level and system availability is as follows:

[0078] Risk level assessment:

[0079] When the safety risk value R∈[0, 0.3), it is considered no risk; when the safety risk value R∈[0.3, 0.6), it is considered low risk; when the safety risk value R∈[0.6, 0.8), it is considered medium risk; and when the safety risk value R∈[0.8, 1), it is considered high risk.

[0080] System availability assessment:

[0081] Availability is considered excellent when the availability status index A ∈ (0.9, 1], good when the availability status index A ∈ (0.7, 0.9], acceptable when the availability status index A ∈ (0.6, 0.7], and vulnerable when the availability status index A ∈ [0, 0.6].

[0082] The security switching control module automatically triggers the security switching protocol based on the main system security risk level or availability status assessed by the risk assessment and analysis module, seamlessly switching service traffic and control.

[0083] Calculation example:

[0084] Example of safety risk value calculation:

[0085] Scene setting:

[0086] Vulnerability data:

[0087] Vulnerability 1: V1 = 8; Vulnerability 2: V2 = 6;

[0088] Business data: D s =0.7, R b =0.6;

[0089] Attack data: A f =50, A max =100;

[0090] W v =0.4, W a =0.3, W d =0.2, W r =0.1;

[0091] Calculation process:

[0092] R=(8 / 10×0.4)+(50 / 100×0.3)+0.7×0.2-0.6×0.1=0.55;

[0093] Conclusion: The current safety risk value is 0.55, indicating a low risk, but stronger supervision is needed.

[0094] Example of Availability Status Index Calculation:

[0095] Parameter settings:

[0096] α=0.5, β=0.3, γ=0.15, δ=0.05, k=0.3; T u =120 minutes, T t = 1440 minutes, C r =0.6, η=0.6, T r = 5 seconds, ΔD = 0.5GB, D t =1GB, N d =2, N c =10;

[0097] Calculation process:

[0098] A c =1-(120 / 1440)≈0.92;

[0099] R e = 0.6 × 0.6 + (1 - 0.4) × e -0.3×5 ≈0.493;

[0100] D h =1 - (0.5 / 1) = 0.5;

[0101] Sp = 2 / 10 = 0.2;

[0102] A=0.5×0.92+0.3×0.493+0.15×0.5-0.05×0.2≈0.67;

[0103] Conclusion: The current availability value is 0.67, indicating that a switchover can be initiated, but the switchover process needs to be more closely monitored.

[0104] In the preferred embodiment of this application, the specific switching process of the safety switching control module is as follows:

[0105] Real-time acquisition of security risk levels and availability status assessed by the risk assessment and analysis module;

[0106] When the switching conditions are met, freeze the main system's business flows and start transaction consistency verification;

[0107] Synchronize unfinished transactions to the redundant backup system;

[0108] Switch DNS resolution and load balancing to the redundant backup system;

[0109] Perform basic service verification tests to verify service integrity;

[0110] Release business flows to the redundant backup system and record the switchover timestamp.

[0111] Furthermore, the transaction consistency verification adopts a two-phase commit protocol, and the verification implementation steps are as follows:

[0112] Extract the complete operation sequence of incomplete transactions from the database transaction log;

[0113] Create an MVCC snapshot at the transaction isolation level to record the system state at the start of the transaction;

[0114] Synchronize transaction logs and checkpoint information to the backup system via atomic broadcast;

[0115] The ACID properties of the primary and backup systems are compared. If they match, the verification passes and the process continues. If they do not match, an alarm is issued immediately, the details of the inconsistency are recorded, the switchover process is paused, and the operations and maintenance personnel assess the risks based on the inconsistencies to determine whether to roll back to the primary system or force a switchover.

[0116] In a preferred embodiment of this application, the switching process of the security switching control module further includes switching back the redundant backup system to the main system, and the specific switching process is as follows:

[0117] Perform a health check after the main system is repaired;

[0118] Incremental synchronous redundancy system runtime data;

[0119] A canary phase switch will be implemented, transferring 10% of the business traffic to the main system.

[0120] After a full switch, both systems will run in parallel.

[0121] After verifying that the main system's SLA compliance rate meets the standard, shut down the business flow of the redundant system.

[0122] It should be further explained that subsequent data synchronization and rollback operations will only be carried out after the health check is passed. After the 10% business flow is switched to the main system in a gray-scale manner, it will be continuously observed for at least 15 minutes. If there are no abnormalities, such as CPU load rate, memory usage rate or network throughput exceeding the threshold, a full switch will be carried out. Otherwise, the switch will be stopped and rolled back to the redundant backup system. After the full switch, the SLA compliance rate of the main system will be verified. When the compliance rate is ≥99.99%, the business flow of the redundant system will be shut down.

[0123] Furthermore, the health check items include CPU utilization, memory leak rate, and availability status. A health check is considered passed when CPU utilization is <80%, memory leak rate is <1MB / s, and system availability status is above "good". The 10% service flow canary switching is implemented through service mesh traffic coloring: in Istio's VirtualService, weight:10% is configured to point to the main system. The criteria for judging abnormal phenomena are: if the error rate after switching is >5% or the P99 latency is >2s.

[0124] In a preferred embodiment of this application, the switching condition is any one of the following conditions:

[0125] Safety risk level ≥ medium risk lasting 5 minutes, i.e. R ≥ 6;

[0126] Availability status index ≤ qualified level for 10 minutes, i.e. A < 0.6;

[0127] Critical service degradation rate ≥ 40%, i.e., N d / N c ≥0.4;

[0128] The difference between primary and backup data exceeds the threshold, i.e., ΔD ≥ D. t And it cannot be fixed within 30 seconds.

[0129] Data storage module: records monitoring data from the data acquisition module, assessment results from the risk assessment and analysis module, switching operations from the security switching control module, and the operating status of the redundant backup system after switching.

[0130] Supervision Center: Visualizes the main system's risk heatmap, backup system readiness status, and switchover event alarms;

[0131] It should be further clarified that the switching time alarm is a tiered alarm. A Level 1 alarm occurs when R ≥ 8 or A ≤ 0.95, triggering an SMS + audible / visual alert. A Level 2 alarm occurs when R ≥ 6 for 5 consecutive minutes, triggering an email alert. When ΔD / D... t A threshold of >50% triggers a Level 3 alarm, which is indicated by a system pop-up window.

[0132] The redundant backup system includes at least one backup subsystem that is functionally equivalent to and data-synchronized with the main system.

[0133] It should be further noted that the redundant backup system uses Redo Log-based change data capture technology to achieve primary and backup data synchronization:

[0134] The Debezium engine is used to parse the MySQL binlog in real time, ensuring that the difference between the primary and backup data ΔD is less than 10ms.

[0135] Functional equivalence verification is performed through an automated testing framework, such as JUnit + Spring Test, covering 98% of the core interfaces. A response time deviation of ≤5% is considered equivalent.

[0136] Finally, it should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A smart city redundant security defense system, characterized in that, include: Data acquisition module: Real-time acquisition of security situation awareness parameters and business impact parameters of core smart city business systems; Redundant backup system: includes at least one backup subsystem that is functionally equivalent to and synchronized with the main system; Risk assessment and analysis module: Receives data from the data acquisition module and dynamically assesses the security risk level and availability status of the main system based on preset security threat models and performance thresholds; Security handover control module: When the security risk level or availability status of the main system assessed by the risk assessment and analysis module meets the handover conditions, the security handover protocol is automatically triggered to seamlessly switch business traffic and control. Data storage module: records monitoring data from the data acquisition module, assessment results from the risk assessment and analysis module, switching operations from the security switching control module, and the operating status of the redundant backup system after switching. Supervision Center: Visualizes the main system risk heat map, backup system readiness status, and switchover event alarms.

2. The smart city redundant security defense system as described in claim 1, characterized in that: The security situation awareness parameters include the main system's vulnerability CVSS score, current attack frequency, data sensitivity coefficient, and defense blocking rate; The business impact parameters include redundancy coverage, fault recovery time, primary and backup data difference, total duration of unplanned faults, number of degraded services, total number of critical services, and total runtime.

3. The smart city redundant security defense system as described in claim 1, characterized in that: The risk assessment and analysis module's specific analysis process is as follows: The system receives security situation awareness parameters and business impact parameters from the data acquisition module in real time. The main system's security risk value is dynamically calculated based on the security risk level calculation formula. The availability status value of the main system is dynamically calculated based on the availability status index calculation formula. Assess risk levels and system availability based on security risk values ​​and availability status values; A risk assessment report is generated by combining preset risk levels and availability status.

4. The smart city redundant security defense system as described in claim 3, characterized in that: The formula for calculating the security risk value is as follows: In the formula, R represents the system security risk value, and V... max The highest vulnerability CVSS score, A f A represents the actual attack frequency. max D represents the highest attack frequency in history. s R is the data sensitivity coefficient. b To defend against blocking rate, W v W a W d and W r These are the weighting coefficients.

5. A smart city redundant security defense system as described in claim 3, characterized in that: The formula for calculating the availability status index is: A = α·A c +β·R e +γ·D h -δ·S p In the formula, A represents the system availability state value, and α, β, γ, and δ are weighting coefficients. c R represents the percentage of non-failure time. e D is the redundancy efficiency coefficient. h For the data health index, S p The penalty coefficient for service degradation.

6. A smart city redundant security defense system as described in claim 3, characterized in that: The specific methods for assessing risk levels and system availability are as follows: Risk level assessment: When the safety risk value R∈[0, 0.3), it is considered no risk; when the safety risk value R∈[0.3, 0.6), it is considered low risk; when the safety risk value R∈[0.6, 0.8), it is considered medium risk; and when the safety risk value R∈[0.8, 1), it is considered high risk. System availability assessment: Availability is considered excellent when the availability status index A ∈ (0.9, 1], good when the availability status index A ∈ (0.7, 0.9], acceptable when the availability status index A ∈ (0.6, 0.7], and vulnerable when the availability status index A ∈ [0, 0.6].

7. A smart city redundant security defense system as described in claim 1, characterized in that: The specific switching process of the security switching control module includes: Real-time acquisition of security risk levels and availability status assessed by the risk assessment and analysis module; When the switching conditions are met, freeze the main system's business flows and start transaction consistency verification; Synchronize unfinished transactions to the redundant backup system; Switch DNS resolution and load balancing to the redundant backup system; Perform basic service verification tests to verify service integrity; Release business flows to the redundant backup system and record the switchover timestamp.

8. A smart city redundant security defense system as described in claim 1, characterized in that: The switching process of the security switching control module also includes the redundant backup system switching back to the main system, and the specific switching process is as follows: Perform a health check after the main system is repaired; Incremental synchronous redundancy system runtime data; A canary phase switch will be implemented, transferring 10% of the business traffic to the main system. After a full switch, both systems will run in parallel. After verifying that the main system's SLA compliance rate meets the standard, shut down the business flow of the redundant system.

9. A smart city redundant security defense system as described in claim 1, characterized in that: The switching condition is that any of the following conditions are met: Safety risk level ≥ Medium risk lasting 5 minutes; Availability status index ≤ qualified level for 10 minutes; Critical service degradation rate ≥ 40%; The difference between the primary and backup data exceeds the threshold and cannot be repaired within 30 seconds.