Network security threat perception and adaptive defense system based on artificial intelligence

By using an AI-based cybersecurity threat perception and adaptive defense system, the shortcomings of traditional cybersecurity defense methods in responding to changing threats and monitoring defense effectiveness are addressed, achieving comprehensive, intelligent, and adaptive cybersecurity management.

CN121125304APending Publication Date: 2025-12-12YALONG RIVER HYDROPOWER DEV CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511431441.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-09
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

Traditional cybersecurity defense methods struggle to cope with ever-changing cyber threats, are unable to detect unknown attacks in a timely manner, lack flexibility, cannot dynamically adjust defense strategies, and cannot monitor defense effectiveness, resulting in significant challenges and low levels of intelligence in cybersecurity management.

Method used

An AI-based cybersecurity threat perception and adaptive defense system is adopted, including modules for data collection and preprocessing, intelligent threat feature mining, comprehensive threat situation assessment, adaptive defense strategy generation, and dynamic feedback of defense effectiveness. Through various artificial intelligence algorithms, it performs in-depth analysis and real-time monitoring, generates adaptive defense strategies, and evaluates the defense effect.

Benefits of technology

It achieves comprehensive, intelligent, and adaptive network security protection, enabling timely identification and response to network threats, dynamic adjustment of defense strategies, reduction of network security risks, and improvement of the flexibility and accuracy of defense.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125304A_ABST
    Figure CN121125304A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network security management and control, and particularly relates to a network security threat perception and adaptive defense system based on artificial intelligence. Comprising a data acquisition preprocessing module, a threat feature intelligent mining module, a threat situation comprehensive evaluation module, a self-adaptive defense strategy generation module, a defense effect dynamic feedback module and a background supervision terminal. The data acquisition and preprocessing module acquires various data from a network environment and performs related preprocessing operation, the threat feature intelligent mining module mines potential network security threat features, and the threat situation comprehensive evaluation module comprehensively evaluates the network security threat situation. The self-adaptive defense strategy generation module generates a self-adaptive defense strategy based on the threat level and the influence range, and the defense effect dynamic feedback module monitors and evaluates the implementation effect of the self-adaptive defense strategy in real time, thereby providing an omnibearing, intelligent and self-adaptive guarantee for network security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security management technology, specifically an artificial intelligence-based network security threat perception and adaptive defense system. Background Technology

[0002] Cybersecurity threats refer to any potential factors or events that may damage the confidentiality, integrity, and availability of network system hardware, software, data, and services. With the rapid development of information technology and the continuous expansion of network scale, network attack methods are becoming increasingly complex and diverse. Therefore, the perception and defense of cybersecurity threats are becoming increasingly important. Traditional network security defense methods are ill-equipped to cope with ever-changing network threats, unable to detect unknown attacks in a timely manner, and lack the flexibility of defense strategies to be dynamically adjusted according to real-time threat situations. They also cannot monitor and track the effectiveness of defenses or reasonably assess the performance of defenses and the degree of network threat risks, which is not conducive to comprehensive, intelligent, and adaptive protection of network security and makes network security management difficult. To address the aforementioned technical shortcomings, a solution is proposed. Summary of the Invention

[0003] The purpose of this invention is to provide an artificial intelligence-based network security threat perception and adaptive defense system, which solves the problems of existing technologies being unable to cope with constantly changing network threats, unable to dynamically adjust according to real-time threat situations, and unable to monitor and track the defense effect and reasonably evaluate the defense performance and the degree of network threat risks. This is not conducive to comprehensive, intelligent and adaptive protection of network security, and the network security management is difficult and has a low level of intelligence.

[0004] To achieve the above objectives, the present invention provides the following technical solution: An AI-based cybersecurity threat perception and adaptive defense system includes a data acquisition and preprocessing module, a threat feature intelligent mining module, a threat situation comprehensive assessment module, an adaptive defense strategy generation module, a defense effect dynamic feedback module, and a backend monitoring terminal. The data acquisition and preprocessing module collects various types of data from the network environment and performs relevant preprocessing operations on the collected raw data. The threat feature intelligent mining module uses artificial intelligence algorithms to perform in-depth analysis on the preprocessed data, mine potential cybersecurity threat features, and identify known and unknown attack patterns. The threat posture comprehensive assessment module, based on received threat characteristic information and combined with real-time network environment status and historical data, comprehensively assesses the network security threat posture to determine the threat level and scope of impact. The adaptive defense strategy generation module, based on the received threat level and scope of impact and combined with preset defense rules and strategy library, generates adaptive defense strategies to deal with different network security threats. The defense effect dynamic feedback module monitors and evaluates the implementation effect of the adaptive defense strategy in real time and feeds back the defense effect information to the background monitoring terminal.

[0005] Furthermore, the data acquisition and preprocessing module collects various network data in real time through network traffic monitoring equipment, system log collection tools, and user behavior monitoring software. For the collected network traffic data, it extracts key information including source IP, destination IP, port number, protocol type, and packet size. For system log data, it parses relevant elements, including event type, timestamp, and operation object. For user behavior data, it records the user's behavior trajectory, including login time, accessed pages, and operation commands. Furthermore, the collected raw data is cleaned to remove duplicate, erroneous, and invalid data records, and different types of data are converted to a format suitable for subsequent analysis. The data is also normalized to eliminate dimensional differences between different data.

[0006] Furthermore, the threat feature intelligent mining module employs a combination of multiple artificial intelligence algorithms for in-depth analysis. It uses clustering algorithms to perform preliminary classification of preprocessed data, grouping similar data together to form different data clusters. It then uses association rule mining algorithms to analyze the relationships between data clusters to identify existing threat patterns. Finally, it utilizes CNN and RNN to perform deep learning on the data, automatically extracting high-level features to further identify complex attack patterns.

[0007] Furthermore, the specific operational process of the threat posture comprehensive assessment module includes: Establish a threat posture assessment index system, including threat type, threat frequency, threat severity, and the importance of affected systems; assign corresponding weights and scores to each index based on threat feature information provided by the intelligent threat feature mining module; assess the scope of threat impact by combining real-time network environment status information, including network bandwidth usage and system resource utilization, as well as historical data; calculate a comprehensive threat posture score using a weighted summation method, and classify the threat posture into different levels, including low-risk, medium-risk, and high-risk, based on the score.

[0008] Furthermore, the adaptive defense strategy generation module's strategy library includes various defense strategies, such as access control strategies, firewall rule adjustment strategies, intrusion detection system parameter adjustment strategies, and intrusion prevention system parameter adjustment strategies. After receiving the threat level and impact scope information output by the threat situation comprehensive assessment module, it selects an appropriate defense strategy from the strategy library according to preset rules. Moreover, when generating defense strategies, the real-time status of the network environment is taken into account.

[0009] Furthermore, the defense effect dynamic feedback module is connected to the defense detection and evaluation module. The defense effect dynamic feedback module feeds back the defense effect information to the defense detection and evaluation module. The defense detection and evaluation module is used to set the detection period, evaluate and analyze the defense performance during the detection period, generate a defense qualified signal or a defense potential signal through analysis, and send the defense qualified signal or defense potential signal to the background monitoring terminal. When the background monitoring terminal receives the defense potential signal, it issues a corresponding warning.

[0010] Furthermore, the specific analysis process of the defense detection and evaluation module includes: All defense effectiveness information within the detection period is obtained. If the defense is not successfully completed within the specified time, a defense anomaly symbol HY-1 is assigned to the corresponding defense process. The number of times the defense anomaly symbol HY-1 is assigned within the detection period is obtained and the ratio is calculated with the total number of defenses within the detection period to obtain the defense anomaly value. The defense anomaly value is compared with the preset defense anomaly threshold. If the defense anomaly value exceeds the preset defense anomaly threshold, a defense vulnerability signal is generated.

[0011] Furthermore, if the defense anomaly detection value does not exceed the preset defense anomaly detection threshold, the corresponding defense process will be marked as the target process when the defense is successfully completed within the corresponding specified time. The actual defense time of the target process will be collected, and the defense time occupancy value will be calculated by comparing the actual defense time with the corresponding specified time. The average defense time occupancy value of all target processes within the detection period will be calculated to obtain the defense status value. The defense assessment value is obtained by weighted summation of the defense anomaly measurement value and the defense status value. The defense assessment value is then compared with a preset defense assessment threshold. If the defense assessment value exceeds the preset defense assessment threshold, a defense vulnerability signal is generated; if the defense assessment value does not exceed the preset defense assessment threshold, a defense qualified signal is generated.

[0012] Furthermore, the defense detection and evaluation module is connected to the threat decision output module. The defense detection and evaluation module sends a defense pass signal to the threat decision output module. When the threat decision output module receives the defense pass signal, it analyzes the degree of network security threat during the detection period, generates a threat alarm signal or a threat controllable signal through analysis, and sends the threat alarm signal or threat controllable signal to the background monitoring terminal. When the background monitoring terminal receives the threat alarm signal, it issues a corresponding warning.

[0013] Furthermore, the specific analysis process of the threat decision output module is as follows: The number of times low-risk, medium-risk, and high-risk threats are classified during the detection period is obtained and defined as low-risk feature value, medium-risk feature value, and high-risk feature value, respectively. The low-risk feature value, medium-risk feature value, and high-risk feature value are weighted and summed to obtain the initial threat detection value. The initial threat detection value is compared with the preset initial threat detection threshold. If the initial threat detection value exceeds the preset initial threat detection threshold, a threat alarm signal is generated. If the initial threat detection value does not exceed the preset initial threat detection threshold, then when there are no management personnel in the area where the back-end monitoring terminal is located, it is marked as an abnormal state. The total duration of the back-end monitoring terminal in the abnormal state during the detection period is obtained and marked as the abnormal time detection value. The number of times the single duration of the back-end monitoring terminal in the abnormal state exceeds the corresponding preset duration threshold during the detection period is marked as the abnormal holding risk value. The system collects and marks the moments when management personnel optimize defenses during the detection period as optimization moments, calculates the time difference between two adjacent optimization moments to obtain the interval duration, compares the interval duration with the corresponding preset interval duration threshold, marks the number of interval durations exceeding the corresponding preset interval duration threshold during the detection period as interval anomaly values, and calculates the average of all interval durations to obtain the optimized interval test value. The threat decision output value is calculated by weighting and summing the end-to-end time detection value, end-to-end risk value, interval anomaly value, and optimized interval detection value. The threat decision output value is then compared with a preset threat decision output threshold. If the threat decision output value exceeds the preset threat decision output threshold, a threat alarm signal is generated. If the threat decision output value does not exceed the preset threat decision output threshold, a threat controllable signal is generated.

[0014] Compared with the prior art, the beneficial effects of the present invention are: 1. In this invention, various types of data are collected from the network environment and preprocessed through a data acquisition and preprocessing module; a threat feature intelligent mining module mines potential network security threat features; a threat situation comprehensive assessment module comprehensively assesses the network security threat situation; an adaptive defense strategy generation module generates adaptive defense strategies based on threat level and scope of impact; and a defense effect dynamic feedback module monitors and evaluates the implementation effect of the adaptive defense strategy in real time, providing comprehensive, intelligent, and adaptive protection for network security. 2. In this invention, the defense performance during the detection period is evaluated and analyzed through the defense detection and evaluation module. When a defense vulnerability signal is generated, the defense is upgraded and optimized to ensure subsequent defense performance. When a defense controllable signal is generated, the degree of network security threat during the detection period is analyzed through the threat decision output module. When a threat alarm signal is generated, the subsequent supervision of network security and management personnel is strengthened, and network security risks are significantly reduced. Attached Figure Description

[0015] To facilitate understanding by those skilled in the art, the present invention will be further described below with reference to the accompanying drawings; Figure 1 This is a system block diagram of Embodiment 1 of the present invention; Figure 2 This is a system block diagram of Embodiments 2 and 3 of the present invention. Detailed Implementation

[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0017] Example 1: As Figure 1 As shown, the present invention proposes an artificial intelligence-based network security threat perception and adaptive defense system, which includes a data acquisition and preprocessing module, a threat feature intelligent mining module, a threat situation comprehensive assessment module, an adaptive defense strategy generation module, a defense effect dynamic feedback module, and a background monitoring terminal. The data acquisition and preprocessing module collects various types of data from the network environment, including network traffic data, system log data, and user behavior data. It also performs preprocessing operations such as cleaning, transformation, and normalization on the collected raw data. By comprehensively collecting various types of data from the network environment and preprocessing them, it provides an accurate, complete, and standardized data foundation for subsequent analysis, which helps to improve the accuracy of subsequent threat perception and defense. Specifically, firstly, the data acquisition and preprocessing module collects various data from the network in real time through network traffic monitoring devices, system log collection tools, and user behavior monitoring software; for the collected network traffic data, it extracts key information including source IP, destination IP, port number, protocol type, and packet size. For system log data, we analyze elements such as event type, timestamp, and operation object; for user behavior data, we record user login time, visited pages, operation commands, and other behavioral trajectories; then, we clean the collected raw data to remove duplicate, erroneous, and invalid data records; next, we transform different types of data to unify them into a format suitable for subsequent analysis; finally, we normalize the data to eliminate differences in units between different data to make the data comparable.

[0018] The threat signature intelligent mining module uses artificial intelligence algorithms to perform in-depth analysis of preprocessed data, mine potential cybersecurity threat signatures, identify known and unknown attack patterns, and can automatically mine potential threat signatures. It can not only identify known attack patterns, but also discover unknown attack methods, which greatly improves the comprehensiveness and accuracy of threat perception. Specifically, the threat feature intelligent mining module uses a combination of various artificial intelligence algorithms for in-depth analysis, such as convolutional neural networks (CNN) and recurrent neural networks (RNN) in deep learning, as well as clustering algorithms and association rule mining algorithms in machine learning. For example, firstly, clustering algorithms are used to initially classify the preprocessed data, grouping similar data together to form different data clusters. Then, association rule mining algorithms are used to analyze the relationships between data clusters to identify potential threat patterns. Next, CNNs and RNNs are used for deep learning on the data to automatically extract high-level features and further identify complex attack patterns. For instance, for network traffic data, CNNs can extract spatial features from data packets, while RNNs can capture temporal series features between data packets, thus more accurately identifying malicious traffic.

[0019] The comprehensive threat posture assessment module, based on received threat characteristic information and combined with real-time network environment status and historical data, comprehensively assesses the network security threat posture, determines the threat level and scope of impact, and provides a comprehensive and objective assessment of the network security threat posture. This provides an accurate basis for the subsequent generation of adaptive defense strategies, making the defense strategies more targeted and effective. Specifically, the specific operation process of the comprehensive threat posture assessment module includes: First, establish a threat situation assessment index system, including indicators such as threat type, threat frequency, threat severity, and importance of affected systems. Then, based on the threat feature information provided by the threat feature intelligent mining module, assign corresponding weights and scores to each indicator. For example, assign higher severity scores to known high-risk attack types and increase the frequency scores for frequently occurring threats. By combining real-time network environment status information, such as network bandwidth usage and system resource utilization, with historical data, the scope of threat impact is assessed. A comprehensive threat situation score is calculated using a weighted summation method, and the threat situation is classified into different levels, such as low risk, medium risk, and high risk, based on the score.

[0020] The adaptive defense strategy generation module generates adaptive defense strategies based on the received threat level and scope of impact, combined with preset defense rules and strategy libraries, to deal with different network security threats. It can dynamically generate adaptive defense strategies according to the real-time threat situation, improving the flexibility and timeliness of defense and effectively resisting various network security threats. It should be noted that the adaptive defense strategy generation module's strategy library includes various defense strategies, such as access control strategies, firewall rule adjustment strategies, intrusion detection system (IDS) parameter adjustment strategies, and intrusion prevention system (IPS) parameter adjustment strategies. After receiving the threat level and impact scope information output by the threat situation comprehensive assessment module, it selects an appropriate defense strategy from the strategy library according to preset rules. For example, for low-risk threats, only the firewall's access control rules may be adjusted to restrict access from some suspicious IPs; for high-risk threats, multiple defense strategies such as access control, firewall rule adjustment, and IDS / IPS parameter optimization are enabled simultaneously to strengthen network protection; and when generating defense strategies, the real-time status of the network environment is considered to ensure that the implementation of the defense strategies will not have an excessive impact on normal business operations.

[0021] The dynamic feedback module for defense effectiveness monitors and evaluates the implementation effect of adaptive defense strategies in real time, feeding back the defense effectiveness information to the backend monitoring terminal. By monitoring and feeding back the defense effectiveness in real time, problems in the defense strategy can be identified and adjusted in a timely manner, improving the continuous effectiveness of network security defense. Preferably, the dynamic feedback module for defense effectiveness also feeds back the defense effectiveness information to the threat situation comprehensive assessment module and the adaptive defense strategy generation module, so as to adjust the defense strategy in a timely and automatic manner.

[0022] Example 2: Figure 2As shown, the difference between this embodiment and Embodiment 1 is that the defense effect dynamic feedback module is communicatively connected to the defense detection and evaluation module. The defense effect dynamic feedback module feeds back the defense effect information to the defense detection and evaluation module. The defense detection and evaluation module is used to set the detection period, preferably thirty days. The defense performance during the detection period is evaluated and analyzed, and a defense qualified signal or a defense hidden danger signal is generated through analysis. Furthermore, it sends either a defense pass / fail signal or a defense vulnerability signal to the backend monitoring terminal. Upon receiving a defense vulnerability signal, the backend monitoring terminal issues a corresponding warning to facilitate timely defense upgrades and optimization, ensuring subsequent defense performance and thus reducing network security risks. The specific analysis process of the defense detection and evaluation module is as follows: All defense effectiveness information within the detection period is obtained. If the defense fails to be completed within the specified time, a defense anomaly symbol HY-1 is assigned to the corresponding defense process. The number of times the defense anomaly symbol HY-1 is assigned within the detection period is obtained and the ratio of it to the total number of defenses within the detection period is calculated to obtain the defense anomaly value. The defense anomaly value is compared with the preset defense anomaly threshold. If the defense anomaly value exceeds the preset defense anomaly threshold, it indicates that the defense performance within the detection period is poor and the defense risk is high, and a defense vulnerability signal is generated.

[0023] Furthermore, if the defense anomaly detection value does not exceed the preset defense anomaly detection threshold, the corresponding defense process will be marked as the target process when the defense is successfully completed within the corresponding specified time. The actual defense time of the target process will be collected, and the defense time occupancy value will be calculated by comparing the actual defense time with the corresponding specified time. The average defense time occupancy value of all target processes within the detection period will be calculated to obtain the defense status value. The defense assessment value is obtained by weighted summation of the defense anomaly test value and the defense status value. Specifically, the defense anomaly test value and the defense status value are assigned corresponding preset weight coefficients, and the defense anomaly test value and the defense status value are multiplied by the corresponding preset weight coefficients. The sum of the two sets of products is marked as the defense assessment value. It should be noted that the larger the defense assessment value, the worse the overall defense performance during the detection period. The defense assessment value is compared with the preset defense assessment threshold. If the defense assessment value exceeds the preset defense assessment threshold, it indicates that the overall defense performance during the detection period is poor, and a defense vulnerability signal is generated. If the defense assessment value does not exceed the preset defense assessment threshold, it indicates that the overall defense performance during the detection period is good, and a defense qualified signal is generated.

[0024] Example 3: Figure 2As shown, the difference between this embodiment and Embodiment 1 and Embodiment 2 is that the defense detection and evaluation module is communicatively connected to the threat decision output module. The defense detection and evaluation module sends the defense qualified signal to the threat decision output module. When the threat decision output module receives the defense qualified signal, it analyzes the degree of network security threat during the detection period and generates a threat alarm signal or a threat controllable signal through analysis. Furthermore, the threat alarm signal or threat controllability signal is sent to the backend monitoring terminal. Upon receiving the threat alarm signal, the backend monitoring terminal issues a corresponding warning to promptly strengthen the follow-up supervision of network security and management personnel, and further reduce network security risks. The specific analysis process of the threat decision output module is as follows: The number of times the low-risk, medium-risk, and high-risk threats were classified during the detection period was obtained and defined as low-risk characteristic value, medium-risk characteristic value, and high-risk characteristic value, respectively. The low-risk characteristic value, medium-risk characteristic value, and high-risk characteristic value were weighted and summed to obtain the initial threat detection value. That is, assign corresponding preset weight coefficients to low-risk, medium-risk, and high-risk feature values ​​respectively, and multiply the low-risk, medium-risk, and high-risk feature values ​​by their respective preset weight coefficients, and mark the sum of the three sets of product results as the initial threat detection value; It should be noted that the higher the initial threat value, the higher the initial level of cybersecurity threat during the detection period. The initial threat value is compared with the preset initial threat threshold. If the initial threat value exceeds the preset initial threat threshold, it indicates that the initial level of cybersecurity threat during the detection period is relatively high, and a threat alarm signal is generated. If the initial threat detection value does not exceed the preset initial threat detection threshold, then when there are no management personnel in the area where the back-end monitoring terminal is located, it is marked as an abnormal state. The total duration of the back-end monitoring terminal in the abnormal state during the detection period is obtained and marked as the abnormal time detection value. The number of times the single duration of the back-end monitoring terminal in the abnormal state exceeds the corresponding preset duration threshold during the detection period is marked as the abnormal holding risk value. The system collects and marks the moments when management personnel optimize defenses during the detection period as optimization moments, calculates the time difference between two adjacent optimization moments to obtain the interval duration, compares the interval duration with the corresponding preset interval duration threshold, marks the number of interval durations exceeding the corresponding preset interval duration threshold during the detection period as interval anomaly values, and calculates the average of all interval durations to obtain the optimized interval test value. The threat decision output value is obtained by weighting and summing the end-time anomaly detection value, end-time anomaly risk value, interval anomaly value, and optimized interval detection value. Specifically, the end-time anomaly detection value, end-time anomaly risk value, interval anomaly value, and optimized interval detection value are each assigned a corresponding preset weight coefficient, and the end-time anomaly detection value, end-time anomaly risk value, interval anomaly value, and optimized interval detection value are each multiplied by their respective preset weight coefficients. The sum of the four sets of multiplication results is then marked as the threat decision output value. It should be noted that the higher the threat decision output value, the worse the overall network security management performance during the detection period, and the less conducive it is to reducing the degree of network security threat risks. The threat decision output value is compared with the preset threat decision output threshold. If the threat decision output value exceeds the preset threat decision output threshold, it indicates that the overall network security management performance during the detection period is poor and not conducive to reducing the degree of network security threat risks, and a threat alarm signal is generated. If the threat decision output value does not exceed the preset threat decision output threshold, it indicates that the overall degree of security threat risks during the detection period is low, and a threat controllable signal is generated.

[0025] The working principle of this invention is as follows: During use, the data acquisition and preprocessing module collects various types of data from the network environment and performs relevant preprocessing operations. The threat feature intelligent mining module mines potential network security threat features based on the preprocessed data, improving the comprehensiveness and accuracy of threat perception. The threat situation comprehensive assessment module comprehensively assesses the network security threat situation, providing accurate basis for defense strategy generation and making defense more targeted. The adaptive defense strategy generation module generates adaptive defense strategies based on threat level and impact scope, effectively resisting various threats. The defense effect dynamic feedback module monitors and evaluates the implementation effect of the adaptive defense strategy in real time, enabling timely detection and adjustment of defense strategy problems, providing comprehensive, intelligent, and adaptive protection for network security.

[0026] In this invention, the threshold, preset value, or preset range settings are for result comparison and analysis to determine whether the result is good or bad. The magnitude of these values ​​is determined by a combination of large-scale model analysis of sample data and human experience, and can also be appropriately adjusted based on seasonal or common-sense influence conditions. Similarly, the preset weight coefficients and influence factors are assigned specific values ​​based on the magnitude of each parameter's influence on the result, ultimately reflecting the impact on the result. These settings are also determined by a combination of large-scale model analysis of sample data and human experience, and can also be appropriately adjusted based on seasonal or common-sense influence conditions.

[0027] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to any specific implementation. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, enabling those skilled in the art to better understand and utilize it. The invention is limited only by the claims and their full scope and equivalents.

Claims

1. A cybersecurity threat perception and adaptive defense system based on artificial intelligence, characterized in that, It includes a data acquisition and preprocessing module, a threat feature intelligent mining module, a threat situation comprehensive assessment module, an adaptive defense strategy generation module, a defense effect dynamic feedback module, and a back-end monitoring terminal; The data acquisition and preprocessing module collects various types of data from the network environment and performs relevant preprocessing operations on the collected raw data; The threat signature intelligent mining module uses artificial intelligence algorithms to perform in-depth analysis on preprocessed data, uncover potential cybersecurity threat signatures, and identify known and unknown attack patterns; The threat posture comprehensive assessment module comprehensively assesses the network security threat posture based on the received threat characteristic information, combined with the real-time status of the network environment and historical data, and determines the threat level and scope of impact. The adaptive defense strategy generation module generates adaptive defense strategies based on the received threat level and scope of impact, combined with preset defense rules and strategy library. The defense effect dynamic feedback module monitors and evaluates the implementation effect of the adaptive defense strategy in real time and feeds back the defense effect information to the background monitoring terminal.

2. The artificial intelligence-based network security threat perception and adaptive defense system according to claim 1, characterized in that, The data acquisition and preprocessing module collects various data from the network in real time through network traffic monitoring equipment, system log collection tools, and user behavior monitoring software; for the collected network traffic data, it extracts key information including source IP, destination IP, port number, protocol type, and packet size. For system log data, relevant elements are analyzed; for user behavior data, user behavior trajectories are recorded; and the collected raw data is cleaned, different types of data are transformed, and the data is normalized.

3. The artificial intelligence-based network security threat perception and adaptive defense system according to claim 1, characterized in that, The threat feature intelligent mining module uses clustering algorithms to perform preliminary classification on the preprocessed data, grouping similar data together to form different data clusters. It then analyzes the relationships between data clusters using association rule mining algorithms to identify existing threat patterns. Finally, it utilizes CNN and RNN to perform deep learning on the data and automatically extract high-level features from the data.

4. The artificial intelligence-based network security threat perception and adaptive defense system according to claim 1, characterized in that, The specific operation process of the threat situation comprehensive assessment module includes: establishing a threat situation assessment index system; assigning corresponding weights and scores to each index based on the threat feature information provided by the threat feature intelligent mining module; assessing the scope of threat impact by combining real-time network environment status information and historical data; calculating the comprehensive threat situation score through a weighted summation method; and classifying the threat situation into different levels based on the score, including low risk, medium risk, and high risk.

5. The artificial intelligence-based network security threat perception and adaptive defense system according to claim 1, characterized in that, The adaptive defense strategy generation module's strategy library includes various defense strategies, such as access control strategies, firewall rule adjustment strategies, intrusion detection system parameter adjustment strategies, and intrusion prevention system parameter adjustment strategies. After receiving threat level and impact range information output by the threat situation comprehensive assessment module, it selects an appropriate defense strategy from the strategy library according to preset rules. Furthermore, the real-time status of the network environment is taken into account when generating defense strategies.

6. The artificial intelligence-based network security threat perception and adaptive defense system according to claim 1, characterized in that, The defense effect dynamic feedback module communicates with the defense detection and evaluation module. The defense effect dynamic feedback module feeds back defense effect information to the defense detection and evaluation module. The defense detection and evaluation module is used to set the detection period, evaluate and analyze the defense performance during the detection period, and send defense qualified signals or defense potential signals to the background monitoring terminal.

7. The artificial intelligence-based network security threat perception and adaptive defense system according to claim 6, characterized in that, The specific analysis process of the defense detection and evaluation module includes: The number of times the defense anomaly symbol HY-1 is assigned during the detection period is obtained and the ratio is calculated with the total number of defenses during the detection period to obtain the defense anomaly value. If the defense anomaly value exceeds the preset defense anomaly threshold, a defense hidden danger signal is generated.

8. The artificial intelligence-based network security threat perception and adaptive defense system according to claim 7, characterized in that, If the defense anomaly detection value does not exceed the preset defense anomaly detection threshold, the defense evaluation value is calculated by weighted summation of the defense anomaly detection value and the defense status value. If the defense evaluation value exceeds the preset defense evaluation threshold, a defense vulnerability signal is generated; otherwise, a defense qualified signal is generated.

9. A network security threat perception and adaptive defense system based on artificial intelligence according to claim 6, characterized in that, The defense detection and evaluation module communicates with the threat decision output module. When the threat decision output module receives a defense pass signal, it analyzes the degree of network security threat during the detection period and sends the threat alarm signal or threat controllable signal to the background monitoring terminal.

10. A network security threat perception and adaptive defense system based on artificial intelligence according to claim 9, characterized in that, The specific analysis process of the threat decision output module is as follows: The initial threat detection value is obtained by weighted summation of low-risk, medium-risk, and high-risk feature values. If the initial threat detection value exceeds the preset initial threat detection threshold, a threat alarm signal is generated. If the initial threat detection value does not exceed the preset initial threat detection threshold, the threat decision output value is obtained by weighted summation of end-to-end time detection value, end-to-end risk value, interval anomaly value, and optimized interval detection value. If the threat decision output value exceeds the preset threat decision output threshold, a threat alarm signal is generated; otherwise, a threat controllable signal is generated.

Citation Information

Cited By

  • Remote monitoring and environment control method and device of GSM-R system

    CN121968128A